Cloud desktop operation state management and control method and system and medium
By acquiring cloud desktop monitoring log information, calculating security and operational status anomaly detection indices, and combining user operation data to predict connection disconnection situations, the problem of accurate monitoring of cloud desktop operational status is solved, and adaptive adjustment of thin client connection status is achieved.
Patent Information
- Application Number
- CN202511110394.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-08
- Publication Date
- 2025-11-14
AI Technical Summary
Existing technologies lack accurate monitoring of cloud desktop operation status, especially in terms of security anomaly detection, operation status anomaly detection, and user habit analysis, resulting in thin client connection status not being able to adaptively adjust.
By acquiring monitoring logs from cloud desktops, server hardware, network, and abnormal attack monitoring data are extracted. Security anomaly detection index and operational status anomaly detection index are calculated, and user historical operation data is combined to predict connection disconnection situations. Finally, the results are compared with preset thresholds, and a disconnection request is sent to achieve adaptive adjustment.
It enables precise detection of security anomalies and monitoring of the operational status of cloud desktops, and can adaptively adjust according to user habits, thereby improving the intelligent management of thin client connection status.
Smart Images

Figure CN120956469A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of big data and cloud computing technology, and more specifically, to methods, systems, and media for managing the operational status of cloud desktops. Background Technology
[0002] Cloud desktops are virtualized desktop solutions based on cloud computing technology. They host the operating system and applications on cloud servers, allowing users to access and use these resources through thin clients (thin clients are low-spec PCs / mobile devices where system processing is handled by the server). Monitoring the operational status of cloud desktops can detect potential security threats in real time, ensuring user safety. However, currently, there is a lack of technology that can comprehensively analyze security anomalies, operational anomalies, and user habits to obtain accurate monitoring results of cloud desktop operation and adaptively adjust thin client connection status based on these results.
[0003] Effective technical solutions are urgently needed to address the above problems. Summary of the Invention
[0004] The purpose of this application is to provide a method, system, and medium for managing the operational status of cloud desktops. First, monitoring log information of the cloud desktop is acquired. Server hardware monitoring data, network monitoring data, and abnormal attack monitoring data are extracted from the monitoring log information. Then, the abnormal attack monitoring data is processed to obtain a security anomaly detection index. The server hardware monitoring data and network monitoring data are processed to obtain an operational status anomaly detection index. User historical operation data is processed to obtain a connection disconnection prediction index. Finally, the connection disconnection prediction index is combined with the security anomaly detection index and the operational status anomaly detection index to obtain a cloud desktop operational monitoring index. This index is then compared with a preset cloud desktop operational monitoring index threshold. If the threshold comparison result meets the preset threshold comparison requirements, the thin client sends a disconnection request to the cloud desktop. This application performs security anomaly detection and operational status anomaly detection on the cloud desktop, obtains connection disconnection prediction results based on user habits, and finally processes the data to obtain accurate monitoring results of the cloud desktop's operational status, achieving a technology for adaptively adjusting the connection status of thin clients.
[0005] This application also provides a method for managing the running status of cloud desktops, including the following steps:
[0006] Obtain monitoring log information from the cloud desktop, and extract server hardware monitoring data, network monitoring data, and abnormal attack monitoring data based on the monitoring log information;
[0007] The abnormal attack monitoring data is processed to obtain a security anomaly detection index.
[0008] An abnormal operation status detection index is obtained by processing the server hardware monitoring data and the network monitoring data.
[0009] Based on the monitoring log information, extract the user's historical operation data, input the user's historical operation data into a preset user habit analysis model, and obtain the connection disconnection prediction index.
[0010] The cloud desktop operation monitoring index is obtained by processing the connection disconnection prediction index in combination with the security anomaly detection index and the operation status anomaly detection index.
[0011] The cloud desktop operation monitoring index is compared with a preset cloud desktop operation monitoring index threshold. If the threshold comparison result meets the preset threshold comparison requirements, the terminal sends a disconnection request to the cloud desktop.
