Information recommendation method and device, equipment, medium and program product
By linking and analyzing device performance, cloud platform resources, and security device data in multiple dimensions, a global data link diagram is generated, which overcomes the limitations of human-business-business-opportunity analysis in existing technologies and enables accurate information recommendation and automated push.
Patent Information
- Application Number
- CN202511775653.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-28
- Publication Date
- 2026-01-02
AI Technical Summary
In cloud business systems, existing technologies rely on manual or traditional automated tools for business opportunity analysis, resulting in high labor costs, limited coverage, difficulty in achieving accurate information delivery, and delayed and limited information recognition.
By acquiring device performance data, cloud platform resource data, and security device data, multi-dimensional correlations are performed to generate a global data link diagram. Risk detection and information analysis are then conducted to generate security potential and performance potential analyses, and an information list is automatically generated.
It enables accurate identification of user risks and automated generation of product lists, achieving flexible and accurate information recommendations, reducing labor costs and increasing coverage.
Smart Images

Figure CN121256147A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the technical field of data processing, and in particular relates to an information recommendation method, apparatus, device, medium and program product. Background Technology
[0002] Currently, in cloud business systems, business data is mainly queried through internal government affairs management platforms. The management of business data mainly relies on manual or traditional automated tools. In particular, information mining relies heavily on customer managers' manual visits and manual analysis of multiple data sources to analyze business opportunities. This not only results in high labor costs but also limited coverage, making it easy to miss high-value customers, making it difficult to achieve accurate information push, leading to information recognition delays and an inability to flexibly recommend information, thus exhibiting significant limitations. Summary of the Invention
[0003] This application provides an information recommendation method, apparatus, device, medium, and program product that can comprehensively collect data, analyze information from multiple dimensions, and recommend information flexibly and accurately.
[0004] On the one hand, embodiments of this application provide an information recommendation method, the method including: Acquire multi-source datasets, which include device performance data, cloud platform resource data, and security device data; Based on the target identifier, the device performance data, cloud platform resource data, and security device data are correlated in multiple dimensions to obtain a global data link diagram corresponding to the target identifier; Risk detection is performed based on the data from the aforementioned security devices to obtain risk detection results; Information analysis is performed based on the device performance data, cloud platform resource data, and security device data to obtain information analysis results; Based on the global data link diagram, risk detection results, and information analysis results, a security potential and performance potential analysis is performed to obtain an information list, which includes a target risk customer and a corresponding product deployment list and / or product optimization list.
[0005] Optionally, the information analysis based on the device performance data, cloud platform resource data, and security device data to obtain the information analysis results includes: Acquire historical resource performance data, security events, and business data for multiple customers; A time-series analysis of the historical resource performance data is performed using a preset time-series prediction model to obtain a resource utilization rate prediction sequence. The resource utilization prediction sequence, security events, and business data are correlated in multiple dimensions to obtain a correlated dataset. Perform multidimensional clustering on the associated dataset to obtain the clustering results; Based on the clustering results, the information of the multiple customers is classified to obtain information analysis results, which include a list of high-potential expansion customers, a list of security services, and a list of inefficient resources.
[0006] Optionally, the step of performing multidimensional clustering on the associated dataset to obtain clustering results includes: Based on the aforementioned associated dataset, a three-dimensional feature vector is constructed; The three-dimensional feature vectors are transformed using a preset standard matrix to obtain a standardized matrix; A preset weighting algorithm is used to determine the feature weight matrix corresponding to the standardized matrix; Using a preset distance calculation algorithm and a preset neighborhood radius, the feature weight matrix is clustered to obtain multiple clusters. The preset neighborhood radius is determined based on a preset contour coefficient optimized neighborhood radius. The multiple clusters are determined as the clustering result.
[0007] Optionally, the security device data includes risk attack data, and the step of performing risk detection based on the security device data to obtain risk detection results includes: Obtain the security product configuration information corresponding to the target identifier; The risk attack data and security product configuration information are correlated to obtain the risk analysis data; Using a pre-defined expert rule base, risk detection is performed on the data to be analyzed to obtain risk detection results.
[0008] Optionally, a security potential analysis is performed based on the global data link diagram, risk detection results, and the information analysis results to obtain an information list, including: Based on the global data link diagram, extract the customer's security logs from the information analysis results; The security logs are analyzed for security potential using preset filtering criteria to identify the target customer group. Based on the risk assessment results of the target customer group, plan a list of security products corresponding to the risk assessment results; The target customer group and the corresponding security product list are defined as an information list.
[0009] Optionally, a performance potential analysis is performed based on the global data link diagram, risk detection results, and information analysis results to obtain an information list, including: Based on the global data link diagram, obtain the customer's performance indicators from the information analysis results; Based on the multi-source dataset, the mean and peak utilization of each performance metric are determined; The product configuration for the customer is optimized based on the average and peak usage rates to obtain a product optimization list.
[0010] Optionally, after performing security and performance potential analysis based on the global data link diagram, risk detection results, and information analysis results to obtain an information list, the method further includes: Obtain the identity identifier of the accessing user; Based on the identity identifier, determine the access permissions for the accessing user; Based on the access permissions, the information list is filtered to obtain a filtered information list, which is then sent to the accessing user.
[0011] Optionally, after filtering the information list based on the access permissions to obtain the filtered information list, the method further includes: The filtered information list is structurally transformed to dynamically generate a structured file; Based on the structured file, generate display links; In response to a user's request to click on a displayed link, the user is authenticated. If the security authentication is successful, download the structured file.
