Security operation and maintenance task scheduling method for big data intelligent platform
Patent Information
- Application Number
- CN202610590876.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-04-30
- Publication Date
- 2026-08-28
AI Technical Summary
[0003]然而,基于现有技术进行安全运维任务调度时,一方面对生产业务负载变化、业务任务依赖关系以及安全运维任务干扰特征的刻画不够准确,另一方面,对运维扰动、正常业务波动和异常侵入行为之间缺少有效区分,也存在容量边界校验和后续优先级调整不够精细的问题,都会降低调度决策的准确性和平台运行的安全性
1、本发明通过采集业务任务依赖数据与历史时序数据构建理想业务处理基准,并结合待调度任务的占用消耗特征进行特征化注入生成理论受干扰状态,实现了对复杂业务负载变化、任务流转先后次序以及运维干扰特征的准确刻画,为后续调度提供了可靠的数据底座,有效提升了调度决策的准确性。
Smart Images

Figure CN122653768A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of security operation and maintenance and task scheduling technology for big data platforms, specifically a security operation and maintenance task scheduling method for big data intelligent platforms. Background Technology
[0002] Security operation and maintenance task scheduling for big data intelligent platforms refers to the arrangement and control of the execution timing of security operation and maintenance tasks such as vulnerability scanning, log verification, and integrity verification during the process of the platform carrying production business operations. Current security operation and maintenance task scheduling methods typically include scheduling based on fixed time windows, scheduling based on human experience, and scheduling based on real-time resource consumption thresholds.
[0003] However, when scheduling security operation and maintenance tasks based on existing technologies, on the one hand, the characterization of changes in production business load, business task dependencies, and security operation and maintenance task interference characteristics is not accurate enough. On the other hand, there is a lack of effective distinction between operation and maintenance disturbances, normal business fluctuations, and abnormal intrusion behaviors. There are also problems with insufficient precision in capacity boundary verification and subsequent priority adjustment. All of these will reduce the accuracy of scheduling decisions and the security of platform operation. Summary of the Invention
[0004] The purpose of this invention is to provide a method for scheduling security operation and maintenance tasks for big data intelligent platforms, and to solve the following technical problems: It avoids resource contention and misjudgment during peak business periods and overlapping operation and maintenance tasks, and enables interpretable scheduling of security operation and maintenance tasks under complex business load fluctuations, balancing business continuity and timeliness of security handling.
[0005] The objective of this invention can be achieved through the following technical solutions: The method for scheduling security operation and maintenance tasks for big data intelligent platforms includes the following steps: The big data intelligent platform collects business task dependency data, service level agreement data including business capacity boundaries, historical business throughput time series data, and real-time business load status data through the business statistics module, and obtains the occupancy and consumption characteristic data of the security operation and maintenance tasks to be scheduled from the preset security operation and maintenance task management profile library. Based on the business task dependency data, the service level agreement data, and the historical business throughput time series data, an ideal business processing benchmark is constructed under a state of no maintenance interference. Based on the occupancy and consumption characteristic data, the ideal service processing benchmark is characterized and injected to generate the theoretically interfered service state; The real-time business load status data, the ideal business processing benchmark, and the theoretically disturbed business status are aligned according to the unified evaluation cycle and unified business dimension determined by the business monitoring granularity of the big data intelligent platform to generate actual deviation data and theoretical deviation data. The actual deviation data and the theoretical deviation data are evaluated for their consistency to generate a multi-dimensional business impact similarity result. The theoretical deviation data is then superimposed on the real-time business load status data to generate a predicted business load status. When the predicted service load status does not exceed the corresponding service capacity boundary across all service dimensions, an execution permission instruction is output; otherwise, a deferred execution instruction is output. When the real-time business load status data exceeds the corresponding business capacity boundary in at least one business dimension or the actual deviation data exceeds the preset abnormal deviation threshold, a business capacity warning is triggered, and in response to the business capacity warning, a preset abnormal behavior feature library is called to generate abnormal intrusion theoretical deviation data. When the actual deviation data matches the abnormal intrusion theoretical deviation data, a forced termination command is output; Update the task handling priority for subsequent management cycles based on the business feedback data after actual execution.
