Abnormality analysis method, device, equipment, medium and product
By constructing a correspondence between operational units and business functions, and using a preset graph structure to automatically convert traffic information for anomaly analysis, the accuracy and efficiency issues of online business anomaly analysis are solved, and efficient anomaly identification and location at the business function level are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-31
- Publication Date
- 2026-03-27
AI Technical Summary
Existing technologies for analyzing anomalies in online business processes are not very accurate or efficient, and typically rely on manual retrieval of operation logs for analysis.
By constructing a correspondence between operation units and business functions, extracting node features using a preset graph structure, automatically converting the call traffic of operation units into traffic information of business functions, performing anomaly analysis from the perspective of business functions, and making difference judgments in conjunction with historical traffic baselines.
It improves the accuracy and efficiency of anomaly analysis, can automatically identify anomalies at the business function level, and simplifies the location of anomaly root causes.
Smart Images

Figure CN121750436A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of artificial intelligence technology and fintech, specifically to an anomaly analysis method, apparatus, device, medium, and product. Background Technology
[0002] With the increasing popularity of online services, more and more users are choosing to conduct business online. For example, users can make appointments online. However, abnormal situations may occur during the execution of online services. For instance, the business system may call a certain interface unusually frequently.
[0003] Currently, for abnormal situations in online business, the only way to analyze them is by having relevant personnel pull operation logs, which results in low accuracy and efficiency in anomaly analysis. Summary of the Invention
[0004] In view of the above problems, this application provides an anomaly analysis method, apparatus, equipment, medium and product to improve the accuracy and efficiency of anomaly analysis.
[0005] According to a first aspect of this application, an anomaly analysis method is provided, comprising: determining call traffic information of n operation units; wherein n is a positive integer; determining the correspondence between the n operation units and business functions; wherein any operation unit is used to implement one or more corresponding business functions; for any business function, determining the function traffic information of the targeted business function based on the call traffic information of the corresponding operation unit; and performing anomaly analysis by combining the function traffic information of different business functions.
[0006] According to an embodiment of this application, the method for constructing the correspondence between the n operation units and business functions includes: determining a preset graph structure; the preset graph structure includes: operation unit nodes for representing any operation unit among the n operation units, and business function nodes for representing any business function; extracting operation unit node features and business function node features for the preset graph structure; in the preset graph structure, for operation unit nodes and business function nodes that meet preset similarity conditions, determining that the operation unit represented by the operation unit node corresponds to the business function represented by the business function node; the preset similarity conditions include: the similarity between the operation unit node features and the business function node features is greater than a preset node similarity threshold.
[0007] According to an embodiment of this application, the preset diagram structure further includes: a service system node for representing a service system; a first side for connecting the service system node and the operation unit node; wherein the first side is used to represent the service system represented by the connected service system node and to call the operation unit represented by the connected operation unit node; and a second side for connecting the service system node and the business function node; wherein the second side is used to represent the service system represented by the connected service system node and to have the business function represented by the connected business function node.
[0008] According to an embodiment of this application, the preset graph structure further includes a third side for connecting different service system nodes; wherein the third side is used to characterize that the system feature similarity between the service systems represented by the two connected service system nodes is greater than a preset system feature similarity threshold.
[0009] According to an embodiment of this application, the weight of the second side is used to characterize the probability that the service system represented by the connected service system node has the business function represented by the connected business function node; the weight of the third side is used to characterize the system feature similarity between the service systems represented by the two connected service system nodes.
[0010] According to an embodiment of this application, in the n operation units, a functional weight is set between any operation unit and any corresponding business function; the step of determining the functional traffic information of the business function based on the call traffic information of the corresponding operation unit for any business function includes: for any business function, determining the functional traffic information of the business function by weighting the call traffic information of the corresponding different operation units according to the functional weights set between the corresponding different operation units and the business function.
[0011] According to an embodiment of this application, the anomaly analysis based on the integrated functional traffic information of different business functions includes: determining the degree of difference between the functional traffic information of different business functions and the functional traffic baseline information; the functional traffic baseline information is determined based on historical functional traffic information.
[0012] According to embodiments of this application, the anomaly analysis based on the integrated functional traffic information of different business functions includes at least one of the following: determining the degree of difference between the distribution of functional traffic information of different business functions and a preset distribution baseline; determining the degree of difference between the ratio of functional traffic information of different business functions and a preset functional traffic ratio baseline; determining the degree of difference between the functional traffic information of different business functions and a preset functional traffic information baseline; and determining the degree of difference between the context information of functional traffic information of different business functions and a preset context information baseline.
[0013] According to an embodiment of this application, the method further includes: for a newly added operation unit, determining, among the n operation units, a target operation unit whose similarity to the newly added operation unit is greater than a preset unit similarity threshold; and determining the business function corresponding to the determined target operation unit as the business function corresponding to the newly added operation unit.
[0014] A second aspect of this application provides an anomaly analysis apparatus, comprising: a determination module, configured to determine call flow information of n operation units; wherein n is a positive integer; and to determine the correspondence between the n operation units and business functions; wherein any operation unit is used to implement one or more corresponding business functions; a function flow module, configured to determine the function flow information of any business function based on the call flow information of the corresponding operation unit; and a synthesis module, configured to synthesize the function flow information of different business functions and perform anomaly analysis.
[0015] A third aspect of this application provides an electronic device comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method described above.
[0016] A fourth aspect of this application also provides a computer-readable storage medium having a computer program or instructions stored thereon, which, when executed by a processor, implement the steps of the above-described method.
[0017] The fifth aspect of this application also provides a computer program product, including a computer program or instructions that, when executed by a processor, implement the steps of the above-described method. Attached Figure Description
[0018] The above-mentioned contents, other objects, features and advantages of this application will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:
[0019] Figure 1 This illustration schematically depicts an application scenario of an anomaly analysis method according to an embodiment of this application.
[0020] Figure 2 A flowchart illustrating an anomaly analysis method according to an embodiment of this application is shown schematically;
[0021] Figure 3 This schematic diagram illustrates a structural block diagram of an anomaly analysis device according to an embodiment of this application;
[0022] Figure 4 A block diagram schematically illustrates an electronic device suitable for implementing an anomaly analysis method according to an embodiment of this application. Detailed Implementation
[0023] The embodiments of this application will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of this application. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of this application for ease of explanation. However, it will be apparent that one or more embodiments may be implemented without these specific details. Furthermore, descriptions of well-known structures and technologies are omitted in the following description to avoid unnecessarily obscuring the concepts of this application.
[0024] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of this application. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0025] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.
[0026] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).
[0027] With the increasing prevalence of online services, more and more users are choosing to conduct business online. For example, users can make appointments online. However, abnormal situations may occur during the execution of online services. For instance, the business system may call a certain interface abnormally frequently. Currently, for abnormal situations in online services, relevant personnel can usually only pull operation logs for analysis, which has low accuracy and efficiency.
[0028] To address the aforementioned technical problems, embodiments of this application provide an anomaly analysis method. This method automatically performs anomaly analysis based on business traffic, improving the efficiency of anomaly analysis. The execution of online business typically requires the invocation of multiple operation units, such as interfaces or endpoints, which perform specific operations. It is understood that, for a received user request, the required business function can be determined, and the multiple operation units needed to implement that function can be invoked to perform the operations. Accordingly, automatic anomaly analysis can be performed based on the call traffic of these operation units, specifically analyzing abnormal changes in call traffic or call traffic exceeding thresholds.
