Service call link anomaly detection method, device, equipment and program product
By acquiring service call link data in real time and using pre-trained models for anomaly detection, the inefficiency problem of existing technologies is solved, efficient and accurate anomaly detection is achieved, and the stability of business execution is ensured.
Patent Information
- Application Number
- CN202510862360.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2025-09-16
AI Technical Summary
In the existing technology, the anomaly detection efficiency of the service call link is low and it is difficult to ensure the accuracy of anomaly detection.
By acquiring the current service call link data in real time and adopting a pre-trained service link anomaly detection model, the anomaly detection result of the current service call link is determined. A pre-trained service call link anomaly detection model is introduced to perform anomaly detection on the current service call link data acquired in real time.
It improves the efficiency and accuracy of service call link anomaly detection and ensures the stability and reliability of the business execution process.
Smart Images

Figure CN120658645A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of artificial intelligence technology, and in particular to a method, device, equipment and program product for detecting anomalies in a service call link. Background Art
[0002] In existing technologies, service call links are tagged. The call relationships between service call links are distinguished based on the service call link tags and link identifiers. When detecting anomalies in service call links, manual work is required to retrieve link information from the complex call relationships, analyze and locate the cause of the anomaly layer by layer.
[0003] The anomaly detection method of the service call link in the existing technology has low anomaly detection efficiency and is difficult to ensure the accuracy of anomaly detection. Summary of the Invention
[0004] The present invention provides a service call link anomaly detection method, device, equipment and program product, which improve the efficiency and accuracy of service call link anomaly detection.
[0005] According to one aspect of the present invention, a method for detecting anomalies in a service call link is provided, the method comprising:
[0006] Acquire the current service call link data of the current service call link in real time; wherein the current service call link data includes the current link flow direction, the current link length, the current service request status, the current request response time and the current traffic difference;
[0007] A pre-trained service link anomaly detection model is used to determine a current anomaly detection result of the current service call link according to the current service call link data of the current service call link.
[0008] According to another aspect of the present invention, a device for detecting anomalies in a service call link is provided, the device comprising:
[0009] A link data real-time acquisition module is used to obtain the current service call link data of the current service call link in real time; wherein the current service call link data includes the current link flow direction, current link length, current service request status, current request response time and current traffic difference;
[0010] The link anomaly detection module is used to use a pre-trained service link anomaly detection model to determine a current anomaly detection result of the current service call link according to the current service call link data of the current service call link.
[0011] According to another aspect of the present invention, an electronic device is provided, comprising:
[0012] at least one processor; and
[0013] a memory communicatively connected to the at least one processor; wherein,
[0014] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the service call link anomaly detection method described in any embodiment of the present invention.
[0015] According to another aspect of the present invention, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the service call link anomaly detection method according to any embodiment of the present invention.
[0016] The technical solution of the embodiment of the present invention obtains the current service call link data of the current service call link in real time, adopts a pre-trained service link anomaly detection model, and determines the current anomaly detection result of the current service call link according to the current service call link data of the current service call link. It introduces a pre-trained service call link anomaly detection model, and performs anomaly detection on the current service call link data of the current service call link obtained in real time, thereby improving the efficiency and accuracy of service call link anomaly detection and ensuring the stability and reliability of the business execution process.
[0017] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0019] Figure 1 This is a flowchart of a method for detecting anomalies in a service call link according to the first embodiment of the present invention;
[0020] Figure 2 This is a flowchart of a method for detecting anomalies in a service call link according to a second embodiment of the present invention;
[0021] Figure 3 This is a flowchart of a method for detecting anomalies in a service call link according to a second embodiment of the present invention;
[0022] Figure 4 This is a structural diagram of a device for detecting abnormalities in a service call link according to a third embodiment of the present invention;
[0023] Figure 5 It is a structural diagram of an electronic device that implements the service call link anomaly detection method according to an embodiment of the present invention. DETAILED DESCRIPTION
[0024] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0025] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0026] Example 1
[0027] Figure 1 This is a flowchart of a method for detecting anomalies in a service call link, provided in Embodiment 1 of the present invention. This embodiment of the present invention is applicable to situations where anomalies in a service call link are detected. The method can be performed by a service call link anomaly detection device, which can be implemented in hardware and / or software. The device can be configured in an electronic device that carries the service call link anomaly detection function, such as a client or server.