[0012] Optionally, the method further includes: In response to a user's product Q&A request, obtain the product question information entered by the user; Based on the product problem information, synchronous vector retrieval and / or keyword retrieval are performed in a preset knowledge base to obtain retrieval results. The preset knowledge base includes structured product knowledge sources, customer attribute information, historical product problem information, and corresponding solutions. The search results are weighted and sorted to obtain a preset number of knowledge entries that are most relevant to the product problem information; The knowledge entries and product problem information are input into a preset analysis model, which performs semantic analysis on the knowledge entries and product problem information to obtain the target knowledge entries with the highest matching degree with the product problem information. The target knowledge entry is sent to the user.
[0013] Optionally, the method further includes: In response to the fault information input by the user, the fault information is semantically parsed using a preset fault analysis model to obtain target parameters and fault scenarios; Based on the fault scenario, invoke the preset detection process template; According to the preset detection process template, the target parameters are detected to obtain a detection report, which includes problem location, associated abnormal configuration items / resources, and repair suggestions. The detection report is sent to the user.
[0014] Optionally, obtaining the multi-source dataset includes: Based on a preset network protocol, collect device performance data of physical layer devices; Based on the preset network interface, access cloud platform resources; Based on preset crawling technology, capture security device data of security devices.
[0015] On the other hand, embodiments of this application provide a cloud service integrated intelligent system device including: Information recommendation intelligent agent, The information recommendation agent includes: The acquisition module is used to acquire multi-source datasets in the information recommendation agent, wherein the multi-source datasets include device performance data, cloud platform resource data, and security device data; The association module is used to perform multi-dimensional association of the device performance data, cloud platform resource data and security device data based on the target identifier to obtain a global data link diagram corresponding to the target identifier. The detection module is used to perform risk detection based on the data from the security device and obtain the risk detection results; The potential analysis module is used to perform information analysis based on the device performance data, cloud platform resource data, and security device data to obtain information analysis results. The potential analysis module is also used to perform security and performance potential analysis based on the global data link diagram, risk detection results, and information analysis results to obtain an information list, which includes a target risk customer and a corresponding product deployment list and / or product optimization list.
[0016] In another aspect, embodiments of this application provide an electronic device, the device comprising: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, it implements the information recommendation method as described in the first aspect.
[0017] In another aspect, embodiments of this application provide a computer storage medium storing computer program instructions, which, when executed by a processor, implement the information recommendation method as described in the first aspect.
[0018] In another aspect, embodiments of this application provide a computer program product in which instructions, when executed by a processor of an electronic device, cause the electronic device to perform the information recommendation method as described in the first aspect.
[0019] The information recommendation method, apparatus, device, medium, and program product of this application embodiment can integrate device performance data, cloud platform resource data, and security device data to obtain a global data link diagram corresponding to the target identifier. It can also perform information analysis on users through risk detection results and information analysis results to accurately determine the risk of each user and the product list corresponding to each risk. Furthermore, it can automatically generate an information list about products and link it with the user management system by analyzing user data from both security and performance dimensions to achieve accurate information push. In other words, by collecting multi-source datasets and performing information analysis from multiple dimensions, it can flexibly and accurately recommend information. Attached Figure Description
[0020] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 This is a flowchart illustrating an information recommendation method provided in one embodiment of this application; Figure 2 This is a flowchart illustrating an information recommendation method provided in another embodiment of this application; Figure 3 This is a flowchart illustrating an information recommendation method provided in another embodiment of this application; Figure 4 This is a schematic diagram of the structure of a cloud service integrated intelligent system provided in another embodiment of this application; Figure 5 This is a schematic diagram of the structure of an electronic device provided in another embodiment of this application. Detailed Implementation
[0022] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.
[0023] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.
[0024] To address the problems of existing technologies, embodiments of this application provide an information recommendation method, apparatus, device, medium, and program product. By integrating device performance data, cloud platform resource data, and security device data, a global data link diagram corresponding to a target identifier is obtained. Information analysis of users is performed based on risk detection results and information analysis results to accurately determine the risk of each user and the corresponding product list for each risk. Furthermore, by analyzing user data from both security and performance dimensions, an information list about products is automatically generated and linked to the user management system to achieve precise information push. In other words, by comprehensively analyzing information from multiple sources and dimensions through collected datasets, flexible and accurate information recommendation can be performed.
[0025] The information recommendation method provided in the embodiments of this application will be introduced first below.
[0026] Figure 1 A flowchart illustrating an embodiment of the information recommendation method provided in this application is shown. Figure 1 As shown, the information recommendation method may include S101-S105: S101, Obtain multi-source datasets.
[0027] In some embodiments, in order to achieve accurate recommendations for cloud platform business opportunities, data can be obtained from multiple dimensions such as the physical layer devices of cloud platform users, cloud platform resources, and security devices to analyze business opportunities from multiple perspectives and achieve the purpose of accurate recommendations. The multi-source dataset may include device performance data, cloud platform resource data, and security device data.
[0028] S102, based on the target identifier, perform multi-dimensional association of device performance data, cloud platform resource data and security device data to obtain a global data link diagram corresponding to the target identifier.