[0012] Optionally, in the cloud desktop operation status management method described in this application, the step of obtaining cloud desktop monitoring log information and extracting server hardware monitoring data, network monitoring data, and abnormal attack monitoring data based on the monitoring log information includes:
[0013] Obtain monitoring log information from the cloud desktop, and extract server hardware monitoring data, network monitoring data, and abnormal attack monitoring data based on the monitoring log information;
[0014] The server hardware monitoring data includes: memory utilization data, CPU load data, CPU utilization data, and disk space utilization data;
[0015] The network monitoring data includes: bandwidth utilization data, network latency data, and packet loss rate data;
[0016] The abnormal attack monitoring data includes: abnormal access data, firewall abnormal data, vulnerability detection data, and security certificate abnormal monitoring data.
[0017] Optionally, in the cloud desktop operation status management method described in this application, the step of processing the abnormal attack monitoring data to obtain a security anomaly detection index includes:
[0018] The abnormal access data, firewall abnormal data, vulnerability detection data, and security certificate abnormal monitoring data are input into a preset security anomaly detection model for processing to obtain a security anomaly detection index.
[0019] Optionally, in the cloud desktop operation status management method described in this application, the step of obtaining an abnormal operation status detection index based on the server hardware monitoring data and the network monitoring data includes:
[0020] The network anomaly monitoring index is obtained by processing the network latency data and packet loss rate data.
[0021] The server load anomaly detection index is obtained by analyzing and processing the memory utilization data, CPU load data, CPU utilization data, disk space utilization data, and bandwidth utilization data.
[0022] The abnormal operation status detection index is obtained by weighting the network anomaly monitoring index and the server load anomaly detection index with preset weight values.
[0023] Optionally, in the cloud desktop operation status management method described in this application, the step of extracting user historical operation data based on the monitoring log information and inputting the user historical operation data into a preset user habit analysis model to obtain a connection disconnection prediction index includes:
[0024] Based on the monitoring log information, extract the user's historical operation data, including: thin client operation time data, thin client standby time data, and cloud desktop disconnection time data;
[0025] The thin client operation time data, thin client standby time data, and cloud desktop disconnection time data are input into a preset thin client connection prediction model for processing to obtain a connection disconnection prediction index.
[0026] Optionally, in the cloud desktop operation status management method described in this application, the step of processing the connection disconnection prediction index in combination with the security anomaly detection index and the operation status anomaly detection index to obtain the cloud desktop operation monitoring index includes:
[0027] The cloud desktop operation monitoring index is obtained by processing the connection disconnection prediction index in combination with the security anomaly detection index and the operation status anomaly detection index.
[0028] The formula for processing the cloud desktop operation monitoring index is as follows:
[0029]
[0030] Among them, H n For cloud desktop operation monitoring index, Y b For the connection disconnection prediction index, U c K is the safety anomaly detection index. a The index is the abnormal operation status detection index, and γ, ε, θ, and ω are preset characteristic coefficients.
[0031] Optionally, in the cloud desktop operation status management method described in this application, the step of comparing the cloud desktop operation monitoring index with a preset cloud desktop operation monitoring index threshold, and if the threshold comparison result meets the preset threshold comparison requirements, the terminal sends a disconnection request to the cloud desktop, including:
[0032] The cloud desktop operation monitoring index is compared with a preset cloud desktop operation monitoring index threshold to obtain the threshold comparison result.
[0033] If the threshold comparison result meets the preset threshold comparison requirements, the thin terminal sends a disconnection request to the cloud desktop;
[0034] Otherwise, the cloud desktop will remain connected.
[0035] Secondly, this application provides a cloud desktop operation status management system, which includes: a memory and a processor. The memory includes a program for a cloud desktop operation status management method. When the program for the cloud desktop operation status management method is executed by the processor, it implements the following steps:
[0036] Obtain monitoring log information from the cloud desktop, and extract server hardware monitoring data, network monitoring data, and abnormal attack monitoring data based on the monitoring log information;
[0037] The abnormal attack monitoring data is processed to obtain a security anomaly detection index.
[0038] An abnormal operation status detection index is obtained by processing the server hardware monitoring data and the network monitoring data.
[0039] Based on the monitoring log information, extract the user's historical operation data, input the user's historical operation data into a preset user habit analysis model, and obtain the connection disconnection prediction index.
[0040] The cloud desktop operation monitoring index is obtained by processing the connection disconnection prediction index in combination with the security anomaly detection index and the operation status anomaly detection index.
[0041] The cloud desktop operation monitoring index is compared with a preset cloud desktop operation monitoring index threshold. If the threshold comparison result meets the preset threshold comparison requirements, the terminal sends a disconnection request to the cloud desktop.
