Abnormal behavior monitoring method and system for industrial control system

Through dynamic update of exception reports and comprehensive analysis of multi-data source control models, the problem of insufficient intelligent alarm data processing in industrial control systems is solved, and an intelligent monitoring system for fast positioning and accurate handling of exceptions is realized.

CN120386315APending Publication Date: 2025-07-29国网新疆电力有限公司营销服务中心
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510304977.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

The existing industrial control system alarm data processing has problems such as the surge in the number of alarms, low manual processing efficiency, limitations of single-item alarm and comprehensive alarm, lack of abnormal diagnosis functions, and low level of intelligent alarm processing, and it is difficult to fully reflect the system status and provide accurate abnormal handling suggestions.

Method used

By dynamically updating the target monitoring data of the abnormality report, we decide whether the target monitoring data is the previous cycle monitoring data to constitute multi-cycle abnormality monitoring. We use the multi-data source control model to determine the response strategies in multi-cycle abnormality monitoring, conduct comprehensive analysis and extract comprehensive abnormality information from multiple alarm events, and provide accurate exception handling suggestions.

Benefits of technology

It realizes intelligent abnormal behavior monitoring of industrial control systems, improves the intelligent level of alarm information processing, can quickly locate and resolve abnormalities, and provide accurate decision-making support.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120386315A_ABST
    Figure CN120386315A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of intelligent monitoring, in particular to an abnormal behavior monitoring method and system for an industrial control system, and the method comprises the steps: determining whether target monitoring data is monitoring data of a previous period or not through dynamically updating the target monitoring data of an abnormal report, and forming multi-period abnormal monitoring; inputting the related data into a second configuration standard of the multi-data source control model, and determining a first coping strategy of each target index under the action of each piece of previous monitoring data in the multi-period anomaly monitoring and a second coping strategy of each piece of previous index under the action of each piece of target monitoring data in the multi-period anomaly monitoring; and inputting the multi-data source control model, and determining a coping strategy passing through the target monitoring data in the multi-cycle anomaly monitoring. According to the method, the alarm information is comprehensively analyzed, the comprehensive abnormal information is extracted from a plurality of alarm events, the intelligent level is high, and accurate abnormal processing suggestions and decision support are provided for monitoring personnel.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of intelligent monitoring technology, and particularly to an abnormal behavior monitoring method and system for industrial control systems. Background Art

[0002] With the rapid development of Internet technology and the acceleration of enterprise digital transformation, the alarm data generated by data centers and various industrial systems has grown explosively. These alarm data are not only huge in quantity, but also diverse in types, and at the same time bring problems such as a sharp increase in the number of alarms, low manual processing efficiency, limitations of single-item alarms and comprehensive-item alarms, lack of abnormal diagnosis function, and low intelligent level of alarm processing.

[0003] Existing monitoring methods are difficult to cope with this rapidly growing and complex monitoring demand, and the alarm information processing ability is limited: traditional systems mainly focus on single-item alarms and lack the ability to alarm comprehensive items, resulting in a single means of displaying alarm information and being difficult to comprehensively reflect the system state. Moreover, the system does not have the ability to comprehensively analyze alarm information and cannot extract comprehensive abnormal information from multiple alarm events, affecting the rapid positioning and solution of abnormalities. Low intelligent level: lacking intelligent decision support function and unable to provide accurate abnormal handling suggestions and decision support for monitoring personnel. The system has deficiencies in the visual display of alarm information and is difficult to intuitively reflect the system state and the importance of alarm information. Summary of the Invention

[0004] To achieve the above object, the present application provides the following technical solutions:

[0005] According to the first aspect of the present invention, the present invention claims protection for an abnormal behavior monitoring method for an industrial control system, including:

[0006] By dynamically updating the target monitoring data of the abnormal report, determining whether the target monitoring data is the monitoring data of the previous cycle to form multi-cycle abnormal monitoring;

[0007] If not, then controlling the multi-data source control model to output a coping strategy through the target monitoring data;

[0008] If so, then determining the target index of the dynamically updated abnormal report associated with the target monitoring data through the first configuration standard in the multi-data source control model;

[0009] Inputting the target index, target monitoring data, past index, past monitoring data, and past coping strategy in the multi-cycle abnormal monitoring into the second configuration standard of the multi-data source control model;

[0010] Determine the first response strategy of each target index in each multi - cycle anomaly monitoring under the action of each past monitoring data, and the second response strategy of each past index in each multi - cycle anomaly monitoring under the action of each target monitoring data according to the second configuration standard of the multi - data - source control model;

[0011] Input the first response strategy, the second response strategy and the past response strategy into the multi - data - source control model to determine the response strategy of the multi - cycle anomaly monitoring through the target monitoring data.

[0012] Further, the steps of inputting the target index, target monitoring data, past index, past monitoring data and past response strategy in the multi - cycle anomaly monitoring into the second configuration standard of the multi - data - source control model include:

[0013] Obtain each past monitoring data in the multi - cycle anomaly monitoring, the past index of each dynamic update anomaly report associated with each past monitoring data, and the past response strategy associated with each past monitoring data;

[0014] Configure the behavior set in the second configuration standard of the multi - data - source control model according to the configuration length and configuration content type;

[0015] Extract target abnormal behaviors from each past monitoring data, the past index of each dynamic update anomaly report associated with each past monitoring data, the past response strategy associated with each past monitoring data, each target monitoring data, and the target index of each dynamic update anomaly report associated with each target monitoring data; wherein, the target abnormal behaviors meet the requirements of the configuration content type and the configuration length.

[0016] Input each past monitoring data and each target index into the first behavior set at regular intervals, and input each target monitoring data and each past index into the second behavior set at regular intervals.

[0017] Further, the steps of extracting target abnormal behaviors from each past monitoring data, the past index of each dynamic update anomaly report associated with each past monitoring data, the past response strategy associated with each past monitoring data, each target monitoring data, and the target index of each dynamic update anomaly report associated with each target monitoring data include:

[0018] Determine whether there is abnormal text that cannot extract the target abnormal behavior in each past monitoring data, the past indexes of each dynamically updated abnormal report associated with each past monitoring data, the past response strategies associated with each past monitoring data, each target monitoring data, and the target indexes of each dynamically updated abnormal report associated with each target monitoring data;

[0019] If not, perform the step of extracting the target abnormal behavior;

[0020] If so, display the abnormal text on the visualization platform, and generate the target abnormal behavior of the abnormal text in combination with the user confirmation instruction input through the visualization platform.