[0029] In some embodiments, in order to quickly analyze multi-source data, cross-platform association technology can be applied based on IP address, resource ID, tenant ID, and project ID to deeply and multidimensionally associate cloud host, security product, and tenant project information to obtain a global data link diagram.
[0030] In this embodiment of the application, the target identifier can be the user's IP address. During the multi-dimensional association process, since physical layer devices, cloud platform resources, and security device data all use the same IP address, the IP address can be used as the target identifier to perform multi-dimensional association of device performance data, cloud platform resource data, and security device data under the same IP address, forming a global data link diagram. Specifically, the global data link diagram can be security event-resource status-user attribute, where security event, resource status, and user attribute are all data from multiple source datasets.
[0031] S103, risk detection is performed based on security equipment data to obtain risk detection results.
[0032] In some embodiments, in order to match users with products and assess the risks of using cloud resources, it is also necessary to perform risk detection on users' cloud products based on security device data, so as to find similar users in the future, build an information list, and provide optimization suggestions for users with risks, thereby reducing the risks during the use of such users.
[0033] S104 performs information analysis based on device performance data, cloud platform resource data, and security device data to obtain information analysis results.
[0034] In some embodiments, based on the processing and analysis of the multi-source datasets described above, information analysis can be performed on each customer in the customer group based on the multi-source datasets to find customers with the same risks or similar needs, and obtain information lists of different needs, providing convenience for operators.
[0035] S105. Based on the global data link diagram, risk detection results, and information analysis results, a security potential and performance potential analysis is conducted to obtain an information list.
[0036] In some embodiments, the information list may include a target risk customer and a corresponding product deployment list and / or product optimization list. By integrating device performance data, cloud platform resource data, and security device data, a global data link diagram corresponding to the target identifier is obtained. Information analysis of users is performed based on risk detection results and information analysis results to accurately determine the risk of each user and the corresponding product list for each risk. Furthermore, by analyzing user data from both security and performance dimensions, the information list is automatically generated and linked to the user management system to achieve precise information push regarding products. In other words, by comprehensively analyzing information from multiple sources and dimensions through the collection of multi-source datasets, flexible and accurate information recommendations can be made.
[0037] In some embodiments, in order to accurately recommend information, S101 may include: Based on a preset network protocol, collect device performance data of physical layer devices; Based on the preset network interface, access cloud platform resources; Based on preset crawler technology, security device data of security devices is captured. In this embodiment, when acquiring multi-source datasets, different acquisition protocols are used for different data sources. Specifically, for physical layer devices such as servers and network devices, device performance data can be collected using preset network protocols, such as SNMP. Device performance data can include hardware sensor indicators such as CPU utilization, memory usage, disk I / O, fan speed, and power status, as well as device operating system and application logs. For cloud platform resources such as cloud hosts, cloud load balancers, and cloud databases, cloud platform resources can be retrieved through preset network interfaces, such as RESTful API interfaces. Cloud platform resources can include instance specifications, network configuration, storage configuration, tenant projects, and historical performance indicators such as cloud platform CPU, cloud platform memory, cloud platform disk, and network traffic. For security devices, security device data can be captured using preset crawler technology. Security device data can include device status information, alarm times, and policy configurations.
[0038] In other embodiments, the security device data obtained by the preset crawling technology can be structured and parsed to extract key fields, and the above-mentioned multi-source datasets can be standardized by timestamp unification and field name mapping.
[0039] After obtaining the processed multi-source dataset, it can be stored in a data warehouse to provide the original data source for subsequent information recommendations.
[0040] In some embodiments, the security device data may further include risk attack data, and S103 may include: Obtain the security product configuration information corresponding to the target identifier; By linking risk attack data with security product configuration information, data for risk analysis can be obtained. Using a pre-defined expert rule base, risk detection is performed on the data to be analyzed to obtain risk detection results.
[0041] In this embodiment, when performing risk detection, the security product configuration information corresponding to the target identifier can be obtained through the aforementioned data warehouse, i.e., the cloud products that the tenant is using. Then, the risk attack data is associated with the security product configuration information, and the preset expert rule base is used to automatically detect risks such as cloud product configuration errors, exposure of high-dimensional vulnerabilities, and abnormal port openings. Then, based on the detected risks, optimization suggestions are generated, and the risk and the corresponding optimization suggestions are used as the risk detection results to provide risk analysis support for subsequent information recommendations.
[0042] Reference Figure 2 In some other embodiments, S104 may specifically include: S1041: Obtain historical resource performance data, security events, and business data for multiple customers; S1042, Use a preset time series prediction model to perform time series analysis on historical resource performance data to obtain a resource utilization rate prediction sequence; S1043, Multidimensionally correlate the resource utilization prediction sequence, security events and business data to obtain the correlated dataset; S1044, perform multidimensional clustering on the associated dataset to obtain the clustering results; S1045, Classify information from multiple customers based on clustering results to obtain information analysis results; The information analysis results include a list of high-potential expansion customers, a list of security services, and a list of inefficient resources.
[0043] In this embodiment, to analyze cloud products and provide corresponding cloud products to target customer groups, historical resource performance data, security events, and business data of all customers using the cloud platform can be obtained. Historical resource performance data may include cloud platform CPU, memory, and storage utilization rates. A pre-trained time-series prediction model is then used to perform time-series analysis on the historical resource performance data to predict future trends in resource usage, resulting in a resource utilization prediction sequence. This sequence is then combined with customer resource usage patterns, subscription history, and expansion records to perform multi-dimensional correlation, resulting in a correlated dataset. Cluster analysis is then performed on the correlated dataset to identify customer groups with similar behavioral characteristics, i.e., clustering results. Based on the clustering results, information is classified to obtain a list of potential expansion customers, a security service list, and an inefficient resource list, enabling the provision of corresponding product services to customers and achieving accurate information recommendations.