[0029] In the above method, considering that the operation unit is usually used to perform basic operations, the same operation unit can be used to implement different business functions, and the same business function may need to be implemented by multiple different operation units, the call traffic of the operation unit can be converted into the traffic of the business function. By automatically analyzing the abnormal traffic from the perspective of the business function, the accuracy and efficiency of the abnormal analysis can be improved.
[0030] Specifically, by combining the pre-built correspondence between operation units and business functions, the call traffic of operation units can be converted into the traffic of business functions. For a single business function, the traffic situation of the corresponding business function can be comprehensively determined by combining the call traffic of each operation unit.
[0031] The specific method for constructing the correspondence between operation units and business functions can be as follows: First, construct a graph structure containing operation unit nodes and business function nodes. Extract node features from the graph structure to determine the characteristics of operation unit nodes and business function nodes. Further, based on the node feature similarity between the operation unit node features and business function node features, operation units and business functions with high node feature similarity are identified as a set of correspondences. In this approach, the constructed graph structure can represent the relationship between operation units and business functions, thereby improving the accuracy of the constructed correspondence between operation units and business functions.
[0032] It should be noted that the anomaly analysis method and apparatus provided in the embodiments of this application can be applied to the fields of artificial intelligence technology and fintech. For example, for the business operations of financial institutions such as banks, the anomaly analysis method provided in the embodiments of this application can be used for anomaly analysis. The anomaly analysis method and apparatus provided in the embodiments of this application can also be applied to any field other than fintech. The application field of the anomaly analysis method and apparatus provided in the embodiments of this application is not limited.
[0033] In the technical solution of this application, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant laws, regulations, and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse.
[0034] Figure 1 The illustration shows an application scenario diagram of an anomaly analysis method according to an embodiment of this application.
[0035] like Figure 1 As shown, application scenario 100 according to this embodiment may include: a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 serves as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.
[0036] Users can interact with server 105 via network 104 using first terminal device 101, second terminal device 102, or third terminal device 103 to receive or send messages, etc. Various communication client applications can be installed on first terminal device 101, second terminal device 102, and third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).
[0037] The first terminal device 101, the second terminal device 102, and the third terminal device 103 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.
[0038] Server 105 can be a server that provides various services, such as a backend management server that supports websites browsed by users using the first terminal device 101, the second terminal device 102, or the third terminal device 103 (this is just an example). The backend management server can analyze and process data such as received user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.
[0039] It should be noted that the anomaly analysis method provided in this application embodiment can generally be executed by server 105. Correspondingly, the anomaly analysis device provided in this application embodiment can generally be located in server 105. The anomaly analysis method provided in this application embodiment can also be executed by a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105. Correspondingly, the anomaly analysis device provided in this application embodiment can also be located in a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105.
[0040] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0041] Figure 2 A flowchart illustrating an anomaly analysis method according to an embodiment of this application is shown schematically.
[0042] like Figure 2 As shown, the anomaly analysis method provided in this embodiment may include operations S210 to S230. The embodiments of this application do not limit the executing entity of the anomaly analysis method; it can be applied to any electronic device or any software application. Optionally, an anomaly analysis method can be applied to a server, terminal, or preset system, etc.
[0043] In operation S210, the call flow information of n operation units is determined; n is a positive integer; the correspondence between the n operation units and business functions is determined; each operation unit is used to implement one or more corresponding business functions.
[0044] In operation S220, for any business function, the function traffic information of the business function is determined based on the call traffic information of the corresponding operation unit.
[0045] In operating S230, anomaly analysis is performed by integrating the functional traffic information of different business functions.
[0046] This method can determine the functional traffic information of the corresponding business function based on the call traffic information of the operation unit, and can perform anomaly analysis based on the traffic information from the perspective of business function, which can improve the efficiency and accuracy of anomaly analysis.
[0047] The embodiments of this application do not limit the operation unit. Optionally, the operation unit can be used to perform basic operations, specifically an interface or endpoint; the operation unit can be a unit provided by the system that allows invocation of basic operations. In a specific example, an interface or endpoint provided by a microservice or business system that allows invocation of basic operations can be referred to as an operation unit. A single operation unit can be used to implement one or more business functions, and in the process of implementing different business functions, the same operation unit can be invoked to perform basic operations.
[0048] The embodiments of this application do not limit the business functions. Optionally, the business function can be a function implemented at the business level, specifically, for example, user login or user authentication functions. A single business function can be implemented by calling one or more operation units to perform basic operations, and a single business function can correspond to one or more operation units. In a specific example, in the implementation of the user authentication business function, one operation unit can be called first to compare user authentication information, and then another operation unit can be called to perform security verification. If the user authentication information is correctly compared and passes the security verification, then the user authentication is determined to be successful, and the user authentication function is implemented.
[0049] For ease of understanding, in a specific example, multiple service systems can be deployed to execute business operations. These service systems can be microservices. A single service system can deploy one or more operation units, which can be interfaces or endpoints used to perform basic operations. A service system can call its own operation units or the operation units of other service systems to implement business functions. Specifically, for a business function request, the required business function can be determined, and the corresponding service system can call the operation unit to execute the operation, thus implementing the business function requested. A single service system can implement one or more business functions, and the same business function can be implemented by one or more service systems. A single business function can be implemented independently by multiple service systems, or it can be implemented collaboratively by multiple service systems.
[0050] Based on the above explanation of the operation unit and business function, the above method flow can convert the call traffic information of the operation unit into functional traffic information from the perspective of the business function according to the business function implemented by the operation unit. This allows for traffic anomaly analysis from the perspective of the business function, improving the accuracy and efficiency of anomaly analysis.
[0051] Understandably, by converting the call traffic information of an operation unit into functional traffic information from a business function perspective, the execution status of basic operations can be transformed into the execution status of business functions. This allows for anomaly analysis from a business perspective, improving the interpretability of anomaly analysis and facilitating the analysis or understanding of anomalies at the business level. For example, an abnormal increase in call traffic for a certain operation unit might indicate that the corresponding basic operation "page update" is being executed abnormally frequently, but further analysis is difficult. However, by converting the overall call traffic information of the operation unit into functional traffic information from a business function perspective, it can be determined that the execution frequency of a certain business function "information query" has increased abnormally. This allows for anomaly analysis at the business level, identifying which information query functions are malfunctioning and performing root cause analysis.
[0052] The following sections will explain each step in the above method and process.
[0053] 1. In operation S210, determine the call flow information of n operation units; n is a positive integer; determine the correspondence between the n operation units and business functions; where any operation unit is used to implement one or more corresponding business functions.
[0054] The embodiments of this application are not limited to n operation units. Optionally, multiple operation units that need to perform anomaly analysis can be referred to as n operation units, multiple operation units provided in the business system can be referred to as n operation units, or multiple operation units used to implement multiple business functions can be referred to as n operation units.
[0055] In a specific example, an operation unit can be an interface or endpoint belonging to a service system, which can be called to perform basic operations. A service system can be a microservice, providing one or more operation units to perform basic operations, and different service systems can call each other's operation units. Therefore, the operation units provided by multiple service systems can be referred to as n operation units.
[0056] Accordingly, a business function can be a function implemented by a service system. A single service system can implement one or more functions, and the same business function can be implemented by one or more service systems.
