Cloud computing based cloud disk data monitoring method and system
By constructing a data access channel in the cloud computing platform, using graph neural networks and dynamic threshold clustering algorithms to identify the spatiotemporal characteristics of cloud disk data, and combining historical baseline data for contextual correlation analysis, standardized event descriptions are generated and transmitted, solving the real-time and accuracy problems of cloud disk data monitoring and improving the efficiency and security of abnormal event handling.
Patent Information
- Application Number
- CN202511134235.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-14
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2045-08-14
AI Technical Summary
Existing cloud disk data monitoring technologies cannot track massive and rapidly changing data in real time and lack accurate anomaly identification capabilities, resulting in low data security and processing efficiency.
By constructing a data access channel in a cloud computing platform, extracting spatiotemporal features using a graph neural network model, identifying abnormal patterns using a dynamic threshold clustering algorithm, performing contextual correlation analysis using historical baseline data, generating standardized event description objects, and sending abnormal event information to the target device through a hybrid transmission channel.
It enables precise location and real-time identification of complex anomaly patterns, improves the accuracy and efficiency of anomaly event handling, and ensures timely response and accurate transmission of anomaly information.
Smart Images

Figure CN120750790B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of cloud computing data monitoring, and particularly relates to a cloud disk data monitoring method and system based on cloud computing. BACKGROUND
[0002] With the rapid development of cloud computing technology, cloud disks are widely used in personal and enterprise scenarios due to their convenient data storage and sharing functions. However, the existing cloud disk data monitoring technology has many defects. On the one hand, the real-time performance of monitoring is insufficient. Because cloud disk data has the characteristics of mass and frequent real-time changes, data access, modification and other operations may occur at any time, and traditional monitoring methods often perform data scanning based on fixed periods or patterns, which is difficult to achieve real-time tracking. At the same time, its technical architecture and processing capacity are not capable of coping with such a large and rapidly changing amount of data, and the data processing speed lags behind the data change speed, which cannot timely capture and respond, and thus cannot timely handle problems, increasing the risk of data leakage, damage and the like. On the other hand, there is a lack of precise abnormality recognition capability. For complex data operation behaviors, it is difficult to accurately determine whether they are abnormal, which may easily result in misjudgment or omission, affecting the normal use of cloud disks by users, and also failing to effectively protect data security. Furthermore, the data processing and analysis efficiency is low. In the face of massive cloud disk data, the existing technology is difficult to efficiently perform data mining and analysis, and cannot timely discover potential security threats and performance problems.
[0003] Chinese patent publication No. CN119922223A discloses an Internet of Things data integration method and system based on dynamic semantic graph and edge collaboration. The method includes the following steps: step one, device access and protocol conversion, the edge node captures the original data of the device, analyzes the communication interval through the LSTM model, and generates a device fingerprint hash value; step two, the device fingerprint is converted into a hash value, the TinyBERT model is used to parse the message structure, the key fields are extracted, and the standard JSON format is converted, and then uploaded to the cloud through the service grid; step three, dynamic semantic graph construction, the cloud collects multi-source metadata, and uses the Transformer model to generate entity relationships; step four, dynamic optimization mapping rule based on reinforcement learning, automatically associates the Pressure field to the database column PSI; step five, edge cloud collaborative optimization, the edge node caches high-frequency data, the temperature reading within 30 seconds is executed locally, and the cloud load is reduced; step six, the cloud end issues the federated learning model parameters, the edge node jointly trains the anomaly detection model, and the result is encrypted and synchronized to the blockchain. The scheme cannot real-time monitor the original data generated in the target monitoring area during the process of accessing the cloud by the device data, effectively extract the spatio-temporal features at the edge, accurately identify the abnormal patterns, and cannot combine the historical baseline data for association analysis to generate standardized event descriptions, so as to timely send the abnormal event information conforming to the device protocol specification to the associated device, resulting in reduced efficiency and accuracy of abnormal event processing. SUMMARY
[0004] To this end, the present application provides a cloud disk data monitoring method and system based on cloud computing, which overcomes the problem that the prior art cannot real-time monitor the original data generated in the target monitoring area during the process of accessing the cloud by the device data, effectively extract the spatio-temporal features at the edge, accurately identify the abnormal patterns, and cannot combine the historical baseline data for association analysis to generate standardized event descriptions, so as to timely send the abnormal event information conforming to the device protocol specification to the associated device, resulting in reduced efficiency and accuracy of abnormal event processing.
[0005] To achieve the above-mentioned purpose, in one aspect, the present application provides a cloud disk data monitoring method based on cloud computing, comprising the following steps:
[0006] S1, based on the real-time monitoring requirement of the target monitoring area, a data access channel is constructed in the cloud computing platform, and original monitoring data is obtained from the target private cloud storage space deployed on the target edge host through the data access channel;
[0007] S2, spatiotemporal feature extraction is performed on the original monitoring data by a graph neural network model built in the target edge host to obtain a multi-dimensional feature vector, and abnormal pattern recognition is performed on the multi-dimensional feature vector based on a dynamic threshold clustering algorithm to obtain a target monitoring abnormality recognition result;
[0008] S3, a dynamic decision engine is constructed in the target edge host, and context correlation analysis is performed on the target monitoring abnormality recognition result and historical baseline data of the target monitoring area according to the dynamic decision engine to generate a standardized event description object containing an abnormal type code and a spatiotemporal coordinate;
[0009] S4, when the standardized event description object meets a preset alarm threshold, a message routing service built by the cloud computing platform converts the standardized event description object into abnormal event information conforming to a target device protocol specification;
[0010] S5, the abnormal event information is sent to a target device associated with the target object through a hybrid transmission channel cooperated by the target edge host and the cloud computing platform.
[0011] Compared with the prior art, the application has the following advantages:
[0012] 1. By using a graph neural network model to extract spatiotemporal features from original monitoring data and combining a dynamic threshold clustering algorithm to identify abnormal patterns, the topological relationship of spatiotemporal data is modeled through a graph structure, which can capture the implicit spatiotemporal correlation in the data, thereby realizing accurate positioning of complex abnormal patterns at the edge, and the dynamic threshold clustering algorithm can adaptively adjust the threshold range according to real-time data distribution, effectively avoiding false positives or false negatives in data fluctuation scenarios. Unlike the prior art which relies on federated learning or general models for anomaly detection, the application directly couples spatiotemporal feature extraction with dynamic clustering, significantly improving the accuracy and real-time performance of edge abnormal pattern recognition;
[0013] 2. The abnormality recognition result is correlated with the historical baseline data of the target monitoring area by a dynamic decision engine to generate a standardized event description object containing an abnormal type code and a spatiotemporal coordinate. This process dynamically adjusts the decision rules and combines the normal behavior patterns in the historical data to filter noise interference and locate the causal relationship of abnormal events, such as distinguishing between device failures and environmental mutations. The standardized event description object ensures the semantic consistency of subsequent processing steps through unified coding and spatiotemporal coordinates. Compared with the prior art which only uses semantic graph construction or field mapping to standardize data, the application avoids the semantic ambiguity problem caused by isolated analysis through context correlation of historical baseline, significantly improving the completeness and explainability of abnormal event description;
[0014] 3. Through the mixed transmission channel and the message routing service, dynamic conversion of the standardized event description object to the target device protocol specification is realized, ensuring that the abnormal event information can accurately adapt to the communication protocol of multiple types of terminal devices. Compared with the fixed transmission mode of synchronizing the federal learning result through the block chain in the prior art, the application can reduce the delay and protocol conversion loss of cross-level transmission through the collaborative optimization of the edge and the cloud platform, especially in the multi-device collaborative monitoring scene, which can ensure the real-time distribution and accurate delivery of abnormal event information, reduce the delay and error of information transmission, improve the efficiency of abnormal event processing, respond to abnormal situations in time, and avoid losses caused by untimely processing.