[0044] As an example, the training and prediction process of a pre-defined time series prediction model is as follows: Input layer: Receives a historical sequence X = {x_1, x_2, ..., x_T} of length T; LSTM layers (double stacked): Number of units: 64; Activation functions: tanh (candidate state) / sigmoid (gating); Output: The hidden state h_T at the last time step; Fully connected layer: (The last part is incomplete and likely refers to a specific layer or layer.) T Mapping to the prediction space: = W y *h T + b y in, This represents the predicted value for the next K steps, where K=168 corresponds to a 7-day hourly prediction. Output layer: Resource utilization prediction sequence = _1, _2, ..., _K} In other embodiments, see Figure 3 In order to accurately cluster multiple customers, S1044 may include: S10441, Construct a three-dimensional feature vector based on the associated dataset; S10442, the three-dimensional feature vectors are transformed using a preset standard matrix to obtain a standardized matrix; S10443, using a preset weighting algorithm, determine the feature weight matrix corresponding to the standardized matrix; S10444 uses a preset distance calculation algorithm and a preset neighborhood radius to cluster the feature weight matrix, resulting in multiple clusters; S10445 identifies multiple clusters as the clustering result.
[0045] In this embodiment, the three-dimensional feature vector can be the three-dimensional feature vector of resource utilization prediction sequence, security event and business data, the preset standard matrix can be the standardized matrix output by Z-score standardization, the preset weighting algorithm can be the entropy weighting method, the preset distance calculation algorithm can be the Mahalanobis distance algorithm, and the preset neighborhood radius is determined based on the preset contour coefficient optimized neighborhood radius. The contour coefficient can be set manually.
[0046] In this embodiment, the constructed three-dimensional feature vector can be used to cluster multiple customers, classifying all customers into high-potential expansion customers, security service customers, and low-efficiency resource customers, thereby obtaining information analysis results and providing customer data support for subsequent information provision to achieve accurate and proactive information recommendation.
[0047] In some embodiments, the clustering method described above can be used to analyze and identify instances and customers whose resource utilization is close to a preset threshold, whose rapid growth trend is obvious, or whose resources have been running inefficiently for a long time. The customer list can be optimized from these instances and customers, and effective product configuration requirements and optimization suggestions can be provided to these customers.
[0048] In some other embodiments, S105 may specifically include: Based on the global data link diagram, extract customer security logs from the information analysis results; By using preset filtering criteria, security logs are analyzed for security potential to identify the target customer group. Based on the risk assessment results of the target customer group, plan a list of security products corresponding to the risk assessment results; The target customer group and the corresponding security product list are identified as the information list.
[0049] In this embodiment, after the above data processing, a global data view, risk detection results, and information analysis results can be obtained. In order to analyze customer data from the perspective of security performance, security potential analysis can be performed on the global data view, risk detection results, and information analysis results. That is, through the global data link diagram, the security logs of the target customers are extracted. The target customers can be the customers in the three lists in the information analysis results. Then, based on the risk detection results of these customers, different security products are planned, and different security products are configured for the risks existing in these customers. Then, these customers and the corresponding security product lists are determined as the information list.
[0050] Specifically, a rule engine can be used to formulate predefined rules to analyze the risks of these customers. As an example, predefined rules can be set for situations where a customer suffers a specific high-risk attack >= 10 times in a single day or a continuous low-frequency attack for >= 3 days. Other rules can also be predefined, which will not be listed here.
[0051] Based on the security potential analysis above, the target customer group and corresponding security product list are identified as high-risk customer groups and targeted security product lists. To ensure the accuracy of information recommendations, performance potential analysis can also be used to generate an information list. Specifically, S105 may also include: Based on the global data link diagram, obtain customer performance indicators from the information analysis results; Based on multi-source datasets, the mean and peak utilization of each performance metric are determined; Based on the average and peak usage rates, the product configurations for each customer are optimized to obtain a product optimization list.
[0052] In this embodiment, during the potential analysis process, it is necessary to first obtain the performance indicators of all customers in the high-potential expansion customer list, security service list, and inefficient resource list for a preset historical period from the global data link diagram. The preset historical period can be the period of three months from now. Then, the mean and peak utilization rate of each performance indicator can be determined based on the original data in the multi-source dataset. Then, the rule engine is applied to execute threshold rules to optimize product configuration and obtain a product optimization list. The product optimization list is a product upgrade and downgrade optimization list for the above customers, which can not only provide business opportunities for managers, but also adapt to the usage needs of customers.
[0053] Specifically, as an example, the threshold rule can be: continuous average or peak value >= 80% -> overload requires upgrade / expansion; continuous average value <= 20% -> inefficient operation requires downgrading. By using the above threshold rules, the product can be optimized to ensure the rational use of resources.
[0054] In other embodiments, to keep the generated information list confidential, different information lists are presented to different users. Specifically, after S105, the method may further include: Obtain the identity identifier of the accessing user; Based on identity verification, determine and access permissions for users. Based on access permissions, a list of filtered information is generated to send the list of filtered information within the access permissions to the accessing user.
