Single-client anomaly detection method and device, equipment, storage medium and program
By acquiring client-side anomaly alarm data and filtering target abnormal URLs and associated abnormal IPs, the problem of low efficiency in single-client anomaly detection in existing technologies is solved, achieving automated, rapid detection and accurate judgment.
Patent Information
- Application Number
- CN202511746229.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-25
- Publication Date
- 2026-01-13
AI Technical Summary
Existing performance monitoring tools cannot quickly identify abnormal alarms from a single client, requiring a large amount of manual analysis by operations and maintenance personnel, which reduces detection efficiency and accuracy, and cannot achieve automatic real-time analysis of operational and maintenance faults.
By acquiring client-side abnormal alarm data, the system filters out target abnormal URLs and associated abnormal IPs, and determines whether the conditions for single-client URL and IP abnormal alarms are met, thus achieving automated and rapid detection.
It improves the efficiency and accuracy of single-client anomaly detection, reduces the workload of operation and maintenance personnel, and realizes automated and rapid judgment of single-client anomalies.
Smart Images

Figure CN121333879A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the technical field of computer software application, and particularly relate to a single-client exception detection method and device, electronic equipment, storage medium and program. BACKGROUND
[0002] Client exception detection is to capture, record and analyze errors or abnormal behaviors of the client runtime in real time through technical means, so as to discover and solve problems in time.
[0003] With the transformation of traditional business to online mode, the monitoring of application system is becoming more and more important. In order to predict the monitoring state of the application system in advance, enterprises often introduce performance monitoring tools to monitor the response rate, success rate and transaction volume of the system. The performance monitoring tool is based on network traffic analysis. The response code, request address, port and content in the TCP (Transmission Control Protocol) package are parsed out, and the success rate, response rate, transaction volume and response time based on URL (Uniform Resource Locator) are formed in the system dimension to display. Daily maintenance personnel monitor through the pages provided by the performance monitoring tool, and set thresholds according to various indicators to alarm.
[0004] The inventor found the following defects in the prior art in the process of implementing the present application: the existing performance monitoring tool often alarms according to the success rate and response rate of the system URL within a certain period of time when monitoring and alarming the application system. Due to various reasons such as access logic of the application system (access authentication), abnormal access of RPA (Robotic Process Automation), client crawler, key ghost, simulated interface access and abnormal operation of users, a large number of abnormal accesses of a single client within a short time are caused, resulting in abnormal monitoring indicators such as success rate or response rate, causing the performance monitoring tool to alarm, interfering with the accuracy of the monitoring system, and consuming a large amount of maintenance manpower for analysis and troubleshooting, so that the maintenance personnel have to log in to the system to manually verify and confirm each time, which brings a large amount of work to the maintenance personnel and reduces the efficiency of single-client exception detection and analysis. The existing performance monitoring tool is a tool for analyzing network traffic, and it also has no ability to develop and verify the business logic layer for all application systems. If this kind of single-client caused abnormal alarm cannot be quickly identified, the automatic real-time analysis of maintenance faults cannot be realized. SUMMARY
[0005] Embodiments of the present application provide a single-client exception detection method and device, electronic equipment, storage medium and program, which can improve the efficiency and accuracy of single-client exception detection analysis.
[0006] According to an aspect of the present application, a single-client exception detection method is provided, comprising:
[0007] Obtaining client exception alarm data;
[0008] In a case where it is determined that a target exception uniform resource locator URL in the client exception alarm data meets a single-client URL exception alarm condition, obtaining an associated exception IP of the target exception URL;
[0009] In a case where it is determined that the associated exception IP meets a single-client IP exception alarm condition, determining that a single-client exception occurs.
[0010] According to another aspect of the present application, a single-client exception detection device is provided, comprising:
[0011] An exception alarm data obtaining module, configured to obtain client exception alarm data;
[0012] An associated exception IP obtaining module, configured to, in a case where it is determined that a target exception URL in the client exception alarm data meets a single-client URL exception alarm condition, obtain an associated exception IP of the target exception URL;
[0013] A single-client exception determining module, configured to, in a case where it is determined that the associated exception IP meets a single-client IP exception alarm condition, determine that a single-client exception occurs.
[0014] According to another aspect of the present application, an electronic equipment is provided, comprising:
[0015] At least one processor; and
[0016] A memory in communication connection with the at least one processor; wherein
[0017] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the single-client exception detection method according to any one of the embodiments of the present application.
