Software system operation anomaly detection method, device, equipment, medium and product
By utilizing convolutional neural networks, long short-term memory networks, and attention networks in deep learning models, the inaccuracy of traditional software performance testing methods is addressed, achieving high accuracy and timeliness in detecting software system anomalies and ensuring system stability.
Patent Information
- Application Number
- CN202511003482.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-21
- Publication Date
- 2025-11-07
AI Technical Summary
Traditional methods for detecting software performance anomalies based on thresholds and statistical analysis are inaccurate in complex and ever-changing software operating environments and massive amounts of performance data, with a high false positive rate, making it difficult to meet the stability and reliability requirements of software systems.
Deep learning models, including convolutional neural networks, long short-term memory networks, and attention networks, are used to acquire performance index data sequences through a preset acquisition frequency. The data to be detected is determined using time windows and step sizes, and feature extraction, temporal dependency modeling, and attention weight calculation are performed to finally generate anomaly detection results.
It improves the accuracy, reliability, and timeliness of detecting software system malfunctions, enabling more accurate identification of performance anomalies, reducing false positives, and ensuring system stability.
Smart Images

Figure CN120909823A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the technical field of computer technology, and particularly relate to a software system running anomaly detection method, device, equipment, medium and product. BACKGROUND
[0002] With the increasing complexity and large-scale application of software systems, the influence of software performance problems on user experience and system stability is increasingly significant. Traditional software performance anomaly detection methods based on threshold and statistical analysis often have problems such as insufficient detection accuracy and high false positive rate when facing complex and variable software running environments and massive performance data. SUMMARY
[0003] Embodiments of the present application provide a software system running anomaly detection method, device, equipment, medium and product, which can improve the accuracy, reliability and timeliness of software system running anomaly detection through a deep learning model.
[0004] In a first aspect, embodiments of the present application provide a software system running anomaly detection method, which comprises:
[0005] acquiring a data sequence corresponding to at least one performance indicator of a server running a software system according to a preset acquisition frequency;
[0006] determining to-be-detected data in the data sequence according to a preset time window length and step;
[0007] inputting the to-be-detected data into a pre-trained anomaly detection model to obtain an anomaly detection result;
[0008] The anomaly detection model comprises a convolutional neural network, a long short-term memory network and an attention network.
[0009] In a second aspect, embodiments of the present application provide a software system running anomaly detection device, which comprises:
[0010] a data acquisition module configured to acquire a data sequence corresponding to at least one performance indicator of a server running a software system according to a preset acquisition frequency;
[0011] a to-be-detected data determination module configured to determine to-be-detected data in the data sequence according to a preset time window length and step;
[0012] an anomaly detection result determination module configured to input the to-be-detected data into a pre-trained anomaly detection model to obtain an anomaly detection result;
[0013] The anomaly detection model comprises a convolutional neural network, a long short-term memory network and an attention network.
[0014] In a third aspect, the embodiments of the present application further provide a computer device, which comprises:
[0015] one or more processors;
[0016] a memory for storing one or more programs;
[0017] When the one or more programs are executed by the one or more processors, the one or more processors implement the software system running abnormality detection method provided by any of the embodiments of the present application.
[0018] In a fourth aspect, the embodiments of the present application further provide a computer readable storage medium, which stores a computer program, and the program is executed by a processor to implement the software system running abnormality detection method provided by any of the embodiments of the present application.
[0019] In a fifth aspect, the embodiments of the present application further provide a computer program product, which comprises a computer program, and the computer program is executed by a processor to implement the software system running abnormality detection method provided by any of the embodiments of the present application.
[0020] The embodiments of the above application have the following advantages or beneficial effects:
[0021] In the embodiments of the present application, at least one performance index of a server running a software system is acquired according to a preset acquisition frequency to obtain a data sequence corresponding to the performance index; the data to be detected is determined in the data sequence according to a preset time window length and a step; and the data to be detected is input into a pre-trained abnormality detection model to obtain an abnormality detection result; wherein the abnormality detection model comprises a convolutional neural network, a long short-term memory network and an attention network. The technical scheme of the embodiments of the present application solves the problem of low accuracy of software system running abnormality detection, and can improve the accuracy, reliability and timeliness of abnormality detection by collecting data sequences and predicting through a deep learning model. BRIEF DESCRIPTION OF DRAWINGS
[0022] Figure 1 is a flowchart of a software system running abnormality detection method provided by the embodiments of the present application;
[0023] Figure 2 is a flowchart of a software system running abnormality detection method provided by the embodiments of the present application;
[0024] Figure 3 is a schematic diagram of an abnormality detection model provided by the embodiments of the present application;
[0025] Figure 4 is a schematic diagram of an abnormality detection model training process provided by the embodiments of the present application;
[0026] Figure 5 is a structural schematic diagram of a software system running abnormality detection device provided by an embodiment of the present application.