[0028] See also Figure 1 The service call link anomaly detection method shown includes:
[0029] S110. Acquire current service call link data of the current service call link in real time.
[0030] The service call chain can be used to represent the business execution process. This chain can be used to represent the entire call process, from business request initiation, business processing, to result feedback. For example, the service call chain can be used to represent the entire call process in a distributed system, from a business request initiated by a client, processed by multiple microservices, and ultimately returning a result to the client. For example, the service can be a microservice.
[0031] The current service call link may be a service call link currently being executed. The current service call link may correspond to a current service. The current service call link data may be data associated with the service call link currently being executed. The current service call link data may be used to characterize the service execution progress and service execution status of the current service call link. Exemplarily, the current service call link data may include the current link flow direction, the current link length, the current service request status, the current request response time, and the current traffic difference.
[0032] The current link flow direction can be used to characterize the transmission direction of the current business request in the service call link. The current link flow direction can reflect the dependency hierarchy between the services involved in the current business. The current link flow direction can also be used to characterize the complexity of the topology of the current service call link.
[0033] The current link length can be used to characterize the number of service nodes that the current business request passes through. The current link length can be used to characterize the failure risk in the business execution process of the current business, such as the delay probability and failure probability in the business execution process of the current business. Exemplarily, the current link length may include physical length and logical length. Among them, the physical length can be used to characterize the physical distance between the network devices involved in the current business. The logical length can be used to characterize the depth of the call chain of the service involved in the current business. For example, the current service call link is "client → order service → payment service → risk control service", and accordingly, the logical length of the current service call link can be 4.
[0034] The current service request status can be used to identify the processing results of the current service request at each service node. This status can affect the user experience of the current service corresponding to the current service call link. Exemplary statuses include success, failure, and timeout. Success can indicate a normal service response. Failure can indicate a client or server error. Timeout can indicate that a response was not returned within a preset threshold.
[0035] The current request response time can be used to represent the total time consumed from initiating a service request to receiving a response. Exemplarily, the current request response time can include end-to-end time, service processing time, and network transmission time. The end-to-end time can be the total duration from initiating a service request to receiving the final response. Service processing time can be the execution time of a single service's internal logic. Network transmission time can be the data transmission delay across service nodes.
[0036] The current traffic difference can be used to reflect the load imbalance of different service nodes in the current service call link. The current traffic difference can be used to measure the resource utilization of different service nodes in the current service call link.
[0037] Specifically, the application programming interface (API) between this device and each service can be used to obtain the current link direction, current link length, current service request status, current request response time and current traffic difference of the current service call link in real time to obtain the current service call link data of the current service call link.
[0038] In an optional embodiment of the present invention, the current service call link data of the current service call link is obtained in real time, including: obtaining the current request response time, current link length, current link topology, current request path, current service node data and current gateway data of the current service call link in real time; determining the current link flow direction of the current service call link based on the current link topology and current request path of the current service call link; filtering the current service request status of the current service call link in the current service node data; and determining the current traffic difference of the current service call link based on the current gateway data.
[0039] The current link topology can be used to visualize the dependency relationships between service nodes in the current service call link. Optionally, the current link topology can include a tree structure or a graph structure. The current link topology can be used to analyze the dependency relationships between services.
[0040] The current request path can be the complete flow track of the business request in the service. For example, the current request path can be "user request → domain name resolution → gateway routing → service internal processing → database storage".
[0041] Current service node data can be used to characterize the performance and status indicators of the current service node. This data can be used to monitor and optimize service performance. For example, this data may include the current service request status and the current data storage status. The current data storage status can be used to characterize the data storage related information for the current service call link. For example, the current data storage status may include whether the data storage is successful, the number of data replicas, and the health of the data.
[0042] The current gateway data may be data associated with the gateway during request processing. Exemplarily, the current gateway data may include current routing policy data, current service call address mapping, current load balancing data, current access control data, and current flow control data. Among them, the current routing policy data may be used to route the service request to the corresponding service. The current service call address mapping may be used to record the mapping relationship between the service request and each internal service call address. The current load balancing data may be used to record the load conditions of each service involved in the current service call link. The current access control data may be used to record information such as the setting and verification of client access rights. The current flow control data may be used to record the traffic thresholds of each service involved in the service request.