[0018] According to another aspect of the present application, a computer readable storage medium is provided, which stores computer instructions for enabling a processor to implement the single-client exception detection method according to any one of the embodiments of the present application when executed.
[0019] According to another aspect of the present invention, a computer program product is also provided, comprising a computer program that, when executed by a processor, implements the single-client anomaly detection method described in any embodiment of the present invention.
[0020] This invention analyzes the acquired client anomaly alarm data. If the target abnormal URL in the client anomaly alarm data meets the single client URL anomaly alarm condition, the associated abnormal IP of the target abnormal URL is obtained. If the associated abnormal IP meets the single client IP anomaly alarm condition, a single client anomaly is determined to have occurred. This enables automated and rapid detection of single client anomalies, solving the problem of existing methods that cannot automatically detect single client anomalies and improving the efficiency and accuracy of single client anomaly detection and analysis.
[0021] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0022] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 This is a flowchart of a single-client anomaly detection method provided in Embodiment 1 of the present invention;
[0024] Figure 2 This is a flowchart of a single-client anomaly detection method provided in Embodiment 2 of the present invention;
[0025] Figure 3 This is a flowchart illustrating a single-client anomaly detection method provided in Embodiment 2 of the present invention;
[0026] Figure 4 This is a schematic diagram of a single-client anomaly detection device provided in Embodiment 3 of the present invention;
[0027] Figure 5 This is a schematic diagram of the structure of an electronic device provided in Embodiment 4 of the present invention. Detailed Implementation
[0028] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0029] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0030] Example 1
[0031] Figure 1 This is a flowchart of a single-client anomaly detection method provided in Embodiment 1 of the present invention. This embodiment is applicable to the automated and rapid detection of single-client anomalies. The method can be executed by a single-client anomaly detection device, which can be implemented in software and / or hardware, and is generally integrated into an electronic device. This electronic device can be a terminal device or a server device, as long as it can execute the single-client anomaly detection method. The present invention does not limit the specific type of electronic device. Correspondingly, as... Figure 1 As shown, the method includes the following operations:
[0032] S110. Obtain client-side abnormal alarm data.
[0033] In this embodiment of the invention, various optional methods can be used to collect and obtain alarm data for client anomalies. For example, existing performance monitoring tools and other network traffic analysis tools can be used to monitor the access data of each client in the application system and issue an alarm when it is determined that the access data is abnormal. In this case, the client anomaly alarm data provided by the performance monitoring tool can be obtained.
[0034] Alternatively, you can directly monitor the access data of each client in the application system, and when an anomaly is detected based on the real-time access data of the client, directly obtain the abnormal access data of the client as the client anomaly alarm data.
[0035] S120. If it is determined that the target abnormal URL in the client abnormal alarm data meets the single client URL abnormal alarm condition, obtain the associated abnormal IP of the target abnormal URL.
[0036] The target abnormal URL can be any URL from among many URLs accessing the client that meets the single-client URL abnormality alarm criteria. The single-client URL abnormality alarm criteria can be the conditions used to determine whether a URL is causing a single-client abnormality. The associated abnormal IP can be the IP address that accessed the target abnormal URL.
[0037] Optionally, client-side error alert data may include abnormal access information from the client, such as abnormal URLs and IP addresses accessing each client. Therefore, after obtaining the client-side error alert data, the URL information in the data can be analyzed first to determine whether the client-side error is caused by a single client or multiple clients.
[0038] Specifically, URLs causing abnormal alarms can be filtered from client-side abnormal alarm data. For example, URLs with response or success rates below a threshold can be used as initial abnormal URLs. Further, it is determined whether each of the initially filtered abnormal URLs meets preset single-client URL abnormal alarm conditions. If an abnormal URL meets the single-client URL abnormal alarm conditions, it can be identified as the target abnormal URL, and the IP address associated with this target abnormal URL can be obtained as the associated abnormal IP for further analysis.
[0039] S130. If the associated abnormal IP meets the single client IP abnormal alarm conditions, a single client abnormality is determined to have occurred.
[0040] Among them, the single-client IP abnormal alarm condition can be used to determine whether the IP is the condition that caused the single-client abnormality.
