Abnormality monitoring and analyzing method and device for DNS (Domain Name Server) equipment and medium

By using a dynamic baseline data prediction model and sliding window adaptive baseline calculation, combined with root cause probability analysis, the problem of invalid queries and high false alarm rates in DNS devices was solved, enabling more accurate anomaly monitoring and analysis and improving device operating efficiency.

CN120934979APending Publication Date: 2025-11-11BEIJING YOUTEJIE INFORMATION TECH
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511034934.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-25
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

In existing technologies, DNS devices suffer from rampant invalid queries, resulting in significant resource waste. Furthermore, they struggle to perform effective correlation analysis on various types of data, leading to a high false alarm rate and making it difficult to troubleshoot network service failures.

Method used

Collect the current logs and configuration information of the DNS device, use the dynamic baseline data prediction model and sliding window adaptive baseline calculation, and combine root cause probability calculation to determine device anomalies and provide feedback on performance indicators.

Benefits of technology

It improves the accuracy and effectiveness of DNS device data queries, reduces invalid queries, lowers the false alarm rate, and improves troubleshooting efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934979A_ABST
    Figure CN120934979A_ABST
Patent Text Reader

Abstract

The invention discloses an anomaly monitoring and analysis method and device for DNS equipment and a medium. The method comprises the following steps: acquiring current log joint description data corresponding to target DNS equipment and current DNS equipment configuration information, and inputting the current log joint description data and the current DNS equipment configuration information into a dynamic baseline data prediction model to obtain at least one piece of current dynamic baseline data; obtaining current window parameters, obtaining each current sliding window adaptive baseline, and respectively judging each current dynamic baseline data through a DNS equipment abnormity judgment method to generate a target DNS equipment judgment result; and when it is determined that the state is an abnormal result state, obtaining current DNS equipment performance index joint description data, and determining a target DNS equipment performance abnormal index through a root cause probability calculation formula. According to the method, the problems of inundation of invalid queries, difficulty in association analysis of various types of data and high false alarm rate are solved, the accuracy and effectiveness of data query of the DNS equipment are improved, and the problem of invalid queries is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, and in particular to a method, apparatus and medium for anomaly monitoring and analysis of DNS devices. Background Technology

[0002] DNS (Domain Name System) is a crucial infrastructure on the internet, responsible for translating domain names into IP addresses. The proper functioning of DNS devices is fundamental to the normal operation of numerous internet applications, including web services, email services, and file transfer services. As a distributed hierarchical database system, the DNS system, due to its open, complex, and massive nature, and insufficient consideration of access control and security in its initial design, harbors numerous usage errors and potential security threats. Given the fundamental role of the DNS system in the network and the serious consequences of DNS system failure, timely detection of anomalies in the DNS system is of paramount importance.

[0003] In the process of developing this invention, the inventors discovered the following shortcomings in the existing technology: Analysis of root node data in DNS devices reveals that approximately 98% of DNS queries are invalid queries that should not reach the root node. Valid DNS queries account for only about 2% of the total queries received by the root. A large portion of the root server's resources are consumed in processing invalid queries. DNS services are highly coupled with the system, and failures can be highly destructive. Furthermore, DNS data belongs to the network side, and anomaly detection on the network side has always been a major challenge, due to its large data volume, complex rules, and difficulty in tracking, posing significant difficulties for routine troubleshooting. For DNS devices, there is a difficulty in effectively correlating and analyzing various types of data, and a high false alarm rate. Summary of the Invention

[0004] This invention provides a method, apparatus, and medium for anomaly monitoring and analysis of DNS devices, in order to improve the accuracy and effectiveness of DNS device data queries.

[0005] According to one aspect of the present invention, a method for anomaly monitoring and analysis of DNS devices is provided, comprising:

[0006] Collect the current log federated description data and current DNS device configuration information corresponding to the target DNS device;

[0007] The current log combined description data and the current DNS device configuration information are input into a pre-built dynamic baseline data prediction model to obtain at least one current dynamic baseline data.

[0008] The current window parameters are obtained, and the adaptive baseline of each current sliding window is calculated using a pre-set sliding window adaptive baseline calculation formula. The current dynamic baseline data is then judged using a pre-set DNS device anomaly judgment method to generate the target DNS device judgment result.

[0009] When the target DNS device is determined to be in an abnormal state, the combined description data of the current DNS device performance indicators is obtained. Then, the correlation coefficient root cause probability corresponding to each DNS device performance indicator is calculated and analyzed using a pre-set root cause probability calculation formula. The abnormal performance indicators of the target DNS device are identified, and feedback processing is performed to the user.

[0010] According to another aspect of the present invention, an anomaly monitoring and analysis apparatus for a DNS device is provided, comprising:

[0011] The current log federated description data and current DNS device configuration information collection module is used to collect the current log federated description data and current DNS device configuration information corresponding to the target DNS device;

[0012] The current dynamic baseline data determination module is used to input the current log joint description data and the current DNS device configuration information into a pre-built dynamic baseline data prediction model to obtain at least one current dynamic baseline data.

[0013] The target DNS device judgment result generation module is used to obtain the current window parameters, calculate each current sliding window adaptive baseline using a pre-set sliding window adaptive baseline calculation formula, and judge each current dynamic baseline data using a pre-set DNS device anomaly judgment method to generate the target DNS device judgment result.