[0055] In this embodiment of the application, the user's access permissions can be determined in the data warehouse through the user's identity identifier, and then only the information list within the user's role permission scope can be returned. For example, access permissions can be divided into ordinary users and project managers. Ordinary users can only see the information list under their own name, while project managers can see the information list under the projects they manage.
[0056] To ensure users can clearly see the information list and to guarantee the security of the parent list during transmission, after filtering the information list based on access permissions to obtain the filtered information list, the method may further include: The list of filtered information is structurally transformed to dynamically generate a structured file; Generate display links based on structured files; In response to a user's request to click on a displayed link, perform security authentication on the user; Download the structured file once the security authentication is successful.
[0057] In this embodiment, the information recommendation agent can call the database to dynamically generate a structured file, such as a table file, from the filtered information list data. Then, it uploads the structured file to the server and calls the server's interface to generate a display link with independent access credentials. The independent access credentials may include a username and password. These independent user credentials are isolated from the business system account to ensure the security of the structured file. Finally, the display link is sent to the user.
[0058] When a user clicks on a displayed link, the information recommendation agent responds to the user's click request by performing security verification on the user. Specifically, the server's authentication module requires the user to enter independent access credentials. After successful verification, the file can be downloaded, ensuring the privacy compliance of the data distribution process.
[0059] In some other embodiments, a method for applying an information recommendation agent is provided below, with the specific steps as follows: Users can initiate a request to inquire about a list of potential customers through the interactive interface; The information recommendation agent responds to the request to inquire about the list of potential customers by calling the data access service and requesting the security product deployment list and cloud product upgrade / downgrade optimization list in the data warehouse. The information recommendation agent queries permission rules based on the user identity carried in the request and only returns list data within the user's role's permission scope; The information recommendation agent dynamically generates structured files from the filtered list data; The information recommendation agent uploads the file to the server; The server generates individual display links with unique access credentials; Send a display link to the user.
[0060] In other embodiments, in order to clearly understand the user's needs for the product, the method may further include: In response to a user's product Q&A request, obtain the product question information entered by the user; Based on product issue information, synchronous vector retrieval and / or keyword retrieval are performed in a preset knowledge base to obtain search results; The search results are weighted and sorted to obtain a predetermined number of knowledge items that are most relevant to product issue information; The knowledge items and product problem information are input into the preset analysis model. The preset analysis model performs semantic analysis on the knowledge items and product problem information to obtain the target knowledge items with the highest matching degree with the product problem information. Send the target knowledge items to the user.
[0061] In this embodiment, to facilitate users' quick understanding of each cloud product, a product Q&A database can be configured in the system. This database analyzes product-related questions raised by users through the interactive interface, obtaining the user-input product question information. Then, synchronous vector retrieval and / or keyword retrieval are performed in a preset knowledge base. A preset algorithm is then used to weight and rank the retrieval results, resulting in a preset number of knowledge entries with the highest relevance to the user's question information. The preset knowledge base includes structured product knowledge sources, customer attribute information, historical product question information, and corresponding solutions; the preset number can be five. The knowledge entries and product question information are then input into a preset analysis model, which can be a semantic analysis model. This model combines contextual analysis of the knowledge entries, selecting the target knowledge entry with the highest matching degree or generating the most suitable answer, achieving a three-stage refinement of hybrid retrieval, ranking optimization, and semantic reordering. Finally, the knowledge entries are sent to the user to resolve their product-related questions.
[0062] It is worth noting that during the data processing of product Q&A, it is necessary to use a data standardization engine to transform the corpus into structured [problem description, solution] tuples; the problem description field integrates multi-dimensional information such as product modules, operation scenarios, and abnormal phenomena.
[0063] The data sources for the preset knowledge base can be online customer service dialogue records, product usage behavior tracking data, cloud platform technical documents / version logs / API manuals, and historical data from the work order system.
[0064] In this embodiment, synchronous vector retrieval can be based on embedded vector similarity retrieval based on question semantics, and full-text retrieval can be based on keyword matching retrieval.
[0065] In some other embodiments, the preset knowledge base can be constructed by referring to the following steps: a. Collect various questions and solutions that customers ask in their daily consultations.
[0066] b. Integrate knowledge sources such as cloud product technical documents, API manuals, and version logs.
[0067] c. Collect and compile information such as customer product ordering information, product performance data, IP association, filing status, and security protection status.
[0068] d. Apply natural language processing technology to process the above information, and construct a structured question-and-answer knowledge base and a comprehensive customer profile database, which will serve as the corpus source for RAG (Retrieval Enhanced Generation) technology.
[0069] In other embodiments, to improve the efficiency of fault location, the method may further include: In response to the fault information input by the user, the fault information is semantically parsed using a preset fault analysis model to obtain the target parameters and fault scenario; Based on the fault scenario, invoke the preset detection process template; According to the preset testing process template, the target parameters are tested and a test report is obtained; Send the test report to the user.
[0070] In this embodiment, the user can describe the fault phenomenon through the interactive interface, such as "XX server cannot be remotely connected." The system can then identify the fault information and perform semantic parsing to obtain the target parameters and fault scenario. The target parameters may include the source IP address, destination IP address, and hostname. Then, based on the fault scenario, a preset detection process template is invoked. Taking remote access anomaly as an example, the preset detection process template may include: a. Scenario differentiation: Analyze the source / destination IP attributes to distinguish between public network access and private network access.