[0042] Optionally, in the cloud desktop operation status management system described in this application, the step of obtaining the cloud desktop monitoring log information and extracting server hardware monitoring data, network monitoring data, and abnormal attack monitoring data based on the monitoring log information includes:
[0043] Obtain monitoring log information from the cloud desktop, and extract server hardware monitoring data, network monitoring data, and abnormal attack monitoring data based on the monitoring log information;
[0044] The server hardware monitoring data includes: memory utilization data, CPU load data, CPU utilization data, and disk space utilization data;
[0045] The network monitoring data includes: bandwidth utilization data, network latency data, and packet loss rate data;
[0046] The abnormal attack monitoring data includes: abnormal access data, firewall abnormal data, vulnerability detection data, and security certificate abnormal monitoring data.
[0047] Thirdly, this application also provides a computer-readable storage medium including a cloud desktop operation state management method program, which, when executed by a processor, implements the steps of the cloud desktop operation state management method as described in any of the above claims.
[0048] As described above, the cloud desktop operation status management method, system, and medium provided in this application acquire cloud desktop monitoring log information, extract server hardware monitoring data, network monitoring data, and abnormal attack monitoring data from the monitoring log information, process the abnormal attack monitoring data to obtain a security anomaly detection index, process the server hardware monitoring data and network monitoring data to obtain an operation status anomaly detection index, process the user's historical operation data to obtain a connection disconnection prediction index, and process the connection disconnection prediction index in combination with the security anomaly detection index and the operation status anomaly detection index to obtain a cloud desktop operation monitoring index. This index is then compared with a preset cloud desktop operation monitoring index threshold. If the threshold comparison result meets the preset threshold comparison requirements, the thin client sends a disconnection request to the cloud desktop. This application performs security anomaly detection and operation status anomaly detection on the cloud desktop, obtains connection disconnection prediction results based on user habits, and finally processes the data to obtain accurate monitoring results of the cloud desktop operation status, realizing a technology for adaptive adjustment of the thin client connection status.
[0049] Other features and advantages of this application will be set forth in the following description and will be apparent in part from the description or may be learned by practicing embodiments of this application. The objectives and other advantages of this application may be realized and obtained by means of the structures particularly pointed out in the written description and the accompanying drawings. Attached Figure Description
[0050] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0051] Figure 1 A flowchart illustrating the cloud desktop operation status management method provided in this application embodiment;
[0052] Figure 2 A flowchart illustrating the method for controlling the running status of a cloud desktop as provided in this application embodiment for obtaining an abnormal running status detection index;
[0053] Figure 3 A flowchart illustrating the method for controlling the running status of a cloud desktop provided in this application embodiment for obtaining a connection disconnection prediction index; Detailed Implementation
[0054] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. The components of the embodiments of this application described and shown in the accompanying drawings can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely represents selected embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.
[0055] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, the terms "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0056] Please refer to Figure 1 , Figure 1 This is a flowchart of a cloud desktop operation status management method according to some embodiments of this application. This cloud desktop operation status management method is used in terminal devices, such as computers and mobile terminals. The cloud desktop operation status management method includes the following steps:
[0057] S11. Obtain monitoring log information of the cloud desktop, and extract server hardware monitoring data, network monitoring data and abnormal attack monitoring data based on the monitoring log information;
[0058] S12. Process the abnormal attack monitoring data to obtain a security anomaly detection index;
[0059] S13. Obtain the abnormal operation status detection index by processing the server hardware monitoring data and the network monitoring data.
[0060] S14. Extract user historical operation data based on the monitoring log information, input the user historical operation data into a preset user habit analysis model, and obtain the connection disconnection prediction index.
[0061] S15. Process the connection disconnection prediction index in combination with the security anomaly detection index and the operation status anomaly detection index to obtain the cloud desktop operation monitoring index.
[0062] S16. The cloud desktop operation monitoring index is compared with the preset cloud desktop operation monitoring index threshold. If the threshold comparison result meets the preset threshold comparison requirements, the terminal sends a disconnection request to the cloud desktop.