[0014] The target DNS device performance anomaly indicator determination and feedback module is used to obtain the current DNS device performance indicator joint description data when the target DNS device is determined to be in an abnormal state. Then, it calculates and analyzes the correlation coefficient root cause probability corresponding to each DNS device performance indicator through a pre-set root cause probability calculation formula, determines the target DNS device performance anomaly indicator, and provides feedback processing to the user.

[0015] According to another aspect of the present invention, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the anomaly monitoring and analysis method for DNS devices according to any embodiment of the present invention.

[0016] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions, the computer instructions being configured to cause a processor to execute and implement the anomaly monitoring and analysis method for DNS devices according to any embodiment of the present invention.

[0017] The technical solution of this invention involves collecting current log joint description data and current DNS device configuration information corresponding to the target DNS device; inputting the current log joint description data and the current DNS device configuration information into a pre-built dynamic baseline data prediction model to obtain at least one current dynamic baseline data; acquiring current window parameters and calculating them respectively using a pre-set sliding window adaptive baseline calculation formula to obtain each current sliding window adaptive baseline; and judging each current dynamic baseline data respectively using a preset DNS device anomaly judgment method to generate a target DNS device judgment result; when the target DNS device judgment result is determined to be an abnormal result state, acquiring current DNS device performance index joint description data, and calculating and analyzing the correlation coefficient root cause probability corresponding to each DNS device performance index using a pre-set root cause probability calculation formula, and determining the target DNS device performance anomaly index, and providing feedback processing to the user. This solves the problems of rampant invalid queries, difficulty in performing correlation analysis on multiple types of data, and high false alarm rate in the prior art, improves the accuracy and effectiveness of DNS device data queries, and overcomes the problem of invalid queries.

[0018] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 This is a flowchart of a method for anomaly monitoring and analysis of a DNS device according to Embodiment 1 of the present invention;

[0021] Figure 2 This is a detailed flowchart of a DNS device anomaly monitoring and analysis method provided according to Embodiment 2 of the present invention;

[0022] Figure 3This is a schematic diagram of the structure of an anomaly monitoring and analysis device for a DNS device according to Embodiment 3 of the present invention;

[0023] Figure 4 This is a schematic diagram of the structure of an electronic device provided according to Embodiment 4 of the present invention. Detailed Implementation

[0024] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0025] It should be noted that the terms "target," "current," etc., used in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0026] It is worth noting that the information collected in the technical solution of this application is information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data all comply with the relevant laws, regulations and standards of the relevant countries and regions, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse; if the user chooses to refuse, the process will proceed to the expert decision-making process.

[0027] Example 1

[0028] Figure 1 The flowchart of an embodiment of the present invention provides a method for anomaly monitoring and analysis of DNS devices. This embodiment is applicable to the situation of anomaly monitoring and analysis of DNS devices. The method can be executed by an anomaly monitoring and analysis device of DNS devices, which can be implemented in hardware and / or software.

[0029] Correspondingly, such as Figure 1As shown, the method includes:

[0030] S110. Collect the current log combined description data and current DNS device configuration information corresponding to the target DNS device.

[0031] The current log combined description data can specifically include the current parsing log, the current error log, or the current access log.

[0032] In this embodiment, the current log federated description data and current DNS device configuration information corresponding to the target DNS device can be collected by the heka probe and uploaded to the standard object storage database in real time.

[0033] S120. Input the current log joint description data and the current DNS device configuration information into a pre-built dynamic baseline data prediction model to obtain at least one current dynamic baseline data.

[0034] Among them, the dynamic baseline data prediction model can be a model that can make real-time predictions of dynamic baseline data.

[0035] Optionally, the step of inputting the current log joint description data and the current DNS device configuration information into a pre-built dynamic baseline data prediction model to obtain at least one current dynamic baseline data includes: performing data standardization processing on the current log joint description data and the current DNS device configuration information, and obtaining features of the current log joint description data and the current DNS device configuration information through a pre-set feature extraction method; inputting the features of the current log joint description data and the current DNS device configuration information into the pre-built dynamic baseline data prediction model to obtain at least one current dynamic baseline data.

[0036] In this embodiment, the current log combined description data and the current DNS device configuration information first need to be cleaned, deduplicated, and standardized in format. Then, feature extraction processing is performed on the standardized current log combined description data and the current DNS device configuration information to obtain the features of the current log combined description data and the current DNS device configuration information.

[0037] Furthermore, the dynamic baseline data prediction model can analyze the characteristics of the input current log joint description data and the characteristics of the current DNS device configuration information to obtain the corresponding current dynamic baseline data.

[0038] Optionally, before collecting the current log joint description data and current DNS device configuration information corresponding to the target DNS device, the method further includes: acquiring the historical log joint description data and historical DNS device configuration information corresponding to each historical DNS device, as well as historical dynamic baseline data; after standardizing and extracting features from the historical log joint description data and historical DNS device configuration information, inputting them into the initial dynamic baseline data prediction model for model training, and combining the historical dynamic baseline data until the prediction accuracy of the trained initial dynamic baseline data prediction model meets the requirements, thus determining that the training of the dynamic baseline data prediction model is complete.

[0039] In this embodiment, the initial dynamic baseline data prediction model is trained using the historical log combined description data and historical DNS device configuration information corresponding to the historical DNS devices. After training is completed, it is necessary to combine the historical dynamic baseline data to determine whether the dynamic baseline data output by the model is accurate, and then determine the corresponding prediction accuracy.

