Cross-platform operation and maintenance replay scene intelligent identification method and cross-platform operation and maintenance replay method

By employing methods of data collection, preprocessing, and feature fusion, and utilizing intelligent recognition models, cross-platform operation and maintenance scenarios are automatically identified. This solves the problems of complex cross-platform operation and maintenance management and low efficiency in replaying scenario recognition, and achieves rapid and accurate operation and maintenance scenario recognition and decision support.

CN120744317BActive Publication Date: 2026-08-04BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING TOPSEC NETWORK SECURITY TECH
Filing Date
2025-06-30
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

Cross-platform operation and maintenance management is complex and inefficient, and the replay scene recognition is inefficient and inaccurate. Existing technologies cannot meet the needs of efficient operation and maintenance.

Method used

By collecting operation and maintenance related data from different platforms in real time, preprocessing, filtering target related feature data, determining time series features, creating new features, extracting key information, performing multi-scale feature fusion, filtering out composite features with the most independent features, and inputting them into the intelligent recognition model for replay scene recognition.

Benefits of technology

It enables rapid and accurate cross-platform operation and maintenance scenario identification, reduces human error, improves operation and maintenance efficiency, provides timely decision support, and meets the needs of efficient operation and maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120744317B_ABST
    Figure CN120744317B_ABST
Patent Text Reader

Abstract

The application discloses a cross-platform operation and maintenance replay scene intelligent identification method and a cross-platform operation and maintenance replay method. The identification method comprises the following steps: collecting operation and maintenance associated data from different platforms in real time, screening target associated feature data from the operation and maintenance associated data after preprocessing, determining time sequence features of the target associated feature data, and creating new features representing potential structures of the data; extracting key information from all the target associated feature data and the new features; extracting multi-scale features from the key information, performing feature fusion on the multi-scale features, and obtaining a plurality of composite features; screening a composite feature with the most independent features related to an identification target operation and maintenance scene from the plurality of composite features, and marking the composite feature as a target feature; and inputting the target feature into a target scene intelligent identification model to obtain a replay scene identification result. The method can automatically, efficiently and accurately identify an operation and maintenance operation scene that can be repeatedly executed between different operating systems and platforms.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of computer technology, and in particular to a cross-platform operation and maintenance replay scenario intelligent recognition method and a cross-platform operation and maintenance replay method. Background Technology

[0002] In today's era, information technology is developing at an unprecedented pace, and enterprise information systems are becoming increasingly complex, involving a variety of different operating systems and platforms. Common operating systems include Windows, Linux, and macOS, each with its own characteristics, unique command-line interfaces, graphical user interfaces, and logging formats. This diversity directly leads to significant differences in operation and maintenance between different operating systems. Each system is equipped with its own dedicated operation and maintenance tools and follows different operation and maintenance processes, making cross-platform operation and maintenance management extremely complex and inefficient.

[0003] Meanwhile, when performing the same operation and maintenance tasks on a multi-core platform, the lack of consistent operating standards further increases the difficulty of operation and maintenance; when the system encounters a failure, the lack of a unified log format and operation record makes troubleshooting and recovery work extremely difficult, greatly prolonging the time for the system to return to normal operation.

[0004] Currently, the industry has adopted some solutions, such as virtualization and container technologies. These technologies have improved the cross-platform compatibility of the system to some extent. However, their focus is mainly on the deployment and operation of applications, and they do not provide sufficient support for the recording and replay of operation and maintenance functions. In addition, most existing replay scenario identification relies on manual analysis, requiring operation and maintenance personnel to manually determine which operations belong to the replayable scenarios. This method is inefficient and prone to errors, and cannot meet the actual needs of efficient operation and maintenance. Summary of the Invention

[0005] In view of this, the present disclosure provides a cross-platform operation and maintenance replay scenario intelligent recognition method and a cross-platform operation and maintenance replay method, which can solve the problems of complex and inefficient cross-platform operation and maintenance management, low replay scenario recognition efficiency and poor recognition accuracy in the prior art.

[0006] In a first aspect, embodiments of this disclosure provide a cross-platform operation and maintenance replay scenario intelligent identification method, including:

[0007] Collect operation and maintenance related data in real time from different platforms;

[0008] The operation and maintenance related data is preprocessed, and target related feature data is filtered out from the preprocessed operation and maintenance related data;

[0009] Determine the time-series features of all the target-related feature data;

[0010] Based on all the aforementioned time series features, create new features that represent the underlying structure of the data;

[0011] Key information is extracted from all the target-related feature data and the new features, including data representing operational characteristics and behavioral patterns.

[0012] Multi-scale features are extracted from the key information, and feature fusion is performed on the multi-scale features to obtain several composite features;

[0013] The composite feature that is most relevant to the target operation and maintenance scenario and contains the most independent features is selected from the composite features described above and is denoted as the target feature.

[0014] The target features are input into the target scene intelligent recognition model to obtain the replay scene recognition result.

[0015] Secondly, this disclosure also provides a cross-platform operation and maintenance replay method, including:

[0016] Collect operation and maintenance related data in real time from different platforms;

[0017] The operation and maintenance related data is preprocessed, and target related feature data is filtered out from the preprocessed operation and maintenance related data;

[0018] Determine the time-series features of all the target-related feature data;

[0019] Based on all the aforementioned time series features, create new features that represent the underlying structure of the data;

[0020] Key information is extracted from all the target-related feature data and the new features, including data representing operational characteristics and behavioral patterns.

[0021] Multi-scale features are extracted from the key information, and feature fusion is performed on the multi-scale features to obtain several composite features;

[0022] The composite feature that is most relevant to the target operation and maintenance scenario and contains the most independent features is selected from the composite features described above and is denoted as the target feature.

[0023] The target features are input into the target scene intelligent recognition model to obtain the replay scene recognition result;

[0024] Based on the replay scene recognition results and the maintenance operations to be performed, maintenance replay is performed.

[0025] Thirdly, this disclosure also provides a computer device, which adopts the following technical solution:

[0026] The computer device includes:

[0027] At least one processor; and,

[0028] A memory communicatively connected to the at least one processor; wherein,

[0029] The memory stores instructions that can be executed by the at least one processor. The instructions are executed by the at least one processor to enable the at least one processor to execute either the cross-platform operation and maintenance replay scenario intelligent recognition method or the cross-platform operation and maintenance replay method described above.

[0030] Fourthly, embodiments of this disclosure also provide a computer-readable storage medium storing computer instructions for causing a computer to execute any of the cross-platform operation and maintenance replay scenario intelligent identification methods or cross-platform operation and maintenance replay methods described above.

[0031] Fifthly, embodiments of this disclosure also provide a computer program product, including a computer program / instructions that, when executed by a processor, implement the steps of any of the methods described above.