[0015] Further, the S1 comprises the following steps:
[0016] S11, according to the real-time monitoring requirement of the target monitoring area, dynamically configuring an encryption transmission protocol and a routing strategy in a cloud computing platform, and constructing a data access channel conforming to a security specification according to the encryption transmission protocol and the routing strategy;
[0017] S12, based on the data access channel, establishing an identity authentication session in a target edge host and a target private cloud storage space, determining a secure storage interface through the identity authentication session, and obtaining original monitoring data from the target private cloud storage space on the target edge host through the secure storage interface.
[0018] In the scheme, the real-time monitoring requirement refers to the requirement of continuously and timely obtaining monitoring data of the target monitoring area in order to master the dynamic changes of the area in the first time and discover potential problems in time. The routing strategy refers to the rules and methods for determining the transmission path of data in the network. The target edge host refers to a device located near the target monitoring area and responsible for data processing and storage. The target private cloud storage space refers to a private cloud storage area specially set for the target monitoring area to store the monitoring data of the area.
[0019] By dynamically configuring the encryption transmission protocol and the routing strategy in the cloud computing platform according to the real-time monitoring requirement of the target monitoring area to construct the data access channel, the security and efficiency of data transmission are ensured. Based on the identity authentication session established between the target edge host and the target private cloud storage space and the secure storage interface determined based on the data access channel, the original monitoring data is obtained, ensuring the reliability of the data source and the security of the data acquisition process.
[0020] Further, the S2 comprises the following steps:
[0021] S21, determine a historical monitoring data set according to the format specification of the original monitoring data, and mark the historical monitoring data set as an exception to obtain an exception marked historical monitoring data set, and train the graph neural network model according to the exception marked historical monitoring data set, and output the graph neural network model meeting the preset accuracy as a monitoring exception identification model;
[0022] S22, construct an inference computing environment adapted to the original monitoring data through the monitoring exception identification model, and extract spatio-temporal feature parameters according to the inference computing environment to obtain an analysis engine instance to be triggered;
[0023] S23, input the original monitoring data into the monitoring exception identification model based on the analysis engine instance to be triggered for spatio-temporal feature hierarchical extraction to generate a multi-dimensional feature vector containing a motion trajectory vector and environmental context information;
[0024] S24, perform dynamic threshold clustering analysis on the multi-dimensional feature vector based on a dynamic threshold clustering algorithm, convert the multi-dimensional feature vector meeting the preset exception feature threshold into a structured coding object, and perform type marking and spatio-temporal positioning on the structured coding object to obtain a target monitoring exception identification result.
[0025] In the scheme, the historical monitoring data set refers to a data set preset for training the graph neural network model, which is in the form of a historical monitoring abnormal data set-target monitoring abnormality identification result. The historical monitoring data set after abnormality labeling refers to a historical monitoring data set determined according to the format specification of the original monitoring data, and the data in the data set is marked as abnormal. The graph neural network model refers to a deep learning model that directly processes graph structure data (node and edge relationship) through a message passing mechanism and automatically learns node and graph level feature representation. The preset accuracy rate refers to a preset value of the accuracy rate reflecting the training of the graph neural network model, for example, 95%. The analysis engine instance to be triggered refers to an engine instance for analyzing data prepared to be started in a reasoning computing environment adapted to the original monitoring data through the monitoring abnormality identification model. The spatiotemporal feature parameter refers to a feature parameter related to time and space extracted in a reasoning computing environment adapted to the original monitoring data through the monitoring abnormality identification model. The motion trajectory vector refers to a vector representing the motion trajectory of the monitoring object extracted from the original monitoring data. The environmental context information refers to related information reflecting the monitoring scene environment in the original monitoring data. The dynamic threshold clustering algorithm refers to an algorithm for dynamically determining the threshold of clustering according to the characteristics of the data, clustering the multi-dimensional feature vectors that meet the preset abnormal feature threshold, and converting them into structured coding objects. The structured coding object refers to a coding object with a specific structure formed by converting the multi-dimensional feature vectors that meet the preset abnormal feature threshold, which is convenient for subsequent processing. The preset abnormal feature threshold refers to a feature standard value or range preset for judging whether the monitoring data belongs to an abnormal situation.
[0026] By training the graph neural network model using the historical monitoring data set after abnormality labeling and outputting the monitoring abnormality identification model, accurate identification basis can be provided for subsequent analysis. By constructing an adapted reasoning computing environment using the monitoring abnormality identification model and extracting spatiotemporal feature parameters to obtain an analysis engine instance, the original monitoring data can be efficiently processed. By inputting the original monitoring data into the analysis engine instance to extract multi-dimensional feature vectors and then using the dynamic threshold clustering algorithm to analyze them, the multi-dimensional feature vectors that meet the preset abnormal feature threshold can be converted into structured coding objects and labeled with types and spatiotemporal positioning, achieving accurate target monitoring abnormality identification, effectively improving the accuracy and efficiency of monitoring abnormality identification, and reducing the probability of misjudgment and omission.
[0027] Further, the S22 comprises the following steps:
[0028] S221, analyze the topology of the monitoring abnormality identification model to obtain topology information, and perform time series feature analysis on the original monitoring data to obtain time series feature analysis results, associate and map the topology information and the time series feature analysis results, and generate a dynamic parameter mapping table;
[0029] S222, construct a heterogeneous computing resource scheduling framework based on the dynamic parameter mapping table, and couple and analyze the batch processing size of the original monitoring data and the memory occupation mode of the model inference stage according to the heterogeneous computing resource scheduling framework, to obtain an inference computing environment instance;
[0030] S223, inject a model weight file and a data check code into the inference computing environment instance, to obtain an analysis engine instance to be triggered.
[0031] In the scheme, the dynamic parameter mapping table refers to a table generated by analyzing the topology structure of the monitoring abnormality recognition model and the time sequence characteristics of the original monitoring data, the model weight file refers to a file of parameter values learned by the monitoring abnormality recognition model during training, and the data check code refers to a code for verifying the integrity and accuracy of the original monitoring data.
[0032] The dynamic parameter mapping table is generated by analyzing the topology structure of the monitoring abnormality recognition model and the time sequence characteristics of the original monitoring data, which provides accurate parameter guidance for constructing the inference computing environment. The heterogeneous computing resource scheduling framework is constructed based on the dynamic parameter mapping table, and the batch processing size of the original monitoring data and the memory occupation mode of the model inference stage are coupled and analyzed, to obtain an adaptive inference computing environment instance, which improves the utilization of computing resources and the inference efficiency. The model weight file and the data check code are injected into the inference computing environment instance, which ensures that the model can accurately recognize abnormalities and the data is reliable. Finally, an efficient and accurate analysis engine instance to be triggered is obtained, which improves the performance and reliability of monitoring abnormality recognition.