[0040] Furthermore, the required threshold for prediction accuracy can be obtained. If the prediction accuracy meets the threshold, it means that the dynamic baseline data prediction model has been successfully trained. Conversely, if the prediction accuracy does not meet the threshold, it means that the model needs to be retrained. Therefore, it is necessary to continue to obtain the historical log joint description data and historical DNS device configuration information corresponding to the historical DNS devices to perform model retraining.

[0041] The advantage of this setup is that by combining historical log description data, historical DNS device configuration information, and historical dynamic baseline data, a more accurate dynamic baseline data prediction model can be trained. This makes the model's prediction of the current dynamic baseline data more accurate, and thus better able to determine whether the DNS device is in an abnormal state.

[0042] S130. Obtain the current window parameters, calculate them respectively using the pre-set sliding window adaptive baseline calculation formula, obtain the current sliding window adaptive baseline, and judge each current dynamic baseline data respectively using the pre-set DNS device anomaly judgment method to generate the target DNS device judgment result.

[0043] Optionally, obtaining the current window parameters and calculating each current sliding window adaptive baseline using a pre-set sliding window adaptive baseline calculation formula includes: obtaining the current service scenario corresponding to the target DNS device and determining the target sensitivity coefficient using a pre-set scenario sensitivity mapping database; inputting the target sensitivity coefficient and the current window parameters into the sliding window adaptive baseline calculation formula for calculation to obtain the current sliding window adaptive baseline; wherein, the sliding window adaptive baseline calculation formula is Baseline(t)=μ(W)+α·σ(W), where μ(W) represents the mean of the window data corresponding to the current window parameter W, σ(W) represents the standard deviation of the window data corresponding to the current window parameter W, α represents the target sensitivity coefficient, and Baseline(t) represents the sliding window adaptive baseline corresponding to the current time t.

[0044] The current window parameter can be the size of a window parameter preset based on the DNS device over a certain period. The current sliding window adaptive baseline can be used to determine whether there is a baseline with DNS device anomalies in the current dynamic baseline data. The target sensitivity coefficient can be determined differently depending on the current business scenario.

[0045] The scene sensitivity mapping database can be a database that stores historical scenes and different sensitivities set for different historical scenes.

[0046] For example, for a relaxed mode scenario, such as during peak business hours, the sensitivity coefficient can be set to 0.8; for a standard mode scenario, such as during daily operations, the sensitivity coefficient can be set to 1.0; and for a strict mode scenario, such as when high reliability is required, the sensitivity coefficient can be set to 1.2.

[0047] Optionally, the step of judging each of the current dynamic baseline data using a preset DNS device anomaly judgment method to generate a target DNS device judgment result includes: determining the current real-time sliding window adaptive baseline range based on the current sliding window adaptive baseline and combining the window data mean and window data standard deviation; wherein the current real-time sliding window adaptive baseline range is a range composed of the current real-time sliding window adaptive baseline minimum value and the current real-time sliding window adaptive baseline maximum value; sequentially obtaining a target current dynamic baseline data from each of the current dynamic baseline data; judging whether the target current dynamic baseline data falls within the current real-time sliding window adaptive baseline range using the preset DNS device anomaly judgment method; if it falls within the range, then returning to execute the step in In each of the current dynamic baseline data, the operation of sequentially obtaining one target current dynamic baseline data is performed; if it does not fall into the range, it is counted in the total number of non-baseline ranges, and the operation of sequentially obtaining one target current dynamic baseline data in each of the current dynamic baseline data is returned; it is determined whether all the current dynamic baseline data has been traversed. If all the data has been traversed, the total number of non-baseline ranges is determined; a preset threshold for the total number of non-baseline ranges is obtained. If the total number of non-baseline ranges is greater than the threshold, the target DNS device's judgment result is determined to be an abnormal result state; if the total number of non-baseline ranges is less than or equal to the threshold, the target DNS device's judgment result is determined to be a normal result state.

[0048] In this embodiment, after calculating the adaptive baseline of each current sliding window, it is necessary to perform addition and subtraction operations based on the mean and standard deviation of the window data to determine the maximum value and minimum value of the current real-time sliding window adaptive baseline, thereby generating the range of the current real-time sliding window adaptive baseline.

[0049] Furthermore, it is necessary to use DNS device anomaly detection methods to determine whether the current dynamic baseline data of each target falls within the current real-time sliding window adaptive baseline range. Based on whether it falls within or not, the total number of baseline ranges that do not fall within the range is counted. Assuming the total number of baseline ranges that do not fall within the range is 9, and the threshold for the total number of baseline ranges that do not fall within the range is 10; since the total number of baseline ranges that do not fall within the range is less than the threshold, the target DNS device's judgment result is determined to be a normal result.

[0050] If the total number of cases not falling within the baseline range is 15, it means that the total number of cases not falling within the baseline range is greater than the threshold for the total number of cases not falling within the baseline range, and the target DNS device is determined to be in an abnormal result state.

[0051] The advantage of this setting is that by determining the adaptive baseline range of the current real-time sliding window, real-time dynamic judgment operations can be performed on different current dynamic baseline data. This can better adapt to fluctuations in data traffic, overcome the problem of traditional threshold alarms relying on static rules, and thus more accurately determine whether there are any abnormalities in the DNS device.