[0027] Figure 6 is a structural schematic diagram of a computer device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0028] The present application will be further described below in conjunction with the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present application, but not to limit the present application. In addition, it should be noted that, for the convenience of description, only the parts related to the present application are shown in the drawings, but not all the structures.
[0029] Figure 1 is a flowchart of a software system running abnormality detection method provided by an embodiment of the present application. The embodiment can be applicable to the scenario of software system running abnormality detection. The method can be executed by a software system running abnormality detection device. The device can be realized by software and / or hardware, and integrated in a computer device with application development function.
[0030] As shown in Figure 1 , the software system running abnormality detection method of the embodiment includes the following steps:
[0031] S110, acquiring a data sequence corresponding to at least one performance index of a server running a software system according to a preset acquisition frequency.
[0032] The software system can be at least one field software system, such as a software system in the fields of finance, medical treatment, transportation and e-commerce, etc. Software performance abnormality can cause problems such as slow system response, service interruption, data loss, etc., which can bring huge economic losses and adverse effects to enterprises and users. Therefore, timely and accurate detection and discovery of software performance abnormality is of great significance to guarantee the reliability and stability of the software system.
[0033] The server running the software system is the physical carrier of software running. The code logic, resource scheduling, interaction design, etc. of the software can be reflected through the performance data of the server. Therefore, the embodiment acquires a data sequence corresponding to at least one performance index of a server running a software system, and determines whether there is an abnormality in the running of the software system through abnormality analysis on the data sequence. The performance index can include CPU usage, memory occupation, disk I / O, network bandwidth, response time, throughput and the number of concurrent users, etc.
[0034] For example, by deploying performance monitoring tools and agents such as Prometheus, Grafana, etc. in the software system, setting a preset collection frequency according to the system requirements, collecting the performance indicator data of the server in real time, and storing the collected performance data in a time series database for subsequent data processing and analysis.
[0035] S120, determining the to-be-detected data in the data sequence according to the preset time window length and step.
[0036] The data sequence is preprocessed, including data cleaning, data normalization, and time series alignment. The time window length can be the number of data points or the time span contained in a single window, which determines the data range of the input model. The step can be the interval when the window slides, which determines the overlap degree or interval distance of adjacent two windows. Starting from the starting position of the data sequence, a data segment with a length of the preset time window length is intercepted as the first to-be-detected data window, and the window is moved according to the preset step to intercept the next data segment, and the process is repeated until the entire data sequence is covered. The data segment intercepted by each window is the to-be-detected data.
[0037] S130, inputting the to-be-detected data into the pre-trained anomaly detection model to obtain an anomaly detection result.
[0038] The anomaly detection model includes a convolutional neural network, a long short-term memory network, and an attention network.
[0039] The anomaly detection model learns the performance indicator features in normal and abnormal states during the training process. In the prediction stage, the convolutional neural network extracts features from the input to-be-detected data, the long short-term memory network determines the hidden state, and the attention network determines the weighted weight. Finally, the weighted sum is obtained according to the weight to obtain the anomaly judgment score or probability of the data corresponding to each performance indicator. The anomaly detection result is determined according to the anomaly judgment score or probability and the corresponding threshold.
[0040] The technical scheme of the embodiment, by collecting the data sequence of at least one performance indicator of the server running the software system according to the preset collection frequency; determining the to-be-detected data in the data sequence according to the preset time window length and step; inputting the to-be-detected data into the pre-trained anomaly detection model to obtain an anomaly detection result; wherein the anomaly detection model includes a convolutional neural network, a long short-term memory network, and an attention network. The technical scheme of the embodiment of the application solves the problem of low accuracy of software system running anomaly detection, and can improve the accuracy, reliability, and timeliness of anomaly detection by collecting data sequences and predicting through a deep learning model.