[0033] Further, the S3 includes the following steps:
[0034] S31, perform spatiotemporal dimension alignment on the target monitoring abnormality recognition result and the historical baseline data of the target monitoring area, to obtain a structured feature vector set;
[0035] S32, construct a dynamic decision engine in the target edge host, and determine a dynamic associated target motion chain and a geographic fence topology structure according to the dynamic decision engine. The structured feature vector set is subjected to neighborhood propagation analysis through the dynamic associated target motion chain and the geographic fence topology structure, to generate an abnormal event candidate cluster containing abnormal behavior pattern encoding;
[0036] S33, input the geometric center and the confidence weight of the abnormal event candidate cluster into a symbolic coding engine according to the monitoring area digital twin model of the target monitoring area, to generate a standardized event description object containing abnormal type encoding and spatiotemporal coordinates.
[0037] In the scheme, the historical baseline data of the target monitoring area refers to the monitoring data set of the target monitoring area in the normal state, the dynamic decision engine refers to the system component built in the target edge host, which can perform dynamic analysis and decision according to real-time data and preset rules, the dynamic associated target motion chain refers to real-time tracking and recording of the motion trajectory of the target in a period of time, forming a series of target motion chains arranged in time sequence, the geofencing topology refers to defining the monitoring area through virtual geographical boundaries and describing the spatial relationship and connection mode between these geographical boundaries, forming a regional network with specific topology, the monitoring area digital twin model refers to digital modeling of the target monitoring area, simulating the physical and logical characteristics of the area, and the symbolic coding engine refers to encoding and processing the geometric center and confidence weight of the abnormal event candidate cluster and other information to generate a standardized event description object.
[0038] By aligning the target monitoring abnormality recognition result and the historical baseline data of the target monitoring area in time and space dimensions to obtain a structured feature vector set, using the dynamic associated target motion chain and the geofencing topology in the dynamic decision engine to perform neighborhood propagation analysis to generate an abnormal event candidate cluster, and combining the monitoring area digital twin model to input the candidate cluster information into the symbolic coding engine to generate a standardized event description object, the abnormal event can be accurately located, the abnormal type and the time and space coordinates are clear, and the efficiency and accuracy of abnormal event processing are effectively improved.
[0039] Further, the S4 comprises the following steps:
[0040] S41, load the preconfigured alarm threshold template through the distributed computing node, and perform sliding window statistics on the standardized event description object according to the alarm threshold template; when the monitoring value of the continuous three sampling periods exceeds the preset alarm threshold, a binary trigger identifier containing a timestamp is generated, and the binary trigger identifier is converted into a structured verification voucher;
[0041] S42, the message routing service built by the cloud computing platform converts the structured verification voucher into abnormal event information conforming to the target device protocol specification.
[0042] In the scheme, the distributed computing node refers to a device or system that is distributed in the network and can independently perform computing tasks, the alarm threshold template refers to a template that is pre-configured and contains alarm threshold and related rules for guiding statistical analysis of the standardized event description object, the preset alarm threshold refers to a value that is pre-set in the alarm threshold template for judging whether the monitoring value is abnormal, the binary trigger identifier refers to a binary form identifier containing a timestamp generated when the monitoring value of three consecutive sampling periods exceeds the preset alarm threshold, the structured verification voucher refers to a voucher that is converted from the binary trigger identifier, has a specific structure and can be used for subsequent verification and processing, the message routing service refers to a service built in the cloud computing platform for forwarding the structured verification voucher to the target device according to certain rules, and the target device protocol specification refers to a communication protocol and specification followed by the target device.
[0043] By loading the pre-configured alarm threshold template on the distributed computing node to perform sliding window statistics on the standardized event description object, abnormal conditions can be captured in a timely manner, and when the monitoring value of three consecutive sampling periods exceeds the preset alarm threshold, a binary trigger identifier is generated and converted into a structured verification voucher, ensuring the accuracy and verifiability of alarm triggering. Then, the message routing service built in the cloud computing platform converts the structured verification voucher into abnormal event information conforming to the target device protocol specification, realizes accurate delivery of abnormal information, and enables the target device to receive abnormal events in a timely and accurate manner and perform corresponding processing.
[0044] Further, the S41 includes the following steps:
[0045] S411, loading a pre-configured alarm threshold template through a distributed computing node to obtain a numerical interval, a sampling period and boundary condition parameters;
[0046] S412, constructing a structured configuration object containing dynamic threshold rules according to the numerical interval, the sampling period and the boundary condition parameters, and performing sliding window statistics on the standardized event description object according to the structured configuration object;
[0047] S413, when the monitoring value of three consecutive sampling periods exceeds the preset alarm threshold, generating a binary trigger identifier containing a timestamp, and performing timestamp information analysis on the binary trigger identifier according to a predefined bit field mapping rule to obtain a structured verification voucher.
[0048] In the scheme, the dynamic threshold rule refers to a rule for dynamically judging whether the monitoring value is abnormal in the sliding window statistics process, which is constructed based on the numerical interval, the sampling period and the boundary condition parameters, and the bit field mapping rule refers to a rule that is pre-defined and used for analyzing the binary trigger identifier containing the timestamp.
[0049] The pre-configured alarm threshold template is loaded by the distributed computing node to obtain parameters, a structured configuration object containing dynamic threshold rules is constructed, and the standardized event description object is subjected to sliding window statistics according to the structured configuration object, so that abnormal conditions can be flexibly and accurately monitored, a binary trigger identifier is generated when the monitoring value of three consecutive sampling periods exceeds the preset alarm threshold, and a structured verification voucher is obtained according to the bit field mapping rule, so that the accuracy of abnormal trigger judgment and the standardization of the verification voucher are ensured.
[0050] Further, the S5 comprises the following steps:
[0051] S51, generating a hybrid transmission channel containing an encryption algorithm identifier, a segmented transmission rule and an edge node relay strategy by the target edge host and the cloud computing platform;
[0052] S52, analyzing the abnormal event information to obtain a metadata dictionary, and performing data slicing on the metadata dictionary according to the hybrid transmission channel to obtain an encrypted data packet set containing a channel identifier and a sequence number;
[0053] S53, determining a transmission path decision algorithm according to the encrypted data packet set, and sending the encrypted data packet set to the access gateway associated with the target device through the optimal link combination path according to the transmission path decision algorithm.
[0054] In the scheme, the encryption algorithm identifier refers to information for identifying the encryption algorithm used in the hybrid transmission channel, the segmented transmission rule refers to specific rules for dividing and transmitting data, such as data packet size limit, division boundary condition, etc., to ensure that data can be efficiently and orderly transmitted in the transmission channel, the edge node relay strategy refers to a transmission strategy that specifies how edge nodes receive, process and forward data in turn in the process of data transmission, the metadata dictionary refers to a dictionary containing key information of data obtained by analyzing the abnormal event information, the transmission path decision algorithm refers to an algorithm for determining the transmission path of the encrypted data packet set, and the optimal link combination path refers to the best transmission path composed of multiple links calculated according to the transmission path decision algorithm.