[0071] b. Source IP Security Check: Push the source IP to the data access service, query the security protection IP list from the data warehouse, and check whether the source IP has been blocked.
[0072] c. Destination policy check: Push the source / destination IP to the data access service, obtain the destination host security group policy, and check whether the source IP is denied access.
[0073] d. Destination status check: Push the destination IP to the data access service to obtain the host's real-time operating status.
[0074] e. Network connectivity check: Trigger ICMP PING test via task orchestration engine.
[0075] f. Performance bottleneck check: Call the rules engine to check whether the associated performance metrics continuously exceed the threshold, resulting in slow or no response.
[0076] Then, the preset fault analysis model summarizes the results of each detection node, determines the cause of the fault according to the preset logic, and generates a detection report. The detection report includes the problem location, related abnormal configuration items / resources, and repair suggestions, and then sends the detection report to the user.
[0077] It is worth noting that the training data for the preset fault analysis model can include fault phenomena described in natural language by the user; network device operation logs; business system monitoring indicators; security event records; port traffic monitoring; cloud resource management data, which may include specifications, images, status, public / private network / IP, and attribution information; resource security group policies; resource performance data; PING / Telnet test results; firewall rules; VPN whitelists; security protection IP lists; and expert experience bases.
[0078] After collecting the above data, it is necessary to process it, which may include: Centralized IP Association: Valid IP addresses are extracted from cloud resource data, and then regular expression matching and standardization are performed. A mapping relationship is established between IP <—> Cloud Resource ID <—> Configuration Parameters (Specifications, OS, Status) <—> Organizational Structure.
[0079] Resource performance analysis: Aggregates time-series server performance data based on IP / resource ID. An application rule engine determines whether resources are overloaded based on preset thresholds.
[0080] Security risk analysis: Based on IP address association queries, check its security group policies, firewall rules, and VPN whitelists; analyze open port risks; combine security incident attack records and historical security events, and apply rule engines or feature matching to label IP addresses with risks.
[0081] Processing results: A comprehensive analysis view is generated with IP / resources as the core, which is associated with configuration, performance, security and network status, and anomalies are marked. Anomalies may include overloaded resources, high-risk ports, high-risk IPs and network downtime.
[0082] Based on the information recommendation method provided in the above embodiments, this application also provides a specific implementation of a cloud business integrated intelligent system. Please refer to the following embodiments.
[0083] First see Figure 4 The cloud service integrated intelligent system 400 provided in this application embodiment may include: Information recommendation intelligent agent, Information recommendation agents include: The acquisition module 401 is used to acquire multi-source datasets in the information recommendation agent. The multi-source datasets include device performance data, cloud platform resource data, and security device data. The association module 402 is used to perform multi-dimensional association of device performance data, cloud platform resource data and security device data based on the target identifier to obtain a global data link diagram corresponding to the target identifier. Detection module 403 is used to perform risk detection based on security device data and obtain risk detection results; Potential analysis module 404 is used to perform information analysis based on equipment performance data, cloud platform resource data, and security equipment data to obtain information analysis results; The potential analysis module 404 is also used to perform security and performance potential analysis based on the global data link diagram, risk detection results, and information analysis results, and to obtain an information list, which includes a target risk customer and a corresponding product deployment list and / or product optimization list.
[0084] As an alternative implementation, the potential analysis module 404 can also be used for: Acquire historical resource performance data, security events, and business data for multiple customers; By using a pre-defined time-series prediction model to perform time-series analysis on historical resource performance data, a resource utilization rate prediction sequence is obtained. By performing multidimensional correlation between resource utilization prediction sequences, security events, and business data, a correlated dataset is obtained. Perform multidimensional clustering on the associated datasets to obtain the clustering results; Based on the clustering results, information from multiple customers is categorized to obtain information analysis results, which include a list of high-potential expansion customers, a list of security services, and a list of inefficient resources.
[0085] As an alternative implementation, the potential analysis module 404 can also be used for: Construct a three-dimensional feature vector based on the associated dataset; The three-dimensional feature vectors are transformed using a preset standard matrix to obtain a standardized matrix; The feature weight matrix corresponding to the standardized matrix is determined using a pre-defined weighting algorithm; Using a preset distance calculation algorithm and a preset neighborhood radius, the feature weight matrix is clustered to obtain multiple clusters. The preset neighborhood radius is determined based on the preset contour coefficient optimized neighborhood radius. Multiple clusters are identified as the clustering result.
[0086] As an alternative implementation, the detection module 403 can also be used for: Obtain the security product configuration information corresponding to the target identifier; By linking risk attack data with security product configuration information, data for risk analysis can be obtained. Using a pre-defined expert rule base, risk detection is performed on the data to be analyzed to obtain risk detection results.
[0087] As an alternative implementation, the potential analysis module 404 can also be used for: Based on the global data link diagram, extract customer security logs from the information analysis results; By using preset filtering criteria, security logs are analyzed for security potential to identify the target customer group. Based on the risk assessment results of the target customer group, plan a list of security products corresponding to the risk assessment results; The target customer group and the corresponding security product list are identified as the information list.
[0088] As an alternative implementation, the potential analysis module 404 can also be used for: Based on the global data link diagram, obtain customer performance indicators from the information analysis results; Based on multi-source datasets, the mean and peak utilization of each performance metric are determined; Based on the average and peak usage rates, the product configurations for each customer are optimized to obtain a product optimization list.