[0041] After obtaining the associated abnormal IPs of the target abnormal URL, the associated abnormal IPs are further analyzed to determine whether each associated abnormal IP meets the preset single-client IP abnormality alarm conditions. If a certain associated abnormal IP meets the single-client IP abnormality alarm conditions, it can be determined that the currently detected application system has experienced a single-client abnormality.
[0042] Therefore, the above-mentioned single-client anomaly detection method can screen out IP addresses suspected of causing single-client anomalies. By further matching the screened IP addresses with the client address network segments in the application system, the alarm problem caused by the abnormal client IP can be accurately determined. Furthermore, the specific network terminal device can be traced through the network, thereby achieving the effect of accurate and automated rapid judgment of single-client anomalies, and improving the efficiency and accuracy of single-client anomaly detection and analysis.
[0043] This invention analyzes the acquired client anomaly alarm data. If the target abnormal URL in the client anomaly alarm data meets the single client URL anomaly alarm condition, the associated abnormal IP of the target abnormal URL is obtained. If the associated abnormal IP meets the single client IP anomaly alarm condition, a single client anomaly is determined to have occurred. This enables automated and rapid detection of single client anomalies, solving the problem of existing methods that cannot automatically detect single client anomalies and improving the efficiency and accuracy of single client anomaly detection and analysis.
[0044] Example 2
[0045] Figure 2 This is a flowchart of a single-client anomaly detection method provided in Embodiment 2 of the present invention. Figure 3 This is a flowchart illustrating a single-client anomaly detection method according to Embodiment 2 of the present invention. This embodiment is a specific implementation based on the above embodiment. In this embodiment, several specific optional implementation methods are provided for obtaining client anomaly alarm data, determining that the target abnormal URL in the client anomaly alarm data meets the single-client URL anomaly alarm condition, and determining that the associated abnormal IP meets the single-client IP anomaly alarm condition. Correspondingly, as... Figure 2 and Figure 3 As shown, the method in this embodiment may include:
[0046] S210. After determining that the business performance monitoring tool outputs abnormal alarm information, call the interface of the business performance monitoring tool to obtain the original abnormal alarm information output by the business performance monitoring tool.
[0047] Among these, the business performance monitoring tool can be a tool used to monitor the performance of application systems. The raw anomaly alarm information can be the client-side anomaly alarm information originally output by the business performance monitoring tool.
[0048] In this embodiment of the invention, the application system can be monitored using a business performance monitoring tool. When an alarm event occurs during monitoring, i.e., after the business performance monitoring tool outputs abnormal alarm information, its interface can be called to request the original abnormal alarm information output by the tool. This original abnormal alarm information is then aggregated and analyzed multiple times to ultimately determine the suspected abnormal client.
[0049] S220. The original abnormal alarm information is filtered according to the target performance indicator parameters to obtain the client abnormal alarm data; wherein, the target performance indicator parameters include response rate and / or success rate.
[0050] After obtaining the raw anomaly alarm information output by the business performance monitoring tool, the raw anomaly alarm information can be aggregated for the first time. The raw anomaly alarm information can be filtered according to target performance indicators such as response rate and / or success rate, and URLs with response rate or success rate below the threshold can be selected as client anomaly alarm data.
[0051] In an optional embodiment of the present invention, before obtaining the client abnormal alarm data, the method may further include: configuring the abnormal page URL suffix according to the client abnormal access scenario; configuring the normal percentage threshold and abnormal percentage threshold of abnormal URLs, as well as the abnormal IP percentage threshold, according to the client abnormal detection requirements.
[0052] The normal percentage threshold can be one of the thresholds configured to determine whether an abnormal URL is caused by an abnormal access from a single client. The abnormal percentage threshold can be another threshold configured to determine whether an abnormal URL is caused by an abnormal access from a single client. The abnormal IP percentage threshold can be a threshold configured to determine whether an abnormal IP is the IP of a single abnormal client. Optionally, multiple abnormal IP percentage thresholds can be set for the number of associated abnormal IPs filtered out.