[0043] Specifically, the application programming interface between this device and each service can be used to obtain the current request response time, current link length, current link topology, current request path, current service node data, and current gateway data of the current service call link in real time. Based on the current link topology and current request path of the current service call link, the current link flow direction of the current service call link can be determined. The current service node data can be filtered to obtain the current service request status of the current service call link. The current traffic difference of the current service call link can be calculated based on the current load balancing data of the current gateway data.
[0044] This solution introduces a process for determining the current link flow direction, the current service request state, and the current traffic difference, further improving the efficiency of determining the current link flow direction, the current service request state, and the current traffic difference.
[0045] S120: Using a pre-trained service link anomaly detection model, determine a current anomaly detection result of the current service call link according to the current service call link data of the current service call link.
[0046] The service link anomaly detection model can be used to detect anomalies in the current service call link. The input data of the service link anomaly detection model can be the current service call link data of the current service call link; the output result of the service link anomaly detection model can be the current anomaly detection result of the current service call link. The current anomaly detection result can be the anomaly detection result of the current service call link. Exemplarily, the current anomaly detection result can include the current abnormal service call link and the current anomaly cause. The current abnormal service call link can be the current service call link with an anomaly. The current anomaly cause can be the cause of the anomaly in the current abnormal service call link.
[0047] In an optional embodiment of the present invention, the current anomaly detection result includes the current abnormal service call link, the current abnormal service node in the current abnormal service call link, and the current anomaly cause. The current abnormal node may be a service node with an anomaly in the current abnormal service call link. The current abnormal node may further determine the location of the anomaly based on the current abnormal service call link. This solution improves the accuracy and efficiency of service link anomaly detection by concretizing the current anomaly detection result as the current abnormal service call link, the current abnormal service node in the current abnormal service call link, and the current anomaly cause.
[0048] Specifically, the current service call link data of the current service call link may be input into a pre-trained service link anomaly detection model, and the current anomaly detection result of the current service call link may be output.
[0049] The technical solution of the embodiment of the present invention obtains the current service call link data of the current service call link in real time, adopts a pre-trained service link anomaly detection model, and determines the current anomaly detection result of the current service call link according to the current service call link data of the current service call link. It introduces a pre-trained service call link anomaly detection model, and performs anomaly detection on the current service call link data of the current service call link obtained in real time, thereby improving the efficiency and accuracy of service call link anomaly detection and ensuring the stability and reliability of the business execution process.
[0050] In an optional embodiment of the present invention, after determining the current abnormality detection result of the current service call link, the method further includes: when detecting that an abnormality exists in the current service call link, issuing link abnormality reminder information.
[0051] The link anomaly reminder information can be used to indicate the abnormal state of the current service call link. Optionally, the link anomaly reminder information can include the current anomaly detection result of the current service call link. Optionally, the link anomaly reminder information can be in the form of a pop-up message and / or a voice message.
[0052] Specifically, after determining the current anomaly detection result of the current service call link, when an anomaly is detected in the current service call link, a link anomaly reminder message may be sent to the operation and maintenance party of the device or the initiator of the service request.
[0053] This solution can achieve timely adjustment of the abnormal situation of the current service call link by issuing a link abnormality reminder message when an abnormality is detected in the current service call link.
[0054] Example 2
[0055] Figure 2 A flow chart of a service call link anomaly detection method provided for the second embodiment of the present invention. Based on the above embodiments, the embodiment of the present invention further adds "obtaining historical service call link data of multiple historical service call links; wherein, the historical service call link data includes historical link flow direction, historical link length, historical service request status, historical request response time and historical traffic difference; using the historical service call link data of each historical service call link as a training sample to train the service call link anomaly detection model", introduces the training process of the service link anomaly detection model, and improves the accuracy of the service call link anomaly detection model. It should be noted that for the parts not described in detail in the embodiment of the present invention, please refer to the description of other embodiments.
[0056] See also Figure 2 The service call link anomaly detection method shown includes:
[0057] S210: Obtain historical service call link data of multiple historical service call links.
[0058] The historical service call link may be a service call link executed at a historical moment. The historical service call link may correspond to a historical business. The historical service call link data may be data associated with the service call link executed at a historical moment. The historical service call link data may be used to characterize the business execution progress and business execution status of the historical service call link. Optionally, the historical service call link data of the historical service call link may be stored in each service or database. Exemplarily, the historical service call link data may include historical link flow direction, historical link length, historical service request status, historical request response time, and historical traffic difference.