[0041] Figure 2A flowchart of a software system running exception detection method provided by the embodiment of the application, the embodiment and the software system running exception detection method in the above embodiments belong to the same inventive concept, and further describes the process of generating an exception detection result. The method can be executed by a software system running exception detection device, which can be realized by software and / or hardware and integrated in a computer device with application development function.
[0042] As shown in Figure 2 , the software system running exception detection method of the embodiment includes the following steps:
[0043] S210, obtaining a data sequence corresponding to at least one performance index of a server running a software system according to a preset acquisition frequency.
[0044] In the embodiment, after obtaining the data sequence corresponding to the at least one performance index, the data sequence is preprocessed. For example, through denoising techniques such as wavelet transform and Fourier transform, noise interference in the data is eliminated.
[0045] The wavelet transform can be represented by the following formula:
[0046] y=WaveletTransform(x,threshold);
[0047] Wherein, x is the original data, y is the denoised data, and threshold is the denoising threshold.
[0048] After denoising, linear interpolation and other methods can be used to supplement missing data to ensure the continuity of the data.
[0049] The embodiment can also convert performance index data of different dimensions to a unified numerical interval (such as [0, 1]) to facilitate subsequent input into the exception detection model for analysis.
[0050] The normalization can use the following formula:
[0051]
[0052] Wherein, X min and X max are the minimum and maximum values of the index, respectively.
[0053] The embodiment can also ensure that all performance index data sequences have the same sampling rate and timestamp through interpolation and other methods, which facilitates subsequent model input.
[0054] S220, determining the to-be-detected data in the data sequence according to a preset time window length and step.
[0055] S230, input the to-be-detected data into the pre-trained anomaly detection model, perform feature extraction on the to-be-detected data through a convolutional neural network of the anomaly detection model, and obtain a feature extraction result.
[0056] In order to fully tap the complex features and potential patterns of performance data, a convolutional neural network (CNN) layer is constructed to extract local features of time series data, a long short-term memory (LSTM) layer is constructed to capture long-term dependencies, and an attention network (Attention) layer is constructed to automatically focus on important historical information, and finally weighted summation is performed.
[0057] The convolutional neural network can perform feature extraction on the to-be-detected data through different sizes of convolution kernels to obtain a feature extraction result.
[0058] In an optional implementation, the feature extraction on the to-be-detected data through the convolutional neural network of the anomaly detection model can be performed to obtain a feature extraction result, which can be performed through a convolution layer of the convolutional neural network of the anomaly detection model to extract features and perform nonlinear activation on the to-be-detected data to obtain a convolution layer processing result; and a pooling layer of the convolutional neural network can be used to perform feature dimension reduction on the convolution layer processing result to obtain the feature extraction result.
[0059] As shown in Figure 3 The input layer is used to input the software performance data processed by the data, i.e., to-be-detected data, the convolution layer and the pooling layer of the CNN neural network perform feature extraction, the convolution layer completes the feature extraction process by setting different convolution kernels, and different convolution kernels extract different features from the data.
[0060] The formula of the convolution kernel is:
[0061] Conv(x)=ReLU(W*x+b);
[0062] Wherein, W is the weight of the convolution kernel, * represents the convolution operation, and b is the bias term.
[0063] The convolution kernel introduces a nonlinear ReLU activation function, so that the output of the network is not only a simple linear combination of the input, which can effectively alleviate the problem of gradient disappearance and help the regularization of the model. The concept of the ReLU function is that when the input is less than 0, the output is 0, otherwise the output is itself. The formula of the ReLU is as follows:
[0064] f(x)=max{0,x};
[0065] The CNN pooling layer mainly performs feature dimension reduction processing on the results of the nonlinear activation, i.e., the convolution layer processing result, to obtain the feature extraction result, so as to reduce the number of features to avoid overfitting and improve the processing efficiency of the model.
[0066] S240, performing time sequence dependence modeling processing on the feature extraction result by a long short-term memory network of the anomaly detection model to obtain a hidden state.