[0032] The cross-platform operation and maintenance replay scenario intelligent identification method disclosed in this application collects operation and maintenance related data in real time from different platforms, preprocesses the operation and maintenance related data, and filters out target related feature data from the preprocessed operation and maintenance related data. It can adapt to multiple operating systems and device types, solving the problem of cross-platform operation and maintenance scenario identification. It determines the time series features of all target related feature data, taking into account the changing patterns of operation and maintenance operations over time. Based on all time series features, it creates new features representing the potential structure of the data, which can deeply explore the potential patterns and rules behind the data. These new features are not directly reflected in the original data, but are of great significance for identifying replay scenarios, helping to discover the inherent connections and potential scenario patterns between different operation and maintenance operations. It extracts key information from all target related feature data and new features. The key information includes data representing operation and maintenance operation characteristics and behavioral patterns. It extracts multi-scale features from the key information and performs feature fusion on the multi-scale features. The method involves combining several composite features. From these composite features, the composite feature that is most relevant to the target operation and maintenance scenario and contains the most independent features is selected and denoted as the target feature. This target feature highlights the most representative and distinguishable features, reduces feature redundancy, and improves the accuracy and efficiency of identification. The target feature is then input into the target scenario intelligent identification model to obtain the replay scene identification result. Leveraging the powerful learning and analysis capabilities of the intelligent model, the replay scene can be identified quickly and accurately. Compared with existing manual analysis methods, this method effectively improves identification efficiency, reduces human error, and meets the actual needs of efficient operation and maintenance. This method, through comprehensive data collection, preprocessing, feature extraction, and fusion, mines the potential structure and patterns of the data, enabling the description of operation and maintenance operations from multiple perspectives and granularities, thereby improving the accuracy of replay scene identification. The automated identification process saves time and effort from manual analysis, quickly and accurately identifying operation and maintenance scenarios, providing timely decision support for operation and maintenance personnel, and improving operation and maintenance efficiency.

[0033] The above description is merely an overview of the technical solution disclosed herein. In order to better understand the technical means of this disclosure and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this disclosure more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0034] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0035] Figure 1A flowchart illustrating the intelligent identification method for cross-platform operation and maintenance replay scenarios provided in this embodiment of the disclosure.

[0036] Figure 2 This is a flowchart illustrating a method for obtaining several composite features provided in embodiments of this disclosure.

[0037] Figure 3 This is a flowchart illustrating the method for obtaining replay scene recognition results provided in an embodiment of this disclosure.

[0038] Figure 4 This is a flowchart illustrating the cross-platform operation and maintenance replay method provided in this embodiment of the disclosure.

[0039] Figure 5 This is a flowchart illustrating the method for performing operation and maintenance replay provided in an embodiment of this disclosure.

[0040] Figure 6 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present disclosure. Detailed Implementation

[0041] The embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0042] It should be understood that the following specific examples illustrate the implementation of this disclosure, and those skilled in the art can easily understand other advantages and effects of this disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of this disclosure, and not all of them. This disclosure can also be implemented or applied through other different specific implementation methods, and the details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this disclosure. It should be noted that, in the absence of conflict, the following embodiments and features in the embodiments can be combined with each other. Based on the embodiments in this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0043] It should be noted that various aspects of embodiments within the scope of the appended claims are described below. It will be apparent that the aspects described herein can be embodied in a wide variety of forms, and any particular structure and / or function described herein is merely illustrative. Based on this disclosure, those skilled in the art will understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects set forth herein can be used to implement the device and / or practice the method. Additionally, this device and / or method can be implemented using structures and / or functionalities other than one or more of the aspects set forth herein.

[0044] It should also be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of this disclosure. The drawings only show the components related to this disclosure and are not drawn according to the number, shape and size of the components in actual implementation. In actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.

[0045] Furthermore, specific details are provided in the following description to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.

[0046] Reference Figure 1 The first aspect of this application discloses a cross-platform operation and maintenance replay scenario intelligent recognition method, including:

[0047] The S100 collects operation and maintenance related data in real time from different platforms.

[0048] The operation and maintenance related data includes one or more of the following: system log information, configuration file information, system performance index information, and system event record information.

[0049] Real-time collection of operation and maintenance related data from different platforms enables comprehensive and timely acquisition of various information about system operation, providing a rich data foundation for subsequent analysis and identification, avoiding information loss due to untimely or incomplete data collection, thereby improving the accuracy of identification.

[0050] S200 performs preprocessing on operation and maintenance related data.

[0051] The preprocessing includes one or more of the following: noise removal, outlier removal, and missing value handling. For noisy data, such as error messages in system logs caused by network jitter, a threshold can be set for filtering. For missing values, the mean, median, or estimated values ​​based on context can be used for imputation. For duplicate data, deduplication is performed directly.

[0052] Preprocessing can improve data quality by removing noise and duplicate data, filling in missing values, and making the data cleaner, more accurate, and more consistent. This can reduce errors in subsequent analysis and improve the training effect and recognition accuracy of the model.

[0053] S300 filters out target related feature data from preprocessed operation and maintenance related data.

[0054] Among them, the target-related feature data are the features associated with the operation and maintenance scenarios of the identified target.

[0055] Filtering target-related feature data can reduce the dimensionality of the data, remove irrelevant information, and focus on key data related to the target operation and maintenance scenario. This can reduce the complexity of subsequent analysis and improve the efficiency and accuracy of identification.

[0056] S400, determine the time series features of all target associated feature data.

[0057] The time series features include one or more of the following: the time point of data occurrence, the time period, and the periodic pattern.

[0058] This step, based on the previously selected feature subset, further mines the potential time-related structural information in the data, and links the originally isolated data points through the time dimension to obtain new features that more intuitively reflect the relationship between operation and maintenance related data.

[0059] S500 creates new features that represent the underlying structure of the data based on all time series characteristics.

[0060] Among them, the new features include one or more of the following: the average time difference of operation and maintenance data anomalies, the distribution range of the average time difference and the time difference of operation and maintenance data anomalies, the change pattern of operation and maintenance data within a preset period, and the periodicity pattern of operation and maintenance data.

[0061] New features can uncover the potential structure and patterns in data, providing more information for subsequent feature extraction and analysis. By creating new features, hidden patterns and anomalies in operation and maintenance can be discovered, improving the accuracy and reliability of identification.

[0062] The S600 uses feature extraction technology to extract key information from all target-related feature data and new features.

[0063] The key information includes data representing operational characteristics and behavioral patterns, such as operational characteristics, time characteristics, and user behavior characteristics.

[0064] Feature extraction techniques can reduce the dimensionality of data, extract the most representative key information, and reduce data redundancy and noise. This can improve the training efficiency and recognition accuracy of the model, and also facilitate subsequent feature fusion and analysis.

[0065] S700 extracts multi-scale features from key information and performs feature fusion on the multi-scale features to obtain several composite features.

[0066] Multi-scale features can describe operation and maintenance from different perspectives and granularities, providing more comprehensive information. Feature fusion can integrate features at different scales, giving full play to the advantages of each feature and improving the accuracy and robustness of recognition.

[0067] S800 selects the composite feature that is most relevant to the target operation and maintenance scenario and contains the most independent features from several composite features, and denots it as the target feature.

[0068] Independent features are those whose correlation with other features in a single composite feature is below a preset correlation threshold. Filtering target features can further reduce the number of features, focusing on the most representative and relevant features. This improves the model's training efficiency and recognition accuracy, avoiding overfitting caused by too many features.