[0059] The historical link flow direction can be used to characterize the transmission direction of historical business requests in the service call link. The historical link flow direction can reflect the dependency hierarchy between the services involved in the historical business. The historical link flow direction can be used to characterize the complexity of the topological structure of the historical service call link.
[0060] Historical link length can be used to characterize the number of service nodes traversed by historical service requests. Historical link length can also be used to characterize the failure risk during the execution of historical services, such as the probability of delay and failure during the execution of historical services. For example, historical link length can include both physical length and logical length. Physical length can be used to characterize the physical distance between network devices involved in historical services. Logical length can be used to characterize the depth of the service call chain involved in historical services.
[0061] The historical service request status can be used to identify the processing results of historical service requests at each service node. The historical service request status can affect the user experience of the historical service corresponding to the historical service call link. For example, the historical service request status can include success, failure, and timeout.
[0062] The historical request response time can be used to represent the time consumption of the entire process from initiating a service request to receiving a response. For example, the historical request response time may include end-to-end time, service processing time, and network transmission time.
[0063] Historical traffic differences can be used to reflect the load imbalance of different service nodes in the historical service call chain. Historical traffic differences can be used to measure the resource utilization of different service nodes in the historical service call chain.
[0064] Specifically, the historical service call link data of multiple historical service call links may be acquired by using an application programming interface between the device and each service, or by using an application programming interface between the device and a database.
[0065] S220: Use the historical service call link data of each historical service call link as a training sample to train a service call link anomaly detection model.
[0066] Specifically, the historical service call link data of each historical service call link is used as a training sample, and an unsupervised learning method can be used to train the service call link anomaly detection model.
[0067] For example, the historical service call link data of each historical service call link can be divided into a result set, a data set and a test set, and an unsupervised learning method can be used to train the service call link anomaly detection model until the anomaly detection results of the service call link anomaly detection model converge.
[0068] S230. Obtain current service call link data of the current service call link in real time.
[0069] Among them, the current service call link data includes the current link flow direction, current link length, current service request status, current request response time and current traffic difference;
[0070] S240: Using a pre-trained service link anomaly detection model, determine a current anomaly detection result of the current service call link according to the current service call link data of the current service call link.
[0071] The technical solution of the embodiment of the present invention introduces a training process for the service link anomaly detection model. By obtaining historical service call link data of multiple historical service call links, the historical service call link data of each historical service call link is used as a training sample to train the service call link anomaly detection model. By performing unsupervised training on the service call link anomaly detection model, the training efficiency of the service call link anomaly detection model is improved, and the anomaly detection accuracy of the service call link anomaly detection model can be improved.
[0072] In an optional embodiment of the present invention, before using the historical service call link data of each historical service call link as a training sample to train the service call link anomaly detection model, it also includes: obtaining preset service call link data, and based on the difference between the historical service call link data of each historical service call link and the preset service call link data, performing anomaly identification on each historical service call link to obtain a historical anomaly detection result for each historical service call link; accordingly, after using the historical service call link data of each historical service call link as a training sample to train the service call link anomaly detection model, it also includes: using the historical anomaly detection results corresponding to each historical service call link to adjust the service call link anomaly detection model.
[0073] The preset service call link data can be used to characterize the normal value of the preset historical service call link data. Exemplarily, the preset service call link data includes the preset link flow direction, the preset link length, the preset service request status, the preset request response time, and the preset traffic difference. The difference between the historical service call link data and the preset service call link data of the historical service call link can be used to characterize the degree of abnormality of the historical service call link data. The historical anomaly detection result can be the anomaly detection result of the historical service call link. The historical anomaly detection result can include the historical abnormal service call link, the historical abnormal service node, and the historical abnormal cause. The historical abnormal service call link can be a historical service call link with an abnormality. The historical abnormal node can be a service node with an abnormality in the historical abnormal service call link. The historical abnormal cause can be the abnormal cause of the historical abnormal service call link.
[0074] Specifically, predetermined preset service call link data can be obtained. The historical service call link data of each historical service call link can be compared with the preset service call link data to determine the difference between the historical service call link data of each historical service call link and the preset service call link data. It can be detected whether the difference between the historical service call link data of each historical service call link and the preset service call link data is greater than or equal to the corresponding preset difference threshold. If the difference between the historical service call link data of the historical service call link and the preset service call link data is greater than or equal to the corresponding preset difference threshold, it is determined that there is an abnormality in the historical service call link; if the difference between the historical service call link data of the historical service call link and the preset service call link data is less than the corresponding preset difference threshold, it is determined that there is no abnormality in the historical service call link.