[0055] The target edge host and the cloud computing platform generate a mixed transmission channel containing an encryption algorithm identifier, a segmented transmission rule and an edge node relay strategy, ensuring the security and reliability of data transmission. The abnormal event information is parsed to obtain a metadata dictionary and data slicing. The mixed transmission channel is used to generate an encrypted data packet set for efficient transmission. The transmission path decision algorithm is determined according to the encrypted data packet set, and the encrypted data packet set is sent to the access gateway associated with the target device through the optimal link combination path, effectively improving the efficiency and stability of data transmission, reducing transmission delay and packet loss rate, and ensuring that abnormal event information can reach the target device in a timely and accurate manner.
[0056] Further, the S53 comprises the following steps:
[0057] S531, parse the data packet set characteristic vector of the encrypted data packet set, and construct a multi-dimensional parameter matrix containing data packet priority, target address and transmission constraint condition according to the data packet set characteristic vector;
[0058] S532, determine the transmission path decision algorithm based on the multi-dimensional parameter matrix, and analyze the encrypted data packet set according to the transmission path decision algorithm to obtain a multi-path candidate scheme sequence;
[0059] S533, link load dynamic evaluation is performed on the multi-path candidate scheme sequence to obtain an optimal link combination path, and the encrypted data packet set is sent to the access gateway associated with the target device through the optimal link combination path.
[0060] In this scheme, the data packet priority refers to an index for measuring the importance and urgency of the encrypted data packet, the target address refers to the address information of the target device to which the encrypted data packet is finally delivered, the transmission constraint condition refers to various limiting conditions that need to be met in the data transmission process, such as transmission delay upper limit, packet loss rate requirement, bandwidth limitation, etc., and the multi-path candidate scheme sequence refers to the data transmission path scheme obtained by analyzing the encrypted data packet set based on the multi-dimensional parameter matrix and the transmission path decision algorithm.
[0061] By parsing the characteristic vector of the encrypted data packet set, a multi-dimensional parameter matrix containing data packet priority, target address and transmission constraint condition is constructed, providing a comprehensive and accurate information basis for subsequent transmission path decision. Based on the multi-dimensional parameter matrix, the transmission path decision algorithm is determined, and a multi-path candidate scheme sequence is obtained by analysis, fully considering the influence of various factors on transmission. Then, the link load dynamic evaluation is performed on the multi-path candidate scheme sequence to obtain an optimal link combination path, and the encrypted data packet set is sent to the access gateway associated with the target device through the optimal link combination path, ensuring that the data packet can be efficiently and stably transmitted on the optimal path according to its priority and transmission constraint condition, improving the efficiency and quality of data transmission, and reducing the transmission risk.
[0062] In another aspect, the present application also provides a cloud disk data monitoring system based on cloud computing, comprising:
[0063] An original monitoring data acquisition module is configured to construct a data access channel in a cloud computing platform according to real-time monitoring requirements of a target monitoring area, and acquire original monitoring data from a target private cloud storage space deployed on a target edge host through the data access channel;
[0064] An anomaly recognition module is configured to perform spatio-temporal feature extraction on the original monitoring data through a graph neural network model built in the target edge host, obtain a multi-dimensional feature vector, and perform anomaly pattern recognition on the multi-dimensional feature vector based on a dynamic threshold clustering algorithm to obtain a target monitoring anomaly recognition result;
[0065] A standardized event description object generation module is configured to construct a dynamic decision engine in the target edge host, and perform context association analysis on the target monitoring anomaly recognition result and historical baseline data of the target monitoring area according to the dynamic decision engine to generate a standardized event description object containing an anomaly type code and a spatio-temporal coordinate;
[0066] A standardized event description object conversion module is configured to convert the standardized event description object into abnormal event information conforming to a target device protocol specification through a message routing service built by the cloud computing platform when the standardized event description object meets a preset alarm threshold;
[0067] An abnormal event information sending module is configured to send the abnormal event information to a target device associated with a target object through a hybrid transmission channel coordinated by the target edge host and the cloud computing platform. BRIEF DESCRIPTION OF DRAWINGS
[0068] Figure 1 FIG. 1 is a flowchart of a cloud disk data monitoring method based on cloud computing according to an embodiment of the present application;
[0069] Figure 2 FIG. 2 is a structural diagram of a cloud disk data monitoring system based on cloud computing according to an embodiment of the present application. DETAILED DESCRIPTION
[0070] The present application will be further described in detail by specific embodiments:
[0071] Please refer to Figure 1 FIG. 1, which is a flowchart of a cloud disk data monitoring method based on cloud computing according to an embodiment of the present application, comprising the following steps:
[0072] S1, constructing a data access channel in a cloud computing platform based on real-time monitoring requirements of a target monitoring area, and obtaining original monitoring data from a target private cloud storage space deployed on a target edge host through the data access channel;
[0073] S2, performing spatio-temporal feature extraction on the original monitoring data through a graph neural network model built in the target edge host to obtain a multi-dimensional feature vector, and performing abnormal pattern recognition on the multi-dimensional feature vector based on a dynamic threshold clustering algorithm to obtain a target monitoring abnormality recognition result;
[0074] S3, constructing a dynamic decision engine in the target edge host, and performing context association analysis on the target monitoring abnormality recognition result and historical baseline data of the target monitoring area according to the dynamic decision engine to generate a standardized event description object containing an abnormal type code and a spatio-temporal coordinate;
[0075] S4, when the standardized event description object meets a preset alarm threshold, converting the standardized event description object into abnormal event information conforming to a target device protocol specification through a message routing service built by the cloud computing platform;
[0076] S5, sending the abnormal event information to a target device associated with the target object through a hybrid transmission channel cooperated by the target edge host and the cloud computing platform.
[0077] Specifically, S1 includes the following steps:
[0078] S11, dynamically configuring an encrypted transmission protocol and a routing strategy in the cloud computing platform according to real-time monitoring requirements of the target monitoring area, and constructing a data access channel conforming to a security specification according to the encrypted transmission protocol and the routing strategy;
[0079] S12, establishing an identity authentication session in the target edge host with the target private cloud storage space based on the data access channel, determining a secure storage interface through the identity authentication session, and obtaining the original monitoring data from the target private cloud storage space on the target edge host through the secure storage interface.
[0080] In this embodiment, the network management module of the cloud computing platform is interacted through an API interface, an encrypted transmission protocol (such as TLS 1.3) is selected according to real-time monitoring requirements, and a routing rule is dynamically generated to ensure that the data access channel conforms to the security specification. The construction of the data access channel needs to be combined with the SDN technology, and the flow table rule is issued through the OpenFlow protocol to realize the encrypted forwarding of the data flow.
[0081] At the target edge host end, an edge computing node needs to be deployed in advance and integrated with a lightweight identity authentication module. When the logical data channel is established, the target edge host initiates an authentication session with the target private cloud storage space through a secure protocol, exchanges digital certificates and verifies permissions. After authentication, the target private cloud storage space returns an access token and an endpoint address of a temporary secure storage interface. The target edge host uses the token to call the secure storage interface through a RESTful API and obtains encrypted raw monitoring data from a specified path. AES-256 encryption needs to be continuously applied during data transmission, and the integrity is guaranteed through a TLS channel.