[0057] The embodiments of this application do not limit the correspondence between operation units and business functions. Optionally, an operation unit may correspond to one or more business functions, specifically it may be used to implement one or more corresponding business functions, or it may perform basic operations during the implementation of the corresponding business function. A business function may also correspond to one or more operation units, and may be implemented by one or more operation units.
[0058] In a specific example, the correspondence between operation units and business functions may include: operation unit A corresponds to user authentication function, information query function, and risk control function; operation unit B corresponds to order creation function, information query function, and security detection function; and operation unit C corresponds to data management function, permission verification function, and risk control function.
[0059] The embodiments of this application do not limit the specific construction method of the correspondence between operation units and business functions. Optionally, the correspondence can be determined by determining the business function implemented by the operation unit; alternatively, the characteristics of the operation unit and the characteristics of the business function can be extracted, and the correspondence can be determined based on the feature similarity. Specifically, the correspondence can be determined for operation units and business functions with a feature similarity greater than a preset feature similarity threshold. Wherein, if it is difficult to directly determine the business function implemented by the operation unit, or it is difficult to fully determine the business function implemented by the operation unit, the correspondence can be determined through feature similarity.
[0060] In one optional embodiment, a preset graph structure can be pre-constructed. This preset graph structure may include operation unit nodes representing operation units and business function nodes representing business functions. Node features can then be extracted based on the preset graph structure, thereby extracting operation unit node features and business function node features. The preset graph structure can represent the relationship between operation units and business functions in a graph structure form, and can be adapted to a corresponding operation unit architecture. Accordingly, the node features extracted based on the preset graph structure can determine the corresponding relationships based on the node feature similarity.
[0061] Therefore, optionally, the method for constructing the correspondence between n operation units and business functions may specifically include: determining a preset graph structure; the preset graph structure includes: operation unit nodes for representing any operation unit among the n operation units, and business function nodes for representing any business function; extracting operation unit node features and business function node features for the preset graph structure; in the preset graph structure, for operation unit nodes and business function nodes that meet preset similarity conditions, determining that the operation unit represented by the operation unit node corresponds to the business function represented by the business function node; the preset similarity conditions include: the similarity between the operation unit node features and the business function node features is greater than a preset node similarity threshold. This embodiment can combine the preset graph structure to extract the node features of the operation units and the node features of the business functions, determine the node feature similarity, and determine the correspondence between operation units and business functions based on the node feature similarity, which can improve the accuracy of the correspondence between operation units and business functions.
[0062] The embodiments of this application do not limit the specific content of the preset diagram structure.
[0063] Optionally, the preset graph structure may include operation unit nodes and business function nodes, as well as other nodes, to represent the overall system architecture. For example, business function nodes can represent functions at the business layer. Correspondingly, operation unit nodes can first be connected to other nodes used to connect basic operations and the business layer, specifically, nodes representing microservices or business systems. Further, other nodes are connected to business function nodes to determine the association between other nodes and business function nodes at the business layer. The preset graph structure can represent the overall system architecture, facilitating the extraction of node features from the overall architecture and improving the accuracy of the correspondence between operation units and business functions.
[0064] Therefore, optionally, the preset graph structure may further include: a service system node for representing the service system; a first side for connecting the service system node and the operation unit node; wherein the first side represents the service system represented by the connected service system node and calls the operation unit represented by the connected operation unit node; and a second side for connecting the service system node and the business function node; wherein the second side represents the service system represented by the connected service system node and possesses the business function represented by the connected business function node. This embodiment can more accurately represent the architecture of the overall system based on the preset graph structure containing the service system node, combined with the first and second sides, which can improve the accuracy and comprehensiveness of the extracted node features and improve the accuracy of the correspondence between operation units and business functions.
[0065] Specifically, a service system can be a microservice. A microservice can implement one or more business functions and provide one or more operational units (interfaces or endpoints) for being called to perform basic operations. The overall system can contain one or more service systems.
[0066] The calling relationship between service systems and operation units can include the calling relationship between a service system and the operation units it provides, as well as the calling relationship between a service system and the operation units provided by other service systems. It is understandable that a corresponding first-side can be constructed based on the service system and its own provided operation units, or it can be constructed based on the service system and the called operation units in historical call information.
[0067] To determine the relationship between a service system and its business functions, the implemented business functions can be identified based on the service system's description, logs, and documentation. A corresponding second side can then be constructed based on these functions. Furthermore, a confidence level can be set for each identified business function. Specifically, this can be achieved by combining the service system's description, logs, and documentation to determine the implemented business functions and their corresponding confidence levels. The weight of the second side can then be determined based on these confidence levels.
[0068] The embodiments of this application do not limit the method of determining business functions. In an optional embodiment, business functions can be determined from information such as descriptions, logs and documents of multiple service systems, or from the overall log information of multiple service systems, or by clustering the functional description information in the documents of multiple service systems. One or more business functions can be determined as candidate business functions to determine the business functions implemented by the service system.
[0069] In an optional embodiment, for the service system nodes in the aforementioned preset graph structure, edges can be constructed between different service system nodes to represent the relationships between them, specifically, similarity relationships. For example, connecting different service system nodes with high similarity can more accurately represent the overall system architecture and the relationships between service system nodes.
[0070] Therefore, optionally, the preset graph structure may further include a third edge for connecting different service system nodes; wherein the third edge is used to characterize that the system feature similarity between the service systems represented by the two connected service system nodes is greater than a preset system feature similarity threshold. This embodiment, by connecting different service system nodes with high feature similarity, can more accurately characterize the overall system architecture and the relationship between service system nodes, improving the accuracy and comprehensiveness of the extracted node features and enhancing the accuracy of the correspondence between operational units and business functions.
[0071] Alternatively, a third edge can be constructed for any two service system nodes, and the weight of the third edge can be determined based on the similarity of system features between the service systems represented by the two connected service system nodes.
[0072] It is understandable that for different service systems with high similarity, the operation units called and the business functions implemented may also show high similarity. Therefore, by connecting the third side, the accuracy of the node characteristics of the operation units and business functions can be improved.
[0073] The embodiments of this application do not limit the method for determining the weights of edges in the preset graph structure. Optionally, the first edge can be used to characterize whether the service system calls the operation unit. It may not have a weight, or the weight of the first edge may be set based on the number of calls or the call frequency, wherein the number of calls or the call frequency may be positively correlated with the weight of the first edge. Furthermore, the weight of the first edge can be adjusted based on whether the operation unit belongs to the service system.
[0074] Optionally, the weight of the second side is used to characterize the probability that the service system represented by the connected service system node possesses the business function represented by the connected business function node; the weight of the third side is used to characterize the similarity of system features between the service systems represented by the two connected service system nodes. This embodiment can determine the weight of edges in a preset graph structure, more accurately characterize the overall system architecture and the relationship between nodes, improve the accuracy and comprehensiveness of the extracted node features, and improve the accuracy of the correspondence between operating units and business functions.
[0075] The weights on the second side can be positively correlated with the probability that the corresponding service system has the corresponding business function. The probability that the service system has the business function can be determined by combining the information of the service system and the information of the business function. Specifically, it can be determined by pre-trained models or keyword matching.
[0076] The weights on the third side can be positively correlated with the similarity of system features between the two corresponding service systems. The system features of the service system can be determined or extracted based on information such as the service system's documents, descriptions, and logs. Specifically, system features can be extracted from the service system using a pre-trained system feature extraction model.
[0077] The above embodiments explain the content of the preset graph structure. The following explains the operation of extracting node features.