[0075] Accordingly, after training the service call link anomaly detection model using the historical service call link data of each historical service call link as training samples, the historical service call link data of each historical service call link can be respectively input into the trained service call link anomaly detection model to obtain the predicted anomaly detection results of the historical service call link. Based on the difference between the historical anomaly detection results and the corresponding predicted anomaly detection results corresponding to each historical service call link, the model parameters of the service call link anomaly detection model can be adjusted until the difference between the historical anomaly detection results and the corresponding predicted anomaly detection results corresponding to each historical service call link converges.
[0076] This solution introduces the historical anomaly detection results of each historical service call link, further modifies the service link anomaly detection model, and further improves the accuracy of the service call link anomaly detection model.
[0077] In an optional embodiment of the present invention, after obtaining the historical service call link data of multiple historical service call links, it also includes: performing initial classification on each historical service call link according to the historical head node in each historical service call link; calculating the historical distance between the historical service nodes in each historical service call link according to the historical service call link data of each historical service call link; clustering each historical service call link according to the historical distance between the historical service nodes in each historical service call link to obtain at least one historical clustering result for each historical service call link; accordingly, according to the historical service call link data of each historical service call link and the preset The differences between the service call link data are used to identify the anomalies of each historical service call link and obtain the historical anomaly detection results of each historical service call link, including: according to the differences between the historical service call link data of each historical clustering result and the preset service call link data, anomaly identification is performed on each historical clustering result to obtain the historical anomaly detection results of each historical clustering result; accordingly, the historical service call link data of each historical service call link is used as a training sample to train the service call link anomaly detection model, including: the historical service call link data of each historical clustering result is used as a training sample to train the service call link anomaly detection model.
[0078] A historical head node can be used to represent the end that initiated a historical service in a historical service call link. A historical head node can be the starting point of a historical service. Based on historical head nodes, different services can be clearly distinguished. Historical distance can be the degree of similarity between historical service nodes in different historical service call links. Historical clustering results can be the clustering results of each historical service call link.
[0079] Specifically, after obtaining the historical service call link data of multiple historical service call links, the historical service call links with the same historical head node can be classified into the same category, and the historical service call links can be initially classified. The Euclidean distance (or Manhattan distance) between the historical service call link data corresponding to the historical service nodes in each historical service call link can be calculated to obtain the historical distance between the historical service nodes in each historical service call link. Each historical service call link can be assigned to the cluster center that is closest to its historical distance. Each time a historical service call link is assigned, the cluster center of the historical service call link is reset, and the allocation process of the historical service call link is repeated until no historical service call link is assigned to a different cluster or the cluster center no longer changes, and the clustering of each historical service call link is completed, and at least one historical clustering result of each historical service call link is obtained.
[0080] Accordingly, each historical clustering result can be compared with the preset service call link data to determine the difference between each historical clustering result and the preset service call link data. It can be detected whether the difference between each historical clustering result and the preset service call link data is greater than or equal to the corresponding preset difference threshold. If the difference between the historical clustering result and the preset service call link data is greater than or equal to the corresponding preset difference threshold, it is determined that there is an anomaly in the historical service call link; if the difference between the historical clustering result and the preset service call link data is less than the corresponding preset difference threshold, it is determined that there is no anomaly in the historical clustering result.
[0081] Accordingly, each historical clustering result can be input into the trained service call link anomaly detection model to obtain a predicted anomaly detection result for the historical clustering result. Based on the difference between the historical anomaly detection result and the corresponding predicted anomaly detection result corresponding to each historical clustering result, the model parameters of the service call link anomaly detection model can be adjusted until the difference between the historical anomaly detection result and the corresponding predicted anomaly detection result for each historical clustering result converges.
[0082] This solution introduces a clustering process for historical service call links, and trains the service call link anomaly detection model based on the historical clustering results, further improving the training efficiency of the service call link anomaly detection model.
[0083] Based on the above embodiments, Figure 3 The present invention also provides a preferred embodiment of a method for detecting abnormalities in a service call link. Figure 3 The service call link anomaly detection method shown includes:
[0084] S310: Data preprocessing.