[0082] Specifically, S2 includes the following steps:
[0083] S21, determine a historical monitoring data set according to a format specification of the raw monitoring data, and perform anomaly labeling on the historical monitoring data set to obtain an anomaly-labeled historical monitoring data set, and train a graph neural network model according to the anomaly-labeled historical monitoring data set, and output the graph neural network model meeting a preset accuracy as a monitoring anomaly recognition model;
[0084] S22, construct an inference computing environment adapted to the raw monitoring data through the monitoring anomaly recognition model, and extract spatio-temporal feature parameters according to the inference computing environment to obtain an analysis engine instance to be triggered;
[0085] S23, input the raw monitoring data into the monitoring anomaly recognition model based on the analysis engine instance to be triggered to perform spatio-temporal feature hierarchical extraction, and generate a multi-dimensional feature vector containing a motion trajectory vector and environmental context information;
[0086] S24, perform dynamic threshold clustering analysis on the multi-dimensional feature vector based on a dynamic threshold clustering algorithm, convert a feature tensor meeting a preset abnormal feature threshold into a structured coding object, and perform type labeling and spatio-temporal positioning on the structured coding object to obtain a target monitoring anomaly recognition result.
[0087] In this embodiment, the data acquisition protocol of the analysis monitoring system (such as RTSP / RTMP streaming format, sensor data protocol) is analyzed, and the timestamp precision, spatial coordinate system and data modal are determined. The original data is sliced according to the time window (such as 1 second / frame) and the spatial region (camera number, grid map partition), and a metadata index table (containing device ID, acquisition time, data type and the like) is established. The abnormal type classification (such as personnel intrusion, equipment failure, environmental mutation) is defined, and the labeling interface is designed to support the time and space range box selection (time axis dragging + space region drawing). The background modeling algorithm (such as GMM) is used to generate the preliminary abnormal candidate region, and the false positives / misses are corrected by manual correction to form the labeling confidence score (0-1 interval) and the abnormal labeled historical monitoring data set. The training method of the graph neural network model is not limited in this embodiment, and the person skilled in the art can freely set it as long as it meets the requirement of abnormal identification of the abnormal labeled historical monitoring data set, such as setting 75% of the abnormal labeled historical monitoring data set as the data training set and 25% as the data test set, inputting the data training set into the graph neural network model for training, inputting the data test set into the trained graph neural network model, optimizing and iterating the parameters in the graph neural network model, and outputting the graph neural network model as a monitoring abnormal identification model when the accuracy of the output result of the data test set of the graph neural network model reaches the preset accuracy.
[0088] In this embodiment, a reasoning computing environment is constructed to adapt to the original monitoring data, and spatio-temporal feature parameters are extracted according to the reasoning computing environment, including analyzing the format specification of the original data (such as video stream resolution, frame rate or sensor data sampling frequency), and constructing a data decoding module to convert the original data into a tensor format (such as RGB image sequence, point cloud data or time series signal) that can be processed by the model. A data preprocessing pipeline is designed, including normalization (such as scaling pixel values to [0, 1]), noise reduction (such as spatial-temporal domain filtering) and enhancement (such as contrast adjustment) to adapt to the model input requirements. Based on the monitoring anomaly recognition model, a lightweight inference engine (such as TensorRT, ONNX Runtime) is deployed to optimize the computation graph structure (such as operator fusion, memory reuse). Convolutional neural network (CNN) or graph convolution network (GCN) is embedded to extract spatial structure features (such as object edges, textures, semantic segmentation results) in single-frame images. A time series modeling unit (such as LSTM, Transformer or 3D convolution) is designed to capture inter-frame motion patterns (such as optical flow changes, trajectory continuity). The monitoring scene is abstracted as a spatio-temporal graph (nodes represent monitoring areas or targets, edges represent spatial adjacency or temporal association), providing topological structure support for graph neural network inference. Spatial feature modules are used to extract static environment parameters (such as scene layout, fixed obstacle position) and dynamic target parameters (such as target detection box coordinates, velocity vector). Time feature modules are used to generate temporal association parameters (such as motion direction consistency, stay duration distribution). The two types of parameters are fused into a spatio-temporal feature tensor as input for subsequent hierarchical extraction.
[0089] When the original monitoring data is input into the monitoring anomaly recognition model for hierarchical extraction of spatio-temporal features, the bottom layer feature extraction module of the monitoring anomaly recognition model uses a backbone network (such as ResNet or GCN) to generate an initial feature map containing target edges, textures and basic motion vectors; the middle layer feature aggregation module performs correlation analysis on the feature maps of consecutive frames through a temporal attention mechanism to extract short-time motion trajectory segments and scene semantic labels; the high layer feature fusion module encodes the target trajectory and scene context into a high-dimensional feature vector based on spatial graph structure information, where the motion trajectory vector records the time sequence of displacement and velocity, and the environment context information includes scene category, obstacle distribution and dynamic group density. Finally, the spatio-temporal dimension information is mapped to a unified multi-dimensional feature vector through a feature reorganization layer.
[0090] The dynamic threshold clustering analysis realizes the screening of abnormal features through an adaptive mechanism. First, the historical feature vectors are clustered online by using a sliding window, the cluster center and boundary are automatically determined by using a density clustering algorithm such as DBSCAN, and the clustering radius parameter is dynamically adjusted according to the data distribution in the window. Then, the distance measure (such as Mahalanobis distance) of the real-time feature vector from the nearest cluster center is calculated, and a dynamic threshold range is generated in combination with the abnormal sensitivity coefficient of the current scene. The multi-dimensional feature vectors that meet the threshold condition enter the structured coding stage, the abnormal types (such as intrusion, loitering) are labeled by using a pre-trained classifier, and the spatio-temporal metadata (timestamp, device ID, coordinate position) are associated. Finally, the target monitoring abnormality recognition result containing the abnormal type, spatio-temporal positioning and confidence score is output.
[0091] Specifically, S22 includes the following steps:
[0092] S221, analyze the topology structure of the monitoring abnormality recognition model to obtain topology information, and perform time series feature analysis on the original monitoring data to obtain time series feature analysis results, associate the topology information with the time series feature analysis results, and generate a dynamic parameter mapping table;
[0093] S222, construct a heterogeneous computing resource scheduling framework based on the dynamic parameter mapping table, and perform coupling analysis on the batch processing size of the original monitoring data and the memory occupation mode of the model inference stage according to the heterogeneous computing resource scheduling framework to obtain an inference computing environment instance;
[0094] S223, inject a model weight file and a data check code into the inference computing environment instance to obtain an analysis engine instance to be triggered.