[0078] The embodiments of this application are not limited to the specific methods of extracting operation unit node features and business function node features for a preset graph structure.
[0079] Optionally, multiple paths in the preset graph structure can be extracted by a meta-path random walk, and further, the node features of each node in the path can be extracted by combining a context prediction model; alternatively, the node features of each node in the preset graph structure can be extracted by a graph neural network model or a graph convolution model.
[0080] In this context, it can be understood that the context prediction model can predict the context nodes in the path based on any node in the path (called the central node). The hidden layer can extract the node features of the central node, which are used by the output layer to predict the corresponding context nodes. Thus, the hidden layer can be used as a node feature extraction model to extract node features for each node in the preset graph structure.
[0081] To improve the efficiency of node feature extraction, node features can optionally be extracted for operation unit nodes and business function nodes through a hidden layer.
[0082] Accordingly, the context prediction model can be trained using multiple paths obtained from the meta-path random walk as samples. Specifically, any node can be used as the center node (sample feature), and the context nodes of the corresponding path can be used as sample labels for model training.
[0083] Understandably, after extracting the features of operation unit nodes and business function nodes, the correspondence between operation units and business functions in the preset graph structure can be further determined based on the node feature similarity. Specifically, operation units and business functions with node feature similarity greater than a preset node similarity threshold can be selected.
[0084] The embodiments of this application do not limit the preset similarity conditions. Optionally, for any operation unit node, the corresponding relationship can also be determined by selecting the first k business function nodes whose node feature similarity is greater than a preset node similarity threshold and are arranged in descending order of node feature similarity. For any business function unit node, the corresponding relationship can also be determined by selecting the first t operation unit nodes whose node feature similarity is greater than a preset node similarity threshold and are arranged in descending order of node feature similarity. k and t can be positive integers.
[0085] Second, in operation S220, for any business function, the function traffic information of the business function is determined based on the call traffic information of the corresponding operation unit.
[0086] Understandably, for multiple business functions, operation S220 can be executed separately to determine the function traffic information.
[0087] The embodiments of this application do not limit the call traffic information. Optionally, the call traffic information may include at least one of the following: the number of calls and the call frequency. The embodiments of this application also do not limit the function traffic information. Optionally, the function traffic information can be determined based on the call traffic information. When the call traffic information includes the number of calls, the function traffic information may include the number of times the function is used, that is, the number of times the function is used; when the call traffic information includes the call frequency, the function traffic information may include the function usage frequency, that is, the frequency at which the function is used.
[0088] The embodiments of this application do not limit the specific method of determining functional traffic information based on call traffic information. Optionally, a single business function may correspond to one or more operation units, thereby the call traffic information of each corresponding operation unit can be combined to determine the functional traffic information.
[0089] Considering that a single operation unit can also implement one or more business functions, the probability distribution of the operation unit implementing the corresponding business function can be determined, so that the call traffic information of the operation unit can be allocated accordingly for the multiple business functions implemented.
[0090] Optionally, among the n operation units, a functional weight can be set between any operation unit and any corresponding business function. The functional weight can be used to characterize the probability that the operation unit will implement the business function, and the functional weight is positively correlated with the probability that the operation unit will implement the business function. Accordingly, the call traffic information of the operation units can be allocated according to the functional weight.
[0091] Therefore, optionally, among the n operation units, a functional weight is set between any operation unit and any corresponding business function; for any business function, the functional traffic information of the corresponding business function is determined based on the call traffic information of the corresponding operation unit. Specifically, this may include: for any business function, determining the functional traffic information of the corresponding business function by weighting the call traffic information of different operation units according to the functional weights set between them. This embodiment can determine the functional traffic information based on the weight of the operation unit for a single business function, which can improve the accuracy of the determined functional traffic information.
[0092] The embodiments of this application do not limit the method for determining the functional weights. Optionally, the functional weights can be determined based on the node features extracted from the above-mentioned preset graph structure and the similarity of node features between the operation unit and the corresponding business function. The functional weights can be positively correlated with the node feature similarity. Specifically, the functional weights can be determined by normalizing the node feature similarity between the operation unit and each corresponding business function.
[0093] In a specific example, the correspondence between operation units and business functions may include function weights (also known as function implementation probability distributions). For example, the correspondence between operation units and business functions may specifically include: operation unit A corresponds to user authentication function (function weight 0.2), information query function (function weight 0.7), and risk control function (function weight 0.1); operation unit B corresponds to order creation function (function weight 0.5), information query function (function weight 0.3), and security detection function (function weight 0.2).
[0094] Understandably, for a single business function, the call traffic information of each corresponding operation unit and the corresponding function weight can be combined to calculate a weighted sum, which can then be used as the function traffic information.
[0095] Third, in operating S230, perform anomaly analysis by integrating the functional traffic information of different business functions.
[0096] Once the function traffic information (e.g., function usage frequency or number of times a function is used) for multiple business functions is identified, further anomaly analysis can be performed. Specifically, for example, abnormal changes in the frequency of business function usage.
[0097] The embodiments of this application do not limit the specific methods and processes for performing anomaly analysis. Optionally, anomaly analysis can be performed independently for a single business function, or a comprehensive anomaly analysis can be performed on multiple business functions as a whole; it can be based on the function traffic information of different business functions to determine whether an anomaly has occurred, or anomaly location and root cause analysis can be performed on the anomaly that has occurred.
[0098] Optionally, separate anomaly analysis can be performed on the function traffic information of different business functions. Specifically, this can be done by combining the historical function traffic information of the same business function to analyze whether there are any abnormal changes or fluctuations. Alternatively, a comprehensive anomaly analysis can be performed by combining the function traffic information of multiple business functions. Specifically, this can be done by combining the historical traffic distribution among multiple business functions to determine whether there are any abnormal changes in the traffic distribution among multiple business functions, such as a sudden increase or decrease in the total traffic share of a certain business function.
[0099] Optionally, determining whether an anomaly has occurred can be done by combining the normal traffic baseline. The normal traffic baseline can be determined by combining historical functional traffic information. Therefore, optionally, anomaly analysis can be performed by comprehensively analyzing the functional traffic information of different business functions. Specifically, this can include: determining the degree of difference between the functional traffic information of different business functions and the functional traffic baseline information; the functional traffic baseline information is determined based on historical functional traffic information. This embodiment can determine the normal functional traffic baseline information based on historical functional traffic information, thereby enabling anomaly analysis of functional traffic. By determining whether an anomaly has occurred based on the degree of deviation or difference between the functional traffic information and the baseline, combined with historical functional traffic information, the accuracy of anomaly analysis can be improved.
[0100] Accordingly, based on the specific circumstances of the functional traffic information of different business functions, anomaly analysis can be performed by comparing it with the baseline, specifically to determine whether any abnormalities have occurred. Optionally, anomaly analysis by comprehensively analyzing the functional traffic information of different business functions may include at least one of the following: (1) determining the degree of difference between the distribution of functional traffic information of different business functions and the preset distribution baseline; (2) determining the degree of difference between the ratio of functional traffic information of different business functions and the preset functional traffic ratio baseline; (3) determining the degree of difference between the functional traffic information of different business functions and the preset functional traffic information baseline; (4) determining the degree of difference between the context information of functional traffic information of different business functions and the preset context information baseline. In this embodiment, the functional traffic information of different business functions can be compared with the baseline information in different ways to determine the degree of difference or deviation from the baseline, thereby performing anomaly analysis, determining whether any abnormalities have occurred, and improving the accuracy and comprehensiveness of anomaly analysis. It is understandable that an anomaly can be identified if one or more determined differences exceed a preset difference threshold; alternatively, it can be determined whether the weighted sum of multiple determined differences exceeds the preset difference threshold, and if the weighted sum of multiple determined differences exceeds the preset difference threshold, an anomaly can be identified.