[0052] S140. When it is determined that the target DNS device's judgment result is an abnormal result state, the joint description data of the current DNS device performance indicators is obtained, and the correlation coefficient root cause probability corresponding to each DNS device performance indicator is calculated and analyzed through the pre-set root cause probability calculation formula. The abnormal performance indicators of the target DNS device are determined, and feedback processing operations are performed to the user.

[0053] In this embodiment, after determining that the target DNS device's judgment result is abnormal, it is also necessary to combine the current DNS device performance index with the joint description data to analyze which DNS device performance index caused the DNS device abnormality. Then, the obtained target DNS device performance abnormality index can be fed back to the user for processing, so that the user can better solve the DNS device abnormality problem and improve the user experience.

[0054] The technical solution of this invention involves collecting current log joint description data and current DNS device configuration information corresponding to the target DNS device; inputting the current log joint description data and the current DNS device configuration information into a pre-built dynamic baseline data prediction model to obtain at least one current dynamic baseline data; acquiring current window parameters and calculating them respectively using a pre-set sliding window adaptive baseline calculation formula to obtain each current sliding window adaptive baseline; and judging each current dynamic baseline data respectively using a preset DNS device anomaly judgment method to generate a target DNS device judgment result; when the target DNS device judgment result is determined to be an abnormal result state, acquiring current DNS device performance index joint description data, and calculating and analyzing the correlation coefficient root cause probability corresponding to each DNS device performance index using a pre-set root cause probability calculation formula, and determining the target DNS device performance anomaly index, and providing feedback processing to the user. This solves the problems of rampant invalid queries, difficulty in performing correlation analysis on multiple types of data, and high false alarm rate in the prior art, improves the accuracy and effectiveness of DNS device data queries, and overcomes the problem of invalid queries.

[0055] Example 2

[0056] Figure 2This is a detailed flowchart of a DNS device anomaly monitoring and analysis method according to Embodiment 2 of the present invention. This embodiment is a refinement based on the above embodiments. In this embodiment, when the target DNS device is determined to be in an abnormal state, the joint description data of the current DNS device performance indicators is obtained, and the correlation coefficient root cause probability corresponding to each DNS device performance indicator is calculated and analyzed through a pre-set root cause probability calculation formula, and the target DNS device performance anomaly indicators are determined for further refinement.

[0057] S210. Collect the current log combined description data and current DNS device configuration information corresponding to the target DNS device.

[0058] S220. Input the current log joint description data and the current DNS device configuration information into a pre-built dynamic baseline data prediction model to obtain at least one current dynamic baseline data.

[0059] S230. Obtain the current window parameters, calculate them respectively using the pre-set sliding window adaptive baseline calculation formula, obtain the current sliding window adaptive baseline, and judge each current dynamic baseline data respectively using the pre-set DNS device anomaly judgment method to generate the target DNS device judgment result.

[0060] S240. When it is determined that the target DNS device's judgment result is an abnormal result state, obtain the joint description data of the current DNS device's performance indicators.

[0061] The current DNS device performance metrics jointly described include CPU utilization performance metrics, memory usage performance metrics, network throughput performance metrics, and device connection count performance metrics.

[0062] S250: Using a pre-defined conversion function, the CPU utilization performance index, memory usage performance index, network throughput performance index, and device connection number performance index are standardized according to the type of each performance index to obtain the target CPU utilization performance index, target memory usage performance index, target network throughput performance index, and target device connection number performance index.

[0063] In this embodiment, the CPU utilization performance index, memory usage performance index, network throughput performance index, and device connection number performance index can be standardized according to the different types of performance indicators.

[0064] The defined conversion functions can include time-defined conversion functions and address-defined conversion functions, among others.

[0065] For example, assuming that the CPU utilization performance metric is primarily a performance indicator that processes time, then the transformation function can be defined as a time-defined transformation function. Firstly, multi-source data spatiotemporal alignment techniques can be used to identify timestamp drift issues in the CPU utilization performance metric through timestamps.

[0066] Furthermore, let's assume that the time transition function is defined as t. std =T(t) raw ), where t raw The original timestamp corresponding to the CPU utilization performance metric; t std This refers to the standard timestamp corresponding to the target CPU utilization performance metric. Similarly, different processing operations can be performed depending on the type of each performance metric, which will not be elaborated here.

[0067] S260. Obtain the device fault value corresponding to the target DNS device, and calculate the target CPU utilization correlation coefficient, target memory usage correlation coefficient, target network throughput correlation coefficient, and target device connection number correlation coefficient by combining the target CPU utilization performance index, target memory usage performance index, target network throughput performance index, and target device connection number performance index, respectively.

[0068] For example, the solution for the target CPU utilization correlation coefficient can be obtained by further calculating the average device failure value based on the acquired device failure value. Similarly, the average target CPU utilization performance index can be obtained by further calculating the target CPU utilization performance index.

[0069] Furthermore, it can be done according to the formula Where r1 is the target CPU utilization correlation coefficient; z is the device failure value; z1 is the mean device failure value; m is the target CPU utilization performance index; and m1 is the mean target CPU utilization performance index. Similarly, the target memory usage correlation coefficient, target network throughput correlation coefficient, and target device connection number correlation coefficient can be calculated accordingly.

[0070] S270, respectively obtain the abnormal deviation of CPU utilization, abnormal deviation of memory usage, abnormal deviation of network throughput, and abnormal deviation of device connection count.