[0085] Specifically, historical service call link data of multiple historical service call links can be collected. The collected historical service call link data of multiple historical service call links can be cleaned and normalized to extract key information such as historical request response time, historical link length, historical link topology, historical request path, historical service node data and historical gateway data of each historical service call link. The historical link flow direction of the historical service call link can be determined based on the historical link topology and historical request path of the historical service call link. The historical service request status of the historical service call link can be screened in the historical service node data. The historical traffic difference of the historical service call link can be determined based on the historical gateway data. Among them, the historical service call link data includes historical link flow direction, historical link length, historical service request status, historical request response time and historical traffic difference.
[0086] Optionally, based on the historical link topology structure of the historical service call links, historical service call links corresponding to the same historical link topology may be merged, and the corresponding historical service call link data may be persisted in a database table.
[0087] S320, cluster analysis.
[0088] Specifically, each historical service call link can be initially clustered based on the historical head node in each historical service call link based on the K-means algorithm. A single historical service call link can be used as the minimum feature unit for aggregation, and indicators such as historical link flow direction, historical link length, historical service request status, historical request response time and historical traffic difference can be used as features to calculate the historical distance between the historical service nodes of each historical service call link, and assign each historical service call link to the cluster center of the historical service call link closest to it. Each time a historical service call link is assigned, the cluster center of the cluster will be recalculated based on the existing historical service call links in the cluster. Repeat this process until no historical service call link is reassigned to a different cluster, no cluster center changes again and the sum of squared errors is locally minimized, and at least one historical clustering result for each historical service call link is obtained.
[0089] S330: Abnormality detection.
[0090] Optionally, a distance function can be formulated in combination with the test service call scenario, and features of abnormal service nodes can be extracted to formulate preset abnormality thresholds. Historical anomaly detection results can be identified based on historical clustering results.
[0091] S340, model training.
[0092] Specifically, historical clustering results can be used as result sets, data sets, and evaluation sets. By training iterative parameters, the service call link anomaly detection model can learn the complex structure and patterns of historical service call link data from historical clustering results, automatically performing clustering and classification. This allows the service call link anomaly detection model to produce high-quality anomaly detection results.
[0093] S350, abnormal warning.
[0094] Specifically, the trained service call link anomaly detection model can be used to predict and judge the current service call link data of the current service call link obtained in real time, detect the stability of the current service call link, and promptly discover the current anomaly detection results of the current service call link and report the anomaly.
[0095] This solution provides a service call link anomaly detection method based on unsupervised learning clustering training. It detects anomalies in service call links based on the learning and generalization capabilities of the model, improves the accuracy and efficiency of service call link anomaly detection, and ensures the stability and reliability of the business execution process.
[0096] Example 3
[0097] Figure 4 This is a schematic diagram of the structure of a service call link anomaly detection device provided in Example 3 of the present invention. This embodiment of the present invention is applicable to situations where anomaly detection is performed on a service call link. The device can execute a service call link anomaly detection method. The device can be implemented in hardware and / or software. The device can be configured in an electronic device that carries the service call link anomaly detection function, such as a client or server.
[0098] See also Figure 4 The service call link anomaly detection device shown includes: a link data real-time acquisition module 410 and a link anomaly detection module 420. The link data real-time acquisition module 410 is used to acquire the current service call link data of the current service call link in real time; the current service call link data includes the current link flow direction, current link length, current service request status, current request response time, and current traffic difference; and the link anomaly detection module 420 is used to use a pre-trained service link anomaly detection model to determine the current anomaly detection result of the current service call link based on the current service call link data of the current service call link.
[0099] The technical solution of the embodiment of the present invention obtains the current service call link data of the current service call link in real time, adopts a pre-trained service link anomaly detection model, and determines the current anomaly detection result of the current service call link according to the current service call link data of the current service call link. It introduces a pre-trained service call link anomaly detection model, and performs anomaly detection on the current service call link data of the current service call link obtained in real time, thereby improving the efficiency and accuracy of service call link anomaly detection and ensuring the stability and reliability of the business execution process.