[0006] Furthermore, the business task depends on the business flow sequence relationship output by the business statistics module; The ideal business processing benchmark determines the predicted time interval of each business task according to the logical order of the business flow sequence, and extracts the corresponding business capacity occupancy curve from the historical business throughput time series data and then splices or superimposes it according to the predicted time interval to generate the curve. The ideal business processing benchmark includes data occupied by business processing units, data occupied by temporary data storage space, data flow throughput, and information interaction throughput.
[0007] Furthermore, the security operation and maintenance task management profile database records the interactive blocking characteristics of risk scanning tasks, the storage access characteristics of verification tasks, the processing exclusive characteristics of completeness verification tasks, and the channel crowding characteristics of information detection tasks. The profile features include at least one of the following: business dimension identifier, interference intensity, duration, startup interval, repetition attribute, and peak usage. The feature injection calls the corresponding profile features from the security operation and maintenance task management profile library according to the security operation and maintenance task to be scheduled, and applies the interference of each business dimension to the time series position corresponding to the ideal business processing benchmark according to the expected processing time interval.
[0008] Furthermore, the actual deviation data is obtained by removing the ideal service processing benchmark from the real-time service load status data; The theoretical deviation data is obtained by removing the ideal service processing benchmark from the theoretical interfered service state; The unified evaluation cycle is determined by the business monitoring granularity of the big data intelligent platform; the unified business dimension includes business processing unit occupancy, data temporary storage space occupancy, data flow throughput, and information interaction throughput. The actual deviation data and the theoretical deviation data are standardized according to the historical average and fluctuation range of each business dimension, or normalized according to the corresponding business capacity boundary.
[0009] Furthermore, similar results of multi-dimensional business impacts are generated through temporal path matching assessment or spatial vector matching assessment; When using time-series path matching assessment, the degree of path deviation between the actual deviation data and the theoretical deviation data is converted and converted into a matching score; when using spatial vector matching assessment, a matching score is directly generated. When the matching score reaches or exceeds the preset matching acceptance threshold representing the maximum allowable total deviation, the actual deviation data is determined to match the theoretical deviation data; otherwise, it is determined not to match.
[0010] Furthermore, the business capacity boundary includes at least one of the following: the upper limit of business processing unit occupancy, the upper limit of data temporary storage space occupancy, the upper limit of data flow throughput, and the upper limit of information interaction throughput; When verifying the predicted service load status based on the service capacity boundaries in the service level agreement data, if the predicted service load status does not exceed the corresponding service capacity boundaries across all service dimensions, the execution permission instruction is output; if any service dimension exceeds the corresponding service capacity boundary, the execution delay instruction is output.
[0011] Furthermore, in response to the business capacity warning, after generating abnormal intrusion theoretical deviation data by calling the preset abnormal behavior feature library, the method further includes: matching the actual deviation data with the abnormal intrusion theoretical deviation data using the consistency evaluation; when the consistency score reaches or exceeds the preset abnormal matching acceptance threshold, determining that the match is successful and outputting the forced termination instruction; otherwise, maintaining the operation of the current business task and outputting the postponement instruction.
[0012] Furthermore, the abnormal behavior feature library includes features that are continuously computationally intensive, continuously channel-occupied, and periodically stored and traversed. The forced termination instruction is executed through the management and coordination module in the big data intelligent platform. It is used to suspend production business tasks other than scheduled security operation and maintenance tasks and security blocking and handling tasks, upgrade the handling level of the security blocking and handling tasks, and limit at least one target business capacity share among the processing clusters, logic units, execution links or business tasks that trigger business capacity warnings, data temporary storage space shares, data flow shares and information interaction shares.