[0067] The current state of time series data is often related to the historical state. LSTM captures the dependence on the historical state through special gating mechanisms such as input gate, forget gate and output gate, and is suitable for processing long sequences. The output of LSTM at each time step is a fusion representation of the input features and the historical hidden state at that moment, which contains the accumulation of time series information up to the current moment. The final hidden state sequence can be used to reflect the dynamic pattern of the entire feature sequence.
[0068] In an optional implementation, the hidden state can be obtained by performing time sequence dependence modeling processing on the feature extraction result by a long short-term memory network of the anomaly detection model.
[0069] The LSTM layer receives the multi-dimensional features extracted by the CNN layer as input. The LSTM layer updates the cell state and the hidden state through the gating mechanism, and the cell state is the memory state, thereby realizing effective modeling of the time series and capturing the complex feature relationship of long and short time series. The calculation formula is as follows:
[0070] i t =σ(W i x t +U i h t-1 +b i );
[0071] f t =σ(W f x t +U f h t-1 +b f );
[0072] o t =σ(W o x t +U o h t-1 +b o );
[0073] c t =f t ⊙c t-1 +i t ⊙tanh(W c x t +U c h t-1 +b c );
[0074] h t =o t ⊙tanh(c t );
[0075] where i t , f t , o t are input gate, forget gate and output gate respectively, c t is cell state, h t is hidden state.
[0076] S250, attention weight calculation is performed on the hidden state by the attention network of the anomaly detection model to obtain the attention weight of the hidden state at each time step.
[0077] The attention layer receives the output hidden state of the LSTM layer as input and calculates the attention weight of the hidden state at each time step, which represents the contribution degree of different time steps to the prediction result:
[0078]
[0079] where e t is the attention score of time step t, and a t is the attention weight.
[0080] S260, the hidden state is weighted and summed by the fully connected layer of the anomaly detection model according to the attention weight to obtain the anomaly detection result.
[0081] Then in the fully connected layer, i.e. the SoftMax layer, the output hidden state of the LSTM layer is weighted and summed using the attention weight output by the attention layer to obtain the final prediction result.
[0082] In an optional implementation, the hidden state is weighted and summed by the fully connected layer of the anomaly detection model according to the attention weight to obtain the anomaly detection result, which can be that the hidden state is weighted and summed by the fully connected layer of the anomaly detection model according to the attention weight to obtain the anomaly score of the data corresponding to each performance indicator in the to-be-detected data; the mean and standard deviation of the to-be-detected data are calculated, and the anomaly judgment threshold is determined according to the mean and standard deviation; in the case that the anomaly score of the data corresponding to at least one performance indicator exceeds the anomaly judgment threshold, it is determined that the anomaly detection result is abnormal.
[0083] The data corresponding to different performance indicators correspond to different anomaly prediction thresholds. First, the mean and standard deviation are calculated based on the sliding window, and the window size determines the length of the historical data that the model can refer to each time it predicts, dynamically adjusts the threshold of anomaly prediction, and the anomaly judgment threshold calculation formula is as follows:
[0084] Threshold = [μ - kσ, μ + kσ];
[0085] wherein μ and σ are the mean and standard deviation in the sliding window respectively, and k is the confidence interval coefficient;
[0086] The output result of the model is compared with the abnormal score or probability of the data corresponding to each performance indicator in the detection data and the dynamic threshold, i.e., the abnormal judgment threshold, to determine whether the current performance data, i.e., the detection data, is abnormal. The calculation formula is as follows:
[0087]
[0088] wherein p is the confidence of the model output.
[0089] If the abnormal score y output by the model exceeds the dynamic threshold Threshold, it indicates that there is a risk of system failure, and an alarm needs to be given to prompt the system operation personnel to troubleshoot. pred The embodiment fuses LSTM and CNN deep learning architectures and adds an attention mechanism to fully combine the advantages of each other, build an efficient model suitable for software performance anomaly prediction tasks, solve the problem that traditional methods cannot deeply mine complex features and potential patterns in performance indicator data, automatically adjust the threshold according to the actual distribution of performance data, avoid the limitation of manually setting a fixed threshold in traditional methods, and effectively adapt to different software systems and operating environments.
[0090] In an optional embodiment, the training process of the anomaly detection model can be to determine the detection sample data, train the anomaly detection initial model according to the detection sample data, and update the model parameters of the anomaly detection initial model through the back propagation algorithm until the loss function value is less than the preset error threshold, to obtain the anomaly detection model.