[0021] Further, the step of inputting the target index, target monitoring data, past index, past monitoring data, and past response strategy in the multi-period abnormal monitoring into the second configuration standard of the multi-data source control model further includes:

[0022] During the process of inputting the target index, target monitoring data, past index, past monitoring data, and past response strategy in the multi-period abnormal monitoring into the second configuration standard of the multi-data source control model, if the number of behavior sets in the behavior set of the second configuration standard reaches the configuration quantity threshold, delete or merge the behavior sets with the configuration number that is the farthest from the target input time.

[0023] Further, the step of determining whether the target monitoring data is the monitoring data of the previous period to form a multi-period abnormal monitoring through the target monitoring data of the dynamically updated abnormal report includes:

[0024] Determine whether the target monitoring data and the monitoring data of the previous period form a multi-period abnormal monitoring by determining whether the time interval between inputting the target monitoring data and inputting the monitoring data of the previous period is within the configured time range;

[0025] Or,

[0026] Determine whether the target monitoring data and the monitoring data of the previous period form a multi-period abnormal monitoring by determining whether any of the matching degrees between the target monitoring data and the monitoring data of the previous period, the response strategy and index associated with the monitoring data of the previous period meet the configured matching degree threshold.

[0027] Further, the step of controlling the multi-data source control model to output the response strategy through the target monitoring data includes:

[0028] Control the dynamically updated search engine to retrieve at least one dynamically updated abnormal report associated with the target monitoring data through the target monitoring data input through the visualization platform;

[0029] Extract corresponding behavior key points from each of the dynamic update exception reports, and input the behavior key points into a multi-data source control model to determine the index associated with each of the dynamic update exception reports; wherein, the multi-data source control model includes a first configuration criterion for extracting the index, and the first configuration criterion is determined based on the log requirements and feature requirements of the index.

[0030] Determine the confidence level of each dynamic update exception report associated with the index based on the verification rules and verification weights associated with each exception element of the index in the third configuration criterion.

[0031] Based on the confidence level of the dynamic update exception report and the index, determine the target dynamic update exception report associated with the target monitoring data from the dynamic update exception reports.

[0032] Input the target monitoring data and the index of the target dynamic update exception report into the multi-data source control model, and output a coping strategy for the target monitoring data under the action of the second configuration criterion.

[0033] Further, the step of determining the target index of the dynamic update exception report associated with the target monitoring data through the first configuration criterion in the multi-data source control model includes:

[0034] Based on the configuration log requirements and configuration feature requirements of the target index, determine the first configuration criterion for each dynamic update exception report associated with the target monitoring data; wherein, the feature requirements include one or more of the following: requiring the display of the exception elements of the dynamic update exception report, the length of the index to be displayed, and the exception type of the dynamic update exception report to be displayed.

[0035] Extract the corresponding behavior key points from each of the dynamic update exception reports and input them into the multi-data source control model.

[0036] Extract the corresponding first behavior key points from the behavior key points of each dynamic update exception report according to the feature requirements.

[0037] Process each of the first behavior key points according to the log requirements to obtain the index of each dynamic update exception report; wherein, the log requirements include the collection time, the collector, the collection location, and the collection plan, and the collection plan is before the collection time and the collection location.

[0038] Determining the first response strategy of each target index in each multi - cycle anomaly monitoring under the action of each past monitoring data, and the second response strategy of each past index in each multi - cycle anomaly monitoring under the action of each target monitoring data according to the second configuration standard of the multi - data - source control model, includes the following steps:

[0039] Poll the target indices associated with each past monitoring data in the first behavior set, and generate the first response strategy of each target index under the action of the past monitoring data;

[0040] Poll the past indices associated with each target monitoring data in the second behavior set, and generate the second response strategy of each past index under the action of the target monitoring data.

[0041] Further, based on the first response strategy, the second response strategy, and the past response strategy, inputting them into the multi - data - source control model to determine the response strategy of the multi - cycle anomaly monitoring through the target monitoring data, includes the following steps:

[0042] According to the correlation degrees of the target monitoring data with the first response strategy, the second response strategy, and the past response strategy, assign weight ratios to the first response strategy, the second response strategy, and the past response strategy respectively;

[0043] Based on the matching degrees of the first response strategy, the second response strategy, and the past response strategy with the target monitoring data respectively and the weight ratios, determine and output the response strategy of the multi - cycle anomaly monitoring through the target monitoring data.

[0044] According to the second aspect of the present invention, the present invention claims protection for an anomaly behavior monitoring system for an industrial control system, used to execute the anomaly behavior monitoring for an industrial control system, including:

[0045] A decision - making unit, by dynamically updating the target monitoring data of the anomaly report, decides whether the target monitoring data is the monitoring data of the previous cycle to form a multi - cycle anomaly monitoring;

[0046] A first response strategy unit, if not, controls the multi - data - source control model to output the response strategy through the target monitoring data;

[0047] A first determination unit, if so, determines the target index of the dynamically updated anomaly report associated with the target monitoring data through the first configuration standard in the multi - data - source control model;

[0048] An input unit inputs the target index, target monitoring data, past index, past monitoring data, and past response strategy in the multi-cycle anomaly monitoring into the second configuration standard of the multi-data source control model;

[0049] A second determination unit determines, through the second configuration standard of the multi-data source control model, a first response strategy for each target index in the multi-cycle anomaly monitoring under the action of each past monitoring data, and a second response strategy for each past index in the multi-cycle anomaly monitoring under the action of each target monitoring data;

[0050] A second response strategy unit inputs the first response strategy, the second response strategy, and the past response strategy into the multi-data source control model, and determines the response strategy for the multi-cycle anomaly monitoring through the target monitoring data.