[0069] After multi-scale fusion to obtain composite features, these features may constitute a high-dimensional feature space. High-dimensionality means a large number and complexity of features. However, not all of these features are equally important for accurately identifying operational scenarios (such as fault types, operation replay patterns, etc.). Some features may be highly correlated, leading to information redundancy, while others may have little impact on the final identification result. Therefore, techniques such as importance ranking can be used to select the "most relevant and most independent" composite features (or feature subsets) from these fused high-dimensional features. "Most relevant" means that these features are highly correlated with the identification of the target operational scenario, reflecting the essential characteristics of the scenario to the greatest extent; "most independent" indicates low correlation between features, reducing information duplication. The purpose of this is to ensure that the features input to the intelligent identification module can fully represent the operational scenario, guaranteeing identification accuracy, while avoiding the problems of decreased computational efficiency and reduced identification accuracy caused by dimensional redundancy.

[0070] The S900 inputs the target features into the target scene intelligent recognition model to obtain the replay scene recognition result.

[0071] Intelligent recognition models can be used to automatically identify operation and maintenance scenarios, improving the efficiency and accuracy of identification. The models can learn complex patterns and rules in the data, and can handle large amounts of data and complex situations, providing operation and maintenance personnel with timely and accurate identification results.

[0072] The cross-platform operation and maintenance replay scenario intelligent identification method disclosed in this application collects operation and maintenance related data in real time from different platforms, preprocesses the operation and maintenance related data, and filters out target related feature data from the preprocessed operation and maintenance related data. It can adapt to multiple operating systems and device types, solving the problem of cross-platform operation and maintenance scenario identification. It determines the time series features of all target related feature data, taking into account the changing patterns of operation and maintenance operations over time. Based on all time series features, it creates new features representing the potential structure of the data, which can deeply explore the potential patterns and rules behind the data. These new features are not directly reflected in the original data, but are of great significance for identifying replay scenarios, helping to discover the inherent connections and potential scenario patterns between different operation and maintenance operations. It extracts key information from all target related feature data and new features. The key information includes data representing operation and maintenance operation characteristics and behavioral patterns. It extracts multi-scale features from the key information and performs feature fusion on the multi-scale features. The method involves combining several composite features. From these composite features, the composite feature that is most relevant to the target operation and maintenance scenario and contains the most independent features is selected and denoted as the target feature. This target feature highlights the most representative and distinguishable features, reduces feature redundancy, and improves the accuracy and efficiency of identification. The target feature is then input into the target scenario intelligent identification model to obtain the replay scene identification result. Leveraging the powerful learning and analysis capabilities of the intelligent model, the replay scene can be identified quickly and accurately. Compared with existing manual analysis methods, this method effectively improves identification efficiency, reduces human error, and meets the actual needs of efficient operation and maintenance. This method, through comprehensive data collection, preprocessing, feature extraction, and fusion, mines the potential structure and patterns of the data, enabling the description of operation and maintenance operations from multiple perspectives and granularities, thereby improving the accuracy of replay scene identification. The automated identification process saves time and effort from manual analysis, quickly and accurately identifying operation and maintenance scenarios, providing timely decision support for operation and maintenance personnel, and improving operation and maintenance efficiency.

[0073] The intelligent identification method for cross-platform operation and maintenance replay scenarios disclosed in this application is a technical method for automatically identifying replayable operation and maintenance scenarios in cross-platform operation and maintenance environments using intelligent technology. It helps operation and maintenance personnel efficiently and accurately identify repeatable operation and maintenance scenarios across different operating systems and platforms, enabling rapid replay of operation and maintenance operations. This improves the efficiency and accuracy of cross-platform operation and maintenance, reduces the risk of errors caused by manual operation, and better ensures the stable operation of enterprise information systems.

[0074] The methods for S100 to "collect operation and maintenance related data in real time from different platforms" specifically include:

[0075] S110 obtains operation and maintenance related data from operation and maintenance logs and network crawl data from different platforms and environments.

[0076] Obtaining operation and maintenance related data from operation and maintenance logs and network crawling data from different platforms and environments can cover all aspects of system operation, including the internal operating status of the system (such as log information) and external network interaction (such as network traffic data), thereby obtaining more comprehensive operation and maintenance information. By collecting operation and maintenance logs and network data in real time, abnormal situations and potential problems in the system can be detected in a timely manner, providing support for rapid response and handling. Operation and maintenance logs and network data from different platforms and environments have different characteristics and information. Comprehensive utilization of these data can uncover more valuable information, which helps to analyze and solve problems more accurately.

[0077] S120 performs unified format processing on all operation and maintenance related data, and stores all operation and maintenance related data in the target database after the data format is unified.

[0078] Unified format processing ensures that maintenance-related data from different sources and in different formats have a consistent structure and encoding, facilitating subsequent data querying, analysis, and comparison. For example, when conducting cross-platform system performance analysis, a unified data format allows for direct comparison of data from different platforms. Storing formatted data in a target database enables centralized data management and storage, facilitating data backup, recovery, and security control. Simultaneously, the database provides powerful query and indexing capabilities, improving data retrieval efficiency. Unified formatted data is also easier to analyze and mine, allowing various data analysis tools and algorithms to process and analyze the data more conveniently.

[0079] The method for S300 to "select target related feature data from preprocessed operation and maintenance related data" specifically includes: using a preset statistical test method to select target related feature data from preprocessed operation and maintenance related data.

[0080] Among them, all target-related feature data constitute the most relevant feature subset. The most relevant feature subset refers to the set of features that have a significant impact on identifying the target operation and maintenance scenario (such as fault type and operation mode) and have low information redundancy. These features can represent the essence of the scenario to the greatest extent and improve the classification accuracy of the intelligent identification model. Among the selected target-related feature data, there may be data that is not related to time but is related to operation and maintenance.

[0081] In this embodiment, the "creating new features representing the potential structure of data based on all time series features" proposed by S500 is mainly aimed at using time series features to mine potential correlation information between data. In actual operation and maintenance scenarios, many data are closely related to time, such as system performance indicators (such as CPU utilization) and operation and maintenance operation records at different time periods. When these data are observed individually, they may just be isolated points, making it difficult to see the inherent connection between them. By performing time series feature analysis on these data, they can be associated according to the time dimension, thereby discovering some hidden patterns and rules. These patterns and rules can more accurately reflect the essential characteristics of the operation and maintenance scenario, which helps to improve the accuracy of intelligent recognition models in recognizing target operation and maintenance scenarios.

[0082] The following are detailed processing methods for creating new features based on time series features:

[0083] 1) Record time differences; specifically, by calculating the difference between the times of occurrence of two different types of data, we can identify common patterns. For example, in an operations and maintenance scenario, we record the time when a system performance anomaly occurs and the time when operations personnel perform corresponding operations, calculating the time difference between the two. By statistically analyzing a large amount of such time difference data, we can obtain a general pattern of time intervals. Suppose we collect a series of times when the system CPU utilization exceeds a threshold (indicating a performance anomaly), and the times when operations personnel perform restart operations in response to these anomalies. For each set of anomaly occurrence time and restart operation time, we calculate the time difference between them. By statistically analyzing all these time differences, we obtain an average time difference and a distribution range of time differences. This average time difference and distribution range can then be used as new features in subsequent intelligent recognition models to help the model determine how long operations personnel typically take to perform a restart operation when a CPU performance anomaly occurs.