[0101] In one optional embodiment, further root cause analysis can be performed on the detected anomalies. Specifically, this can involve analyzing the call traffic information of the operating units within the business functions where the anomalies occurred, thereby locating the operating units where the anomalies occurred. Alternatively, the cause of the anomaly can be comprehensively analyzed by combining the operation logs of the business functions or the log information of the operating units. Furthermore, the scope of impact of the anomalies can be determined by considering the business functions where the anomalies occurred, so that different anomaly handling strategies can be implemented according to different scopes of impact. Specific anomaly handling strategies may include: traffic migration, shutting down the business system, and stopping the reception of external traffic.
[0102] In addition, in an optional embodiment, the corresponding business function can be determined for the newly added operation unit based on the correspondence between the operation unit and the business function.
[0103] The embodiments of this application do not limit the addition of new operation units. Optionally, the added operation unit may be an operation unit obtained by updating an existing operation unit, or a newly developed operation unit.
[0104] In a specific example, for the interface of a microservice, you can upgrade the version or develop a new interface for the microservice.
[0105] Optionally, from the n operation units whose corresponding business functions have already been determined, a target operation unit similar to the new operation unit can be identified. This allows the business function corresponding to the target operation unit to be directly identified as the business function corresponding to the new operation unit, improving the efficiency of determining the business function corresponding to the new operation unit. It is understandable that for operation units involved in version upgrades, the operation units of the old version can be quickly identified based on similarity, thus allowing the direct determination of the corresponding business function.
[0106] Therefore, optionally, the above method flow further includes: for the newly added operation unit, among the n operation units, determining a target operation unit whose similarity to the newly added operation unit is greater than a preset unit similarity threshold; and determining the business function corresponding to the determined target operation unit as the business function corresponding to the newly added operation unit. This embodiment can determine the corresponding business function by determining the similarity between the newly added operation unit and the n operation units respectively, thereby improving the efficiency of determining the business function corresponding to the newly added operation unit.
[0107] Optionally, determining the target operation unit can specifically involve identifying the target operation unit with the highest similarity to the newly added operation unit among n operation units. The embodiments of this application do not limit the method for determining the similarity between the operation unit and the newly added operation unit; specifically, the similarity can be determined based on the information of the operation unit and the information of the newly added operation unit, or it can be determined based on the features of the operation unit and the features of the newly added operation unit.
[0108] For ease of understanding, this application also provides an application embodiment. Specifically, service endpoints in microservices can be mapped to corresponding functions. By converting the traffic of the service endpoints into the traffic of the corresponding functions, anomaly analysis can be performed on the traffic information from a functional perspective.
[0109] Microservices (corresponding to the service system in the above method embodiments): refer to service units in a distributed system that are independently deployed and cooperate with each other through network calls to complete business functions.
[0110] Service endpoint (corresponding to the operation unit in the above method embodiment): The calling interface provided by the microservice to the outside world, which can be used to perform operations or implement functions.
[0111] Dependency call: A call request (which can be an API call request) or message sending behavior initiated by one microservice to another microservice, as discovered during runtime or static analysis.
[0112] Endpoint similarity completion: The process of judging the structural and semantic similarity of newly added or changed service endpoints and automatically inferring their functional affiliation from existing mappings.
[0113] Heterogeneous graph: A modeling method for complex interactive systems, used to model multiple types of objects and the complex relationships between them.
[0114] With the increasing adoption of microservice architecture in internet and enterprise systems, the number of system dependencies and endpoints is growing rapidly. The security, compliance, and maintainability of microservice systems increasingly depend on a correct understanding and continuous monitoring of inter-service dependencies and endpoint functionality.
[0115] This embodiment proposes an overall technical solution for microservice dependency calls, which combines endpoint function mapping, heterogeneous graph embedding, and similarity completion to build a stable, scalable dependency identification and anomaly detection system that is resistant to endpoint evolution.
[0116] The functions mentioned in this embodiment (corresponding to the business functions in the above method embodiments) are defined as: high-level functional units provided by microservices that are business-value oriented. They are abstract expressions of business semantics, independent of specific technical implementations, and are business-level functions. Specifically, they may include: user authentication: verifying user identity and managing sessions; order processing: creating, modifying, and canceling orders; payment processing: processing fund transfers and recording transactions; data synchronization: maintaining cross-system data consistency; push notifications: sending message reminders to users, etc.
[0117] The purpose of this embodiment is to provide an automatic endpoint function mapping and dependency call detection method for microservice architecture. By constructing a heterogeneous call graph of "endpoint-service-function", combined with graph structure embedding learning and endpoint similarity completion mechanism, the following objectives are achieved: (1) Automatically map massive endpoints to stable functional semantics, thereby reducing the sensitivity to endpoint name / version changes; (2) Automatically complete / identify the functional affiliation of newly added or migrated endpoints, reducing manual maintenance; (3) Utilize the learned functional endpoint associations to construct a functional level view for dependency calls, supporting more robust anomaly detection and compliance auditing; (4) Support online / offline hybrid update strategy to adapt to low-latency monitoring requirements.
[0118] In this embodiment, a heterogeneous call graph can be constructed for multiple microservices, wherein each microservice may contain one or more service endpoints, and each microservice may have one or more functions.
[0119] In a heterogeneous call graph, there may be service nodes that represent microservices, endpoint nodes that represent service endpoints, and function nodes that represent functions.
[0120] The functions represented by the functional nodes can be microservice-level business functions. Therefore, the heterogeneous call graph may not include edges between endpoint nodes and functional nodes. Accordingly, multiple functions can be determined first based on information from multiple microservices, and then corresponding functional nodes can be constructed for each determined function.
[0121] For service nodes, initial node characteristics can be determined based on the information of the microservices they represent. Specifically, this can be done by combining information such as the microservice's documentation, description, and business logic to determine the initial node characteristics, which will facilitate further extraction of node characteristics based on the heterogeneous call graph structure.
[0122] For endpoint nodes, initial node features can be determined based on the information of the represented service endpoint. Specifically, this can be based on the semantic features, raw information, and structural features of the service endpoint. Structural features include, for example, the access path, access parameters, and message subject name roots for the service endpoint; semantic features include, for example, the semantics of the operation performed by the service endpoint, the semantics of the access path to the service endpoint, and the semantic information of the request to the service endpoint. The initial node features can be obtained by weighted fusion of structural and semantic features.
[0123] For functional nodes, initial node features can be determined based on the information of the represented function. Specifically, the initial node features can be determined based on information such as the semantic features of the represented function.
[0124] In a heterogeneous call graph, edges between different nodes can also be included.
[0125] The edge between a service node and an endpoint node (corresponding to the first edge in the above method embodiment) can represent that the microservice represented by the connected service node calls the service endpoint represented by the connected endpoint node. The edge between a service node and an endpoint node can be constructed based on the call information between the microservice and the service endpoint. It can be determined from the call log whether a microservice has called a service endpoint. If a microservice has called a service endpoint, an edge can be constructed for the corresponding service node and the corresponding endpoint node. Furthermore, if a service endpoint belongs to a microservice, an edge can also be constructed for the corresponding service node and the corresponding endpoint node.