[0063] It should be noted that, in order to achieve intelligent detection and control of the cloud desktop's operating status, monitoring log information of the cloud desktop is obtained. Server hardware monitoring data, network monitoring data, and abnormal attack monitoring data are extracted from the monitoring log information. The abnormal attack monitoring data is processed to obtain a security anomaly detection index, which represents the security of the cloud desktop's current operating environment. An operating status anomaly detection index is obtained by processing the server hardware and network monitoring data. A connection disconnection prediction index is obtained by processing the thin client's historical operation data. This connection disconnection prediction index represents data predicting the cloud desktop's connection disconnection. The connection disconnection prediction index is combined with the security anomaly detection index and the operating status anomaly detection index to obtain a cloud desktop operating monitoring index. This index is then compared with a preset cloud desktop operating monitoring index threshold. If the threshold comparison result meets the preset threshold comparison requirements, the thin client sends a disconnection request to the cloud desktop. This application performs security anomaly detection and operating status anomaly detection on the cloud desktop, obtains connection disconnection prediction results based on user habits, and finally processes the data to obtain accurate monitoring results of the cloud desktop's operating status, achieving a technology for adaptive adjustment of the thin client's connection status.
[0064] According to an embodiment of the present invention, obtaining monitoring log information of the cloud desktop and extracting server hardware monitoring data, network monitoring data, and abnormal attack monitoring data based on the monitoring log information includes:
[0065] Obtain monitoring log information from the cloud desktop, and extract server hardware monitoring data, network monitoring data, and abnormal attack monitoring data based on the monitoring log information;
[0066] The server hardware monitoring data includes: memory utilization data, CPU load data, CPU utilization data, and disk space utilization data;
[0067] The network monitoring data includes: bandwidth utilization data, network latency data, and packet loss rate data;
[0068] The abnormal attack monitoring data includes: abnormal access data, firewall abnormal data, vulnerability detection data, and security certificate abnormal monitoring data.
[0069] It should be noted that, in order to obtain the security anomaly detection index and the operational status anomaly detection index by processing the monitoring log information, the monitoring log information of the cloud desktop is obtained, and server hardware monitoring data, network monitoring data and abnormal attack monitoring data are extracted from the monitoring log information.
[0070] According to an embodiment of the present invention, the step of processing the abnormal attack monitoring data to obtain a security anomaly detection index includes:
[0071] The abnormal access data, firewall abnormal data, vulnerability detection data, and security certificate abnormal monitoring data are input into a preset security anomaly detection model for processing to obtain a security anomaly detection index.
[0072] It should be noted that in order to determine the security status of the cloud desktop, abnormal access data, firewall abnormal data, vulnerability detection data, and security certificate abnormal monitoring data need to be input into a preset security anomaly detection model for processing. This security anomaly detection model is obtained by training a large number of historical samples of abnormal access data, firewall abnormal data, vulnerability detection data, security certificate abnormal monitoring data, and security anomaly detection index. The corresponding output security anomaly detection index can be obtained by processing the relevant input information.
[0073] Please refer to Figure 2 , Figure 2 This is a flowchart illustrating the method for controlling the running status of a cloud desktop in some embodiments of this application, specifically the process of obtaining an anomaly detection index. According to an embodiment of the present invention, obtaining the anomaly detection index based on the server hardware monitoring data and the network monitoring data includes:
[0074] S21. Obtain a network anomaly monitoring index by processing the network latency data and packet loss rate data;
[0075] S22. Analyze and process the memory utilization data, CPU load data, CPU utilization data, disk space utilization data and bandwidth utilization data to obtain the server load anomaly detection index.
[0076] S23. Based on the network anomaly monitoring index and the server load anomaly detection index, and using preset weight values, a weighted average is performed to obtain the operating status anomaly detection index.
[0077] It should be noted that, in order to detect anomalies in the operation of cloud desktops, data such as memory utilization, CPU load, CPU utilization, disk space utilization, and bandwidth utilization are analyzed and processed to obtain a server load anomaly detection index.
[0078] The program processing formula for the server load anomaly detection index is as follows:
[0079]
[0080] Among them, K a R is the server load anomaly detection index. b For memory utilization data, L x For CPU load data, B c For CPU utilization data, D f For disk space utilization data, P m The bandwidth utilization data is ξ, φ, λ, χ, μ, and σ, which are preset characteristic coefficients obtained from the cloud desktop operation monitoring information database.