[0053] To enable rapid analysis and judgment of single-client anomalies, the necessary threshold information can be configured before performing single-client anomaly detection. Specifically, the URL suffix for abnormal pages can be configured according to the abnormal client access scenarios. During URL suffix configuration, scenarios where the application system is accessed abnormally can be identified, and the abnormal page URL suffixes can be configured in conjunction with the application system's characteristics. For example, taking a digital invoice system as an application system, since most digital invoice systems are developed using Java, URLs with suffixes such as ".php", ".asp", and ".dll" are all abnormal page URL suffixes (referred to as abnormal URL suffixes). Furthermore, digital invoice systems mostly interface with single-point systems, filtering static page resources such as ".js", ".jsp", "html", and ".css". A large number of accesses to non-existent static resources will also cause anomalies. Additionally, various requests for ".do" and ".dwr" will also cause anomalies when login authentication tickets expire. However, the Servlet (Server Applet) and Webservice (Network Service) interfaces of the digital invoice system are provided to the server, and under normal circumstances, abnormal access should not occur. Understandably, the URL suffix of abnormal pages can be updated in real time according to the needs of the application system.
[0054] In addition, when analyzing abnormal alarms caused by a single client, it is necessary to configure the relevant abnormal thresholds based on the actual monitoring situation. Optionally, you can first configure the threshold for abnormal response rate or success rate of the overall application system, so that business performance monitoring tools can determine whether the application system needs to issue an alarm. You can also configure normal percentage thresholds and abnormal percentage thresholds for URLs. The normal percentage threshold can be used to determine at what level the normal URL index is considered to be caused by an abnormal URL when the application system generates an abnormal alarm. The abnormal percentage threshold is used to determine what percentage of all abnormal URLs the URL that triggered the alarm is considered to be caused by that URL. You can also configure an abnormal IP percentage threshold for IP addresses, which is used to determine what percentage of all IP addresses that meet the above two conditions are considered to be caused by that IP address. For example, the threshold for abnormal response rate or success rate can be configured to 98%, the normal percentage threshold can be configured to 50%, the abnormal percentage threshold can be configured to 5%, and the abnormal IP percentage threshold can be configured to 100%, 50%, or 33%, etc., depending on the number of IPs.
[0055] S230. Obtain the normal percentage threshold and the abnormal percentage threshold of the URL. If it is determined that the normal percentage of URLs is greater than the normal percentage threshold, calculate the top value percentage of each abnormal URL based on the data volume of the abnormal URLs and the total transaction volume.
[0056] In the single-client anomaly detection process, pre-configured thresholds for the normal and abnormal percentages of URLs can be obtained, and client anomaly alarm data can be analyzed based on these thresholds. Specifically, if the percentage of normal URLs is less than or equal to the normal percentage threshold, it indicates that the client anomaly is not caused by a single client, but may be caused by multiple abnormal clients simultaneously. If the percentage of normal URLs is greater than the normal percentage threshold but anomaly alarms still occur, it indicates that the client anomaly may not be caused by a single client. Optionally, normal URLs can refer to all URLs accessing the application system, excluding those that match the pre-configured abnormal page URL suffix. Normal URLs mainly refer to the interfaces provided by the application system; if such URLs are abnormal, it indicates that the application system itself does indeed have anomalies.
[0057] S240. If the top value ratio of the target abnormal URL is greater than the abnormal ratio threshold, the target abnormal URL in the client abnormal alarm data is determined to meet the single client URL abnormal alarm condition.
[0058] Correspondingly, if it is determined that the proportion of normal URLs accessing the application system is greater than the normal proportion threshold, then for each type of abnormal URL matched with abnormal URLs, the ratio between its data volume and total transaction volume can be calculated to obtain the top value proportion of each abnormal URL. Furthermore, the top value proportion of each abnormal URL is compared with a pre-configured abnormal proportion threshold. If the top value proportion of a certain type of abnormal URL is greater than the abnormal proportion threshold, then that type of abnormal URL can be identified as the target abnormal URL, and it can be determined that the target abnormal URL in the client abnormal alarm data meets the single client URL abnormal alarm condition.
[0059] like Figure 3As shown, after filtering the original abnormal alarm information based on target performance metrics such as response rate and / or success rate, and identifying URLs with response rates or success rates below a threshold, it can be further determined whether the filtered URLs with response rates or success rates below the threshold include normal URLs. If it is determined that the filtered URLs with response rates or success rates below the threshold include normal URLs, but all of these URLs are accessed by clients that are not from the preset client network segment (such as the network segment of the LAN where the application system is located), then the client abnormality is not a single-client abnormality. If it is determined that the filtered URLs with response rates or success rates below the threshold do not include normal URLs, nor do they include information from the pre-configured abnormal URL suffixes, then the client abnormality is not a single-client abnormality.