[0084] 2) Data statistics for the same time period: Specifically, the collected data is divided into the same time period (e.g., 24 hours, one week, etc.), and the changes in data within each time period are statistically analyzed to determine the pattern of data change within that time period. This method can help us discover periodic patterns in the data, such as the variation of system performance at different times of the day, or the frequency of maintenance operations at specific times of the week.

[0085] Example: 2.1) By 24-hour period: CPU usage data was collected at different times each day for a month. This data was divided into 24-hour periods, and the average CPU usage per hour was calculated. By analyzing these average CPU usages, peak and off-peak periods of system CPU usage can be identified. For example, peak CPU usage might be found between 10:00 AM and 12:00 PM and between 2:00 PM and 4:00 PM. This peak and off-peak period information can be used as a new feature to determine the system's operating status at different times. 2.2) By week: The number of maintenance operations on different days within a week was calculated. The monthly data was divided into weeks, and the average number of maintenance operations per day from Monday to Sunday was calculated. By analyzing these averages, it can be found that there are patterns where maintenance operations are more frequent on certain specific days. For example, the number of maintenance operations on Fridays might be significantly higher than on other days. This pattern can be used as a new feature to predict the maintenance workload for different days in the future.

[0086] 3) Periodic pattern recognition; Specifically, by performing spectral analysis, autocorrelation analysis and other methods on the data, periodic patterns in the data are identified. Periodic patterns refer to the recurring patterns in the data within a certain time interval, such as periodic changes in system performance on a daily, weekly, or monthly basis. Identifying these periodic patterns can help us better understand the internal structure of the data and provide more valuable information for intelligent recognition models.

[0087] For example, for a long-term collection of system memory usage data, autocorrelation analysis can be used to detect the periodicity of the data. Autocorrelation analysis can calculate the correlation of data at different time delays. By observing the peak position of the autocorrelation function, the period length of the data can be determined. If a significant peak is found in the autocorrelation function at a time delay of 7 days, it indicates that the system memory usage may have a weekly periodic change. Using this periodic information as a new feature can help the model more accurately predict future memory usage.

[0088] 4) Trend analysis; Specifically, by performing operations such as fitting and differencing on the data, we can analyze the trend of data changes over time. Trend analysis can help us understand whether the data is rising, falling, or remaining stable, as well as the rate of change. This trend information can be used as new features to judge the operating status and development trend of the system.

[0089] For example, for continuously collected server disk utilization data, a linear regression method is used to fit the data to obtain a trend line of disk utilization over time. The slope of the trend line is calculated. A positive slope indicates that disk utilization is increasing, and a negative slope indicates that it is decreasing. The absolute value of the slope represents the rate of change. This slope value is used as a new feature to predict the future usage of server disks and to determine whether disk expansion or other operations need to be performed in advance.

[0090] By using these time-series feature-based processing methods, richer information can be extracted from the selected feature subset, creating more representative new features, thereby improving the intelligent recognition model's ability to identify target operation and maintenance scenarios.

[0091] Reference Figure 2 The S700 method of "extracting multi-scale features from key information and fusing these multi-scale features to obtain several composite features," specifically includes:

[0092] S710 extracts time-scale features, numerical-scale features, and category-scale features from key information through a multi-scale extraction method.

[0093] Among them, time scale features are used to determine the periodicity of failure modes or events; numerical scale features are used to characterize the accumulation process of resource pressure or the changes in performance indicators; and categorical scale features are used to locate the specific category of failure type or event.

[0094] Furthermore, time-scale features include the time information of the event's occurrence, which includes both specific time points and time periodicity. For example, in a server failure replay scenario, we meticulously record and analyze the time of server failures. By reviewing a large amount of historical failure data, we discover that failures consistently occur at 3 AM every Monday. This is derived from the statistical analysis and summarization of failure occurrence times over a period of time. We can arrange failure occurrence times by date and time to observe the periodic patterns. Accurate time-scale features can help us determine if a failure pattern is triggered by periodic tasks. In this example, we can infer that certain scheduled tasks may occur at 3 AM every Monday, causing server failures. Based on this pattern, we can check and optimize related periodic tasks or adjust their execution times to prevent recurrence of the failure.

[0095] Furthermore, numerical scaling features include information on the changing trends of numerical indicators in the data. For example, extracting CPU utilization from server monitoring data reveals that before the failure, CPU utilization remained above 90% for two consecutive hours. This was obtained through real-time monitoring of CPU utilization and statistical analysis of historical data. We can calculate the CPU utilization value over different time periods and observe its changing trend. Numerical scaling features clearly characterize the process of resource pressure accumulation. In a server failure replay scenario, two consecutive hours of high CPU utilization indicates that the server resources are already under severe strain, which may be the direct cause of the failure. By analyzing numerical scaling features, we can promptly detect abnormal changes in resource pressure and take corresponding measures, such as increasing server resources and optimizing program code to reduce CPU utilization, thereby preventing server failures due to insufficient resources.

[0096] Furthermore, categorical scale features include categorical information in the data. For example, analyzing server system logs reveals the keyword "OOM Killer." "OOM Killer" is a mechanism triggered in Linux systems when system memory is insufficient, used to kill processes consuming excessive memory. By matching and analyzing keywords in the system logs, we can determine the fault type as memory overflow. Categorical scale features can accurately pinpoint the fault type. In this scenario, after determining the fault type to be memory overflow, we can take targeted measures, such as optimizing memory usage and increasing physical memory, thereby quickly resolving the problem and reducing the impact of the fault on the normal operation of the server.

[0097] S720 encodes and combines time-scale features, numerical-scale features, and categorical-scale features according to preset logic to form composite features.

[0098] For example, following a pre-defined logic, the extracted time-scale features, numerical-scale features, and categorical-scale features are encoded and combined. The time-scale feature "failure occurred every Monday at 3 AM" can be encoded as "period = every Monday at 3 AM," the numerical-scale feature "CPU usage > 90% for 2 consecutive hours before the failure" can be encoded as "CPU trend = > 90% for 2 consecutive hours," and the categorical-scale feature "the keyword 'OOM Killer' appeared in the system log" can be encoded as "log keyword = OOM Killer," ultimately forming a composite feature [period = every Monday at 3 AM, CPU trend = > 90% for 2 consecutive hours, log keyword = OOM Killer]. This encoding combination method connects scattered multi-scale features into a logically related whole, achieving a precise characterization of the operational scenario. In the "server failure replay" scenario, the composite feature integrates information from the time, numerical, and categorical dimensions, allowing operations personnel to comprehensively and clearly understand the background and cause of the failure.