[0071] S280. Using the root cause probability calculation formula P=β|r|+θQ, calculate the correlation coefficient root cause probability P corresponding to each DNS device performance index.

[0072] Where β is the correlation coefficient; θ is the anomaly deviation coefficient; r is one of the target CPU utilization correlation coefficient, target memory usage correlation coefficient, target network throughput correlation coefficient, or target device connection number correlation coefficient; Q is one of the CPU utilization anomaly deviation, memory usage anomaly deviation, network throughput anomaly deviation, or device connection number anomaly deviation.

[0073] Continuing from the previous example, we can calculate the target CPU utilization correlation coefficient r1, obtain the abnormal deviation of CPU utilization as Q1, and set β = 0.7, θ = 0.3, where the sum of β and θ is 1.

[0074] Furthermore, the root cause probability of the correlation coefficient of the CPU utilization performance index can be calculated as P1=β|r|+θQ=0.7|r1|+0.3Q1.

[0075] S290. Based on the root cause probabilities of the correlation coefficients, determine the performance anomaly indicators of the target DNS device.

[0076] In this embodiment, the root cause probabilities of each correlation coefficient can be calculated accordingly. It is assumed that the root cause probabilities of the correlation coefficients corresponding to the CPU utilization performance index, memory usage performance index, network throughput performance index, and device connection number performance index are P1, P2, P3, and P4, respectively.

[0077] Optionally, determining the target DNS device performance anomaly indicator based on the root cause probabilities of each correlation coefficient includes: sorting the root cause probabilities of each correlation coefficient to determine the root cause probability of the maximum correlation coefficient; determining the performance indicator corresponding to the root cause probability of the maximum correlation coefficient as the target DNS device performance anomaly indicator; and providing feedback processing to the user regarding the target DNS device performance anomaly indicator.

[0078] For example, the root cause probabilities of each correlation coefficient are sorted. If P1 > P4 > P2 > P3, then P1 is the root cause probability with the highest correlation coefficient. The CPU utilization performance index corresponding to the root cause probability with the highest correlation coefficient can be determined as the target DNS device performance anomaly index, and the target DNS device performance anomaly index can be fed back to the user for processing.

[0079] S2100, Feedback processing operation to the user.

[0080] The technical solution of this invention, after determining that the target DNS device's judgment result is abnormal, also needs to obtain the joint description data of the current DNS device performance indicators, and calculate and analyze the correlation coefficient root cause probability corresponding to each DNS device performance indicator through a pre-set root cause probability calculation formula, and determine the abnormal performance indicators of the target DNS device, providing feedback processing to the user. This can more accurately determine the most important performance abnormal indicators affecting the target DNS device's abnormality, thus facilitating subsequent maintenance processing for the user. It solves the problems of rampant invalid queries, difficulty in performing correlation analysis on multiple types of data, and high false alarm rates in existing technologies, improving the accuracy and effectiveness of DNS device data queries, overcoming the problem of invalid queries, and enhancing the user experience.

[0081] Example 3

[0082] Figure 3 This is a schematic diagram of a DNS device anomaly monitoring and analysis apparatus provided in Embodiment 3 of the present invention. The DNS device anomaly monitoring and analysis apparatus provided in this embodiment can be implemented by software and / or hardware, and can be configured in a terminal device or server to implement the DNS device anomaly monitoring and analysis method of the present invention. Figure 3 As shown, the device includes: a current log combined description data and current DNS device configuration information collection module 310, a current dynamic baseline data determination module 320, a target DNS device judgment result generation module 330, and a target DNS device performance anomaly indicator determination and feedback module 340.

[0083] Among them, the current log combined description data and current DNS device configuration information collection module 310 is used to collect the current log combined description data and current DNS device configuration information corresponding to the target DNS device;

[0084] The current dynamic baseline data determination module 320 is used to input the current log joint description data and the current DNS device configuration information into a pre-built dynamic baseline data prediction model to obtain at least one current dynamic baseline data.

[0085] The target DNS device judgment result generation module 330 is used to obtain the current window parameters, calculate each current sliding window adaptive baseline using a pre-set sliding window adaptive baseline calculation formula, and judge each current dynamic baseline data using a pre-set DNS device anomaly judgment method to generate the target DNS device judgment result.

[0086] The target DNS device performance anomaly indicator determination and feedback module 340 is used to obtain the current DNS device performance indicator joint description data when the target DNS device is determined to be in an abnormal state, and calculate and analyze the correlation coefficient root cause probability corresponding to each DNS device performance indicator through a pre-set root cause probability calculation formula, determine the target DNS device performance anomaly indicator, and provide feedback processing to the user.

[0087] The technical solution of this invention involves collecting current log joint description data and current DNS device configuration information corresponding to the target DNS device; inputting the current log joint description data and the current DNS device configuration information into a pre-built dynamic baseline data prediction model to obtain at least one current dynamic baseline data; acquiring current window parameters and calculating them respectively using a pre-set sliding window adaptive baseline calculation formula to obtain each current sliding window adaptive baseline; and judging each current dynamic baseline data respectively using a preset DNS device anomaly judgment method to generate a target DNS device judgment result; when the target DNS device judgment result is determined to be an abnormal result state, acquiring current DNS device performance index joint description data, and calculating and analyzing the correlation coefficient root cause probability corresponding to each DNS device performance index using a pre-set root cause probability calculation formula, and determining the target DNS device performance anomaly index, and providing feedback processing to the user. This solves the problems of rampant invalid queries, difficulty in performing correlation analysis on multiple types of data, and high false alarm rate in the prior art, improves the accuracy and effectiveness of DNS device data queries, and overcomes the problem of invalid queries.