[0051] This application relates to the technical field of intelligent monitoring, and in particular to an abnormal behavior monitoring method and system for an industrial control system. By dynamically updating the target monitoring data of an anomaly report, it is decided whether the target monitoring data is the monitoring data of the previous cycle to constitute multi-cycle anomaly monitoring; relevant data is input into the second configuration standard of the multi-data source control model to determine a first response strategy for each target index in the multi-cycle anomaly monitoring under the action of each past monitoring data, and a second response strategy for each past index in the multi-cycle anomaly monitoring under the action of each target monitoring data; input into the multi-data source control model to determine the response strategy for the multi-cycle anomaly monitoring through the target monitoring data. The present invention comprehensively analyzes alarm information, extracts comprehensive anomaly information from multiple alarm events, has a high level of intelligence, and provides accurate anomaly handling suggestions and decision-making support for monitoring personnel. Description of the Drawings

[0052] Figure 1 It is a working flowchart of an abnormal behavior monitoring method for an industrial control system requested to be protected by an embodiment of this application;

[0053] Figure 2 It is a structural module diagram of an abnormal behavior monitoring system for an industrial control system requested to be protected by an embodiment of this application. Detailed Embodiments

[0054] Next, the technical solutions in the embodiments of this application will be clearly and completely described in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Through the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of this application.

[0055] The terms "first", "second", and "third" in this application are only used for descriptive purposes and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first", "second", and "third" may explicitly or implicitly include at least one of such features. In the description of this application, the meaning of "a plurality of" is at least two, such as two, three, etc., unless otherwise specifically defined. In the embodiments of this application, all directional indications (such as up, down, left, right, front, back...) are only used to explain the relative positional relationship and movement conditions between components in a specific posture (as shown in the drawings). If this specific posture changes, then the directional indication also changes accordingly. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products, or devices.

[0056] Referring to "embodiments" herein means that specific features, structures, or characteristics described in connection with the embodiments can be included in at least one embodiment of this application. The phrase appearing in various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0057] Figure 1 It is a flowchart of an abnormal behavior monitoring method for an industrial control system provided by an embodiment of the present invention;

[0058] Referring to Figure 1 , the method mainly includes the following steps:

[0059] In step S102, by dynamically updating the target monitoring data of the abnormal report, it is decided whether the target monitoring data is multi-cycle abnormal monitoring composed of the monitoring data of the previous cycle.

[0060] Among them, the target monitoring data can be input through a visualization platform, and the visualization platform can be understood as an interface integrated in the above-mentioned intelligent device for facilitating user interaction; the monitoring data in the embodiments of the present invention can be understood as the monitoring sensor information obtained by dynamically updating the abnormal report;

[0061] It should be noted that based on the correlation relationship between the target monitoring data and the previous monitoring data, it is decided whether they are in the same abnormal monitoring, that is, it constitutes multi-cycle abnormal monitoring; as an alternative embodiment, it is also based on the correlation relationship between the target monitoring data and the coping strategies of the previous monitoring data to decide whether the target monitoring data and the previous monitoring data constitute multi-cycle abnormal monitoring.

[0062] Step S104, if the answer is no, then control the multi-data source control model to output the coping strategy for the target monitoring data.

[0063] Here, if the target monitoring data and the previous monitoring data belong to different abnormal monitorings, that is, the target monitoring data is the first question in the target abnormal monitoring, then a dynamic update coping strategy is made through the dynamic update abnormal report passed by the monitoring data.

[0064] Step S106, if the answer is yes, then determine the target index of the dynamic update abnormal report associated with the target monitoring data through the first configuration standard in the multi-data source control model.

[0065] Here, if the target monitoring data and the previous monitoring data belong to the same abnormal monitoring, that is, the target monitoring data and the previous monitoring data constitute multi-cycle abnormal monitoring, then it is necessary to determine the dependency relationship between the target monitoring data, the previous monitoring data, and the coping strategy of the previous monitoring data, and then obtain the accurate coping strategy for the monitoring data that is not the first to be proposed in the multi-cycle abnormal monitoring; first, obtain at least one target index associated with the monitoring data through the first configuration standard, and each target index is associated with a dynamic update abnormal report.

[0066] Step S108, input the target index, target monitoring data, past index, past monitoring data, and past coping strategy in the multi-cycle abnormal monitoring into the second configuration standard of the multi-data source control model.

[0067] It should be noted that it is possible to know whether the target monitoring data and the previous monitoring data belong to the same multi-cycle abnormal monitoring through the steps of the foregoing embodiments. In this way, it is possible to correspondingly know whether the previous monitoring data is associated with its associated previous monitoring data, and so on to obtain all the past monitoring data in the target multi-cycle abnormal monitoring, and the associated past coping strategies for each past monitoring data;

[0068] Among them, the second configuration standard (after information input) is based on the processing response strategy logic associated with various pre-configured monitoring types, and guides the multi-data source control model through the response strategy of the monitoring data, and the processing response strategy logic associated with various pre-configured monitoring types; for example, the third configuration standard determines the monitoring type of the monitoring data by identifying specific keywords in the monitoring data, selects the associated response rule through the corresponding monitoring type, and under the action of this response rule, generates an answer through the monitoring data by dynamically updating the index of the abnormal report.

[0069] Here, the second configuration standard itself also configures an input rule to enable information such as the target index, target monitoring data, past index, past monitoring data, and past response strategy to be input into the second configuration standard in a prescribed input requirement and in a conventional manner.

[0070] Step S110, through the second configuration standard of the multi-data source control model, determine the first response strategy of each target index in each past monitoring data in the multi-period abnormal monitoring, and the second response strategy of each past index in each target monitoring data in the multi-period abnormal monitoring.

[0071] Among them, based on the second configuration standard input in a conventional manner, it is possible to realize the first response strategy of the past monitoring data using each target index, and the second response strategy of the target monitoring data using each past index.

[0072] Step S112, based on the first response strategy, the second response strategy, and the past response strategy, input them into the multi-data source control model to determine the response strategy through the target monitoring data in the multi-period abnormal monitoring.

[0073] In a preferred embodiment of the actual application, first, it is determined whether the target monitoring data for dynamically updating the exception report belongs to the first monitoring of the target multi-cycle exception monitoring or belongs to other monitoring in the target multi-cycle exception monitoring before the target monitoring data; if it is the first monitoring, based on the associated dynamically updated exception report, a monitoring data response strategy with dynamic updateability is determined; if it is not the first monitoring, that is, the target monitoring data and the previous monitoring data belong to the same multi-cycle exception monitoring, the target indexes of each dynamically updated exception report associated with the target monitoring data are extracted using the first configuration standard, and then the target monitoring, target indexes, previous monitoring, previous indexes, and previous response strategies in the target multi-cycle exception monitoring are input into the second configuration standard to obtain the first response strategy of each target index to the previous monitoring data, the second response strategy of each previous index to the target monitoring data, and the previous response strategy of each previous index to the previous monitoring data; through the response strategy set obtained by cross-indexing these associated indexes in the same multi-cycle exception monitoring, the response strategy of the target monitoring with a dependency relationship with the multi-cycle exception monitoring is determined, and a response strategy result with a relatively high accuracy for the target monitoring data can be obtained.