[0099] Reference Figure 3 The method of S900, which "inputs target features into the intelligent recognition model of the target scene to obtain the replay scene recognition result", includes the following methods for obtaining the replay scene recognition result:

[0100] S910, determine the initial neural network model.

[0101] Specifically, in cross-platform operation and maintenance replay scenarios, RNN (Recurrent Neural Network) is preferred as the initial neural network model because RNN is particularly suitable for processing sequential data, and time series data (such as system performance indicators at different points in time) and log file data (log records with a chronological order) in cross-platform operation and maintenance are both sequential data.

[0102] Furthermore, the method for determining the initial neural network model specifically includes: 1) building the model structure; 2) selecting the activation function.

[0103] The specific steps for building the model structure include: 1.1) Building the input layer: The number of neurons in the input layer is determined based on the multi-scale features (i.e., time-scale features, numerical-scale features, and categorical-scale features) extracted in previous steps (such as S710). For example, composite features include time-scale features, numerical-scale features, and categorical-scale features. These features are encoded and used as the input to the input layer. Assuming the dimension of the encoded feature vector is n, the input layer has n neurons. 1.2) Building the hidden layer: RNNs contain recurrent structures. The neurons in the hidden layer can retain historical information in the sequence data through recurrent connections. The number of neurons and the number of layers in the hidden layer can be determined according to the complexity of the data and the performance requirements of the model. Generally, it is advisable to first try setting one hidden layer, and the number of neurons can be experimentally adjusted from tens to hundreds. 1.3) Building the output layer: The number of neurons in the output layer is determined based on the number of classifications of the replayed scene recognition results. For example, if we want to classify system operations, there are m different system operation categories, then the output layer has m neurons.

[0104] When choosing an activation function, tanh or ReLU can be used in the hidden layer to introduce non-linearity and enhance the model's expressive power. The output layer can select an appropriate activation function based on the specific task, such as using the softmax function in classification tasks to convert the output into a probability distribution.

[0105] The S920 trains an initial neural network model using historical feature sets within a preset period, and uses the trained initial neural network model as the target scene intelligent recognition model.

[0106] Specifically, this includes: 1) Data preparation. The historical feature set collected within the preset period (i.e., the composite features extracted and combined in previous steps) is divided into a training set and a test set according to a certain ratio (e.g., 8:2). The training set is used for model training, and the test set is used to evaluate the model's performance. The data is normalized to map feature values ​​of different scales to the same range, such as the [0, 1] interval, in order to speed up model training and improve model stability.

[0107] 2) Execute training. Select an appropriate loss function based on the type of scene recognition task. For example, in classification tasks, the cross-entropy loss function is used to measure the difference between the model's prediction and the true label. Choose a suitable optimization algorithm to update the model's parameters, such as stochastic gradient descent (SGD) or Adam. Input the training set data into the initial neural network model according to a certain batch size for training. In each training cycle, the model updates its parameters using the optimization algorithm based on the loss function calculation results, continuously adjusting the model's weights and biases so that the model's prediction results gradually approach the true label. After each training cycle, evaluate the model using a test set, calculating metrics such as accuracy, precision, and recall. Accuracy refers to the proportion of correctly predicted samples out of the total number of samples; precision refers to the proportion of samples predicted as positive that are actually positive; recall refers to the proportion of samples that are actually positive that were correctly predicted as positive. By continuously adjusting the model's parameters and hyperparameters (such as the number of hidden layer neurons and the learning rate), these evaluation metrics are optimized.

[0108] 3) Model determination. When the model achieves a satisfactory level of evaluation metrics on the test set, this model is used as the target scene intelligent recognition model.

[0109] The S930 inputs the target features into the target scene intelligent recognition model to obtain the replay scene recognition result.

[0110] Specifically, this includes: 1) Inputting the target features (which are also composite features extracted and combined according to the previous steps) that need to be identified in the replay scene into the trained target scene intelligent recognition model; 2) The model calculates and predicts based on the input target features and outputs the replay scene recognition results. The recognition results include the classification of system operations (such as normal operation, abnormal operation, etc.), the marking of abnormal behavior (such as the time point when the system abnormality occurred, the type of abnormality, etc.) or other key information. These recognition results will be used to guide the cross-platform operation and maintenance replay process.

[0111] For example, if the identification results indicate that a certain system operation is an abnormal operation, the replay process can focus on the execution process of that operation and analyze the cause of the anomaly. If the time point and type of the abnormal behavior are marked, the environment in which the abnormal behavior occurred can be simulated during replay to better troubleshoot and repair the problem. By applying machine learning to cross-platform operation and maintenance replay scenarios and using trained models for intelligent identification, the efficiency and accuracy of the replay process can be improved, providing strong support for cross-platform operation and maintenance.

[0112] Reference Figure 4 The second aspect of this application discloses a cross-platform operation and maintenance replay method, including:

[0113] S1 collects operation and maintenance related data in real time from different platforms;

[0114] S2, preprocesses operation and maintenance related data;

[0115] S3, Filter out target related feature data from the preprocessed operation and maintenance related data;

[0116] S4, determine the time series features of all target-related feature data;

[0117] S5, based on all time series features, create new features that represent the underlying structure of the data;

[0118] S6 extracts key information from all target-related feature data and new features. Key information includes data representing operational characteristics and behavioral patterns.

[0119] S7. Extract multi-scale features from key information and perform feature fusion on the multi-scale features to obtain several composite features;

[0120] S8. Select the composite feature that is most relevant to the target operation and maintenance scenario and contains the most independent features from several composite features, and denote it as the target feature.

[0121] S9, input the target features into the target scene intelligent recognition model to obtain the replay scene recognition result;

[0122] S10: Perform operation and maintenance replay based on the replay scene recognition results and the operation and maintenance operations to be performed.

[0123] In this embodiment, the scheme that S1-S9 want to protect is consistent with the intelligent identification method for cross-platform operation and maintenance replay scenarios disclosed in the first aspect of this application. The specific implementation scheme is the same as the aforementioned scheme, so it will not be described in detail here.

[0124] For the method of "performing operation and maintenance replay based on the replay scene recognition results and the operation and maintenance operations to be performed", please refer to [the relevant documentation]. Figure 5 The specific methods for performing operation and maintenance replay include:

[0125] A11 determines the target platform and target environment based on the replay scene recognition results and the operation and maintenance operations to be performed.

[0126] Specifically, based on the operating system type (such as different distributions of Windows and Linux) involved in the replay scene identification results, select the same or compatible operating system platform. For example, if the original maintenance operation was performed on the Ubuntu 20.04 system, then the replay should also select that version or a highly compatible Ubuntu system. Referencing the hardware configuration of the original operation and maintenance scenario, such as the number of CPU cores, memory size, and storage capacity, select an environment with similar hardware resources. If the original operation was performed on a server with an 8-core CPU and 16GB of memory, the replay environment should also be as close to this configuration as possible to ensure the accuracy of the simulation results. Determine the software and tools that the original operation and maintenance operation relied on, and install the same versions of the software on the replay platform. For example, if the original operation used a specific version of the database management system (such as MySQL 8.0) and programming language environment (such as Python 3.8), then the replay environment also needs to install these software. Consider the network environment of the original operation and maintenance scenario, including network bandwidth, network topology, and network security policies. If the original operation was performed in a local area network (LAN) environment, the replay should simulate the same LAN environment as much as possible. If external network access is involved, corresponding network proxies or firewall rules also need to be configured.