[0088] Based on the above embodiments, the current dynamic baseline data determination module 320 can be specifically used to: perform data standardization processing on the current log joint description data and the current DNS device configuration information, and obtain the current log joint description data features and the current DNS device configuration information features through a pre-set feature extraction method; input the current log joint description data features and the current DNS device configuration information features into a pre-built dynamic baseline data prediction model to obtain at least one current dynamic baseline data.

[0089] Based on the above embodiments, a dynamic baseline data prediction model training module is also included, which can be specifically used to: before collecting the current log joint description data and current DNS device configuration information corresponding to the target DNS device, obtain the historical log joint description data and historical DNS device configuration information corresponding to each historical DNS device, as well as historical dynamic baseline data; after standardizing and extracting features from the historical log joint description data and historical DNS device configuration information, input them into the initial dynamic baseline data prediction model for model training, and combine them with historical dynamic baseline data until the prediction accuracy of the initial dynamic baseline data prediction model obtained by training meets the requirements, and determine that the training of the dynamic baseline data prediction model is complete.

[0090] Based on the above embodiments, the target DNS device judgment result generation module 330 can be specifically used to: obtain the current business scenario corresponding to the target DNS device, and determine the target sensitivity coefficient through a pre-set scenario sensitivity mapping database; input the target sensitivity coefficient and the current window parameter into the sliding window adaptive baseline calculation formula for calculation to obtain the current sliding window adaptive baseline; wherein, the sliding window adaptive baseline calculation formula is Baseline(t)=μ(W)+α·σ(W), where μ(W) represents the mean of the window data corresponding to the current window parameter W, σ(W) represents the standard deviation of the window data corresponding to the current window parameter W, α represents the target sensitivity coefficient, and Baseline(t) represents the sliding window adaptive baseline corresponding to the current time t.

[0091] Based on the above embodiments, the target DNS device judgment result generation module 330 can be specifically used to: determine the current real-time sliding window adaptive baseline range based on the current sliding window adaptive baseline and in combination with the window data mean and window data standard deviation; wherein, the current real-time sliding window adaptive baseline range is a range composed of the current real-time sliding window adaptive baseline minimum value and the current real-time sliding window adaptive baseline maximum value; sequentially obtain a target current dynamic baseline data from each of the current dynamic baseline data; determine whether the target current dynamic baseline data falls within the current real-time sliding window adaptive baseline range using a preset DNS device anomaly judgment method; if it falls within the range, return to execute the step of determining the target current dynamic baseline data from each of the current dynamic baseline data. The process involves sequentially acquiring the current dynamic baseline data of a target; if a target is not included, it is counted in the total number of targets not included in the baseline range, and the process returns to execute the operation of sequentially acquiring the current dynamic baseline data of a target from each of the current dynamic baseline data; it is determined whether all the current dynamic baseline data has been traversed; if all the data has been traversed, the total number of targets not included in the baseline range is determined; a preset threshold for the total number of targets not included in the baseline range is obtained; if the total number of targets not included in the baseline range is greater than the threshold, the target DNS device's judgment result is determined to be an abnormal result state; if the total number of targets not included in the baseline range is less than or equal to the threshold, the target DNS device's judgment result is determined to be a normal result state.

[0092] Based on the above embodiments, the target DNS device performance anomaly indicator determination and feedback module 340 can be specifically used for: when determining that the target DNS device's judgment result is an anomaly, obtaining the current DNS device performance indicator joint description data; wherein, the current DNS device performance indicator joint description data includes CPU utilization performance indicators, memory usage performance indicators, network throughput performance indicators, and device connection number performance indicators; through a pre-set defined conversion function, according to the type of each performance indicator, standardizing the CPU utilization performance indicators, memory usage performance indicators, network throughput performance indicators, and device connection number performance indicators respectively, to obtain the target CPU utilization performance indicators, target memory usage performance indicators, target network throughput performance indicators, and target device connection number performance indicators; obtaining the device fault value corresponding to the target DNS device, and combining it with the target CPU utilization performance indicators, target memory usage performance indicators, and target network throughput performance indicators respectively. The throughput performance index and the target device connection count performance index are used to calculate the correlation coefficients for target CPU utilization, target memory usage, target network throughput, and target device connection count. Abnormal deviations in CPU utilization, memory usage, network throughput, and device connection count are obtained respectively. Using the root cause probability calculation formula P = β|r| + θQ, the root cause probability P corresponding to each DNS device performance index is calculated. Where β is the correlation coefficient; θ is the abnormal deviation coefficient; r is one of the correlation coefficients for target CPU utilization, target memory usage, target network throughput, or target device connection count; and Q is one of the abnormal deviations in CPU utilization, memory usage, network throughput, or device connection count. Based on the root cause probabilities of each correlation coefficient, the abnormal performance indexes of the target DNS device are determined.

[0093] Based on the above embodiments, the target DNS device performance anomaly indicator determination and feedback module 340 can also be specifically used to: sort the root cause probabilities of each correlation coefficient, determine the root cause probability of the maximum correlation coefficient; determine the performance indicator corresponding to the root cause probability of the maximum correlation coefficient as the target DNS device performance anomaly indicator, and perform feedback processing operation on the target DNS device performance anomaly indicator to the user.