[0081] Please refer to Figure 3 , Figure 3 This is a flowchart illustrating the method for controlling the cloud desktop's operating status in some embodiments of this application, specifically for obtaining a connection disconnection prediction index. According to an embodiment of the present invention, the step of extracting historical user operation data based on the monitoring log information, inputting the historical user operation data into a preset user habit analysis model, and obtaining the connection disconnection prediction index includes:
[0082] S31. Extract user historical operation data based on the monitoring log information, including: thin client operation time data, thin client standby time data, and cloud desktop disconnection time data;
[0083] S32. Input the thin client operation time data, thin client standby time data, and cloud desktop disconnection time data into a preset thin client connection prediction model for processing to obtain a connection disconnection prediction index.
[0084] It should be noted that the connection disconnection prediction index is a prediction data of cloud desktop connection disconnection obtained by analyzing users' historical operating habits of thin clients. Thin client operation time data, thin client standby time data, and cloud desktop disconnection time data are input into a preset thin client connection prediction model for processing to obtain the connection disconnection prediction index. This thin client connection prediction model is a model trained by acquiring a large number of historical samples of thin client operation time data, thin client standby time data, cloud desktop disconnection time data, and connection disconnection prediction index. The corresponding output connection disconnection prediction index can be obtained by processing relevant input information.
[0085] According to an embodiment of the present invention, the step of processing the connection disconnection prediction index in combination with the security anomaly detection index and the operational status anomaly detection index to obtain the cloud desktop operation monitoring index includes:
[0086] The cloud desktop operation monitoring index is obtained by processing the connection disconnection prediction index in combination with the security anomaly detection index and the operation status anomaly detection index.
[0087] The formula for processing the cloud desktop operation monitoring index is as follows:
[0088]
[0089] Among them, H n For cloud desktop operation monitoring index, Y b For the connection disconnection prediction index, U c G is a safety anomaly detection index. t The index is used for detecting abnormal operating status. γ, ε, θ, and ω are preset feature coefficients, which are obtained from the cloud desktop operation monitoring information database.
[0090] It should be noted that by comprehensively analyzing and processing the results of security anomaly detection, operational anomaly detection, and cloud desktop connection disconnection prediction, the goal of accurately monitoring the operational status of the cloud desktop can be achieved.
[0091] This invention also discloses a cloud desktop operation status management system, including a memory and a processor. The memory includes a cloud desktop operation status management method program, which, when executed by the processor, performs the following steps:
[0092] Obtain monitoring log information from the cloud desktop, and extract server hardware monitoring data, network monitoring data, and abnormal attack monitoring data based on the monitoring log information;
[0093] The abnormal attack monitoring data is processed to obtain a security anomaly detection index.
[0094] An abnormal operation status detection index is obtained by processing the server hardware monitoring data and the network monitoring data.
[0095] Based on the monitoring log information, extract the user's historical operation data, input the user's historical operation data into a preset user habit analysis model, and obtain the connection disconnection prediction index.
[0096] The cloud desktop operation monitoring index is obtained by processing the connection disconnection prediction index in combination with the security anomaly detection index and the operation status anomaly detection index.
[0097] The cloud desktop operation monitoring index is compared with a preset cloud desktop operation monitoring index threshold. If the threshold comparison result meets the preset threshold comparison requirements, the terminal sends a disconnection request to the cloud desktop.
[0098] It should be noted that, in order to achieve intelligent detection and control of the cloud desktop's operating status, monitoring log information of the cloud desktop is obtained. Server hardware monitoring data, network monitoring data, and abnormal attack monitoring data are extracted from the monitoring log information. The abnormal attack monitoring data is processed to obtain a security anomaly detection index, which represents the security of the cloud desktop's current operating environment. An operating status anomaly detection index is obtained by processing the server hardware and network monitoring data. A connection disconnection prediction index is obtained by processing the thin client's historical operation data. This connection disconnection prediction index represents data predicting the cloud desktop's connection disconnection. The connection disconnection prediction index is combined with the security anomaly detection index and the operating status anomaly detection index to obtain a cloud desktop operating monitoring index. This index is then compared with a preset cloud desktop operating monitoring index threshold. If the threshold comparison result meets the preset threshold comparison requirements, the thin client sends a disconnection request to the cloud desktop. This application performs security anomaly detection and operating status anomaly detection on the cloud desktop, obtains connection disconnection prediction results based on user habits, and finally processes the data to obtain accurate monitoring results of the cloud desktop's operating status, achieving a technology for adaptive adjustment of the thin client's connection status.