[0089] As an alternative implementation, the potential analysis module 404 can also be used for: Obtain the identity identifier of the accessing user; Based on identity verification, determine and access permissions for users. Based on access permissions, a list of filtered information is generated to send the list of filtered information within the access permissions to the accessing user.
[0090] As an alternative implementation, the potential analysis module 404 can also be used for: The list of filtered information is structurally transformed to dynamically generate a structured file; Generate display links based on structured files; In response to a user's request to click on a displayed link, perform security authentication on the user; Download the structured file once the security authentication is successful.
[0091] As an alternative implementation, the cloud business integrated intelligent system may also include: The product question-and-answer intelligent agent includes: The acquisition module is used to respond to product Q&A requests input by the user and acquire product question information input by the user; The retrieval module is used to perform synchronous vector retrieval and / or keyword retrieval in a preset knowledge base based on product problem information to obtain retrieval results. The preset knowledge base includes structured product knowledge sources, customer attribute information, historical product problem information, and corresponding solutions. The sorting module is used to perform weighted fusion sorting on the search results to obtain a preset number of knowledge items that are most relevant to product problem information; The semantic analysis module is used to input knowledge items and product problem information into a preset analysis model. The preset analysis model performs semantic analysis on the knowledge items and product problem information to obtain the target knowledge item with the highest matching degree with the product problem information. The sending module is used to send target knowledge items to users.
[0092] As an alternative implementation, the cloud business integrated intelligent system may also include: Fault-bound intelligent agents, including: The semantic parsing module is used to respond to user-input fault information by performing semantic parsing on the fault information using a preset fault analysis model to obtain target parameters and fault scenarios. The calling module is used to invoke a preset detection process template based on the fault scenario; The detection module is used to detect target parameters according to a preset detection process template and generate a detection report. The detection report includes problem location, associated abnormal configuration items / resources, and repair suggestions. The sending module is used to send the test report to the user.
[0093] Figure 5 A schematic diagram of the hardware structure of the electronic device provided in an embodiment of this application is shown.
[0094] An electronic device may include a processor 501 and a memory 502 storing computer program instructions.
[0095] Specifically, the processor 501 may include a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.
[0096] Memory 502 may include mass storage for data or instructions. For example, and not limitingly, memory 502 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. In one instance, memory 502 may include removable or non-removable (or fixed) media, or memory 502 may be non-volatile solid-state storage. Memory 502 may be internal or external to the integrated gateway disaster recovery device.
[0097] In one instance, memory 502 may be read-only memory (ROM). In one instance, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically rewritable ROM (EAROM), or flash memory, or a combination of two or more of these.
[0098] Memory 502 may include read-only memory (ROM), random access memory (RAM), disk storage media device, optical storage media device, flash memory device, electrical, optical, or other physical / tangible memory storage device. Therefore, generally, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described in the method recommended by reference to the first aspect of this disclosure.
[0099] The processor 501 reads and executes computer program instructions stored in the memory 502 to achieve... Figure 1 An information recommendation method is shown in the embodiment.
[0100] In one example, the electronic device may also include a communication interface 503 and a bus 504. For example, Figure 5 As shown, the processor 501, memory 502, and communication interface 503 are connected through bus 504 and complete communication with each other.
[0101] The communication interface 503 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.
[0102] Bus 504 includes hardware, software, or both, that couples components of an electronic device together. For example, and not as a limitation, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Extended Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 504 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, this application contemplates any suitable bus or interconnect.
[0103] The electronic device can execute the information recommendation method in the embodiments of this application, thereby achieving a combination Figures 1-4 The described information recommendation methods and apparatus.
[0104] Furthermore, in conjunction with the information recommendation methods in the above embodiments, this application embodiment can provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the information recommendation methods in the above embodiments.
[0105] In an optional embodiment, in conjunction with the information recommendation methods in the above embodiments, this application embodiment can provide a computer program product to implement the method. The instructions in the computer program product are executed by the processor of an electronic device, enabling the electronic device to implement any of the information recommendation methods in the above embodiments.
[0106] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.
[0107] The functional blocks shown in the above block diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.
[0108] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0109] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.
[0110] The functional blocks shown in the above-described structural diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.
[0111] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0112] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.
[0113] The above description is merely a specific implementation of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.
Claims
1. An information recommendation method, characterized in that, The method, applied to a cloud-based integrated intelligent system, includes: Acquire multi-source datasets, which include device performance data, cloud platform resource data, and security device data; Based on the target identifier, the device performance data, cloud platform resource data, and security device data are correlated in multiple dimensions to obtain a global data link diagram corresponding to the target identifier; Risk detection is performed based on the data from the aforementioned security devices to obtain risk detection results; Information analysis is performed based on the device performance data, cloud platform resource data, and security device data to obtain information analysis results; Based on the global data link diagram, risk detection results, and information analysis results, a security potential and performance potential analysis is performed to obtain an information list, which includes a target risk customer and a corresponding product deployment list and / or product optimization list.
2. The method according to claim 1, characterized in that, The information analysis based on the device performance data, cloud platform resource data, and security device data yields the following results: Acquire historical resource performance data, security events, and business data for multiple customers; A time-series analysis of the historical resource performance data is performed using a preset time-series prediction model to obtain a resource utilization rate prediction sequence. The resource utilization prediction sequence, security events, and business data are correlated in multiple dimensions to obtain a correlated dataset. Perform multidimensional clustering on the associated dataset to obtain the clustering results; Based on the clustering results, the information of the multiple customers is classified to obtain information analysis results, which include a list of high-potential expansion customers, a list of security services, and a list of inefficient resources.