[0013] Furthermore, updating the task handling priority within subsequent management cycles includes the following processing: recording business feedback data after actual execution based on the permitted execution instruction; The business impact prediction deviation is generated based on the difference between the business feedback data and the theoretically affected business status, and the corresponding profile features in the security operation and maintenance task management profile library are corrected based on the business impact prediction deviation. When the estimated deviation of the business impact does not exceed the preset deviation tolerance threshold, the processing priority of the corresponding task in the subsequent management cycle is increased; when the estimated deviation of the business impact exceeds the preset deviation tolerance threshold, the processing priority of the corresponding task in the subsequent management cycle is decreased.
[0014] The beneficial effects of this invention are: 1. This invention constructs an ideal business processing benchmark by collecting business task dependency data and historical time-series data, and combines the occupancy and consumption characteristics of the tasks to be scheduled to generate theoretical interference states through feature injection. This enables accurate characterization of complex business load changes, task flow order, and operation and maintenance interference characteristics, providing a reliable data foundation for subsequent scheduling and effectively improving the accuracy of scheduling decisions.
[0015] 2. This invention evaluates the consistency between actual deviation data and theoretical deviation data using multi-dimensional time series or spatial vectors, and calls the abnormal behavior feature library for anomaly matching when a capacity warning is triggered. This mechanism can scientifically distinguish between normal business fluctuations, known maintenance task disturbances, and potential abnormal intrusion behaviors, avoiding core business interruptions due to misjudgments and improving the platform's operational security.
[0016] 3. This invention superimposes theoretical deviations onto the real-time load generation prediction state and combines it with the multi-dimensional business capacity boundaries in the service level agreement for strict permission and deferral verification. When encountering abnormal matching, it performs forced termination by limiting the target business capacity share of specific logical units or processing clusters, thus achieving fine-grained quota control and balancing the timeliness of safe handling with the continuity of production business.
[0017] 4. During the closed-loop execution phase, this invention generates a predicted deviation based on the actual business feedback data after execution and the theoretical interference state. This not only enables dynamic self-correction of the profile characteristics of security operation and maintenance tasks, but also finely adjusts the handling priority of the task in subsequent management cycles based on the deviation tolerance, so that the scheduling strategy can adapt to the evolution of the platform environment and further improve the stability of long-term scheduling. Attached Figure Description
[0018] The invention will now be further described with reference to the accompanying drawings.
[0019] Figure 1 This is a flowchart illustrating the security operation and maintenance task scheduling method for a big data intelligent platform provided in an embodiment of this application. Detailed Implementation
[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0021] Please see Figure 1 A method for scheduling security operation and maintenance tasks for big data intelligent platforms includes the following steps: collecting business task dependency data, service level protocol data including business capacity boundaries, historical business throughput time series data and real-time business load status data through the business statistics module in the big data intelligent platform, and obtaining the occupancy and consumption characteristic data of the security operation and maintenance tasks to be scheduled from the preset security operation and maintenance task management profile library. Based on the business task dependency data, the service level agreement data, and the historical business throughput time series data, an ideal business processing benchmark is constructed under a state without operational interference; based on the occupancy and consumption characteristic data, the ideal business processing benchmark is characterized and injected to generate a theoretically interfered business state; The real-time business load status data, the ideal business processing benchmark, and the theoretically disturbed business status are aligned according to the unified evaluation cycle and unified business dimension determined by the business monitoring granularity of the big data intelligent platform to generate actual deviation data and theoretical deviation data. The actual deviation data and the theoretical deviation data are evaluated for their consistency to generate a multi-dimensional business impact similarity result. The theoretical deviation data is then superimposed on the real-time business load status data to generate a predicted business load status. When the predicted business load status does not exceed the corresponding business capacity boundary in all business dimensions, an execution permission instruction is output; otherwise, a postponement instruction is output. When the real-time business load status data exceeds the corresponding business capacity boundary in at least one business dimension or the actual deviation data exceeds the preset abnormal deviation threshold, a business capacity warning is triggered, and in response to the business capacity warning, a preset abnormal behavior feature library is called to generate abnormal intrusion theoretical deviation data. When the actual deviation data matches the abnormal intrusion theoretical deviation data, a forced termination command is output; the task handling priority in the subsequent management cycle is updated based on the business feedback data after actual execution.