[0127] Suppose the replay scenario identification results show that a certain operation and maintenance (O&M) operation is prone to anomalies on a specific cloud platform (such as Alibaba Cloud) and under specific environment configurations (such as 8GB of memory and 4 CPU cores), and the O&M operation to be performed is an upgrade of the online transaction system. Then, the target platform is Alibaba Cloud, and the target environment is an environment with 8GB of memory and 4 CPU cores. Clearly defining the target platform and target environment ensures that the replay operation is performed in an environment similar to the actual situation, improving the accuracy and reliability of the replay results and providing a more targeted basis for subsequent troubleshooting and system optimization.

[0128] A12 simulates the operation and maintenance process to be performed on the target platform and in the target environment, and obtains the simulation results of the operation and maintenance.

[0129] Specifically, on the defined target platform (Alibaba Cloud) and in the target environment (8GB memory, 4 CPU cores), scripts are written and executed according to the steps of the operation and maintenance operation (online transaction system upgrade). The scripts simulate each step of the upgrade process, such as downloading the new version of the system program, stopping the old version of the service, installing the new version of the program, and starting the new version of the service. The system response and operation results of each step are recorded as the simulation results of the operation and maintenance operation.

[0130] A13. Analyze the simulation results of operation and maintenance based on the expected results to obtain the differences in key indicators.

[0131] The key differences include differences in system performance indicators and differences in business function indicators. Specifically, differences in system performance indicators include differences in system memory utilization and CPU utilization, while differences in business function indicators include differences in business response time and business processing success rate.

[0132] System memory usage difference refers to the difference in the proportion of system memory usage before and after a maintenance operation is replayed. For example, if the system memory usage is stable at 30% before the maintenance operation is executed, but rises to 50% after the operation is replayed, then the memory usage difference is 20%. Causes include: the maintenance operation may have triggered memory leaks in the program, preventing memory from being released properly; memory usage may increase as the operation progresses; new maintenance operations may have introduced more business functions or data processing tasks, requiring more memory to support these operations; and the maintenance operation may have changed the system's caching strategy, causing changes in cache memory usage and thus increasing overall memory consumption.

[0133] CPU utilization difference refers to the change in the proportion of CPU usage before and after a maintenance operation is replayed. For example, if the average CPU utilization was 20% before the operation and rose to 60% afterward, the CPU utilization difference is 40%. Reasons for this include: the new maintenance operation may have used more complex algorithms or processing logic, requiring more CPU computation; the operation may have initiated more concurrent tasks, causing the CPU to handle multiple tasks simultaneously, thus increasing CPU utilization; and resource contention between different processes or threads may have led to increased CPU utilization. For example, multiple programs simultaneously vying for CPU time slices will cause the CPU to frequently switch between different tasks, increasing CPU overhead.

[0134] Business response time difference refers to the change in the time it takes for a business system to respond to a user request before and after a maintenance operation is replayed. For example, if the average business response time was 1 second before the operation and became 3 seconds after the operation, then the business response time difference is 2 seconds.

[0135] The difference in business processing success rate refers to the change in the proportion of business requests successfully processed by the business system before and after the operation and maintenance replay. For example, if the business processing success rate was 99% before the operation and dropped to 95% after the operation, then the difference in business processing success rate is 4%.

[0136] Furthermore, the analysis of the simulation results of operation and maintenance can be approached from the following aspects: 1) Functional verification: Check whether the simulation results have achieved the expected functions. For example, if the purpose of the operation and maintenance is to install a new application and make it run normally, then it is necessary to verify whether the application can start successfully and provide normal services; 2) Performance indicator analysis: Focus on the system's performance indicators, such as CPU utilization, memory utilization, disk I / O, network bandwidth, etc., compare the changes of these indicators before and after the simulation, and judge the impact of the operation and maintenance on system performance. If it is found that a certain operation causes a significant increase in CPU utilization, it may be necessary to further analyze the resource consumption of the operation; 3) Log information review: View the system and application log files to obtain detailed operation records and error information. Logs can help locate the specific location and cause of the problem. For example, the log may record the specific error code and related prompts of a command execution failure; 4) Data consistency check: If the operation and maintenance involves data modification or transmission, it is necessary to check the data consistency. For example, after database operations, verify whether the data in the database meets expectations and whether the integrity and accuracy of the data are guaranteed.

[0137] A14: When the differences in key indicators are within the preset range, obtain the simulation environment log information and store it in the review database.

[0138] The preset system response time difference range is ±0.2 seconds, and the business processing success rate difference range is ±0.5%. If the system response time difference obtained from the analysis in S93 is 0.1 seconds and the business processing success rate difference is 0.3%, both are within the preset range. At this time, all log information in the simulation environment is collected, including user operation logs, system response logs, and exception information logs. This log information is stored in the replay database to facilitate subsequent auditing and analysis. By reviewing and analyzing historical logs, lessons learned can be summarized, operation and maintenance strategies can be optimized, and the stability and performance of the system can be improved.

[0139] Furthermore, when the simulation results meet expectations, it indicates that the original operation and maintenance scenario has been successfully reproduced. Users can then perform the following operations: 1) Conduct in-depth analysis of the operation and maintenance process, specifically by analyzing logs, performance indicators, and other information in the simulation environment to identify potential problems or optimization points during the operation and maintenance process. For example, analyze which operation caused the increase in system memory so that improvements can be made in subsequent operation and maintenance work; 2) Summarize lessons learned, specifically by summarizing the successful experiences of this operation and maintenance operation and forming documents or operation guidelines to provide reference for future operation and maintenance work; 3) Develop optimization strategies, specifically by developing corresponding optimization strategies based on the analysis results, such as adjusting system configuration and optimizing application code, to improve system performance and stability.

[0140] A15: When the difference in key indicators is outside the preset range, obtain all the difference information and send the difference information to the target personnel.

[0141] If the system response time difference obtained from S93 analysis is 0.5 seconds and the business processing success rate difference is 1%, both outside the preset range, then all information related to the differences in key indicators should be collected, such as changes in system performance indicators (CPU utilization, memory utilization, etc.) and the execution status of operation steps. This difference information should be sent to the operation and maintenance team leader, system developers, and other target personnel via email, SMS, or system messages. Timely delivery of difference information to target personnel allows them to quickly understand the problems in the system, take timely measures to address them, prevent the problems from escalating, and reduce the impact on business operations.