[0095] In this embodiment, the topology structure of the monitoring abnormality recognition model is analyzed, the graph theory method is used to extract the topology information such as the number of model layers, node connection relationship and data flow direction, and a structured description model is constructed; time series feature analysis is performed on the original monitoring data, statistical features (mean, variance), frequency domain features (FFT transform results) and trend features (linear regression coefficients) are extracted by using a sliding window mechanism, and a multi-dimensional feature vector set is formed; an association mapping mechanism of topology information and feature vectors is established, the feature similarity calculation (such as cosine similarity) is used to match the model structure unit and the data feature dimension, and a parameter mapping table is generated by using a dynamic programming algorithm, the table updates the weight coefficient in real time through a feedback learning mechanism, realizes the dynamic adaptation of the model parameters and the monitoring data features, and ensures that the abnormality recognition model can automatically adjust the detection threshold and the sensitivity according to the data time series characteristics.
[0096] In the coupling analysis stage, a heterogeneous computing resource scheduling framework is constructed based on a dynamic parameter mapping table. The resource scheduling framework calls the resource management module of the cloud platform through the API, dynamically allocates the number of CPU cores and the capacity of GPU memory. The batch size of the original monitoring data is taken as the input, and the memory occupation mode (obtained through the Profiling tool) in the model inference stage is combined to perform multiple stress tests in the simulation environment. The memory consumption and inference delay under different batch sizes are observed, and the optimal configuration is selected to generate an inference computing environment instance.
[0097] In the inference computing environment instance, the pre-trained model weight file is downloaded from the object storage service (such as AWS S3) to the local high-speed storage (such as NVMe SSD) through the secure file transfer protocol (such as SFTP). At the same time, a hash check tool (such as SHA-256) is used to generate a data check code, which is written into a configuration file. When starting the containerized inference service, the loading module reads the weight file and the check code at the same time, verifies the file integrity, and injects it into the TensorFlow Serving process to form an analysis engine instance to be triggered.
[0098] Specifically, S3 includes the following steps:
[0099] S31, aligning the target monitoring anomaly recognition result and the historical baseline data of the target monitoring area in time and space dimensions to obtain a set of structured feature vectors;
[0100] S32, constructing a dynamic decision engine in the target edge host, and determining a dynamic associated target motion chain and a geographic fence topology structure according to the dynamic decision engine, performing neighborhood propagation analysis on the set of structured feature vectors through the dynamic associated target motion chain and the geographic fence topology structure, and generating an abnormal event candidate cluster containing an abnormal behavior pattern code;
[0101] S33, inputting the geometric center and confidence weight of the abnormal event candidate cluster into the symbolic coding engine according to the monitoring area digital twin model of the target monitoring area, and generating a standardized event description object containing an abnormal type code and a space-time coordinate.
[0102] In this embodiment, the time reference and spatial coordinate system of the target monitoring area are established. The synchronization timestamp and latitude and longitude coordinates of the monitoring camera are obtained through the GPS module or the RTSP protocol, and the target monitoring anomaly recognition result (such as the detection box coordinates and the timestamp) in the original monitoring data and the historical baseline data (such as the preset normal behavior time pattern) are projected into the same space-time coordinate system. The coordinate conversion is performed using a spatial database (such as PostGIS) to ensure that all data points have a unified geographic reference. For the time dimension, the non-uniformly sampled data is aligned to a fixed time interval (such as every second) using linear interpolation, forming a set of structured feature vectors.
[0103] In the neighborhood propagation analysis stage, the dynamic decision engine loads the pre-constructed geofence topology (such as polygon area boundary data). By graph algorithm (such as Dijkstra algorithm), the target motion chain (composed of consecutive target position points) and the neighborhood relationship of the geofence are calculated to identify abnormal patterns such as crossing the fence or long-term residence. Using a sliding window mechanism, the structured feature vector is spatiotemporally clustered (such as DBSCAN algorithm) to generate abnormal event candidate clusters containing abnormal behavior pattern codes, and each cluster contains multiple associated target trajectory segments.
[0104] Using the digital twin model (three-dimensional building information model) of the monitoring area, the geometric center (obtained by cluster center calculation) of the abnormal event candidate cluster is mapped to the spatial coordinate system of the model. At the same time, combined with the confidence weight (such as the point density within the cluster) output by the clustering algorithm, the spatiotemporal coordinates and abnormal type code (such as "INTRUSION_ZONE1") are formatted into a JSON object through a rule engine (such as Drools). The symbolic encoding engine verifies the data integrity and publishes the standardized event description object to the event processing bus through the MQTT protocol.
[0105] Specifically, S4 includes the following steps:
[0106] S41, load the pre-configured alarm threshold template through the distributed computing node, and perform sliding window statistics on the standardized event description object according to the alarm threshold template, and when the monitoring value of the continuous three sampling periods exceeds the preset alarm threshold, generate a binary trigger identifier containing a timestamp, and convert the binary trigger identifier into a structured verification voucher;
[0107] S42, the structured verification voucher is converted into abnormal event information conforming to the target device protocol specification through the message routing service constructed by the cloud computing platform.
[0108] Specifically, S41 includes the following steps:
[0109] S411, load the pre-configured alarm threshold template through the distributed computing node to obtain the numerical interval, sampling period and boundary condition parameters;
[0110] S412, construct a structured configuration object containing dynamic threshold rules according to the numerical interval, sampling period and boundary condition parameters, and perform sliding window statistics on the standardized event description object according to the structured configuration object;
[0111] S413, when the monitoring value of the continuous three sampling periods exceeds the preset alarm threshold, a binary trigger identifier containing a timestamp is generated, and the binary trigger identifier is timestamp information parsed according to the pre-defined bit field mapping rule to obtain a structured verification voucher.
[0112] In this embodiment, a configuration management service is deployed in a distributed computing node (such as a Pod in a Kubernetes cluster), which pulls a pre-configured alarm threshold template from a configuration center (such as Consul) through a REST API, parses the numerical interval (such as the temperature range 20-30℃), the sampling period (such as 5 seconds), and the boundary condition parameters (such as the allowed instantaneous fluctuation ±2℃), and calculates the parameters into a rule engine (such as Drools) to build a structured configuration object containing dynamic threshold rules. The engine starts a sliding window statistics module to process the input standardized event description object (containing real-time monitoring values) in a windowed manner. Each window spans three consecutive sampling periods, and the engine continuously compares the monitoring values in the window with the threshold template.
[0113] When it is detected that the monitoring values of three consecutive periods exceed the preset threshold, a bit operation algorithm is used to convert the current timestamp (millisecond level precision) into binary format, and through a bit field mapping rule (such as the high 16 bits representing the second level time and the low 16 bits recording the millisecond offset), it is compressed into a compact binary trigger identifier. Subsequently, the timestamp part of the binary trigger identifier is parsed, and a structured verification credential is generated after verifying the timeliness of the timestamp part of the binary trigger identifier.
[0114] The structured verification credential is protocol-converted by a message routing service (based on Apache Kafka). The message routing service queries a protocol mapping table according to the target device type (such as Modbus or SNMP), encapsulates the structured data into a device-specific message format, and sends it to the field device through a TCP / UDP channel. The entire process needs to record the cross-node call chain in a distributed tracing system (such as Jaeger) to ensure that the fault can be traced back.