[0099] According to an embodiment of the present invention, obtaining monitoring log information of the cloud desktop and extracting server hardware monitoring data, network monitoring data, and abnormal attack monitoring data based on the monitoring log information includes:
[0100] Obtain monitoring log information from the cloud desktop, and extract server hardware monitoring data, network monitoring data, and abnormal attack monitoring data based on the monitoring log information;
[0101] The server hardware monitoring data includes: memory utilization data, CPU load data, CPU utilization data, and disk space utilization data;
[0102] The network monitoring data includes: bandwidth utilization data, network latency data, and packet loss rate data;
[0103] The abnormal attack monitoring data includes: abnormal access data, firewall abnormal data, vulnerability detection data, and security certificate abnormal monitoring data.
[0104] It should be noted that, in order to obtain the security anomaly detection index and the operational status anomaly detection index by processing the monitoring log information, the monitoring log information of the cloud desktop is obtained, and server hardware monitoring data, network monitoring data and abnormal attack monitoring data are extracted from the monitoring log information.
[0105] According to an embodiment of the present invention, the step of processing the abnormal attack monitoring data to obtain a security anomaly detection index includes:
[0106] The abnormal access data, firewall abnormal data, vulnerability detection data, and security certificate abnormal monitoring data are input into a preset security anomaly detection model for processing to obtain a security anomaly detection index.
[0107] It should be noted that in order to determine the security status of the cloud desktop, abnormal access data, firewall abnormal data, vulnerability detection data, and security certificate abnormal monitoring data need to be input into a preset security anomaly detection model for processing. This security anomaly detection model is obtained by training a large number of historical samples of abnormal access data, firewall abnormal data, vulnerability detection data, security certificate abnormal monitoring data, and security anomaly detection index. The corresponding output security anomaly detection index can be obtained by processing the relevant input information.
[0108] According to an embodiment of the present invention, the step of obtaining an anomaly detection index based on the server hardware monitoring data and the network monitoring data includes:
[0109] The network anomaly monitoring index is obtained by processing the network latency data and packet loss rate data.
[0110] The server load anomaly detection index is obtained by analyzing and processing the memory utilization data, CPU load data, CPU utilization data, disk space utilization data, and bandwidth utilization data.
[0111] The abnormal operation status detection index is obtained by weighting the network anomaly monitoring index and the server load anomaly detection index with preset weight values.
[0112] It should be noted that, in order to detect anomalies in the operation of cloud desktops, data such as memory utilization, CPU load, CPU utilization, disk space utilization, and bandwidth utilization are analyzed and processed to obtain a server load anomaly detection index.
[0113] The program processing formula for the server load anomaly detection index is as follows:
[0114]
[0115] Among them, K a R is the server load anomaly detection index. b For memory utilization data, L x For CPU load data, B c For CPU utilization data, D f For disk space utilization data, P m The bandwidth utilization data is ξ, φ, λ, χ, μ, and σ, which are preset characteristic coefficients obtained from the cloud desktop operation monitoring information database.
[0116] According to an embodiment of the present invention, the step of extracting user historical operation data based on the monitoring log information, inputting the user historical operation data into a preset user habit analysis model, and obtaining a connection disconnection prediction index includes:
[0117] Based on the monitoring log information, extract the user's historical operation data, including: thin client operation time data, thin client standby time data, and cloud desktop disconnection time data;
[0118] The thin client operation time data, thin client standby time data, and cloud desktop disconnection time data are input into a preset thin client connection prediction model for processing to obtain a connection disconnection prediction index.
[0119] It should be noted that the connection disconnection prediction index is a prediction data of cloud desktop connection disconnection obtained by analyzing users' historical operating habits of thin clients. Thin client operation time data, thin client standby time data, and cloud desktop disconnection time data are input into a preset thin client connection prediction model for processing to obtain the connection disconnection prediction index. This thin client connection prediction model is a model trained by acquiring a large number of historical samples of thin client operation time data, thin client standby time data, cloud desktop disconnection time data, and connection disconnection prediction index. The corresponding output connection disconnection prediction index can be obtained by processing relevant input information.
[0120] According to an embodiment of the present invention, the step of processing the connection disconnection prediction index in combination with the security anomaly detection index and the operational status anomaly detection index to obtain the cloud desktop operation monitoring index includes:
[0121] The cloud desktop operation monitoring index is obtained by processing the connection disconnection prediction index in combination with the security anomaly detection index and the operation status anomaly detection index.