[0142] In this embodiment, when the simulation results do not meet expectations, it is first necessary to confirm whether the replay environment is consistent with the original operation and maintenance scenario, including the operating system, hardware resources, software dependencies, etc. It is possible that there is a problem with the configuration of the replay environment, which leads to the simulation results not meeting expectations. Check whether there is an error between the user's expectations and the actual situation. It is possible that the user has too high expectations for the results of the operation and maintenance operation, or that there is a misunderstanding of the operation process. Communicate with the user to clarify the correct expected goals. Furthermore, adopt a step-by-step troubleshooting method to decompose the operation and maintenance operation into multiple steps, simulate and analyze them separately, and find out the specific steps and reasons that lead to the results not meeting expectations.

[0143] In this embodiment, the replay system allows operations personnel to quickly replay previous operation processes and reproduce specific operational scenarios. It automatically reproduces the original operational environment, operations, and results, eliminating the tedious steps of setting up the environment. This allows for faster identification of the root cause of problems, reduces troubleshooting time, and improves overall operational efficiency. Utilizing intelligent recognition methods, the system automatically analyzes data and behaviors during the operational process to identify different replay scenarios. This automated scenario recognition helps operations personnel better understand historical operations, avoid repeating mistakes, and optimize operational strategies. By simulating and replaying operational operations on different platforms and environments, potential problems and risks can be identified in advance, ensuring the online trading system can operate stably on different cloud platforms and environments after upgrades, while improving system security and performance. The system monitors the impact of replay operations on the performance of each platform in real time and dynamically adjusts the replay strategy based on monitoring data to optimize resource utilization and reduce operational costs. The system generates detailed replay reports, summarizing replay results and performance data, providing a basis for system optimization and helping the operations team make more scientific and reasonable decisions.

[0144] A third aspect of this application discloses a cross-platform operation and maintenance replay scenario intelligent recognition system, used to execute the cross-platform operation and maintenance replay scenario intelligent recognition method disclosed in this application. The system includes:

[0145] The operation and maintenance related data collection module is used to collect operation and maintenance related data from different platforms in real time.

[0146] The preprocessing module is used to preprocess the operation and maintenance related data and filter out the target related feature data from the preprocessed operation and maintenance related data;

[0147] The time series feature determination module is used to determine the time series features of all target-related feature data;

[0148] The new feature creation module is used to create new features that represent the underlying structure of the data based on all time series features;

[0149] The key information extraction module is used to extract key information from all target-related feature data and new features. Key information includes data representing operational characteristics and behavioral patterns.

[0150] The composite feature extraction module is used to extract multi-scale features from key information and perform feature fusion on the multi-scale features to obtain several composite features.

[0151] The target feature determination module is used to filter out the composite feature that is most relevant to the identified target operation and maintenance scenario and contains the most independent features from several composite features, which is denoted as the target feature;

[0152] The recognition module is used to input target features into the target scene intelligent recognition model to obtain the replay scene recognition results.

[0153] The fourth aspect of this application discloses a cross-platform operation and maintenance replay system for executing the cross-platform operation and maintenance replay method disclosed in this application. The system includes:

[0154] The operation and maintenance related data collection module is used to collect operation and maintenance related data from different platforms in real time.

[0155] The preprocessing module is used to preprocess the operation and maintenance related data and filter out the target related feature data from the preprocessed operation and maintenance related data;

[0156] The time series feature determination module is used to determine the time series features of all target-related feature data;

[0157] The new feature creation module is used to create new features that represent the underlying structure of the data based on all time series features;

[0158] The key information extraction module is used to extract key information from all target-related feature data and new features. Key information includes data representing operational characteristics and behavioral patterns.

[0159] The composite feature extraction module is used to extract multi-scale features from key information and perform feature fusion on the multi-scale features to obtain several composite features.

[0160] The target feature determination module is used to filter out the composite feature that is most relevant to the identified target operation and maintenance scenario and contains the most independent features from several composite features, which is denoted as the target feature;

[0161] The recognition module is used to input target features into the target scene intelligent recognition model to obtain the replay scene recognition results.

[0162] The operation and maintenance replay module is used to replay operation and maintenance based on the replay scenario identification results and the operation and maintenance operations to be performed.

[0163] A computer device according to embodiments of the present disclosure includes a memory and a processor. The memory is used to store non-transitory computer-readable instructions. Specifically, the memory may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM) and / or cache memory. The non-volatile memory may, for example, include read-only memory (ROM), hard disk, flash memory, etc.

[0164] The processor may be a central processing unit (CPU) or other form of processing unit with data processing capabilities and / or instruction execution capabilities, and may control other components in the computer device to perform desired functions. In one embodiment of this disclosure, the processor is used to execute computer-readable instructions stored in the memory, causing the computer device to perform all or part of the steps of the cross-platform operation and maintenance replay scenario intelligent recognition method or cross-platform operation and maintenance replay method described in the foregoing embodiments of this disclosure.

[0165] Those skilled in the art will understand that, in order to solve the technical problem of how to achieve a good user experience, this embodiment may also include well-known structures such as communication buses and interfaces, and these well-known structures should also be included within the protection scope of this disclosure.

[0166] like Figure 6 This is a schematic diagram of a computer device provided for an embodiment of the present disclosure. It illustrates a structural schematic diagram suitable for implementing the computer device in the embodiments of the present disclosure. Figure 6The computer device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0167] like Figure 6 As shown, a computer device may include a processor (such as a central processing unit, graphics processing unit, etc.), which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) or programs loaded from storage devices into random access memory (RAM). The RAM also stores various programs and data required for the operation of the computer device. The processor, ROM, and RAM are interconnected via a bus. Input / output (I / O) interfaces are also connected to the bus.

[0168] Typically, the following devices can be connected to the I / O interface: input devices, such as sensors or visual information acquisition devices; output devices, such as displays; storage devices, such as magnetic tapes or hard drives; and communication devices. Communication devices allow the computer device to communicate wirelessly or wiredly with other devices (such as edge computing devices) to exchange data. Although Figure 6 A computer apparatus with various devices is shown, but it should be understood that it is not required to implement or have all of the devices shown. More or fewer devices may be implemented or included alternatively.

[0169] Specifically, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processor, all or part of the steps of the cross-platform operation and maintenance replay scenario intelligent recognition method or the cross-platform operation and maintenance replay method of the embodiments of this disclosure are performed.

[0170] For a detailed description of this embodiment, please refer to the corresponding descriptions in the foregoing embodiments, which will not be repeated here.

[0171] According to embodiments of the present disclosure, a computer-readable storage medium stores non-transitory computer-readable instructions thereon. When the non-transitory computer-readable instructions are executed by a processor, all or part of the steps of the cross-platform operation and maintenance replay scenario intelligent recognition method or the cross-platform operation and maintenance replay method described in the foregoing embodiments of the present disclosure are performed.

[0172] The aforementioned computer-readable storage media include, but are not limited to: optical storage media (e.g., CD-ROM and DVD), magneto-optical storage media (e.g., MO), magnetic storage media (e.g., magnetic tape or portable hard drive), media with built-in rewritable non-volatile memory (e.g., memory card), and media with built-in ROM (e.g., ROM cartridge).

[0173] For a detailed description of this embodiment, please refer to the corresponding descriptions in the foregoing embodiments, which will not be repeated here.