[0074] In some embodiments, in step S102, determining whether the target monitoring data and the previous cycle's monitoring data constitute a multi-cycle exception monitoring can be achieved through the following methods, including:

[0075] Step 1.1), by determining whether the time interval between the input target monitoring data and the input previous cycle's monitoring data is within the configured time range, it is determined whether the target monitoring data and the previous cycle's monitoring data constitute a multi-cycle exception monitoring.

[0076] Here, if the time interval between the time when the target monitoring data is input to the visualization platform and the time when the previous cycle's monitoring data is input to the visualization platform conforms to the configured time range, the target monitoring data and the previous cycle's monitoring data can be recognized as the same multi-cycle exception monitoring.

[0077] Step 1.2), by determining whether the matching degree between the target monitoring data and the previous cycle's monitoring data, the response strategy and index associated with the previous cycle's monitoring data meets the configured matching degree threshold, it is determined whether the target monitoring data and the previous cycle's monitoring data constitute a multi-cycle exception monitoring.

[0078] Here, as an optional embodiment, it can be determined that the target monitoring data and the previous cycle's monitoring data with a matching degree meeting the requirements constitute the same multi-cycle exception monitoring by comparing the matching degrees of the target monitoring data and the previous cycle's monitoring data, the indexes of each dynamically updated exception report respectively associated with the previous cycle's monitoring data, and the corresponding response strategies with the configured matching degree threshold.

[0079] As another alternative embodiment, it is necessary to meet both step 1.1) and step 1.2) simultaneously, that is, while the time interval between the target monitoring data and the previous cycle's monitoring data meets the requirements, the target monitoring data, as well as the associated index and response strategy, have a matching degree with the previous cycle's monitoring data that meets the requirements. Only at this time will the target monitoring data and the previous cycle's monitoring data be recognized as the same multi-cycle anomaly monitoring.

[0080] Based on the actual application situation and accuracy requirements, the determination method of whether the target monitoring data and the previous cycle's monitoring data constitute multi-cycle anomaly monitoring can be selected.

[0081] It should be noted that the target monitoring data may be associated with at least one dynamically updated anomaly report. The dynamically updated anomaly reports associated with the target monitoring data can be determined through a dynamically updated search engine. The same applies to the situation of the dynamically updated anomaly reports associated with the previous cycle's monitoring data. In actual applications, the matching degree between the dynamically updated anomaly report 1 associated with the previous cycle's monitoring data and the dynamically updated anomaly report 2 associated with the target monitoring data can also be used to determine whether the target monitoring data and the previous cycle's monitoring data belong to the same multi-cycle anomaly monitoring.

[0082] It can be understood that the operations such as determining the matching degree in the foregoing steps of the embodiments of the present invention can all be implemented through a matching model in a neural network.

[0083] In some embodiments, if the target monitoring data and the previous monitoring data do not belong to the same multi-cycle anomaly monitoring, then the target monitoring data belongs to the first monitoring of the target multi-cycle anomaly monitoring. At this time, step S104 can be determined through the precise dynamic update of the dynamically updated anomaly report to ensure the reliability of the response strategy result. Specifically, it includes:

[0084] Step 2.1), through the target monitoring data input by the visualization platform, control the dynamically updated search engine to retrieve at least one dynamically updated anomaly report associated with the target monitoring data.

[0085] Step 2.2), extract the corresponding behavior key points from each dynamically updated anomaly report, and input the behavior key points into the multi-data source control model to determine the index associated with each dynamically updated anomaly report.

[0086] Step 2.3), based on the verification rules and verification weights associated with each anomaly element of the index in the third configuration standard, determine the confidence level of each index-associated dynamically updated anomaly report.

[0087] It should be noted that each dynamic update exception report of the target is only captured because it is related to the monitoring data, and the confidence level of such dynamic update exception reports themselves cannot be guaranteed. In this embodiment of the present invention, the third configuration standard is used here to verify the abnormal element situation associated with each dynamic update exception report to determine the confidence level of each dynamic update exception report;

[0088] Among them, each type of exception report includes at most six abnormal elements, such as abnormal time, operator, abnormal equipment, abnormal reason, abnormal process, and abnormal consequence; the verification rules for each abnormal element and the verification weights associated with each abnormal element are pre-configured in the third configuration standard, that is, whether each type of abnormal element passes the verification plays a different role in the confidence level of this dynamic update exception report.

[0089] Step 2.4), based on the confidence level and index of the dynamic update exception report, determine the target dynamic update exception report associated with the monitoring data from the dynamic update exception reports.

[0090] It can be understood that, combined with the verification of the confidence level of each dynamic update exception report and the index extracted from each dynamic update exception report in the foregoing embodiment steps, the target dynamic update exception report with the highest matching degree with the monitoring data is determined; in other words, the target dynamic update exception report generally has a high confidence level while conforming to the monitoring data.

[0091] Step 2.5), input the monitoring data and the index of the target dynamic update exception report into the multi-data source control model, and output the response strategy for the target monitoring data under the action of the second configuration standard.

[0092] Here, the multi-data source control model also includes the second configuration standard, which can perform a response strategy on the input monitoring data passing through the target dynamic update exception report and output the reply information of the monitoring data.

[0093] In some other embodiments, if the target monitoring data and the previous monitoring data belong to the same multi-cycle abnormal monitoring, then through the dependence between the target monitoring data, the target index and the past monitoring and past index in the multi-cycle abnormal monitoring, determine the precise response strategy of the target monitoring data in the multi-cycle abnormal monitoring; first, as described in step S106, first extract the target index from the dynamic update exception report associated with the target monitoring data, specifically including:

[0094] Step 3.1), based on the configuration log requirements and configuration feature requirements of the target index, determine the first configuration standard of each dynamic update exception report associated with the target monitoring data.