[0115] Specifically, S5 includes the following steps:
[0116] S51, generating a hybrid transmission channel containing an encryption algorithm identifier, a segmented transmission rule, and an edge node relay strategy through a target edge host and a cloud computing platform;
[0117] S52, parsing the abnormal event information to obtain a metadata dictionary, and performing data slicing on the metadata dictionary according to the hybrid transmission channel to obtain an encrypted data packet set containing a channel identifier and a sequence number;
[0118] S53, determining a transmission path decision algorithm according to the encrypted data packet set, and sending the encrypted data packet set to the access gateway associated with the target device through the optimal link combination path according to the transmission path decision algorithm.
[0119] Specifically, S53 includes the following steps:
[0120] S531, analyze the feature vector of the encrypted data packet set, and construct a multi-dimensional parameter matrix containing data packet priority, target address and transmission constraint condition according to the feature vector;
[0121] S532, determine a transmission path decision algorithm based on the multi-dimensional parameter matrix, and analyze the encrypted data packet set according to the transmission path decision algorithm to obtain a multi-path candidate scheme sequence;
[0122] S533, dynamically evaluate the multi-path candidate scheme sequence for link load to obtain an optimal link combination path, and send the encrypted data packet set to the access gateway associated with the target device through the optimal link combination path.
[0123] In this embodiment, a secure communication channel is established between the target edge host and the cloud computing platform. The encryption algorithm identifier (such as AES-256-GCM) is negotiated through the TLS handshake protocol, and the segmented transmission rule (such as 1KB per packet) is formulated. The edge node relay strategy is implemented through the SDN controller to issue flow table rules, realizing automatic switching of multi-hop transmission. After the abnormal event information reaches the edge host, the metadata dictionary (including event type, timestamp, etc.) is extracted, and the data is divided into multiple slices according to the segmentation rule. Each slice is attached with a channel identifier (used to distinguish different priority channels) and a sequence number (to ensure ordered recombination), forming an encrypted data packet set.
[0124] The data packet set feature vector of the data packet (such as packet size, target gateway address) is analyzed, a multi-dimensional parameter matrix is constructed, and the multi-dimensional parameter matrix contains data packet priority (high / medium / low), geographical location coordinates of the target address, and transmission constraint condition (such as maximum delay 500ms). The transmission path decision engine loads the pre-trained reinforcement learning model, inputs the multi-dimensional parameter matrix, and calculates the Q value of different paths through the Q-learning algorithm to generate a multi-path candidate scheme sequence. The multi-path candidate scheme sequence needs to be dynamically evaluated by the link load monitoring module, and the bandwidth utilization and packet loss rate of each link are collected in real time through the SNMP protocol. The decision engine selects the path combination with the highest Q value and the load below the threshold (such as 70%), and distributes the encrypted data packet set to the optimal link through the BGP protocol. The data packet set continuously monitors the link state during transmission, and if congestion (such as sudden delay) is detected, a fast reroute mechanism is triggered to switch to a backup path. The entire process needs to record the transmission performance indicators in the time series database (such as InfluxDB) of the edge host for subsequent optimization reference.
[0125] Please refer to Figure 2 As shown in the figure, it is a structural schematic diagram of the cloud disk data monitoring system based on cloud computing of the embodiment of the application, which comprises:
[0126] An original monitoring data acquisition module is configured to build a data access channel in a cloud computing platform according to real-time monitoring requirements of a target monitoring area, and acquire original monitoring data from a target private cloud storage space deployed on a target edge host through the data access channel;
[0127] An anomaly recognition module is configured to perform spatio-temporal feature extraction on the original monitoring data through a graph neural network model built in the target edge host, obtain a multi-dimensional feature vector, and perform anomaly pattern recognition on the multi-dimensional feature vector based on a dynamic threshold clustering algorithm to obtain a target monitoring anomaly recognition result.
[0128] A standardized event description object generation module is configured to build a dynamic decision engine in the target edge host, and perform context association analysis on the target monitoring anomaly recognition result and historical baseline data of the target monitoring area according to the dynamic decision engine to generate a standardized event description object containing an anomaly type code and a spatio-temporal coordinate.
[0129] A standardized event description object conversion module is configured to convert the standardized event description object into abnormal event information conforming to a target device protocol specification through a message routing service built by the cloud computing platform when the standardized event description object meets a preset alarm threshold.
[0130] An abnormal event information sending module is configured to send the abnormal event information to a target device associated with a target object through a hybrid transmission channel cooperated by the target edge host and the cloud computing platform.
[0131] The above is only an embodiment of the present application, and common knowledge of specific structures and characteristics in the scheme is not described in detail. The person skilled in the art knows all the ordinary technical knowledge in the field of the application before the filing date or the priority date, can know all the prior art in the field, and has the ability to apply conventional experimental means before that date. The person skilled in the art can improve and implement the present scheme under the guidance of the present application, and some typical known structures or known methods should not be an obstacle to the implementation of the present application. It should be noted that for those skilled in the art, without departing from the structure of the present application, a number of modifications and improvements can be made, which should be considered as the protection scope of the present application, and these will not affect the effect and practicality of the present application. The protection scope of the present application should be subject to the content of its claims, and the specific implementation mode and the like in the specification can be used to explain the content of the claims.
Claims
1. A cloud disk data monitoring method based on cloud computing, characterized in that: The method comprises the following steps: S1, constructing a data access channel in a cloud computing platform based on the real-time monitoring requirements of the target monitoring area, and obtaining original monitoring data from a target private cloud storage space deployed on a target edge host through the data access channel; S2, performing spatio-temporal feature extraction on the original monitoring data through a graph neural network model built in the target edge host to obtain a multi-dimensional feature vector, and performing abnormal pattern recognition on the multi-dimensional feature vector based on a dynamic threshold clustering algorithm to obtain a target monitoring anomaly recognition result; S3, constructing a dynamic decision engine in the target edge host, and performing context association analysis on the target monitoring anomaly recognition result and historical baseline data of the target monitoring area according to the dynamic decision engine to generate a standardized event description object containing an abnormal type code and a spatio-temporal coordinate; S4, when the standardized event description object meets a preset alarm threshold, converting the standardized event description object into abnormal event information conforming to a target device protocol specification through a message routing service built by the cloud computing platform; S5, sending the abnormal event information to a target device associated with the target object through a hybrid transmission channel cooperated by the target edge host and the cloud computing platform; The S3 comprises the following steps: S31, performing spatio-temporal dimension alignment on the target monitoring anomaly recognition result and the historical baseline data of the target monitoring area to obtain a structured feature vector set; S32, constructing a dynamic decision engine in the target edge host, and determining a dynamic associated target motion chain and a geographic fence topology according to the dynamic decision engine, performing neighborhood propagation analysis on the structured feature vector set through the dynamic associated target motion chain and the geographic fence topology to generate an abnormal event candidate cluster containing an abnormal behavior pattern code; S33, inputting the geometric center and confidence weight of the abnormal event candidate cluster into a symbolic coding engine according to a monitoring area digital twin model of the target monitoring area to generate a standardized event description object containing an abnormal type code and a spatio-temporal coordinate.