[0174] The basic principles of this disclosure have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this disclosure are merely examples and not limitations, and should not be considered as essential features of each embodiment of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the aforementioned specific details for implementation.

[0175] In this disclosure, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The block diagrams of devices, apparatuses, devices, and systems involved in this disclosure are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as "comprising," "including," "having," etc., are open-ended terms meaning "including but not limited to," and are used interchangeably with them. The terms "or" and "and" as used herein refer to the terms "and / or," and are used interchangeably with them unless the context clearly indicates otherwise. The term "such as" as used herein refers to the phrase "such as but not limited to," and is used interchangeably with it.

[0176] Additionally, as used herein, the "or" used in a list of items beginning with "at least one" indicates a separate list, such that a list of, for example, "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word "exemplary" does not imply that the described example is preferred or better than other examples.

[0177] It should also be noted that in the systems and methods of this disclosure, the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered as equivalent solutions to this disclosure.

[0178] Various changes, substitutions, and modifications can be made to the technology described herein without departing from the teachings defined by the appended claims. Furthermore, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, events, means, methods, and actions described above. Currently existing or later-developed processes, machines, manufactures, events, means, methods, or actions that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Therefore, the appended claims include such processes, machines, manufactures, events, means, methods, or actions within their scope.

[0179] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.

[0180] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations therein.

Claims

1. A cross-platform operation and maintenance replay scenario intelligent recognition method, characterized in that, include: Collect operation and maintenance related data in real time from different platforms; The operation and maintenance related data is preprocessed, and target related feature data is filtered out from the preprocessed operation and maintenance related data; Determine the time-series features of all the target-related feature data; Based on all the time series features, new features representing the potential structure of the data are created, wherein the new features include one or more of the following: the average time difference of anomalies in operation and maintenance data, the distribution range of the average time difference and the time difference of anomalies in operation and maintenance data, the change pattern of operation and maintenance data within a preset period, and the periodic pattern of operation and maintenance data. Key information is extracted from all the target-related feature data and the new features, including data representing operational characteristics and behavioral patterns. Multi-scale features are extracted from the key information, and feature fusion is performed on the multi-scale features to obtain several composite features. Specifically, this includes: extracting time-scale features, numerical-scale features, and categorical-scale features from the key information using a multi-scale extraction method; encoding and combining the time-scale features, numerical-scale features, and categorical-scale features according to a preset logic to form composite features; wherein, the time-scale features are used to determine the periodicity of fault modes or events; the numerical-scale features are used to characterize the accumulation process of resource pressure or changes in performance indicators; and the categorical-scale features are used to locate the specific category of fault type or event. The composite feature that is most relevant to the target operation and maintenance scenario and contains the most independent features is selected from the composite features described above and is denoted as the target feature. The target features are input into the target scene intelligent recognition model to obtain the replay scene recognition result.

2. The intelligent identification method for cross-platform operation and maintenance replay scenarios according to claim 1, characterized in that, The real-time collection of operation and maintenance related data from different platforms includes: Obtain operation and maintenance related data from operation and maintenance logs and network crawl data from different platforms and environments; All the aforementioned operation and maintenance related data are processed to a unified format, and the unified data format of all the aforementioned operation and maintenance related data is stored in the target database; The operation and maintenance related data includes one or more of the following: system log information, configuration file information, system performance index information, and system event record information.

3. The intelligent identification method for cross-platform operation and maintenance replay scenarios according to claim 1, characterized in that, The step of filtering target related feature data from the preprocessed operation and maintenance related data includes: using a preset statistical test method to filter target related feature data from the preprocessed operation and maintenance related data; The target-related feature data refers to features associated with the operation and maintenance scenario of the identified target.

4. The intelligent identification method for cross-platform operation and maintenance replay scenarios according to claim 1, characterized in that, The step of inputting the target features into the target scene intelligent recognition model to obtain the replay scene recognition result includes: Determine the initial neural network model; The initial neural network model is trained using a historical feature set within a preset period, and the trained initial neural network model is used as a target scene intelligent recognition model. The target features are input into the target scene intelligent recognition model to obtain the replay scene recognition result.

5. A cross-platform operation and maintenance replay method, characterized in that, include: Collect operation and maintenance related data in real time from different platforms; The operation and maintenance related data is preprocessed, and target related feature data is filtered out from the preprocessed operation and maintenance related data; Determine the time-series features of all the target-related feature data; Based on all the time series features, new features representing the potential structure of the data are created, wherein the new features include one or more of the following: the average time difference of anomalies in operation and maintenance data, the distribution range of the average time difference and the time difference of anomalies in operation and maintenance data, the change pattern of operation and maintenance data within a preset period, and the periodic pattern of operation and maintenance data. Key information is extracted from all the target-related feature data and the new features, including data representing operational characteristics and behavioral patterns. Multi-scale features are extracted from the key information, and feature fusion is performed on the multi-scale features to obtain several composite features. Specifically, this includes: extracting time-scale features, numerical-scale features, and categorical-scale features from the key information using a multi-scale extraction method; encoding and combining the time-scale features, numerical-scale features, and categorical-scale features according to a preset logic to form composite features; wherein, the time-scale features are used to determine the periodicity of fault modes or events; the numerical-scale features are used to characterize the accumulation process of resource pressure or changes in performance indicators; and the categorical-scale features are used to locate the specific category of fault type or event. The composite feature that is most relevant to the target operation and maintenance scenario and contains the most independent features is selected from the composite features described above and is denoted as the target feature. The target features are input into the target scene intelligent recognition model to obtain the replay scene recognition result; Based on the replay scene recognition results and the maintenance operations to be performed, maintenance replay is performed.

6. The cross-platform operation and maintenance replay method according to claim 5, characterized in that, The step of performing operation and maintenance replay based on the replay scene recognition result and the operation and maintenance operation to be performed includes: The target platform and target environment are determined based on the replay scene recognition results and the operation and maintenance operations to be performed. The process of simulating the operation and maintenance operations to be performed on the target platform and in the target environment is used to obtain the simulation results of the operation and maintenance operations. The simulation results of the operation and maintenance were analyzed based on the expected results to obtain the differences in key indicators; The differences in key indicators include differences in system performance indicators and differences in business function indicators; When the differences in the key indicators are within a preset range, the simulation environment log information is obtained and stored in the review database; When the difference in the key indicators is outside the preset range, obtain all the difference information and send the difference information to the target personnel.

7. A computer device, characterized in that, The computer device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, which are executed by the at least one processor to enable the at least one processor to perform the cross-platform operation and maintenance replay scenario intelligent recognition method according to any one of claims 1-4 or the cross-platform operation and maintenance replay method according to any one of claims 5-6.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing the computer to execute the cross-platform operation and maintenance replay scenario intelligent recognition method according to any one of claims 1-4 or the cross-platform operation and maintenance replay method according to any one of claims 5-6.

9. A computer program product comprising computer instructions, characterized in that, When executed by the processor, the computer instruction implements the steps of the intelligent recognition method for cross-platform operation and maintenance replay scenarios as described in any one of claims 1-4 or the cross-platform operation and maintenance replay method as described in any one of claims 5-6.