[0100] In an optional embodiment of the present invention, the device also includes: a historical service call link data acquisition module, which is used to obtain historical service call link data of multiple historical service call links before obtaining the current service call link data of the current service call link in real time; wherein, the historical service call link data includes historical link flow direction, historical link length, historical service request status, historical request response time and historical traffic difference; a historical service call link data training module, which is used to use the historical service call link data of each of the historical service call links as a training sample to train the service call link anomaly detection model.
[0101] In an optional embodiment of the present invention, the device also includes: a historical anomaly detection result determination module, which is used to obtain preset service call link data before using the historical service call link data of each of the historical service call links as training samples to train the service call link anomaly detection model, and identify anomalies of each of the historical service call links based on the difference between the historical service call link data of each of the historical service call links and the preset service call link data to obtain historical anomaly detection results of each of the historical service call links; a service call link anomaly detection model adjustment module, which is used to adjust the service call link anomaly detection model using the historical anomaly detection results corresponding to each of the historical service call links after using the historical service call link data of each of the historical service call links as training samples to train the service call link anomaly detection model.
[0102] In an optional embodiment of the present invention, the device further includes: a historical service call link initial classification module for initially classifying each of the historical service call links according to the historical head node in each of the historical service call links after obtaining the historical service call link data of the plurality of historical service call links; a historical distance calculation module for calculating the historical distance between the historical service nodes in each of the historical service call links according to the historical service call link data of each of the historical service call links; a historical clustering result determination module for clustering each of the historical service call links according to the historical distance between the historical service nodes in each of the historical service call links. The paths are clustered to obtain at least one historical clustering result of each of the historical service call links; accordingly, the historical anomaly detection result determination module includes: a historical anomaly detection result determination unit, which is used to identify anomalies on each of the historical clustering results according to the difference between the historical service call link data of each of the historical clustering results and the preset service call link data, to obtain a historical anomaly detection result of each of the historical clustering results; accordingly, the training effect detection module includes: a training effect detection unit, which is used to use the historical service call link data of each historical clustering result as a training sample to train the service call link anomaly detection model.
[0103] In an optional embodiment of the present invention, the link data real-time acquisition module 410 includes: a link data real-time acquisition unit, which is used to obtain in real time the current request response time, current link length, current link topology, current request path, current service node data and current gateway data of the current service call link; a current link flow direction determination unit, which is used to determine the current link flow direction of the current service call link based on the current link topology and current request path of the current service call link; a current link flow direction screening unit, which is used to screen the current service request status of the current service call link in the current service node data; and a current traffic difference determination unit, which is used to determine the current traffic difference of the current service call link based on the current gateway data.
[0104] In an optional embodiment of the present invention, the device further includes: a link abnormality reminder module, which is used to issue a link abnormality reminder message when an abnormality is detected in the current service call link after the current abnormality detection result of the current service call link is determined.
[0105] In an optional embodiment of the present invention, the device further includes: the current abnormality detection result includes a current abnormal service call link, a current abnormal service node of the current abnormal service call link, and a current abnormality cause.
[0106] The service call link anomaly detection device provided in the embodiment of the present invention can execute the service call link anomaly detection method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0107] In the technical solution of the embodiment of the present invention, the collected information is information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with the relevant laws, regulations and standards of the relevant countries and regions, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0108] Example 4
[0109] According to an embodiment of the present invention, the present invention further provides an electronic device, a readable storage medium and a computer program product.
[0110] Figure 5 A schematic diagram of the structure of an electronic device 500 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.
[0111] like Figure 5 As shown, the electronic device 500 includes at least one processor 501, and a memory connected to the at least one processor 501 in communication, such as a read-only memory (ROM) 502, a random access memory (RAM) 503, etc., wherein the memory stores a computer program that can be executed by the at least one processor, and the processor 501 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 502 or the computer program loaded from the storage unit 508 into the random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the electronic device 500 can also be stored. The processor 501, ROM 502 and RAM 503 are connected to each other via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.
[0112] Multiple components in the electronic device 500 are connected to the I / O interface 505, including: an input unit 506, such as a keyboard, a mouse, etc.; an output unit 507, such as various types of displays, speakers, etc.; a storage unit 508, such as a magnetic disk, an optical disk, etc.; and a communication unit 509, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 509 allows the electronic device 500 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0113] The processor 501 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the processor 501 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors that run machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 501 executes the various methods and processes described above, such as the service call link anomaly detection method.