2. The cloud computing based cloud disk data monitoring method according to claim 1, characterized in that: The S1 comprises the following steps: S11, dynamically configuring an encrypted transmission protocol and a routing strategy in the cloud computing platform according to the real-time monitoring requirements of the target monitoring area, and constructing a data access channel conforming to a security specification according to the encrypted transmission protocol and the routing strategy; S12, establishing an identity authentication session in the target edge host with the target private cloud storage space based on the data access channel, determining a secure storage interface through the identity authentication session, and obtaining original monitoring data from the target private cloud storage space on the target edge host through the secure storage interface. 3.The cloud computing based cloud disk data monitoring method according to claim 1, characterized in that: The S2 comprises the following steps: S21, determining a historical monitoring data set according to the format specification of the original monitoring data, performing abnormal annotation on the historical monitoring data set to obtain an abnormal annotated historical monitoring data set, and training the graph neural network model according to the abnormal annotated historical monitoring data set, and outputting the graph neural network model meeting the preset accuracy as a monitoring anomaly recognition model; S22, a reasoning computing environment adapted to the original monitoring data is constructed through the monitoring anomaly recognition model, and a spatio-temporal feature parameter is extracted according to the reasoning computing environment, so as to obtain an analysis engine instance to be triggered; S23, the original monitoring data is input into the monitoring anomaly recognition model based on the analysis engine instance to be triggered, so as to extract spatio-temporal features in layers and generate a multi-dimensional feature vector containing a motion trajectory vector and environmental context information; S24, a dynamic threshold clustering algorithm is used for dynamic threshold clustering analysis on the multi-dimensional feature vector, the multi-dimensional feature vector meeting a preset abnormal feature threshold is converted into a structured coding object, and the structured coding object is type-labeled and spatio-temporally positioned, so as to obtain a target monitoring anomaly recognition result.
4. The cloud computing based cloud disk data monitoring method according to claim 3, characterized in that: The S22 includes the following steps: S221, a topology structure of the monitoring anomaly recognition model is analyzed to obtain topology information, and a time sequence feature of the original monitoring data is analyzed to obtain a time sequence feature analysis result, the topology information is associated and mapped with the time sequence feature analysis result, and a dynamic parameter mapping table is generated; S222, a heterogeneous computing resource scheduling framework is constructed based on the dynamic parameter mapping table, and a batch processing size of the original monitoring data is coupled and analyzed with a memory occupation mode in a model reasoning stage according to the heterogeneous computing resource scheduling framework, so as to obtain a reasoning computing environment instance; S223, a model weight file and a data check code are injected into the reasoning computing environment instance, so as to obtain an analysis engine instance to be triggered.
5. The cloud computing based cloud disk data monitoring method according to claim 1, characterized in that: The S4 includes the following steps: S41, a pre-configured alarm threshold template is loaded through a distributed computing node, a sliding window statistics is performed on a standardized event description object according to the alarm threshold template, a binary trigger identifier containing a time stamp is generated when monitoring values of three continuous sampling periods exceed a preset alarm threshold, and the binary trigger identifier is converted into a structured check voucher; S42, the structured check voucher is converted into abnormal event information conforming to a target device protocol specification through a message routing service constructed by a cloud computing platform.
6. The cloud computing based cloud disk data monitoring method according to claim 5, characterized in that: The S41 includes the following steps: S411, a pre-configured alarm threshold template is loaded through a distributed computing node, so as to obtain a numerical interval, a sampling period and boundary condition parameters; S412, a structured configuration object containing a dynamic threshold rule is constructed according to the numerical interval, the sampling period and the boundary condition parameters, and a sliding window statistics is performed on a standardized event description object according to the structured configuration object; S413, a binary trigger identifier containing a time stamp is generated when monitoring values of three continuous sampling periods exceed a preset alarm threshold, and a structured check voucher is obtained by performing time stamp information analysis on the binary trigger identifier according to a pre-defined bit field mapping rule.
7. The cloud computing based cloud disk data monitoring method according to claim 1, characterized in that: The S5 includes the following steps: S51, a hybrid transmission channel containing an encryption algorithm identifier, a segmented transmission rule and an edge node relay strategy is generated through a target edge host and a cloud computing platform; S52, the abnormal event information is analyzed to obtain a metadata dictionary, and the metadata dictionary is data-sliced according to the hybrid transmission channel, so as to obtain an encrypted data packet set containing a channel identifier and a sequence number; S53, determine a transmission path decision algorithm according to the encrypted data packet set, and send the encrypted data packet set to the access gateway associated with the target device through an optimal link combination path according to the transmission path decision algorithm. 8.The cloud-computing-based cloud disk data monitoring method according to claim 7, characterized in that: The S53 includes the following steps: S531, analyze the data packet set characteristics vector of the encrypted data packet set, and construct a multi-dimensional parameter matrix containing data packet priority, target address and transmission constraint conditions according to the data packet set characteristics vector; S532, determine a transmission path decision algorithm based on the multi-dimensional parameter matrix, and analyze the encrypted data packet set according to the transmission path decision algorithm to obtain a multi-path candidate scheme sequence; S533, dynamically evaluate the link load of the multi-path candidate scheme sequence to obtain an optimal link combination path, and send the encrypted data packet set to the access gateway associated with the target device through the optimal link combination path.
9. A cloud computing based cloud disk data monitoring system, characterized in that: It includes: An original monitoring data acquisition module is configured to construct a data access channel in a cloud computing platform according to real-time monitoring requirements of a target monitoring area, and acquire original monitoring data from a target private cloud storage space deployed on a target edge host through the data access channel; An anomaly identification module is configured to extract time-space features of the original monitoring data through a graph neural network model built-in the target edge host to obtain a multi-dimensional feature vector, and identify an abnormal pattern of the multi-dimensional feature vector based on a dynamic threshold clustering algorithm to obtain a target monitoring anomaly identification result; A standardized event description object generation module is configured to construct a dynamic decision engine in the target edge host, and perform context association analysis on the target monitoring anomaly identification result and historical baseline data of the target monitoring area according to the dynamic decision engine to generate a standardized event description object containing an abnormal type code and a time-space coordinate, wherein the context association analysis on the target monitoring anomaly identification result and the historical baseline data of the target monitoring area according to the dynamic decision engine specifically includes: Aligning the target monitoring anomaly identification result and the historical baseline data of the target monitoring area in time-space dimensions to obtain a structured feature vector set; Constructing a dynamic decision engine in the target edge host, and determining a dynamically associated target motion chain and a geofence topology structure according to the dynamic decision engine, performing neighborhood propagation analysis on the structured feature vector set through the dynamically associated target motion chain and the geofence topology structure to generate an abnormal event candidate cluster containing an abnormal behavior pattern code; Inputting the geometric center and confidence weight of the abnormal event candidate cluster into a symbolic coding engine according to a monitoring area digital twin model of the target monitoring area; A standardized event description object conversion module is configured to convert the standardized event description object into abnormal event information conforming to a target device protocol specification through a message routing service built in the cloud computing platform when the standardized event description object meets a preset alarm threshold; An abnormal event information sending module is configured to send the abnormal event information to a target device associated with a target object through a hybrid transmission channel cooperated by the target edge host and the cloud computing platform.
Citation Information
Patent Citations
Internet of Things data integration method and system based on dynamic semantic atlas and edge collaboration
CN119922223A
Network security communication control method and system based on Internet of Things
CN118337539A
Power optical communication network alarm analysis method and system based on time-space diagram neural network
CN119449580A