[0060] S250. Call the interface of the business performance monitoring tool to obtain client IP access data, aggregate the client IP access data, and filter the IPs that access the target abnormal URL as the associated abnormal IPs based on the aggregation results.
[0061] Furthermore, using abnormal URLs as filtering conditions, the interface of the business performance monitoring tool is called again to obtain client IP access data. The client IP access data is aggregated a second time, and the IPs that access the target abnormal URLs are filtered as associated abnormal IPs based on the aggregation results.
[0062] S260. Count the number of associated abnormal IPs and the percentage of abnormal IPs for each associated abnormal IP, and determine the target abnormal IP percentage threshold based on the number of associated abnormal IPs.
[0063] Furthermore, all IPs accessing the target abnormal URL can be counted as a single associated abnormal IP, thus obtaining the number of associated abnormal IPs. Simultaneously, the abnormal IP percentage of each associated abnormal IP can be determined based on the client IP access data corresponding to those associated abnormal IPs. Optionally, the abnormal IP percentage can be the ratio of the access data volume of the current associated abnormal IP to the access data volume of all associated abnormal IPs. Additionally, a target abnormal IP percentage threshold can be determined based on the number of associated abnormal IPs. For example, when the number of associated abnormal IPs is 1, the target abnormal IP percentage threshold can be 0; when the number of associated abnormal IPs is 2, the target abnormal IP percentage threshold can be 50%; when the number of associated abnormal IPs is 3, the target abnormal IP percentage threshold can be 33%, and so on.
[0064] S270. Filter the abnormal IP percentage of the target abnormal IP based on the abnormal IP percentage of each associated abnormal IP.
[0065] Among them, the target abnormal IP can be the associated abnormal IP with the largest proportion of abnormal IPs.
[0066] S280. If the percentage of abnormal IPs of the target abnormal IP is greater than or equal to the target abnormal IP percentage threshold, the target abnormal IP is determined to meet the single client IP abnormal alarm condition, and a single client abnormality is determined to have occurred.
[0067] After calculating the percentage of abnormal IPs for each associated abnormal IP, the associated abnormal IP with the highest percentage can be selected as the target abnormal IP. Simultaneously, the percentage of abnormal IPs for the target abnormal IP is compared with the corresponding target abnormal IP percentage threshold. If the percentage of abnormal IPs for the target abnormal IP is greater than or equal to the target abnormal IP percentage threshold, it can be determined that the target abnormal IP meets the single-client IP abnormality alarm condition, and a single-client abnormality is preliminarily identified.
[0068] For example, if there is only one associated abnormal IP, it can be determined that the application system abnormality is caused by that associated abnormal IP. If there are two associated abnormal IPs, and the abnormal IPs of the first associated abnormal IP account for more than 50% of the total number of abnormal IPs, it is considered that the application system abnormality is caused by that associated abnormal IP. If there are three associated abnormal IPs, and the abnormal IPs of the first associated abnormal IP account for more than 33% of the total number of abnormal IPs, it is considered that the application system abnormality is caused by that associated abnormal IP.
[0069] Based on the application system's status and historical data analysis, it's clear that server-side access involves API calls and actual business logic. Most anomalies caused by single clients originate from abnormal access from computers within the local area network (LAN). Therefore, the IP address ranges of office computers on the LAN hosting the application system can be compiled and configured as a baseline IP data source to further identify abnormal client addresses. Correspondingly, if the target abnormal IP matches the baseline IP data source (i.e., it's an IP within the baseline IP data source), then a single-client anomaly can be confirmed.
[0070] The above technical solution, combined with the application system's access logic, configures parameters such as abnormal URL suffixes, relevant alarm thresholds, and office IP network segments. By calling the business performance monitoring tool interface, it continuously aggregates response rates, success rates, and URLs, and excludes interface URLs accessed by normal servers based on transaction volume and alarm thresholds. It also compares and configures abnormal URLs and page request types (unauthenticated) URLs. Using a binary tree recursive traversal approach, it judges abnormal information layer by layer, and dynamically adjusts abnormal URL suffixes and the proportion thresholds of each stage in a timely manner, thereby achieving accurate analysis of single-client anomalies. Simultaneously, it effectively improves the operational efficiency of the application system, providing the most basic analysis step for enhancing the application system's automated operation and maintenance capabilities in the future.