[0122] The formula for processing the cloud desktop operation monitoring index is as follows:
[0123]
[0124] Among them, H n For cloud desktop operation monitoring index, Y b For the connection disconnection prediction index, U c G is a safety anomaly detection index. t The index is used for detecting abnormal operating status. γ, ε, θ, and ω are preset feature coefficients, which are obtained from the cloud desktop operation monitoring information database.
[0125] It should be noted that by comprehensively analyzing and processing the results of security anomaly detection, operational anomaly detection, and cloud desktop connection disconnection prediction, the goal of accurately monitoring the operational status of the cloud desktop can be achieved.
[0126] A third aspect of the present invention provides a readable storage medium including a cloud desktop operation state management method program, wherein when the cloud desktop operation state management method program is executed by a processor, it implements the steps of the cloud desktop operation state management method as described in any of the preceding claims.
[0127] This invention discloses a method, system, and medium for managing the operational status of a cloud desktop. First, it acquires monitoring log information of the cloud desktop. Based on this log information, it extracts server hardware monitoring data, network monitoring data, and abnormal attack monitoring data. Then, it processes the abnormal attack monitoring data to obtain a security anomaly detection index. Next, it processes the server hardware and network monitoring data to obtain an operational status anomaly detection index. Finally, it processes user historical operation data to obtain a connection disconnection prediction index. Finally, it combines the connection disconnection prediction index with the security anomaly detection index and the operational status anomaly detection index to obtain a cloud desktop operational monitoring index. This index is then compared with a preset cloud desktop operational monitoring index threshold. If the threshold comparison result meets the preset threshold comparison requirements, the thin client sends a disconnection request to the cloud desktop. This application performs security anomaly detection and operational status anomaly detection on the cloud desktop, obtains connection disconnection prediction results based on user habits, and finally processes these results to obtain accurate monitoring results of the cloud desktop's operational status, achieving a technology for adaptively adjusting the connection status of thin clients.
[0128] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.
[0129] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units. They may be located in one place or distributed across multiple network units. Some or all of the units may be selected to achieve the purpose of this embodiment according to actual needs.
[0130] In addition, in the various embodiments of the present invention, each functional unit can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.
[0131] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0132] Alternatively, if the integrated units of this invention are implemented as software functional modules and sold or used as independent products, they can also be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of this invention, or the parts that contribute to the prior art, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROM, RAM, magnetic disks, or optical disks.
Claims
1. A method for managing the running status of a cloud desktop, characterized in that, Includes the following steps: Obtain monitoring log information from the cloud desktop, and extract server hardware monitoring data, network monitoring data, and abnormal attack monitoring data based on the monitoring log information; The abnormal attack monitoring data is processed to obtain a security anomaly detection index. An abnormal operation status detection index is obtained by processing the server hardware monitoring data and the network monitoring data. Based on the monitoring log information, extract the user's historical operation data, input the user's historical operation data into a preset user habit analysis model, and obtain the connection disconnection prediction index. The cloud desktop operation monitoring index is obtained by processing the connection disconnection prediction index in combination with the security anomaly detection index and the operation status anomaly detection index. The cloud desktop operation monitoring index is compared with a preset cloud desktop operation monitoring index threshold. If the threshold comparison result meets the preset threshold comparison requirements, the terminal sends a disconnection request to the cloud desktop.
2. The method for controlling the running status of a cloud desktop according to claim 1, characterized in that, The process of obtaining cloud desktop monitoring log information, and extracting server hardware monitoring data, network monitoring data, and abnormal attack monitoring data based on the monitoring log information, includes: Obtain monitoring log information from the cloud desktop, and extract server hardware monitoring data, network monitoring data, and abnormal attack monitoring data based on the monitoring log information; The server hardware monitoring data includes: memory utilization data, CPU load data, CPU utilization data, and disk space utilization data; The network monitoring data includes: bandwidth utilization data, network latency data, and packet loss rate data; The abnormal attack monitoring data includes: abnormal access data, firewall abnormal data, vulnerability detection data, and security certificate abnormal monitoring data.
3. The method for controlling the running status of a cloud desktop according to claim 2, characterized in that, The process of processing the abnormal attack monitoring data to obtain a security anomaly detection index includes: The abnormal access data, firewall abnormal data, vulnerability detection data, and security certificate abnormal monitoring data are input into a preset security anomaly detection model for processing to obtain a security anomaly detection index.