[0091] The performance data of the server running the software system is collected in real time, and the collected data can be divided into a test set, a training set, and a validation set according to a preset proportion, for example, 70% is divided into a training set, 15% is divided into a test set, and 15% is divided into a validation set. The test set is used to evaluate the performance indicators, the training set is used to train the anomaly detection initial model, the data in the training set is the detection sample data, and the validation set is used to adjust the model parameters. For example, Figure 4As shown, the constructed network model is trained using the pre-processed training set and target output, and is optimized using a back propagation algorithm. The back propagation algorithm calculates the derivative of the loss function as the gradient of the network parameter update, then multiplies the gradient by the learning rate as the actual update value of the model parameter, i.e., the network parameter, so as to continuously reduce the loss function value of the network model, until the loss function value e calculated according to the actual output and the target output is less than a preset error threshold, or a preset iteration number is reached, to obtain an anomaly detection model.
[0092] The loss function can be a mean squared error (MSE) loss function, which is mainly aimed at regression problems to minimize the distance of each training point from the optimal fitting line. The mean squared error loss function is expressed as the square of the difference between each real value and the predicted value, and then the mean is removed. f(x) is the network prediction value, y is the real value, and θ is the network parameter. The mean squared error cost function is shown in the following formula:
[0093]
[0094] In the training process, an adaptive optimization algorithm such as Adam can also be used to utilize past gradients to speed up learning, and simultaneously increase the first-order momentum m t of the gradient and the second-order momentum t-1 of the gradient based on SGD. t This adjusts the learning rate corresponding to each network parameter, and β1 is set to 0.9 by default, and β2 is set to 0.999 by default.
[0095] The initial values of m and v are 0, which makes m t and v t tend to 0 at the beginning of network model training, so bias correction is needed for m t and v t , and their formulas are shown in the following formulas, respectively:
[0096]
[0097] Finally, the corrected values are used to update the network parameters, as shown in the following formula:
[0098]
[0099] The learning rate α is set to 0.001 by default, and the hyperparameter ε is set to 10 -8 by default.
[0100] Therefore, in the training process, the Adam optimization algorithm and the mean squared error loss function are used to minimize the loss function of the model on the training set to determine the final model parameters and obtain an anomaly detection model.
[0101] Finally, the results of the application stage anomaly judgment are fed back to the model training process for further optimization of the model. If some abnormal conditions are found to be not correctly identified in actual detection, these data can be re-included in the training set, and the model is re-trained to improve the detection ability of the model, so that the model can continuously adapt to new data and abnormal patterns, and maintain good prediction performance. The anomaly detection model trained in this embodiment can automatically adjust parameters according to historical performance data during the training process, and adapt to different software systems and running environments.
[0102] The technical scheme of this embodiment comprises the following steps: acquiring a data sequence corresponding to at least one performance indicator of a server running a software system according to a preset acquisition frequency; determining to-be-detected data in the data sequence according to a preset time window length and step; inputting the to-be-detected data into a pre-trained anomaly detection model, performing feature extraction on the to-be-detected data through a convolutional neural network of the anomaly detection model to obtain a feature extraction result; performing time sequence dependence modeling processing on the feature extraction result through a long short-term memory network of the anomaly detection model to obtain a hidden state; performing attention weight calculation on the hidden state through an attention network of the anomaly detection model to obtain an attention weight of the hidden state at each time step; and performing weighted summation on the hidden state according to the attention weight through a fully connected layer of the anomaly detection model to obtain an anomaly detection result. The technical scheme of the embodiment of the application solves the problem of low accuracy of current software system running anomaly detection, and can acquire data sequences and perform prediction through a deep learning model combining a convolutional neural network, a long short-term memory network and an attention network, so as to exert the prediction advantages of different networks and improve the accuracy, reliability and timeliness of anomaly detection.
[0103] Figure 5 A structural schematic diagram of a software system running anomaly detection device provided by the embodiment of the application is shown in the figure. The embodiment of the application can be applied to the scene of software system running anomaly detection. The software system running anomaly detection device can be realized by software and / or hardware, and integrated in a computer terminal device with application development function.