[0095] Here, the first configuration criteria for each dynamically updated exception report can be determined in advance. The first configuration criteria associated with each dynamically updated exception report may be the same or different. The first configuration criteria are determined according to the log requirements and feature requirements of the index. In other words, the index expectation requirements associated with each dynamically updated exception report may be different, which may lead to different first configuration criteria for different dynamically updated exception reports.

[0096] As an optional embodiment, based on the source URL and exception type of each dynamically updated exception report, the initial configuration criteria respectively associated with each dynamically updated exception report can be determined. Then, each initial configuration criteria is processed through the logs presented by the requirements of the index and the features presented by the requirements to obtain the first configuration criteria respectively associated with each dynamically updated exception report.

[0097] Step 3.2), extract the corresponding behavior key points from each dynamically updated exception report and input them into the multi-data source control model.

[0098] Step 3.3), extract the corresponding first behavior key points from the behavior key points of each dynamically updated exception report according to the feature requirements.

[0099] Among them, the feature requirements include one or more of the following: requirements to display the exception elements of the dynamically updated exception report, the index length to be displayed, and the exception type of the dynamically updated exception report to be displayed;

[0100] According to the feature requirements, extract several exception elements associated with the dynamically updated exception report including a specific exception type and the first behavior key points presented according to a specific index length;

[0101] In the foregoing embodiments, each of the dynamically updated exception reports matching the monitoring data may be associated with multiple different exception types, or each dynamically updated exception report includes multiple exception types. Here, the target exception type of each dynamically updated exception report can be determined based on the feature requirements in the first configuration criteria.

[0102] Step 3.4), process each first behavior key point according to the log requirements to obtain the index of each dynamically updated exception report.

[0103] Among them, the log requirements include the collection time, the collector, the collection location, and the collection plan, and the collection plan is before the collection time and the collection location.

[0104] Here, on the basis that the first behavior key points meet the feature requirements, the composition of the specific sensor information in the first behavior key points is also arranged according to the log requirements.

[0105] In some embodiments, the target index associated with the target monitoring data and the past index associated with the past monitoring data are both input according to the constraint conditions configured in the second configuration standard. This step S108 can also be implemented through the following steps, including:

[0106] Step 4.1), obtain each past monitoring data in the multi-period anomaly monitoring, the past index of each dynamic update anomaly report associated with each past monitoring data, and the past response strategy associated with each past monitoring data.

[0107] Among them, based on step S102 in the foregoing embodiments, it is possible to know whether the monitoring data input at each target time belongs to the same multi-period anomaly monitoring as the monitoring data input at the previous time, and in this way, all past monitoring of each multi-period anomaly monitoring can be known;

[0108] For example, a certain multi-period anomaly monitoring includes two past monitorings A and B in total. The target monitoring input can know that it belongs to the same multi-period anomaly monitoring as the previous monitoring B. At this time, using the previous monitoring B as the target monitoring, it is decided whether the target monitoring B and its previous monitoring A belong to the same multi-period anomaly monitoring. In the case of belonging, using the past monitoring A as the target monitoring, it is decided that it belongs to a different multi-period anomaly monitoring from the previous monitoring input to the visualization platform, that is, the past monitoring A is the first monitoring data of the target multi-period anomaly monitoring, and the index and response strategy associated with each monitoring data in the target multi-period anomaly monitoring are obtained respectively.

[0109] Step 4.2), configure the behavior set in the second configuration standard of the multi-data source control model according to the configured length and configured content type.

[0110] Here, the second configuration standard can be configured based on the configured service requirements and scenarios. After configuration, only the information that meets the configured content type can be input into the behavior set of the second configuration standard with the configured length; the configured content type can include content types such as collection time, collector, collection location, collection plan, etc.

[0111] Step 4.3), extract the target abnormal behavior from each past monitoring data, the past index of each dynamic update anomaly report associated with each past monitoring data, the past response strategy associated with each past monitoring data, each target monitoring data, and the target index of each dynamic update anomaly report associated with each target monitoring data.

[0112] Among them, the target abnormal behavior meets the requirements of the configured content type and the configured length. It can be understood that there may be parts in the past monitoring data, past indexes, past response strategies, target monitoring data, and each target monitoring data and target index that do not meet the provisions of the second configuration standard. Extract the target abnormal behaviors that meet the requirements and then input them into the second configuration standard.

[0113] As an optional embodiment, to ensure the input reliability of the second configuration standard, in addition to the way of timing input through constraint conditions such as the configured length requirement and the configured content type shown in step 4.3), the content to be input can also be verified through step 4.4) to ensure the reliability of the content to be input that passes the verification. Specifically, it includes:

[0114] Step 4.4.1), determine whether there is abnormal text in each past monitoring data, the past indexes of each dynamic update abnormal report associated with each past monitoring data, the past response strategies associated with each past monitoring data, each target monitoring data, and the target indexes of each dynamic update abnormal report associated with each target monitoring data that cannot extract the target abnormal behavior.

[0115] Here, the abnormal text can be understood as the text information in the past monitoring data, past indexes, past response strategies, target monitoring data, and target indexes that cannot extract the target abnormal behavior.

[0116] Step 4.4.2), if not, execute step 4.3) of extracting the target abnormal behavior.

[0117] Here, if the target abnormal behavior can be extracted from the past monitoring data, past indexes, past response strategies, target monitoring data, and target indexes, they can be directly extracted respectively.

[0118] Step 4.4.3), if there is, display the abnormal text on the visualization platform, and generate the target abnormal behavior of the abnormal text in combination with the user confirmation instruction input through the visualization platform.

[0119] Step 4.5), input each past monitoring data and each target index into the first behavior set at regular intervals, and input each target monitoring data and each past index into the second behavior set at regular intervals.

[0120] It can be understood here that the target abnormal behaviors of each past monitoring data are respectively and regularly input into the first behavior set together with the target abnormal behaviors of each target index; each first behavior set includes the target abnormal behavior of a past monitoring data and the target abnormal behavior of a target index associated with this past monitoring data; there may be multiple past monitoring data, and there may also be multiple target indexes, that is, each past monitoring data may also be associated with multiple target indexes, so it can be known that the first behavior set includes at least one;

[0121] Similarly, the target abnormal behaviors of each target monitoring data are respectively and regularly input into the second behavior set together with the target abnormal behaviors of each past index, and the second behavior set also includes at least one.