3. The method according to claim 2, characterized in that, The multidimensional clustering of the associated dataset to obtain the clustering results includes: Based on the aforementioned associated dataset, a three-dimensional feature vector is constructed; The three-dimensional feature vectors are transformed using a preset standard matrix to obtain a standardized matrix; A preset weighting algorithm is used to determine the feature weight matrix corresponding to the standardized matrix; Using a preset distance calculation algorithm and a preset neighborhood radius, the feature weight matrix is clustered to obtain multiple clusters. The preset neighborhood radius is determined based on a preset contour coefficient optimized neighborhood radius. The multiple clusters are determined as the clustering result.
4. The method according to claim 1, characterized in that, The security device data includes risk attack data, and the risk detection based on the security device data to obtain risk detection results includes: Obtain the security product configuration information corresponding to the target identifier; The risk attack data and security product configuration information are correlated to obtain the risk analysis data; Using a pre-defined expert rule base, risk detection is performed on the data to be analyzed to obtain risk detection results.
5. The method according to claim 1, characterized in that, Based on the global data link diagram, risk detection results, and the aforementioned information analysis results, a security potential analysis is conducted to obtain an information list, including: Based on the global data link diagram, extract the customer's security logs from the information analysis results; The security logs are analyzed for security potential using preset filtering criteria to identify the target customer group. Based on the risk assessment results of the target customer group, plan a list of security products corresponding to the risk assessment results; The target customer group and the corresponding security product list are defined as an information list.
6. The method according to claim 1, characterized in that, Based on the global data link diagram, risk detection results, and information analysis results, a performance potential analysis is performed to obtain an information list, including: Based on the global data link diagram, obtain the customer's performance indicators from the information analysis results; Based on the multi-source dataset, the mean and peak utilization of each performance metric are determined; The product configuration for the customer is optimized based on the average and peak usage rates to obtain a product optimization list.
7. The method according to any one of claims 1-6, characterized in that, After performing security and performance potential analysis based on the global data link diagram, risk detection results, and information analysis results to obtain an information list, the method further includes: Obtain the identity of the accessing user; Based on the identity identifier, determine the access permissions for the accessing user; Based on the access permissions, the information list is filtered to obtain a filtered information list, which is then sent to the accessing user.
8. The method according to claim 7, characterized in that, After filtering the information list based on the access permissions to obtain the filtered information list, the method further includes: The filtered information list is structurally transformed to dynamically generate a structured file; Based on the structured file, generate display links; In response to a user's request to click on a displayed link, the user is authenticated. If the security authentication is successful, download the structured file.
9. The method according to claim 1, characterized in that, The method further includes: In response to a user's product Q&A request, obtain the product question information entered by the user; Based on the product problem information, synchronous vector retrieval and / or keyword retrieval are performed in a preset knowledge base to obtain retrieval results. The preset knowledge base includes structured product knowledge sources, customer attribute information, historical product problem information, and corresponding solutions. The search results are weighted and sorted to obtain a preset number of knowledge entries that are most relevant to the product problem information. The knowledge entries and product problem information are input into a preset analysis model, which performs semantic analysis on the knowledge entries and product problem information to obtain the target knowledge entries with the highest matching degree with the product problem information. The target knowledge entry is sent to the user.
10. The method according to claim 1 or 9, characterized in that, The method further includes: In response to the fault information input by the user, the fault information is semantically parsed using a preset fault analysis model to obtain target parameters and fault scenarios; Based on the fault scenario, invoke the preset detection process template; According to the preset detection process template, the target parameters are detected to obtain a detection report, which includes problem location, associated abnormal configuration items / resources, and repair suggestions. The detection report is sent to the user.
11. The method according to claim 1, characterized in that, The acquisition of multi-source datasets includes: Based on a preset network protocol, collect device performance data of physical layer devices; Based on the preset network interface, access cloud platform resources; Based on preset crawling technology, capture security device data of security devices.
12. A cloud business integrated intelligent system, characterized in that, include: Information recommendation intelligent agent, The information recommendation agent includes: The acquisition module is used to acquire multi-source datasets in the information recommendation agent, wherein the multi-source datasets include device performance data, cloud platform resource data, and security device data; The association module is used to perform multi-dimensional association of the device performance data, cloud platform resource data and security device data based on the target identifier to obtain a global data link diagram corresponding to the target identifier. The detection module is used to perform risk detection based on the data from the security device and obtain the risk detection results; The potential analysis module is used to perform information analysis based on the device performance data, cloud platform resource data, and security device data to obtain information analysis results. The potential analysis module is also used to perform security and performance potential analysis based on the global data link diagram, risk detection results, and information analysis results to obtain an information list, which includes a target risk customer and a corresponding product deployment list and / or product optimization list.
13. An electronic device, characterized in that, The device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, it implements the information recommendation method as described in any one of claims 1-11.
14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions that, when executed by a processor, implement the information recommendation method as described in any one of claims 1-11.
15. A computer program product, characterized in that, When the instructions in the computer program product are executed by the processor of the electronic device, the electronic device performs the information recommendation method as described in any one of claims 1-11.