4. The method for controlling the running status of a cloud desktop according to claim 3, characterized in that, The process of obtaining the anomaly detection index based on the server hardware monitoring data and the network monitoring data includes: The network anomaly monitoring index is obtained by processing the network latency data and packet loss rate data. The server load anomaly detection index is obtained by analyzing and processing the memory utilization data, CPU load data, CPU utilization data, disk space utilization data, and bandwidth utilization data. The abnormal operation status detection index is obtained by weighting the network anomaly monitoring index and the server load anomaly detection index with preset weight values.
5. The method for controlling the running status of a cloud desktop according to claim 4, characterized in that, The step of extracting user historical operation data based on the monitoring log information, inputting the user historical operation data into a preset user habit analysis model, and obtaining a connection disconnection prediction index includes: Based on the monitoring log information, extract the user's historical operation data, including: thin client operation time data, thin client standby time data, and cloud desktop disconnection time data; The thin client operation time data, thin client standby time data, and cloud desktop disconnection time data are input into a preset thin client connection prediction model for processing to obtain a connection disconnection prediction index.
6. The method for controlling the running status of a cloud desktop according to claim 5, characterized in that, The process of obtaining the cloud desktop operation monitoring index by combining the connection disconnection prediction index with the security anomaly detection index and the operation status anomaly detection index includes: The cloud desktop operation monitoring index is obtained by processing the connection disconnection prediction index in combination with the security anomaly detection index and the operation status anomaly detection index. The formula for processing the cloud desktop operation monitoring index is as follows: Among them, H n For cloud desktop operation monitoring index, Y b For the connection disconnection prediction index, U c K is the safety anomaly detection index. a The index is the abnormal operation status detection index, and γ, ε, θ, and ω are preset characteristic coefficients.
7. The method for controlling the running status of a cloud desktop according to claim 6, characterized in that, The step of comparing the cloud desktop operation monitoring index with a preset cloud desktop operation monitoring index threshold, and if the threshold comparison result meets the preset threshold comparison requirements, the terminal sends a disconnection request to the cloud desktop, including: The cloud desktop operation monitoring index is compared with a preset cloud desktop operation monitoring index threshold to obtain the threshold comparison result. If the threshold comparison result meets the preset threshold comparison requirements, the thin terminal sends a disconnection request to the cloud desktop; Otherwise, the cloud desktop will remain connected.
8. A cloud desktop operation status management system, characterized in that, It includes a memory and a processor. The memory includes a method program for managing the running state of the cloud desktop. When the processor executes the method program for managing the running state of the cloud desktop, it performs the following steps: Obtain monitoring log information from the cloud desktop, and extract server hardware monitoring data, network monitoring data, and abnormal attack monitoring data based on the monitoring log information; The abnormal attack monitoring data is processed to obtain a security anomaly detection index. An abnormal operation status detection index is obtained by processing the server hardware monitoring data and the network monitoring data. Based on the monitoring log information, extract the user's historical operation data, input the user's historical operation data into a preset user habit analysis model, and obtain the connection disconnection prediction index. The cloud desktop operation monitoring index is obtained by processing the connection disconnection prediction index in combination with the security anomaly detection index and the operation status anomaly detection index. The cloud desktop operation monitoring index is compared with a preset cloud desktop operation monitoring index threshold. If the threshold comparison result meets the preset threshold comparison requirements, the terminal sends a disconnection request to the cloud desktop.
9. The cloud desktop operation status management system according to claim 8, characterized in that, The process of obtaining cloud desktop monitoring log information, and extracting server hardware monitoring data, network monitoring data, and abnormal attack monitoring data based on the monitoring log information, includes: Obtain monitoring log information from the cloud desktop, and extract server hardware monitoring data, network monitoring data, and abnormal attack monitoring data based on the monitoring log information; The server hardware monitoring data includes: memory utilization data, CPU load data, CPU utilization data, and disk space utilization data; The network monitoring data includes: bandwidth utilization data, network latency data, and packet loss rate data; The abnormal attack monitoring data includes: abnormal access data, firewall abnormal data, vulnerability detection data, and security certificate abnormal monitoring data.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a cloud desktop operation state management method program, which, when executed by a processor, implements the steps of the cloud desktop operation state management method as described in any one of claims 1 to 7.