[0094] The DNS device anomaly monitoring and analysis apparatus provided in this embodiment of the invention can execute the DNS device anomaly monitoring and analysis method provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the method execution.

[0095] Example 4

[0096] Figure 4 A schematic diagram of an electronic device 10, which can be used to implement Embodiment 4 of the present invention, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0097] like Figure 4 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0098] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0099] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as methods for anomaly monitoring and analysis of DNS devices.

[0100] In some embodiments, the DNS device anomaly monitoring and analysis method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the DNS device anomaly monitoring and analysis method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the DNS device anomaly monitoring and analysis method by any other suitable means (e.g., by means of firmware).

[0101] The method includes: collecting current log joint description data and current DNS device configuration information corresponding to the target DNS device; inputting the current log joint description data and the current DNS device configuration information into a pre-built dynamic baseline data prediction model to obtain at least one current dynamic baseline data; obtaining current window parameters, calculating them respectively using a pre-set sliding window adaptive baseline calculation formula to obtain each current sliding window adaptive baseline, and judging each current dynamic baseline data respectively using a pre-set DNS device anomaly judgment method to generate a target DNS device judgment result; when the target DNS device judgment result is determined to be an abnormal result state, acquiring current DNS device performance index joint description data, and calculating and analyzing the correlation coefficient root cause probability corresponding to each DNS device performance index respectively using a pre-set root cause probability calculation formula, determining the target DNS device performance anomaly index, and providing feedback processing to the user.

[0102] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0103] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0104] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0105] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0106] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0107] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0108] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0109] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

[0110] Example 5

[0111] Embodiment 5 of the present invention also provides a computer-readable storage medium, wherein the computer-readable instructions, when executed by a computer processor, are used to perform an anomaly monitoring and analysis method for a DNS device. The method includes: collecting current log joint description data and current DNS device configuration information corresponding to a target DNS device; inputting the current log joint description data and the current DNS device configuration information into a pre-constructed dynamic baseline data prediction model to obtain at least one current dynamic baseline data; obtaining current window parameters, calculating each current sliding window adaptive baseline using a pre-set sliding window adaptive baseline calculation formula, and judging each current dynamic baseline data using a pre-set DNS device anomaly judgment method to generate a target DNS device judgment result; when the target DNS device judgment result is determined to be an anomaly, obtaining current DNS device performance index joint description data, calculating and analyzing the correlation coefficient root cause probability corresponding to each DNS device performance index using a pre-set root cause probability calculation formula, determining the target DNS device performance anomaly index, and providing feedback processing to the user.

[0112] Of course, the computer-readable storage medium provided in the embodiments of the present invention has computer-executable instructions that are not limited to the method operations described above, but can also perform related operations in the anomaly monitoring and analysis of DNS devices provided in any embodiment of the present invention.

[0113] Based on the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0114] It is worth noting that in the above embodiments of anomaly monitoring and analysis of DNS devices, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the scope of protection of the present invention.

[0115] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A method for anomaly monitoring and analysis of DNS devices, characterized in that, include: Collect the current log federated description data and current DNS device configuration information corresponding to the target DNS device; The current log combined description data and the current DNS device configuration information are input into a pre-built dynamic baseline data prediction model to obtain at least one current dynamic baseline data. The current window parameters are obtained, and the adaptive baseline of each current sliding window is calculated using a pre-set sliding window adaptive baseline calculation formula. The current dynamic baseline data is then judged using a pre-set DNS device anomaly judgment method to generate the target DNS device judgment result. When the target DNS device is determined to be in an abnormal state, the combined description data of the current DNS device performance indicators is obtained. Then, the correlation coefficient root cause probability corresponding to each DNS device performance indicator is calculated and analyzed using a pre-set root cause probability calculation formula. The abnormal performance indicators of the target DNS device are identified, and feedback processing is performed to the user.

2. The method according to claim 1, characterized in that, The step of inputting the current log combined description data and the current DNS device configuration information into a pre-built dynamic baseline data prediction model to obtain at least one current dynamic baseline data includes: The current log combined description data and the current DNS device configuration information are subjected to data standardization processing, and the features of the current log combined description data and the current DNS device configuration information are obtained by using a pre-set feature extraction method; The current log joint description data features and the current DNS device configuration information features are input into a pre-built dynamic baseline data prediction model to obtain at least one current dynamic baseline data.

3. The method according to claim 2, characterized in that, Before collecting the current log federated description data and current DNS device configuration information corresponding to the target DNS device, the following is also included: Obtain the combined description data of the historical logs and the configuration information of the historical DNS devices, as well as the historical dynamic baseline data, for each historical DNS device. After standardization and feature extraction, historical log description data and historical DNS device configuration information are input into the initial dynamic baseline data prediction model for training. The training continues until the prediction accuracy of the initial dynamic baseline data prediction model meets the requirements, thus confirming the completion of the training of the dynamic baseline data prediction model.

4. The method according to claim 3, characterized in that, The process of obtaining the current window parameters involves calculating each current sliding window's adaptive baseline using a pre-set formula, including: Obtain the current business scenario corresponding to the target DNS device, and determine the target sensitivity coefficient through a pre-set scenario sensitivity mapping database; The target sensitivity coefficient and the current window parameters are respectively input into the sliding window adaptive baseline calculation formula for calculation to obtain the current sliding window adaptive baseline; The formula for calculating the adaptive baseline of the sliding window is Baseline(t) = μ(W) + α·σ(W), where μ(W) represents the mean of the window data corresponding to the current window parameter W, σ(W) represents the standard deviation of the window data corresponding to the current window parameter W, α represents the target sensitivity coefficient, and Baseline(t) represents the adaptive baseline of the sliding window at the current time t.