[0022] This embodiment provides a security operation and maintenance task scheduling mechanism for big data intelligent platforms; specifically, the following description focuses on a scenario where a financial-grade clearing and settlement big data platform simultaneously undertakes payment clearing, refund verification, anti-fraud tracing, and regulatory reporting tasks during the month-end reconciliation window. The platform typically operates between 22:00 and 02:00 the next day, when the peak business hours overlap with the peak batch processing hours. It needs to perform both production operations and security maintenance tasks such as vulnerability scanning, log verification, and integrity checks, which makes it prone to resource access conflicts and misjudgments of anomalies. The platform's business statistics module first collects business task dependency data to characterize the order of clearing tasks, write-off tasks, and reporting tasks, as well as service level agreement data to provide the allowable upper limits for various resources. The business statistics module deploys lightweight collection probes in various business logic components and underlying resource pools, uses distributed tracing technology to extract dependencies in the business pipeline, and periodically pulls the real-time load status of computing, storage, and network of each node and the upper limit threshold of the service level protocol by connecting with the container orchestration system and platform monitoring bus. Simultaneously, historical business throughput time-series data is collected to describe the normal business intensity at each moment within multiple past settlement cycles, and real-time business load status data is collected to reflect the actual occupancy of each resource at the current moment. At the same time, the system retrieves the usage and consumption characteristics of the task to be scheduled from the security operation and maintenance task management profile library. For example, the log verification task continuously increases storage access and occupies processing units at a preset low limit within 20 minutes. The system first constructs an ideal business processing benchmark under no maintenance interference. The ideal business processing benchmark does not use a single historical average value, but combines the business dependency order and historical throughput curve to reconstruct the resource consumption characteristics presented by the platform under normal production business operation. For example, within a 10-minute evaluation window, by statistically analyzing four business dimensions by minute, the ideal business processing baseline sequence shows that the business processing unit occupancy, data temporary storage space occupancy, data flow throughput, and information interaction throughput exhibit temporal variations of [52,55,58,60], [48,50,53,55], [60,66,70,68], and [45,47,49,50], respectively. The system performs feature injection based on the occupancy and consumption characteristics of the security operation and maintenance task to be scheduled, and generates the theoretically interfered business state; Feature injection refers to using one or more combinations of linear superposition, nonlinear multiplicative coefficient adjustment, or time window extension calculation operations at the corresponding time series node of the ideal business processing benchmark, based on the interference dimension and interference intensity recorded in the profile database, to deduce the expected resource consumption sequence after being interfered with by the operation and maintenance task. Assuming the task to be scheduled is a log verification task, its profile features are that within 4 consecutive evaluation points, the data temporary storage space occupied by the storage access increases by [8,10,9,7], and the information exchange throughput increases by [3,4,4,3]. After injection, the theoretically interfered business state is obtained, where the data temporary storage space occupancy becomes [56,60,62,62], the information interaction throughput becomes [48,51,53,53], and the other dimensions can remain unchanged or be adjusted synchronously according to the preset low interference threshold parameters in the portrait library. Then, the real-time business load status, ideal business processing benchmark, and theoretically disrupted business status are aligned according to a unified evaluation cycle and a unified business dimension. The unified assessment period can be 1 minute, and the unified business dimensions can be unified as business processing unit occupancy, data temporary storage space occupancy, data flow throughput, and information interaction throughput; assuming that the real-time business load status collected in the same period is: business processing unit occupancy [53,57,59,61]; data temporary storage space occupancy [57,61,61,63]; data flow throughput [61,67,71,69]; information interaction throughput [49,50,54,54]; This yields the actual deviation data, which is the real-time business load status minus the ideal business processing baseline; the actual deviation in the data temporary storage space dimension is [9,11,8,8], and the actual deviation in the information interaction throughput dimension is [4,3,5,4]; the theoretical deviation data is obtained by subtracting