[0126] The edges between different service nodes (corresponding to the third edge in the above method embodiments) can represent the functional and semantic similarity of the microservices represented by the two connected service nodes. Specifically, for two microservices with a feature similarity greater than a preset service similarity threshold, an edge can be constructed between the corresponding two service nodes. For edges between different service nodes, the feature similarity between the different microservices can be used as the edge weight. Specifically, the edge weight can be determined based on the semantic feature similarity between the different microservices.
[0127] The edge between a service node and a functional node (corresponding to the second edge in the above method embodiment) can represent that the microservice represented by the connected service node possesses, includes, or calls the functionality represented by the connected functional node. For the edge between a service node and a functional node, the functionality implemented or possessed by the microservice can be determined based on the microservice's logs, descriptions, or documentation, thus allowing the construction of edges for the corresponding service node and functional node. Specifically, the edge weight can be determined based on the similarity between the microservice and the functionality. In a specific example, the probability distribution of multiple topics can be extracted from the microservice information using a topic model, and a mapping relationship between topics and functions can be further constructed. Topic keywords can be determined for each function, and then the edge weight can be determined based on the hit rate or similarity of the topic keywords in the microservice information, representing the probability that the microservice implements the corresponding functionality.
[0128] In a heterogeneous call graph, a single service node can connect to multiple different endpoint nodes, and a single service node can also connect to multiple different functional nodes. A single functional node can connect to multiple different service nodes. A single endpoint node can connect to multiple different service nodes.
[0129] In this embodiment, after constructing the heterogeneous call graph, the node features can be further extracted from the heterogeneous call graph.
[0130] Specifically, methods such as graph neural networks or graph convolution can be used to extract node features.
[0131] Alternatively, multiple paths can be extracted using meta-path random walks, and for these multiple paths, node features of each node in the path can be extracted using a pre-trained context prediction model.
[0132] In a specific example, since subsequent node features are needed to determine the feature similarity between service endpoints and functions, meta-paths such as "endpoint-service-function" and "function-service-endpoint" can be set up for random walks during meta-path execution. Service nodes can be repeated within these meta-paths. During the random walk, the walk probability can be determined based on the edge weights, resulting in multiple paths. These paths can be from a heterogeneous call graph and include multiple nodes.
[0133] The obtained multiple paths can then be used as training samples to train a context prediction model. Specifically, a single node in the path can be used as the center word (sample feature), and other nodes or other nodes within a preset window size can be used as the context (sample label) to train the context prediction model. This allows the model to predict the probability that other nodes belong to the context for a single node.
[0134] In the context prediction model, the input layer can input a single node (center word) in the path, the hidden layer can extract the node features of the input single node, and the output layer can predict the probability that each other node in the heterogeneous call graph belongs to the context of the input single node based on the node features of the input single node.
[0135] After training the context prediction model, the node features extracted from the hidden layer can be identified as node features extracted from the heterogeneous call graph.
[0136] Therefore, the endpoint node features of the endpoint nodes in the heterogeneous call graph and the functional node features of the functional nodes can be extracted using the above method.
[0137] In this embodiment, based on the similarity between the extracted endpoint node features and functional node features, endpoint node features and functional node features with high similarity can be determined as a set of service endpoint and function mapping relationships.
[0138] Specifically, for each functional node, the similarity of node features with each endpoint node can be calculated, and the top k endpoint nodes with the highest similarity can be selected to construct the mapping relationship between functions and service endpoints.
[0139] Alternatively, for each endpoint node, the node feature similarity with each functional node can be calculated, and the top t functional nodes with the highest similarity can be selected to construct the mapping relationship between functions and service endpoints.
[0140] A single service endpoint can be mapped to one or more functions. This mapping can include the function implementation probability distribution or function weights of the service endpoint. The function implementation probability distribution or function weights can be determined based on node feature similarity. Specifically, this can be achieved by normalizing the node feature similarity between the service endpoint and multiple functions to obtain the function implementation probability distribution or function weights.
[0141] In a specific example, the mapping relationship between service endpoints and functions can be: Service endpoint A: User authentication (0.88), data management (0.75), permission verification (0.65).
[0142] After determining the mapping relationship between server endpoints and functions, the traffic patterns of the server endpoints can be converted into the traffic patterns of the functions based on the mapping relationship. Since the same function may be implemented by multiple server endpoints, the traffic patterns of the functions can be determined by combining the traffic patterns of multiple server endpoints.
[0143] Furthermore, anomaly analysis can be conducted comprehensively based on the traffic data of the function.
[0144] In this embodiment, anomaly analysis can be performed based on the overall traffic situation of the functional combination. Specifically, the following operations can be performed.
[0145] (1) Baseline establishment phase: Business function mapping: Construct the mapping relationship between business functions and service interfaces; Normal behavior modeling: Learn the business function combination pattern of normal business process from historical data; Threshold setting: Set abnormal thresholds for different business function combinations.
[0146] (2) Real-time detection phase: Interface call capture: capture real-time interface calls through service mesh / gateway; business function conversion: convert interface calls into business function feature vectors; anomaly score calculation: compare business function combination with normal baseline; dynamic response: trigger different response strategies according to the degree of anomaly.
[0147] (3) Adaptive update: Business drift detection: Identify the natural evolution of business models; Mapping relationship update: Adapt to interface version iteration and business function adjustment; Baseline optimization: Continuously optimize the normal behavior baseline.
[0148] Specifically, historical logs and historical traffic can be converted into function-level dependency representations based on the mapping relationship between functions and service endpoints, thereby suggesting function-level behavioral baselines, including baselines such as the frequency distribution of function calls within normal traffic time windows.
[0149] When conducting specific anomaly detection and analysis, it's possible to combine normal behavior baselines with functional traffic detection to identify functional-level traffic anomalies. Alternatively, it can be combined with models such as classifiers to identify abnormal traffic or abnormal operations.
[0150] In addition, it can also support tracing for anomalies detected by analysis. It can identify the abnormal microservice or abnormal service endpoint based on the abnormal points of functional traffic, and realize root cause analysis.
[0151] For ease of understanding, in a specific example, we can collect data showing that endpoint A was called 500 times, endpoint B was called 10 times, and endpoint C was called 10 times. The mapping relationship between endpoint A and functions can include: function 1 (0.3), function 2 (0.7). The mapping relationship between endpoint B and functions can include: function 1 (0.4), function 3 (0.6). The mapping relationship between endpoint C and functions can include: function 1 (0.5), function 2 (0.5).
[0152] Based on the mapping relationship between endpoints and functions, and the function weights, the number of function calls can be calculated by combining the endpoint call count and the function weight for each function. For example, for function 1, the number of function calls is 500×0.3+10×0.4+10×0.5=159.
[0153] Subsequent analysis can be conducted based on the number of function calls for each feature. Specifically, this analysis can be performed in conjunction with the aforementioned baseline of normal behavior. Considerations could include the distribution or proportion of function call counts, as well as any sudden changes in call frequency.
[0154] In addition, when endpoint versions are iterated, the endpoint similarity completion module can determine the similarity between the new endpoint and the existing endpoints, and bind the new endpoint to the function corresponding to the most similar endpoint, thus achieving low-cost updates.