[0071] It should be noted that all information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for display, data used for analysis, etc.) involved in this disclosure are information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data comply with the relevant laws, regulations and standards of the relevant regions.
[0072] It should be noted that any arrangement or combination of the technical features in the above embodiments also falls within the protection scope of this invention.
[0073] Example 3
[0074] Figure 4 This is a schematic diagram of a single-client anomaly detection device provided in Embodiment 3 of the present invention, as shown below. Figure 4 As shown, the device includes: an abnormal alarm data acquisition module 410, an associated abnormal IP acquisition module 420, and a single client abnormal determination module 430, wherein:
[0075] The abnormal alarm data acquisition module 410 is used to acquire abnormal alarm data from the client.
[0076] The associated abnormal IP acquisition module 420 is used to acquire the associated abnormal IP of the target abnormal URL when it is determined that the target abnormal URL in the client abnormal alarm data meets the single client URL abnormal alarm condition.
[0077] The single-client anomaly determination module 430 is used to determine that a single-client anomaly has occurred when the associated abnormal IP meets the single-client IP anomaly alarm conditions.
[0078] This invention analyzes the acquired client anomaly alarm data. If the target abnormal URL in the client anomaly alarm data meets the single client URL anomaly alarm condition, the associated abnormal IP of the target abnormal URL is obtained. If the associated abnormal IP meets the single client IP anomaly alarm condition, a single client anomaly is determined to have occurred. This enables automated and rapid detection of single client anomalies, solving the problem of existing methods that cannot automatically detect single client anomalies and improving the efficiency and accuracy of single client anomaly detection and analysis.
[0079] Optionally, the abnormal alarm data acquisition module 410 is further configured to: after determining that the business performance monitoring tool outputs abnormal alarm information, call the interface of the business performance monitoring tool to obtain the original abnormal alarm information output by the business performance monitoring tool; filter the original abnormal alarm information according to the target performance indicator parameters to obtain the client abnormal alarm data; wherein, the target performance indicator parameters include response rate and / or success rate.
[0080] Optionally, the associated abnormal IP acquisition module 420 is further configured to: acquire the normal percentage threshold and the abnormal percentage threshold of the URL; if it is determined that the normal URL percentage is greater than the normal percentage threshold, calculate the top value percentage of each abnormal URL based on the data volume and total transaction volume of the abnormal URL; if it is determined that the top value percentage of the target abnormal URL is greater than the abnormal percentage threshold, determine that the target abnormal URL in the client abnormal alarm data meets the single client URL abnormal alarm condition.
[0081] Optionally, the associated abnormal IP acquisition module 420 is further configured to: call the interface of the business performance monitoring tool to obtain client IP access data; aggregate the client IP access data, and filter the IPs that access the target abnormal URL as the associated abnormal IPs based on the aggregation results.
[0082] Optionally, the single-client anomaly determination module 430 is further configured to: count the number of associated abnormal IPs and the percentage of abnormal IPs for each associated abnormal IP; determine a target abnormal IP percentage threshold based on the number of associated abnormal IPs; filter the percentage of abnormal IPs for the target abnormal IP based on the percentage of abnormal IPs for each associated abnormal IP; and determine that the target abnormal IP meets the single-client IP anomaly alarm condition if the percentage of abnormal IPs for the target abnormal IP is greater than or equal to the target abnormal IP percentage threshold.
[0083] Optionally, the above device also includes an information configuration module, used to configure the URL suffix of abnormal pages according to the abnormal access scenario of the client; and to configure the normal proportion threshold and abnormal proportion threshold of abnormal URLs, as well as the abnormal IP proportion threshold, according to the abnormal detection requirements of the client.
[0084] The aforementioned single-client anomaly detection device can execute the single-client anomaly detection method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method. Technical details not described in detail in this embodiment can be found in the single-client anomaly detection method provided in any embodiment of the present invention.
[0085] Since the single-client anomaly detection device described above is capable of executing the single-client anomaly detection method in the embodiments of the present invention, those skilled in the art can understand the specific implementation and various variations of the single-client anomaly detection device in this embodiment based on the single-client anomaly detection method described in the embodiments of the present invention. Therefore, how the single-client anomaly detection device implements the single-client anomaly detection method in the embodiments of the present invention will not be described in detail here. Any device used by those skilled in the art to implement the single-client anomaly detection method in the embodiments of the present invention falls within the scope of protection of this application.