the ideal business processing baseline from the theoretically disturbed business status, for example, the data temporary storage space dimension is [8,10,9,7], and the information interaction throughput dimension is [3,4,4,3]; Furthermore, the consistency between actual deviation data and theoretical deviation data is evaluated to generate multi-dimensional business impact similarity results. If an exemplary calculation method is used, the absolute value of the difference can be calculated dimension by dimension first, and then converted into a percentage consistency. For example, if the absolute value of the difference at four time points in the data temporary storage space dimension is [1,1,1,1], it can be converted into a consistency of more than 90%. The absolute value of the difference in the information exchange throughput dimension is [1,1,1,1], which can also reach the preset consistency threshold. After four-dimensional integration, if the similarity result reaches the preset threshold, for example, 0.86, and the threshold is set to 0.80, it is determined that the current real disturbance and the theoretical disturbance of this type of log verification task have a high degree of consistency. During the scheduling decision-making phase, the system superimposes the theoretical deviation data onto the current real-time business load status to form the predicted business load status. If the upper limit of data temporary storage space occupancy is 75 and the upper limit of information interaction throughput is 65, the superimposed predicted values are approximately [65,71,70,70] and [52,54,58,57], respectively, which do not reach their respective upper limits. At this time, the execution instruction is output. If the limit is exceeded after the superposition of a certain dimension, for example, the predicted data storage space reaches [74,77,79,78], then a delay execution instruction will be output, and the system will continue to wait for the next management cycle to recalculate; On the other hand, when the real-time business load status has triggered a business capacity warning, the system calls the abnormal behavior feature library to generate abnormal intrusion theoretical deviation data and matches it with the actual deviation data. If the actual deviation matches a certain abnormal intrusion pattern according to a preset matching standard, such as a continuous increase in the business processing unit occupancy of a continuous computationally intensive anomaly as [15,16,18,19], and the actual deviation also shows a similar path, then a forced termination command will be output to prioritize the platform's security handling. In terms of closed-loop execution, the platform updates the task handling priority in subsequent management cycles based on business feedback data after actual execution; for example, if the actual impact after a certain execution is lower than the theoretical estimate of the preset impact difference threshold, the scheduling priority of similar tasks can be appropriately increased in the future. Conversely, its priority is reduced to avoid excessive occupation of core settlement business again; if historical throughput data is missing at a certain moment, it can be supplemented by the same business segment of the most recent adjacent management cycle; if real-time load status data is missing, the evaluation point is marked as invalid and does not directly participate in the consistency accumulation. Instead, it is required to reach at least a preset number of valid points, such as at least 3 out of 4 points being valid, in order to form a scheduling result; if there are insufficient valid points, a delay execution instruction is output instead of direct release. At 23:10 at the end of the month, the platform is executing refund verification and regulatory reporting. The operations and maintenance center plans to insert a log verification task. The system will first reconstruct the non-interference business baseline, and then inject the log verification profile to form a theoretically interfered state. If the superimposed predicted business load does not exceed the capacity limit of the clearing and settlement platform, an execution permission instruction will be issued immediately. If a sudden change occurs in the real-time load at 23:18 that exceeds the capacity threshold, and the actual deviation is highly consistent with the preset continuous computationally intensive abnormal deviation, the platform will then output a forced stop command, suspend the normal production extension task, and upgrade the security blocking task to the highest handling level. The purpose of this step is to transform the scheduling judgment under multi-dimensional business interference data into a differential comparison between ideal benchmark, theoretical interference and actual disturbance, so as to achieve interpretable scheduling of security operation and maintenance tasks, while taking into account business continuity and security handling timeliness. Furthermore, to avoid the predicted business load status from repeatedly including disturbances that have already occurred, the method described in this embodiment of superimposing theoretical deviation data onto real-time business load status data is aimed at scenarios where the scheduled security operation and maintenance task has not