[0155] The following is a schematic diagram of the end-to-end process of the system, divided into "initialization and build process" and "running detection / completion process".
[0156] Initialize the build process (one-time / periodic).
[0157] (1) Data collection: Data is collected from the registry center, source code, historical collection services, endpoints, and sample call data.
[0158] (2) Endpoint normalization: path template, parameter extraction, annotation / description capture and desensitization.
[0159] (3) Determine the functions implemented by the microservice.
[0160] (4) Heterogeneous graph construction: Based on the collected static and dynamic data, construct a graph structure containing endpoint nodes, service nodes and functional nodes, and calculate the weight of the edges.
[0161] (5) Metapath walking sampling: Based on the set metapath, a large number of walking sequences are sampled on the graph.
[0162] (6) Embedding training: Train the node vector representation using the context prediction model.
[0163] (7) Endpoint function mapping generation: Calculate the mapping table based on vector similarity and apply the confidence threshold.
[0164] (8) Construct functional behavior baselines: Project historical runtime calls onto the functional space and statistically analyze the baseline distribution.
[0165] (9) Launch the mapping library: Publish the mapping relationship between endpoints and functions for use in operation detection and anomaly analysis.
[0166] Run the detection and completion process (online continuously).
[0167] (1) Collect the event stream in real time and write it into the real-time processing pipeline.
[0168] (2) Projection to function: For each event, use the mapping relationship between endpoint and function to project the traffic of the endpoint into the traffic of the function.
[0169] (3) Real-time detection: Update short-term window statistics, make anomaly judgments (thresholds / models), and generate temporary alarms if the rules are triggered.
[0170] (4) Handling new endpoints: If an unmapped or low-confidence endpoint appears in the event, trigger a similarity comparison with existing endpoints, attempt to automatically assign the endpoint or mark it as pending review.
[0171] (5) Alarms and root causes: If an anomaly is detected, an alarm with a mapping confidence level is constructed, including an example call path, the scope of impact and handling suggestions.
[0172] (6) Feedback loop: After confirmation or judgment, the results are fed back to the mapping database; periodic offline retraining integrates new samples.
[0173] The technical effects achieved by this embodiment include at least the following:
[0174] (1) Enhance robustness to endpoint evolution: By mapping the volatile endpoint signature to a more stable functional semantic layer, the system’s sensitivity to endpoint path / version / protocol migration is significantly reduced, reducing manual maintenance costs.
[0175] (2) Automatically add new endpoints: Automatically or semi-automatically infer the function of newly launched or migrated endpoints, greatly shortening the time window from the appearance of a new endpoint to its inclusion in the whitelist, and reducing the exposure period of security risks.
[0176] (3) Functional representation facilitates high-level analysis: Projecting endpoint calls to the functional space enables anomaly detection, compliance auditing and root cause analysis to be performed at the business semantic level (facilitating understanding by security analysts, operations and maintenance personnel and products).
[0177] (4) Supports end-to-end detection and tracing: By combining the endpoint function mapping and call path of embedded learning, the system can detect anomalies at both the function and endpoint levels and trace back to specific call examples, thereby improving the operability and interpretability of alarms.
[0178] (5) Efficiency and scalability: The meta-path-based random walk and context prediction model embedded in the large-scale call graph can be trained efficiently and supports periodic offline reconstruction and online incremental completion.
[0179] (6) Reduce false positives and false negatives: The functional level model takes into account both semantic and structural information, which can reduce misjudgments caused by differences in endpoint naming. At the same time, functional aggregation helps to improve the recall of minor but high-impact lateral calls.
[0180] Based on the above method embodiments, this application also provides an anomaly analysis apparatus. The following will be combined with... Figure 3 The device is described in detail.
[0181] Figure 3 The diagram illustrates a structural block diagram of an anomaly analysis device according to an embodiment of this application.
[0182] like Figure 3 As shown, the anomaly analysis device 300 provided in this embodiment includes: a determination module 310, a functional flow module 320, and a comprehensive module 330.
[0183] The determining module 310 is used to determine the call flow information of n operation units; n is a positive integer; and to determine the correspondence between the n operation units and business functions; wherein each operation unit is used to implement one or more corresponding business functions. In one embodiment, the determining module 310 can be used to execute the operation S210 described above and related operations, which will not be repeated here.
[0184] The function flow module 320 is used to determine the function flow information of any given business function based on the call flow information of the corresponding operation unit. In one embodiment, the function flow module 320 can be used to execute the operation S220 described above and related operations, which will not be repeated here.
[0185] The integration module 330 is used to integrate the functional traffic information of different business functions and perform anomaly analysis. In one embodiment, the integration module 330 can be used to execute the operation S230 described above and related operations, which will not be repeated here.
[0186] According to embodiments of this application, the method for constructing the correspondence between n operation units and business functions includes: determining a preset graph structure; the preset graph structure includes: operation unit nodes for representing any operation unit among the n operation units, and business function nodes for representing any business function; extracting operation unit node features and business function node features for the preset graph structure; in the preset graph structure, for operation unit nodes and business function nodes that meet preset similarity conditions, determining that the operation unit represented by the operation unit node corresponds to the business function represented by the business function node; the preset similarity conditions include: the similarity between the operation unit node features and the business function node features is greater than a preset node similarity threshold.
[0187] According to an embodiment of this application, the preset diagram structure further includes: a service system node for representing a service system; a first side for connecting the service system node and the operation unit node; wherein the first side is used to represent the service system represented by the connected service system node and to call the operation unit represented by the connected operation unit node; and a second side for connecting the service system node and the business function node; wherein the second side is used to represent the service system represented by the connected service system node and to have the business function represented by the connected business function node.
[0188] According to an embodiment of this application, the preset graph structure further includes a third side for connecting different service system nodes; wherein the third side is used to characterize that the system feature similarity between the service systems represented by the two connected service system nodes is greater than a preset system feature similarity threshold.
[0189] According to an embodiment of this application, the weight of the second side is used to characterize the probability that the service system represented by the connected service system node has the business function represented by the connected business function node; the weight of the third side is used to characterize the similarity of system features between the service systems represented by the two connected service system nodes.
[0190] According to an embodiment of this application, in n operation units, a functional weight is set between any operation unit and any corresponding business function; the functional flow unit 320 is used to: for any business function, according to the functional weight set between the corresponding different operation units and the business function, determine the functional flow information of the business function by weighting the call flow information between the corresponding different operation units.
[0191] According to an embodiment of this application, the integration module 330 is used to: determine the degree of difference between the functional traffic information and the functional traffic baseline information of different business functions; the functional traffic baseline information is determined based on historical functional traffic information.
[0192] According to an embodiment of this application, the integration module 330 is configured to perform at least one of the following: determining the degree of difference between the distribution of functional traffic information of different business functions and a preset distribution baseline; determining the degree of difference between the ratio of functional traffic information of different business functions and a preset functional traffic ratio baseline; determining the degree of difference between the functional traffic information of different business functions and a preset functional traffic information baseline; and determining the degree of difference between the context information of functional traffic information of different business functions and a preset context information baseline.
[0193] According to an embodiment of this application, the above-mentioned device further includes a new module, configured to: for the new operation unit, determine, among n operation units, a target operation unit whose similarity to the new operation unit is greater than a preset unit similarity threshold; and determine the business function corresponding to the determined target operation unit as the business function corresponding to the new operation unit.