[0086] Example 4
[0087] Figure 5 A schematic diagram of an electronic device 10, which can be used to implement embodiments of the present invention, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0088] like Figure 5 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0089] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0090] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as single-client anomaly detection methods.
[0091] Optionally, the single-client anomaly detection method may include: acquiring client anomaly alarm data; if it is determined that the target anomaly Uniform Resource Locator URL in the client anomaly alarm data meets the single-client URL anomaly alarm condition, acquiring the associated anomaly IP of the target anomaly URL; if it is determined that the associated anomaly IP meets the single-client IP anomaly alarm condition, determining that a single-client anomaly has occurred.
[0092] In some embodiments, the single-client anomaly detection method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the single-client anomaly detection method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the single-client anomaly detection method by any other suitable means (e.g., by means of firmware).
[0093] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0094] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0095] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0096] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0097] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0098] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0099] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.
[0100] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. A single-client anomaly detection method, characterized in that, include: Obtain client-side error alert data; If it is determined that the target abnormal Uniform Resource Locator URL in the client abnormal alarm data meets the single client URL abnormal alarm condition, the associated abnormal IP of the target abnormal URL is obtained. If the associated abnormal IP meets the single client IP abnormality alarm conditions, then a single client abnormality is determined to have occurred.
2. The method according to claim 1, characterized in that, The acquisition of client-side abnormal alarm data includes: After determining that the business performance monitoring tool outputs abnormal alarm information, the interface of the business performance monitoring tool is called to obtain the original abnormal alarm information output by the business performance monitoring tool. The original abnormal alarm information is filtered according to the target performance indicator parameters to obtain the client abnormal alarm data; wherein, the target performance indicator parameters include response rate and / or success rate.
3. The method according to claim 1, characterized in that, The step of determining that the target abnormal URL in the client abnormal alarm data meets the single client URL abnormal alarm condition includes: Obtain the normal and abnormal percentage thresholds for URLs; If the proportion of normal URLs is determined to be greater than the normal proportion threshold, the top value proportion of each abnormal URL is calculated based on the data volume of the abnormal URLs and the total transaction volume. If the top value proportion of the target abnormal URL is determined to be greater than the abnormal proportion threshold, the target abnormal URL in the client abnormal alarm data is determined to meet the single client URL abnormal alarm condition.
4. The method according to claim 1, characterized in that, The step of obtaining the associated abnormal IP of the target abnormal URL includes: Call the API of the business performance monitoring tool to obtain client IP access data; The client IP access data is aggregated, and the IPs that access the target abnormal URL are selected as the associated abnormal IPs based on the aggregation results.
5. The method according to claim 1, characterized in that, The step of determining that the associated abnormal IP meets the single client IP abnormal alarm conditions includes: The number of the associated abnormal IPs and the percentage of abnormal IPs for each of the associated abnormal IPs are counted. Determine the target abnormal IP percentage threshold based on the number of associated abnormal IPs; The abnormal IP percentage of the target abnormal IP is filtered based on the abnormal IP percentage of each associated abnormal IP; If the percentage of abnormal IPs of the target abnormal IP is greater than or equal to the target abnormal IP percentage threshold, the target abnormal IP is determined to meet the single client IP abnormal alarm condition.
6. The method according to claim 1, characterized in that, Before obtaining client-side error alarm data, the following is also included: Configure the URL suffix for abnormal pages based on the client's abnormal access scenario; Configure the normal percentage threshold and abnormal percentage threshold for abnormal URLs, as well as the abnormal IP percentage threshold, according to the client's anomaly detection requirements.
7. A single-client anomaly detection device, characterized in that, include: The abnormal alarm data acquisition module is used to acquire abnormal alarm data from the client. The associated abnormal IP acquisition module is used to acquire the associated abnormal IP of the target abnormal URL when it is determined that the target abnormal URL in the client abnormal alarm data meets the single client URL abnormal alarm condition. The single-client anomaly determination module is used to determine that a single-client anomaly has occurred when the associated abnormal IP meets the single-client IP anomaly alarm conditions.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that is executed by the at least one processor, such that the at least one processor is able to perform the single-client anomaly detection method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the single-client anomaly detection method according to any one of claims 1-6.
10. A computer program product, characterized in that, It includes a computer program / instruction, wherein the computer program / instruction, when executed by a processor, implements the single-client anomaly detection method according to any one of claims 1-6.