[0114] In some embodiments, the service call link anomaly detection method may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 508. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 500 via the ROM 502 and / or the communication unit 509. When the computer program is loaded into the RAM 503 and executed by the processor 501, one or more steps of the service call link anomaly detection method described above may be performed. Alternatively, in other embodiments, the processor 501 may be configured to execute the service call link anomaly detection method in any other appropriate manner (e.g., by means of firmware).
[0115] Various embodiments of the systems and techniques described above can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0116] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0117] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0118] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0119] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0120] A computing system may include clients and servers. The clients and servers are generally remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within a cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS (Virtual Private Server) services.
[0121] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0122] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
Claims
1. A method for detecting anomalies in a service call link, characterized in that: The method comprises: Acquire the current service call link data of the current service call link in real time; wherein the current service call link data includes the current link flow direction, the current link length, the current service request status, the current request response time and the current traffic difference; A pre-trained service link anomaly detection model is used to determine a current anomaly detection result of the current service call link according to the current service call link data of the current service call link.
2. The method according to claim 1, characterized in that Before acquiring the current service call link data of the current service call link in real time, the method further includes: Obtaining historical service call link data for multiple historical service call links; wherein the historical service call link data includes historical link flow direction, historical link length, historical service request status, historical request response time, and historical traffic difference; The historical service call link data of each of the historical service call links is used as a training sample to train the service call link anomaly detection model.
3. The method according to claim 2, characterized in that Before using the historical service call link data of each of the historical service call links as training samples to train the service call link anomaly detection model, the method further includes: Obtaining preset service call link data, and performing anomaly identification on each of the historical service call links based on a difference between the historical service call link data of each of the historical service call links and the preset service call link data, to obtain a historical anomaly detection result for each of the historical service call links; Accordingly, after using the historical service call link data of each of the historical service call links as training samples to train the service call link anomaly detection model, the method further includes: The service call link anomaly detection model is adjusted by using the historical anomaly detection results corresponding to each of the historical service call links.
4. The method according to claim 3, characterized in that After acquiring the historical service call link data of the plurality of historical service call links, the method further includes: Initially classifying each of the historical service call links according to the historical head nodes in the historical service call links; Calculating the historical distances between the historical service nodes in each of the historical service call links according to the historical service call link data of each of the historical service call links; Clustering each of the historical service call links according to the historical distances between the historical service nodes in each of the historical service call links to obtain at least one historical clustering result for each of the historical service call links; Accordingly, the abnormality identification is performed on each of the historical service call links based on the difference between the historical service call link data of each of the historical service call links and the preset service call link data, to obtain the historical abnormality detection result of each of the historical service call links, including: According to the difference between the historical service call link data of each historical clustering result and the preset service call link data, anomaly identification is performed on each historical clustering result to obtain a historical anomaly detection result of each historical clustering result; Accordingly, the historical service call link data of each of the historical service call links is used as a training sample to train the service call link anomaly detection model, including: The historical service call link data of each historical clustering result is used as a training sample to train the service call link anomaly detection model.
5. The method according to claim 1, characterized in that The real-time acquisition of the current service call link data of the current service call link includes: Obtain the current request response time, current link length, current link topology, current request path, current service node data, and current gateway data of the current service call link in real time; Determining a current link flow direction of the current service call link according to a current link topology structure and a current request path of the current service call link; Filter the current service request status of the current service call link in the current service node data; According to the current gateway data, the current traffic difference of the current service call link is determined.
6. The method according to claim 1, characterized in that After determining the current abnormality detection result of the current service call link, the method further includes: When an abnormality is detected in the current service call link, a link abnormality reminder message is issued.
7. The method according to claim 1, characterized in that The current abnormality detection result includes the current abnormal service call link, the current abnormal service node of the current abnormal service call link, and the current abnormality cause.
8. A service call link anomaly detection device, characterized in that: The device comprises: A link data real-time acquisition module is used to obtain the current service call link data of the current service call link in real time; wherein the current service call link data includes the current link flow direction, current link length, current service request status, current request response time and current traffic difference; The link anomaly detection module is used to use a pre-trained service link anomaly detection model to determine a current anomaly detection result of the current service call link according to the current service call link data of the current service call link.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the service call link anomaly detection method according to any one of claims 1 to 7.
10. A computer program product, characterized in that The computer program product includes a computer program, and when the computer program is executed by a processor, the computer program implements the service call link anomaly detection method according to any one of claims 1 to 7.