[0122] It should be noted that the second configuration standard has preset the cross-correlation relationship between the target monitoring and the past index, and between the past monitoring and the target index, and the same correlation relationship is stored and input in the same behavior set. Among them, the past response strategy is stored in the third behavior set.

[0123] As an optional embodiment, in order to ensure the input reliability of the second configuration standard, in addition to the method of regularly inputting into the first behavior set and the second behavior set shown in step 4.5), the number of the first behavior set and the second behavior set can also be restricted by another constraint condition preset by the second configuration standard, including:

[0124] Step 4.6), in the process of inputting the target index, target monitoring data, past index, past monitoring data and past response strategy in the multi-period abnormal monitoring into the second configuration standard of the multi-data source control model, if the number of the behavior sets of the second configuration standard reaches the configuration quantity threshold, then delete or merge the behavior sets with the configured number that are farthest from the target input time.

[0125] It should be noted that the second configuration standard may not only include the behavior set information associated with the target multi-period abnormal monitoring. In order to ensure the storage space of the second configuration standard, the number of the behavior sets carried in the second configuration standard is pre-configured;

[0126] In practical applications, cross-type answers are respectively generated through the first behavior set and the second behavior set after input in the second configuration standard; as described in step S110, it includes:

[0127] Step 5.1), poll the target indexes respectively associated with each past monitoring data in the first behavior set, and generate the first response strategy of each target index under the action of the past monitoring data.

[0128] Among them, there may be n pieces of past monitoring data, and there are also m target indexes. Therefore, m*n first-row sets will be generated in the second configuration standard, and m*n first-response strategies for each piece of past monitoring data through each target index will be generated by polling the m*n first-row sets.

[0129] In step 5.2), poll the past indexes associated with each target monitoring data in the second-row set, and generate second-response strategies for each past index under the action of the target monitoring data.

[0130] Similar to step 5.1), by polling the second-row set, multiple second-response strategies for the target monitoring data based on the past indexes can be obtained.

[0131] Step S112 obtains the response strategy for the target monitoring data through the first-response strategy, the second-response strategy, and the past response strategy. This response strategy is dependent on the past monitoring, the past response strategy, and the past index in the multi-period anomaly monitoring, and has higher accuracy, including:

[0132] In step 6.1), according to the correlation degrees of the target monitoring data with the first-response strategy, the second-response strategy, and the past response strategy, weight ratios are respectively assigned to the first-response strategy, the second-response strategy, and the past response strategy.

[0133] Here, the second-response strategy that answers through the target monitoring data has the highest correlation degree with the target monitoring data, the first-response strategy has the second-highest correlation degree with the target monitoring data, and the past response strategy has the lowest correlation degree with the target monitoring data. Corresponding configuration weight ratios are respectively assigned according to this correlation degree ranking.

[0134] In step 6.2), based on the matching degrees and weight ratios of the first-response strategy, the second-response strategy, and the past response strategy with the target monitoring data respectively, determine and output the response strategy for the target monitoring data in the multi-period anomaly monitoring.

[0135] Here, taking the foregoing example for illustration, it can be understood that the multi-data-source control model can determine the field / semantic matching degrees of each response strategy with the target monitoring data based on the foregoing response strategy set; based on the target monitoring data, the response strategies with the highest matching degrees can be obtained as the first-response strategy and the second-response strategy a, and then by combining the product of the weight ratios respectively associated with each response strategy, the response strategy for the target monitoring data in the multi-period anomaly monitoring can be obtained.

[0136] The embodiment of the present invention can obtain multiple sets of response strategy sets with dependent correlations in the multi-period anomaly monitoring through the cross-answer of the target monitoring data and the past index, and the past monitoring data and the target index, and then through this response strategy set, the multi-data-source control model can obtain the accurate response strategy for the target monitoring data.

[0137] In some embodiments, as Figure 2 shown, the embodiment of the present invention provides an abnormal behavior monitoring system for an industrial control system, including:

[0138] A decision-making unit, by dynamically updating the target monitoring data of the abnormal report, decides whether the target monitoring data is multi-cycle abnormal monitoring composed of the monitoring data of the previous cycle;

[0139] A first response strategy unit, if not, controls the multi-data source control model to output a response strategy passing through the target monitoring data;

[0140] A first determination unit, if so, determines the target index of the dynamically updated abnormal report associated with the target monitoring data through the first configuration standard in the multi-data source control model;

[0141] An input unit inputs the target index, target monitoring data, past index, past monitoring data, and past response strategy in the multi-cycle abnormal monitoring into the second configuration standard of the multi-data source control model;

[0142] A second determination unit determines the first response strategy of each target index in the multi-cycle abnormal monitoring under the action of each past monitoring data, and the second response strategy of each past index in the multi-cycle abnormal monitoring under the action of each target monitoring data through the second configuration standard of the multi-data source control model;

[0143] A second response strategy unit inputs the first response strategy, the second response strategy, and the past response strategy into the multi-data source control model, and determines the response strategy passing through the target monitoring data in the multi-cycle abnormal monitoring.

[0144] Further, the input unit is further configured to obtain each past monitoring data in the multi-cycle anomaly monitoring, the past indexes of each dynamic update anomaly report associated with each past monitoring data, and the past response strategies associated with each past monitoring data; configure the behavior set in the second configuration standard of the multi-data source control model according to the configured length and configured content type; extract target abnormal behaviors from each past monitoring data, the past indexes of each dynamic update anomaly report associated with each past monitoring data, the past response strategies associated with each past monitoring data, each target monitoring data, and the target indexes of each dynamic update anomaly report associated with each target monitoring data, respectively, where the target abnormal behaviors meet the requirements of the configured content type and the configured length; input each past monitoring data and each target index into the first behavior set at regular intervals, and input each target monitoring data and each past index into the second behavior set at regular intervals.

[0145] Further, the input unit is further configured to determine whether there is abnormal text that cannot extract target abnormal behaviors among each past monitoring data, the past indexes of each dynamic update anomaly report associated with each past monitoring data, the past response strategies associated with each past monitoring data, each target monitoring data, and the target indexes of each dynamic update anomaly report associated with each target monitoring data; if not, execute the step of extracting target abnormal behaviors; if so, display the abnormal text on the visualization platform, and generate the target abnormal behavior of the abnormal text in combination with the user confirmation instruction input through the visualization platform.