[0104] As shown in Figure 5 , the software system running anomaly detection device comprises a data acquisition module 310, a to-be-detected data determination module 320 and an anomaly detection result determination module 330.
[0105] The data acquisition module 310 is configured to acquire a data sequence corresponding to at least one performance index of a server running a software system according to a preset acquisition frequency; the to-be-detected data determination module 320 is configured to determine to-be-detected data in the data sequence according to a preset time window length and a step; and the abnormality detection result determination module 330 is configured to input the to-be-detected data into a pre-trained abnormality detection model to obtain an abnormality detection result; wherein the abnormality detection model comprises a convolutional neural network, a long short-term memory network and an attention network.
[0106] The technical scheme of the embodiment is configured to acquire a data sequence corresponding to at least one performance index of a server running a software system according to a preset acquisition frequency; determine to-be-detected data in the data sequence according to a preset time window length and a step; and input the to-be-detected data into a pre-trained abnormality detection model to obtain an abnormality detection result; wherein the abnormality detection model comprises a convolutional neural network, a long short-term memory network and an attention network. The technical scheme of the embodiment can improve the accuracy, reliability and timeliness of abnormality detection by collecting data sequences and using a deep learning model for prediction, thereby solving the problem of low accuracy of software system operation abnormality detection.
[0107] In an optional implementation, the abnormality detection result determination module 330 is specifically configured to:
[0108] The to-be-detected data is input into the pre-trained abnormality detection model, the convolutional neural network of the abnormality detection model is used to perform feature extraction on the to-be-detected data to obtain a feature extraction result, the long short-term memory network of the abnormality detection model is used to perform time sequence dependent modeling processing on the feature extraction result to obtain a hidden state, the attention network of the abnormality detection model is used to perform attention weight calculation on the hidden state to obtain an attention weight of the hidden state at each time step, and the full connection layer of the abnormality detection model is used to perform weighted summation on the hidden state according to the attention weight to obtain the abnormality detection result.
[0109] In an optional implementation, the abnormality detection result determination module 330 is further configured to:
[0110] The convolutional neural network of the abnormality detection model is used to perform feature extraction and nonlinear activation on the to-be-detected data through a convolutional layer to obtain a convolutional layer processing result, and the pooling layer of the convolutional neural network is used to perform feature dimension reduction on the convolutional layer processing result to obtain the feature extraction result.
[0111] In an optional implementation, the abnormality detection result determination module 330 is further configured to:
[0112] The long short-term memory network of the abnormality detection model is used to perform time sequence dependent modeling processing on the feature extraction result through a gating mechanism and a memory cell state updating mechanism to obtain the hidden state.
[0113] In an optional implementation, the anomaly detection result determination module 330 is further configured to:
[0114] The anomaly detection model uses a fully connected layer to perform a weighted summation of the hidden states based on attention weights to obtain the anomaly score for each performance metric in the data to be detected. The mean and standard deviation of the data to be detected are calculated, and the anomaly judgment threshold is determined based on the mean and standard deviation. If the anomaly score of at least one performance metric exceeds the anomaly judgment threshold, the anomaly detection result is determined to be anomaly.
[0115] In one alternative embodiment, the apparatus further includes:
[0116] The model training module is used to determine the sample data to be detected, train the initial anomaly detection model based on the sample data, and update the model parameters of the initial anomaly detection model through the backpropagation algorithm until the loss function value is less than the preset error threshold, thus obtaining the anomaly detection model.
[0117] The software system operation anomaly detection device provided in the embodiments of the present invention can execute the software system operation anomaly detection method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0118] Figure 6 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present invention. Figure 6 A block diagram of an exemplary computer device 12 suitable for implementing embodiments of the present invention is shown. Figure 6 The computer device 12 shown is merely an example and should not be construed as limiting the functionality or scope of the embodiments of the present invention. The computer device 12 can be any terminal device with computing capabilities, such as intelligent controllers and servers, mobile phones, and other terminal devices.
[0119] like Figure 6 As shown, the computer device 12 is represented in the form of a general-purpose computing device. The components of the computer device 12 may include, but are not limited to: one or more processors or processing units 16, system memory 28, and a bus 18 connecting different system components (including system memory 28 and processing unit 16).
[0120] Bus 18 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. For example, these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.