[0194] According to embodiments of this application, any multiple modules among the determined module 310, functional flow module 320, integrated module 330, and new module can be implemented in one module, or any one of these modules can be split into multiple modules. Alternatively, at least some functions of one or more of these modules can be combined with at least some functions of other modules and implemented in one module. According to embodiments of this application, at least one of the determined module 310, functional flow module 320, integrated module 330, and new module can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), programmable logic array (PLA), system-on-a-chip, system-on-a-substrate, system-on-package, application-specific integrated circuit (ASIC), or implemented in hardware or firmware by any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, and firmware, or in any appropriate combination of any of these three implementation methods. Alternatively, at least one of the determined module 310, functional flow module 320, integrated module 330, and new module can be at least partially implemented as a computer program module, which can perform corresponding functions when the computer program module is run.
[0195] The explanation of the above device embodiments can be found in other embodiments, and any operation in the above method embodiments can be executed by the corresponding module in the above device embodiments.
[0196] Figure 4 A block diagram schematically illustrates an electronic device suitable for implementing an anomaly analysis method according to an embodiment of this application.
[0197] like Figure 4 As shown, an electronic device 900 according to an embodiment of this application includes a processor 901, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 902 or a program loaded from a storage portion 908 into a random access memory (RAM) 903. The processor 901 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 901 may also include onboard memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of this application.
[0198] RAM 903 stores various programs and data required for the operation of electronic device 900. Processor 901, ROM 902, and RAM 903 are interconnected via bus 904. Processor 901 executes various operations of the method flow according to embodiments of this application by executing programs in ROM 902 and / or RAM 903. It should be noted that the programs may also be stored in one or more memories other than ROM 902 and RAM 903. Processor 901 may also execute various operations of the method flow according to embodiments of this application by executing programs stored in said one or more memories.
[0199] According to embodiments of this application, the electronic device 900 may further include an input / output (I / O) interface 905, which is also connected to a bus 904. The electronic device 900 may also include one or more of the following components connected to the input / output (I / O) interface 905: an input section 906 including a keyboard, mouse, etc.; an output section 907 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 908 including a hard disk, etc.; and a communication section 909 including a network interface card such as a LAN card, modem, etc. The communication section 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the input / output (I / O) interface 905 as needed. A removable medium 911, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 910 as needed so that computer programs read from it can be installed into the storage section 908 as needed.
[0200] This application also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of this application.
[0201] According to embodiments of this application, the computer-readable storage medium can be a non-volatile computer-readable storage medium, such as including but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this application, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this application, the computer-readable storage medium may include ROM 902 and / or RAM 903 and / or one or more memories other than ROM 902 and RAM 903 described above.
[0202] Embodiments of this application also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to enable the computer system to implement an anomaly analysis method provided in the embodiments of this application.
[0203] When the computer program is executed by the processor 901, it performs the functions defined in the system / apparatus of this application embodiment. According to the embodiments of this application, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0204] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and downloaded and installed via the communication section 909, and / or installed from a removable medium 911. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.
[0205] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 909, and / or installed from the removable medium 911. When the computer program is executed by the processor 901, it performs the functions defined in the system of this application embodiment. According to the embodiments of this application, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0206] According to embodiments of this application, program code for executing the computer programs provided in the embodiments of this application can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C", or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0207] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0208] Those skilled in the art will understand that the features described in the various embodiments of this application can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in this application. In particular, the features described in the various embodiments of this application can be combined and / or combined in various ways without departing from the spirit and teachings of this application. All such combinations and / or combinations fall within the scope of this application.
Claims
1. An anomaly analysis method, characterized in that, The method includes: Determine the call flow information of n operation units; where n is a positive integer; determine the correspondence between the n operation units and business functions; wherein each operation unit is used to implement one or more corresponding business functions; For any given business function, determine the function traffic information of the corresponding business function based on the call traffic information of the corresponding operation unit; Anomaly analysis is performed by integrating the functional traffic information from different business functions.
2. The method according to claim 1, characterized in that, The methods for constructing the correspondence between the n operation units and business functions include: A preset diagram structure is determined; the preset diagram structure includes: an operation unit node for representing any operation unit among the n operation units, and a business function node for representing any business function; For the preset graph structure, extract the features of operation unit nodes and business function nodes; In the preset graph structure, for operation unit nodes and business function nodes that meet the preset similarity conditions, the operation unit represented by the operation unit node is determined, and the business function represented by the business function node is determined. The preset similarity conditions include: the similarity between the features of the operation unit node and the features of the business function node is greater than the preset node similarity threshold.
3. The method according to claim 2, characterized in that, The preset diagram structure also includes: Service system nodes used to characterize the service system; A first side is used to connect service system nodes and operation unit nodes; wherein, the first side is used to represent the service system represented by the connected service system node and to call the operation unit represented by the connected operation unit node; The second side is used to connect the service system node and the business function node; wherein, the second side is used to represent the service system represented by the connected service system node and has the business function represented by the connected business function node.
4. The method according to claim 3, characterized in that, The preset diagram structure also includes: A third side is used to connect different service system nodes; wherein the third side is used to indicate that the system feature similarity between the service systems represented by the two connected service system nodes is greater than a preset system feature similarity threshold.
5. The method according to claim 4, characterized in that, The weight of the second side is used to represent the probability that the service system represented by the connected service system node has the business function represented by the connected business function node. The weight of the third side is used to characterize the similarity of system features between the service systems represented by the two connected service system nodes.
6. The method according to claim 1, characterized in that, In the n operation units, a functional weight is set between any operation unit and any corresponding business function; For any given business function, the function traffic information for that business function is determined based on the call traffic information of the corresponding operation unit, including: For any given business function, based on the functional weights set between the corresponding different operation units and the business function, the weighted sum of the call traffic information of the corresponding different operation units is determined as the functional traffic information of the business function.
7. The method according to claim 1, characterized in that, The analysis of anomalies based on the integrated traffic information from different business functions includes: Determine the degree of difference between the functional traffic information and the functional traffic baseline information for different business functions; the functional traffic baseline information is determined based on historical functional traffic information.
8. The method according to claim 1, characterized in that, The anomaly analysis of the integrated functional traffic information from different business functions includes at least one of the following: Determine the degree of difference between the distribution of functional traffic information for different business functions and the preset baseline distribution. Determine the degree of difference between the ratio of functional traffic information of different business functions and the preset functional traffic ratio baseline; Determine the degree of difference between the functional traffic information of different business functions and the preset functional traffic information baseline; Determine the degree of difference between the context information of the functional traffic information of different business functions and the preset context information baseline.
9. The method according to claim 1, characterized in that, The method further includes: For the newly added operation unit, among the n operation units, a target operation unit with a similarity greater than a preset unit similarity threshold is determined; The business function corresponding to the identified target operation unit is determined as the business function corresponding to the newly added operation unit.
10. An anomaly analysis device, characterized in that, The device includes: A determination module is used to determine the call flow information of n operation units, where n is a positive integer; and to determine the correspondence between the n operation units and business functions, wherein each operation unit is used to implement one or more corresponding business functions. The function traffic module is used to determine the function traffic information of any business function based on the call traffic information of the corresponding operation unit. The integration module is used to integrate the functional traffic information of different business functions and perform anomaly analysis.
11. An electronic device, comprising: One or more processors; Memory, used to store one or more computer programs. The characteristic feature is that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 9.
12. A computer-readable storage medium having a computer program or instructions stored thereon, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 9.
13. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 9.