[0146] Further, the input unit is further configured to, when inputting the target index, target monitoring data, past index, past monitoring data, and past response strategy in the multi-cycle anomaly monitoring into the second configuration standard of the multi-data source control model, if the number of behavior sets in the behavior set of the second configuration standard reaches the configured quantity threshold, delete or merge the behavior sets of the configured number that are farthest from the target input time.

[0147] Further, the decision-making unit is further configured to determine whether the target monitoring data and the previous cycle monitoring data constitute a multi-cycle anomaly monitoring by determining whether the time interval between inputting the target monitoring data and inputting the previous cycle monitoring data is within the configured time range; or determine whether the target monitoring data and the previous cycle monitoring data constitute a multi-cycle anomaly monitoring by determining whether the matching degree of the target monitoring data with the previous cycle monitoring data, the response strategy and index associated with the previous cycle monitoring data meets the configured matching degree threshold.

[0148] Further, the first response strategy unit is further configured to control the dynamic update of the search engine to retrieve at least one dynamically updated exception report associated with the target monitoring data through the target monitoring data input by the visualization platform; extract corresponding behavior key points from each of the dynamically updated exception reports, and input the behavior key points into the multi-data source control model to determine the index associated with each of the dynamically updated exception reports; wherein, the multi-data source control model includes a first configuration criterion for extracting the index, and the first configuration criterion is determined based on the log requirements and feature requirements of the index; determine the confidence level of the dynamically updated exception report associated with each index based on the verification rules and verification weights associated with each exception element of the index in the third configuration criterion; determine the target dynamically updated exception report associated with the monitoring data from the dynamically updated exception reports based on the confidence level of the dynamically updated exception report and the index; input the monitoring data and the index of the target dynamically updated exception report into the multi-data source control model, and output the response strategy for the target monitoring data under the action of the second configuration criterion.

[0149] Further, the first determination unit is further configured to determine the first configuration criterion for each dynamically updated exception report associated with the target monitoring data based on the configured log requirements and configured feature requirements of the target index; wherein, the feature requirements include one or more of the following: the requirement to display the exception elements of the dynamically updated exception report, the required display index length, and the exception type of the dynamically updated exception report to be displayed; extract corresponding behavior key points from each of the dynamically updated exception reports and input them into the multi-data source control model; extract the corresponding first behavior key points for each of the behavior key points of the dynamically updated exception reports according to the feature requirements; process each of the first behavior key points according to the log requirements to obtain the index of each of the dynamically updated exception reports; wherein, the log requirements include the collection time, the collector, the collection location, and the collection plan, and the collection plan is before the collection time and the collection location.

[0150] Further, the second determination unit is further configured to poll the target index associated with each past monitoring data in the first behavior set to generate a first response strategy for each target index under the action of the past monitoring data; poll the past index associated with each target monitoring data in the second behavior set to generate a second response strategy for each past index under the action of the target monitoring data.

[0151] Further, the second response strategy unit is further configured to assign weight ratios to the first response strategy, the second response strategy, and the past response strategies respectively according to the correlation degrees between the target monitoring data and the first response strategy, the second response strategy, and the past response strategies; and determine and output the response strategy for the multi-period anomaly monitoring that passes the target monitoring data based on the matching degrees between the first response strategy, the second response strategy, and the past response strategies and the target monitoring data respectively and the weight ratios.

[0152] In several embodiments provided in the present application, it should be understood that the disclosed systems, systems, and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of systems or units can be in electrical, mechanical, or other forms.

[0153] In addition, the functional units in each embodiment of the present application can be integrated in a processing unit, or each unit can be physically separate, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. The above is only the implementation mode of the present application and does not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the content of the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, is equally included in the patent protection scope of the present application.

[0154] The specific implementation manners of the invention have been described in detail above, but it is only an example, and the present application is not limited to the specific implementation manners described above. For those skilled in the art, any equivalent modification or substitution to the invention is also within the scope of the present application. Therefore, equivalent transformations, modifications, improvements, etc. made without departing from the spirit and principle of the present application should all be covered by the scope of the present application.

Claims

1. An abnormal behavior monitoring method for industrial control systems, characterized in that, Including: By dynamically updating the target monitoring data of the exception report, determining whether the target monitoring data is the monitoring data of the previous cycle to constitute multi-cycle exception monitoring; If not, controlling the multi-data source control model to output a coping strategy through the target monitoring data; If so, determining the target index of the dynamically updated exception report associated with the target monitoring data through the first configuration standard in the multi-data source control model; Inputting the target index, target monitoring data, past index, past monitoring data, and past coping strategy in the multi-cycle exception monitoring into the second configuration standard of the multi-data source control model; Determining, through the second configuration standard of the multi-data source control model, the first coping strategy of each target index in the multi-cycle exception monitoring under the action of each past monitoring data, and the second coping strategy of each past index in the multi-cycle exception monitoring under the action of each target monitoring data; Based on the first coping strategy, the second coping strategy, and the past coping strategy input into the multi-data source control model, determining the coping strategy through the target monitoring data in the multi-cycle exception monitoring.

2. The method according to claim 1, characterized in that, The step of inputting the target index, target monitoring data, past index, past monitoring data, and past coping strategy in the multi-cycle exception monitoring into the second configuration standard of the multi-data source control model includes: Obtaining each past monitoring data in the multi-cycle exception monitoring, the past index of each dynamically updated exception report associated with each past monitoring data, and the past coping strategy associated with each past monitoring data; Configuring the behavior set in the second configuration standard of the multi-data source control model according to the configuration length and configuration content type; Extracting target abnormal behaviors from each past monitoring data, the past index of each dynamically updated exception report associated with each past monitoring data, the past coping strategy associated with each past monitoring data, each target monitoring data, and the target index of each dynamically updated exception report associated with each target monitoring data; wherein, the target abnormal behavior meets the requirements of the configuration content type and the configuration length; Timely inputting each past monitoring data and each target index into the first behavior set respectively, and timely inputting each target monitoring data and each past index into the second behavior set respectively.