[0121] Computer device 12 typically includes a variety of computer system readable media. Such media can be any available media that is located either internally or externally to computer device 12, such as volatile and non-volatile media, removable and non-removable media.
[0122] System memory 28 can include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache 32. Computer device 12 can further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 can be provided for reading from and writing to a non-removable, non-volatile magnetic media (e.g., a "hard drive"). Figure 6 not shown in FIG. 1, a magnetic hard disk drive for reading from and writing to non-removable, non-volatile magnetic media (e.g., a "hard drive"). Figure 6 not shown in FIG. 1, a magnetic hard disk drive for reading from and writing to non-removable, non-volatile magnetic media (e.g., a "hard drive").
[0123] Program / utility 40 having a set (at least one) of program modules 42 can be stored in, for example, system memory 28 by way of example, without limitation, operating system, one or more application programs, other program modules, and program data, each of which
[0124] Computer device 12 can also communicate with one or more external devices 14 such as a keyboard, a pointing device, a display 24, etc.; one or more devices that enable a user to interact with computer device 12; and / or one or more devices that enable computer device 12 to communicate with one or more other computing devices. Such communication can be via input / output (I / O) interfaces 22. Still yet, computer device 12 can communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or the Internet) through network adapter 20. As an example, network adapter 20 can include a modem, a network card (wireless or wired), or other well-known interface devices. Computer device 12 can also contain communication devices such as a joystick or force feedback device. Figure 6Other hardware and / or software modules can be used in conjunction with computer device 12, as shown in FIG. 1, including, but not limited to, microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archival storage systems, etc.
[0125] The processing unit 16 performs various functional applications and data processing by running programs stored in the system memory 28, such as implementing the software system running anomaly detection method provided by the embodiments of the present application, which comprises:
[0126] Obtaining a data sequence corresponding to at least one performance index of a server running a software system according to a preset acquisition frequency;
[0127] Determining to-be-detected data in the data sequence according to a preset time window length and step;
[0128] Inputting the to-be-detected data into a pre-trained anomaly detection model to obtain an anomaly detection result;
[0129] The anomaly detection model comprises a convolutional neural network, a long short-term memory network and an attention network.
[0130] The embodiments of the present application also provide a computer readable storage medium, which stores a computer program, and the program is executed by a processor to implement the software system running anomaly detection method provided by any of the embodiments of the present application, which comprises:
[0131] Obtaining a data sequence corresponding to at least one performance index of a server running a software system according to a preset acquisition frequency;
[0132] Determining to-be-detected data in the data sequence according to a preset time window length and step;
[0133] Inputting the to-be-detected data into a pre-trained anomaly detection model to obtain an anomaly detection result;
[0134] The anomaly detection model comprises a convolutional neural network, a long short-term memory network and an attention network.
[0135] The computer storage medium of the embodiments of the present application can adopt any combination of one or more computer-readable media. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any combination thereof. More specific examples (non-exhaustive list) of the computer-readable storage medium include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus or device.
[0136] The computer-readable signal medium can include a data signal propagated in baseband or propagated as a carrier wave, in which computer-readable program code is embodied. Such propagated data signals can take a wide variety of forms, including but not limited to electro-magnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium that is not a storage medium, that is, that is not a tangible medium, and that can communicate, propagate or transport programming for use by or in connection with an instruction execution system, apparatus or device.
[0137] The program code embodied on the computer-readable media can be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the above.
[0138] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object-oriented programming language such as Java, Smalltalk, Python, C++, or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0139] The embodiment of the present application further provides a computer program product comprising a computer program which, when executed by a processor, implements the software system running exception detection method provided by any embodiment of the present application.
[0140] The computer program product, in implementation, can be written in one or more programming languages or combinations thereof to implement computer program codes for performing operations of the present application, including object-oriented programming languages such as Java, Smalltalk, Python, C++, and conventional procedural programming languages such as "C" language or similar programming languages. The program codes can be executed entirely on a user computer, partially on a user computer, as an independent software package, partially on a user computer and partially on a remote computer, or entirely on a remote computer or server. In the case involving a remote computer, the remote computer can be connected to the user computer through any kind of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, through the Internet by using an Internet service provider).