5. The method according to claim 4, characterized in that, The step of using a preset DNS device anomaly detection method to determine each of the current dynamic baseline data and generate a target DNS device determination result includes: Based on the current sliding window adaptive baseline, and in combination with the mean and standard deviation of the window data, the range of the current real-time sliding window adaptive baseline is determined. Wherein, the current real-time sliding window adaptive baseline range is the range consisting of the minimum value of the current real-time sliding window adaptive baseline and the maximum value of the current real-time sliding window adaptive baseline; From each of the current dynamic baseline data, one target current dynamic baseline data is obtained sequentially; Using a preset DNS device anomaly detection method, determine whether the target's current dynamic baseline data falls within the range of the current real-time sliding window adaptive baseline. If it does, return to the operation of sequentially obtaining the target's current dynamic baseline data from each of the current dynamic baseline data. If it does not fall within the baseline range, it is counted in the total number of non-fallen baseline ranges, and the operation of sequentially obtaining one target current dynamic baseline data from each of the current dynamic baseline data is returned. Determine whether all the current dynamic baseline data has been traversed. If all data has been traversed, determine the total number of data that does not fall within the baseline range. Obtain a preset threshold for the total number of non-baseline ranges. If the total number of non-baseline ranges is greater than the threshold, the target DNS device's judgment result is determined to be an abnormal result. If the total number of non-baseline ranges is less than or equal to the threshold, the target DNS device's judgment result is determined to be a normal result.

6. The method according to claim 5, characterized in that, When the target DNS device's judgment result is determined to be an abnormal result state, the current DNS device performance index joint description data is obtained, and the correlation coefficient root cause probability corresponding to each DNS device performance index is calculated and analyzed using a pre-set root cause probability calculation formula, and the abnormal performance index of the target DNS device is determined, including: If the target DNS device determines that the result is abnormal, then obtain the combined description data of the current DNS device's performance metrics. The current DNS device performance metrics jointly described include CPU utilization performance metrics, memory usage performance metrics, network throughput performance metrics, and device connection count performance metrics. By using pre-defined conversion functions, the CPU utilization performance index, memory usage performance index, network throughput performance index, and device connection number performance index are standardized according to the type of each performance index, to obtain the target CPU utilization performance index, target memory usage performance index, target network throughput performance index, and target device connection number performance index. Obtain the device fault value corresponding to the target DNS device, and calculate the target CPU utilization correlation coefficient, target memory usage correlation coefficient, target network throughput correlation coefficient, and target device connection number correlation coefficient by combining the target CPU utilization performance index, target memory usage performance index, target network throughput performance index, and target device connection number performance index, respectively. Obtain the abnormal deviations in CPU utilization, memory usage, network throughput, and device connection count, respectively. The root cause probability P corresponding to each DNS device performance index is calculated using the root cause probability calculation formula P = β|r| + θQ. Where β is the correlation coefficient; θ is the anomaly deviation coefficient; r is one of the target CPU utilization correlation coefficient, target memory usage correlation coefficient, target network throughput correlation coefficient, or target device connection number correlation coefficient; Q is one of the CPU utilization anomaly deviation, memory usage anomaly deviation, network throughput anomaly deviation, or device connection number anomaly deviation. Based on the root cause probabilities of each correlation coefficient, the performance anomalies of the target DNS device are determined.

7. The method according to claim 6, characterized in that, The step of determining the target DNS device performance anomaly indicators based on the root cause probabilities of each correlation coefficient includes: The root cause probabilities of each correlation coefficient are sorted, and the root cause probability of the largest correlation coefficient is determined. The performance index corresponding to the root cause probability of the maximum correlation coefficient is determined as the target DNS device performance anomaly index, and the target DNS device performance anomaly index is fed back to the user.

8. An anomaly monitoring and analysis device for DNS devices, characterized in that, include: The current log federated description data and current DNS device configuration information collection module is used to collect the current log federated description data and current DNS device configuration information corresponding to the target DNS device; The current dynamic baseline data determination module is used to input the current log joint description data and the current DNS device configuration information into a pre-built dynamic baseline data prediction model to obtain at least one current dynamic baseline data. The target DNS device judgment result generation module is used to obtain the current window parameters, calculate each current sliding window adaptive baseline using a pre-set sliding window adaptive baseline calculation formula, and judge each current dynamic baseline data using a pre-set DNS device anomaly judgment method to generate the target DNS device judgment result. The target DNS device performance anomaly indicator determination and feedback module is used to obtain the current DNS device performance indicator joint description data when the target DNS device is determined to be in an abnormal state. Then, it calculates and analyzes the correlation coefficient root cause probability corresponding to each DNS device performance indicator through a pre-set root cause probability calculation formula, determines the target DNS device performance anomaly indicator, and provides feedback processing to the user.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements a method for anomaly monitoring and analysis of a DNS device as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute a method for monitoring and analyzing anomalies in a DNS device as described in any one of claims 1-7.

Citation Information

Cited By

  • Temperature fluctuation detection method and device based on revolving door algorithm and medium

    CN121384244A