3. The method according to claim 2, wherein The step of extracting target abnormal behaviors from each past monitoring data, the past index of each dynamically updated exception report associated with each past monitoring data, the past coping strategy associated with each past monitoring data, each target monitoring data, and the target index of each dynamically updated exception report associated with each target monitoring data includes: Determining whether there is abnormal text in each past monitoring data, the past index of each dynamically updated exception report associated with each past monitoring data, the past coping strategy associated with each past monitoring data, each target monitoring data, and the target index of each dynamically updated exception report associated with each target monitoring data that cannot extract target abnormal behaviors; If not, perform the step of extracting the target abnormal behavior; If so, display the abnormal text on the visualization platform, and combine with the user confirmation instruction input through the visualization platform to generate the target abnormal behavior of the abnormal text.

4. The method according to claim 2, characterized in that, The step of inputting the target index, target monitoring data, past index, past monitoring data, and past coping strategies in the multi-cycle abnormal monitoring into the second configuration standard of the multi-data source control model further includes: During the process of inputting the target index, target monitoring data, past index, past monitoring data, and past coping strategies in the multi-cycle abnormal monitoring into the second configuration standard of the multi-data source control model, if the number of behavior sets in the behavior set of the second configuration standard reaches the configuration quantity threshold, delete or merge the behavior sets of the configuration quantity that are farthest from the target input time.

5. The method according to claim 1, wherein The step of determining whether the target monitoring data is the monitoring data of the previous cycle to form multi-cycle abnormal monitoring by dynamically updating the target monitoring data of the abnormal report includes: Determine whether the target monitoring data and the monitoring data of the previous cycle form multi-cycle abnormal monitoring by determining whether the time interval between inputting the target monitoring data and inputting the monitoring data of the previous cycle is within the configured time range; Or, Determine whether the target monitoring data and the monitoring data of the previous cycle form multi-cycle abnormal monitoring by determining whether any of the matching degrees between the target monitoring data and the monitoring data of the previous cycle, the coping strategies and indexes associated with the monitoring data of the previous cycle meet the configured matching degree threshold.

6. The method according to claim 1, characterized in that The step of controlling the multi-data source control model to output the coping strategy through the target monitoring data includes: Control the dynamic update search engine to retrieve at least one dynamically updated abnormal report associated with the target monitoring data through the target monitoring data input through the visualization platform; Extract the corresponding behavior key points from each of the dynamically updated abnormal reports, and input the behavior key points into the multi-data source control model to determine the index associated with each of the dynamically updated abnormal reports; wherein, the multi-data source control model includes a first configuration standard for extracting the index, and the first configuration standard is determined based on the log requirements and feature requirements of the index. Determine the confidence level of each dynamically updated abnormal report associated with the index based on the verification rules and verification weights associated with each abnormal element of the index in the third configuration standard; Determine the target dynamically updated abnormal report associated with the target monitoring data from the dynamically updated abnormal reports based on the confidence level of the dynamically updated abnormal reports and the index; Input the target monitoring data and the index of the target dynamically updated abnormal report into the multi-data source control model, and output the coping strategy through the target monitoring data under the action of the second configuration standard.

7. The method according to claim 1, characterized in that The step of determining the target index of the dynamically updated abnormal report associated with the target monitoring data through the first configuration standard in the multi-data source control model includes: Based on the configuration log requirements and configuration feature requirements of the target index, determine the first configuration criteria for associating the target monitoring data with each dynamically updated exception report; wherein, the feature requirements include one or more of the following: the requirement to display the exception elements of the dynamically updated exception report, the required index length to be displayed, and the exception type of the dynamically updated exception report to be displayed. Extract the corresponding behavior key points from each of the dynamically updated exception reports and input them into the multi-data source control model. Extract the corresponding first behavior key points from the behavior key points of each of the dynamically updated exception reports according to the feature requirements. Process each of the first behavior key points according to the log requirements to obtain the index of each of the dynamically updated exception reports; wherein, the log requirements include the collection time, the collector, the collection location, and the collection plan, and the collection plan is before the collection time and the collection location.

8. The method according to claim 2 or 3 or 4, characterized in that, The steps of determining the first response strategy of each target index in each past monitoring data and the second response strategy of each past index in each target monitoring data in the multi-period anomaly monitoring through the second configuration criteria of the multi-data source control model include: Poll the target indexes associated with each past monitoring data in the first behavior set to generate the first response strategy of each target index under the action of the past monitoring data. Poll the past indexes associated with each target monitoring data in the second behavior set to generate the second response strategy of each past index under the action of the target monitoring data.

9. The method according to claim 1, wherein The steps of determining the response strategy of the multi-period anomaly monitoring through the target monitoring data based on the first response strategy, the second response strategy, and the past response strategy input into the multi-data source control model include: Assign weight ratios to the first response strategy, the second response strategy, and the past response strategy respectively through the correlation degrees of the target monitoring data with the first response strategy, the second response strategy, and the past response strategy. Determine and output the response strategy of the multi-period anomaly monitoring through the target monitoring data based on the matching degrees of the first response strategy, the second response strategy, and the past response strategy with the target monitoring data and the weight ratios.

10. An abnormal behavior monitoring system for an industrial control system, which is used to perform the abnormal behavior monitoring for an industrial control system as described in any one of claims 1-9, and is characterized in that, Include: A decision-making unit, which decides whether the target monitoring data is the monitoring data of the previous period to form a multi-period anomaly monitoring through the target monitoring data of the dynamically updated exception report. A first response strategy unit, if not, then control the multi-data source control model to output the response strategy through the target monitoring data. A first determination unit, if so, then determine the target index of the dynamically updated exception report associated with the target monitoring data through the first configuration criteria in the multi-data source control model. An input unit, input the target index, target monitoring data, past index, past monitoring data, and past response strategy in the multi-period anomaly monitoring into the second configuration criteria of the multi-data source control model. The second determination unit determines, according to the second configuration criterion of the multi-data source control model, the first response strategy of each target index in the multi-period anomaly monitoring under the action of each past monitoring data, and the second response strategy of each past index in the multi-period anomaly monitoring under the action of each target monitoring data; The second response strategy unit inputs the multi-data source control model based on the first response strategy, the second response strategy and the past response strategy, and determines the response strategy of the multi-period anomaly monitoring through the target monitoring data.