[0141] Those skilled in the art should understand that the modules or steps of the present application described above can be implemented by general computing devices, which can be concentrated on a single computing device or distributed on a network composed of multiple computing devices, and optionally, can be implemented by program codes executable by the computing devices, so that they can be stored in storage devices and executed by the computing devices, or they can be respectively manufactured into individual integrated circuit modules, or multiple modules or steps among them can be manufactured into a single integrated circuit module. Thus, the present application is not limited to any specific combination of hardware and software.
[0142] Note that the above are only preferred embodiments of the present application and the technical principles applied. Those skilled in the art will understand that the present application is not limited to the specific embodiments described herein, and those skilled in the art can make various obvious changes, readjustments and substitutions without departing from the scope of the present application. Therefore, although the present application has been described in more detail through the above embodiments, the present application is not limited to the above embodiments, and can include more other equivalent embodiments without departing from the concept of the present application, and the scope of the present application is determined by the appended claims.
Claims
1. A software system abnormality detection method, characterized by, The method comprises the following steps: acquiring a data sequence corresponding to at least one performance index of a server running a software system according to a preset acquisition frequency; determining to-be-detected data in the data sequence according to a preset time window length and a step; inputting the to-be-detected data into a pre-trained anomaly detection model to obtain an anomaly detection result; wherein the anomaly detection model comprises a convolutional neural network, a long short-term memory network and an attention network.
2. The method of claim 1, wherein, The method comprises the following steps: inputting the to-be-detected data into the pre-trained anomaly detection model, performing feature extraction on the to-be-detected data through the convolutional neural network of the anomaly detection model to obtain a feature extraction result; performing time sequence dependent modeling processing on the feature extraction result through the long short-term memory network of the anomaly detection model to obtain a hidden state; performing attention weight calculation on the hidden state through the attention network of the anomaly detection model to obtain an attention weight of the hidden state at each time step; performing weighted summation on the hidden state according to the attention weight through a fully connected layer of the anomaly detection model to obtain an anomaly detection result.
3. The method of claim 2, wherein, The method comprises the following steps: performing feature extraction and nonlinear activation on the to-be-detected data through a convolutional layer of the convolutional neural network of the anomaly detection model to obtain a convolutional layer processing result; performing feature dimension reduction on the convolutional layer processing result through a pooling layer of the convolutional neural network to obtain a feature extraction result.
4. The method of claim 2, wherein, The method comprises the following steps: performing time sequence dependent modeling processing on the feature extraction result through a gating mechanism and a memory cell state updating mechanism of the long short-term memory network of the anomaly detection model to obtain a hidden state.
5. The method of claim 2, wherein, The method comprises the following steps: performing weighted summation on the hidden state according to the attention weight through a fully connected layer of the anomaly detection model to obtain an anomaly score of data corresponding to each performance index in the to-be-detected data; calculating a mean value and a standard deviation of the to-be-detected data, and determining an anomaly judgment threshold according to the mean value and the standard deviation; in a case where the anomaly score of the data corresponding to at least one performance index exceeds the anomaly judgment threshold, determining that the anomaly detection result is abnormal.
6. The method according to any one of claims 1 to 5, characterized in that, The training process of the anomaly detection model comprises the following steps: determining to-be-detected sample data, training an anomaly detection initial model according to the to-be-detected sample data, and updating model parameters of the anomaly detection initial model through a back propagation algorithm until a loss function value is less than a preset error threshold to obtain an anomaly detection model.
7. A software system abnormality detection apparatus characterized by comprising: The method comprises the following steps: a data acquisition module is configured to acquire a data sequence corresponding to at least one performance index of a server running a software system according to a preset acquisition frequency; The to-be-detected data determination module is configured to determine to-be-detected data in the data sequence according to a preset time window length and a step length. The anomaly detection result determination module is configured to input the to-be-detected data into a pre-trained anomaly detection model to obtain an anomaly detection result. The anomaly detection model comprises a convolutional neural network, a long short-term memory network, and an attention network.
8. A computer device, comprising: The computer device comprises: one or more processors; a memory for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the software system running anomaly detection method according to any one of claims 1-6.
9. A computer-readable storage medium having stored thereon a computer program, characterized in that, The program is executed by the processor to implement the software system running anomaly detection method according to any one of claims 1-6.
10. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the software system running anomaly detection method according to any one of claims 1-6.