yet been officially put into operation, or has entered the queue but has not yet actually occupied the target resources; at this time, the theoretical deviation data represents the incremental interference that will be introduced once the scheduled task is executed, and therefore can be directly superimposed onto the current real-time business load status. If there are already registered and running similar security operation and maintenance tasks within the same time window, the corresponding realized interference will be removed from the real-time business load status based on the execution record of the running task or its confirmed profile, or it will be marked as an existing source of disturbance in the task list. Then, the theoretical deviation of the task to be scheduled will be added to ensure that the prediction results only reflect the additional impact of the newly added task to be scheduled. Furthermore, the aforementioned assessment of the consistency between actual deviation data and theoretical deviation data is mainly used in this embodiment to identify whether the actual disturbance pattern in the current window is the same as the target task profile, and to provide an interpretable basis for the scheduling results, without requiring the task to be scheduled to be executed before it can participate in the judgment; When the actual deviation is very close to the profile of a certain type of task to be scheduled, it can be understood that the current platform already has a background disturbance or a similar excessive resource occupation pattern to that type of task. Based on this, the system judges the current tolerance status of the platform for this type of interference; and then, combined with the theoretical deviation increment of the task to be scheduled and the business capacity boundary, it makes a decision to allow or postpone it. This processing allows the consistency assessment and capacity boundary verification to respectively assume the responsibilities of identifying the current disturbance type and verifying whether the newly added execution exceeds the limit, thereby avoiding confusion in the scheduling logic.
[0023] In a preferred embodiment of the present invention, the business task dependency data is the business flow sequence relationship output by the business statistics module; the ideal business processing benchmark determines the predicted time interval of each business task according to the logical order of the business flow sequence relationship, and extracts the corresponding business capacity occupancy curve from the historical business throughput time series data and then splices or superimposes it according to the predicted time interval to generate the ideal business processing benchmark; the ideal business processing benchmark includes business processing unit occupancy data, data temporary storage space occupancy data, data flow throughput data, and information interaction throughput data.
[0024] This embodiment provides a business flow sequence modeling mechanism for constructing an ideal business processing benchmark; specifically, it still takes the aforementioned financial-grade clearing and settlement big data platform as the main line to further explain how to derive a more stable ideal business processing benchmark from the business flow sequence relationship; Relying solely on historical average resource values can lead to a drawback: transactions within the month-end reconciliation window do not occur simultaneously and evenly, but rather exhibit significant dependencies between them; for example, refund verification can only be partially initiated before payment clearing is completed; and regulatory reporting often has to wait for the first two summary outputs to be completed before it can enter centralized processing. If this business flow sequence is ignored and an ideal benchmark is constructed based solely on a simple average value, it is easy for business sequences with different time-series characteristics to overlap abnormally, which in turn produces a benchmark data deviation and distorts subsequent differential judgments. Therefore, in this embodiment, the business flow sequence relationship output by the business statistics module is used as the main framework for generating an ideal benchmark; the platform abstracts the main business of the evening into three task segments, defining payment clearing, refund verification, and regulatory reporting as task segments A, B, and C respectively, and their logical flow relationship is A→B→C; If historical data shows that A typically lasts 10 minutes, B lasts 6 minutes, and C lasts 4 minutes, then the predicted time interval for each task segment can be determined first; for example, 22:00 to 22:10 corresponds to A, 22:08 to 22:14 corresponds to B, and 22:13 to 22:17 corresponds to C; here, B and A are allowed to partially overlap, and C and B are allowed to partially overlap, in order to reflect the characteristics of the pipeline-like progress in the real business chain; Extract the corresponding capacity occupancy curves from historical business throughput time-series data and stitch or overlay them; in the example, the historical curve of task A in the business processing unit occupancy dimension can be simplified to [40,45,48,50], task B to [15,18,20], and task C to [10,12]; if there is time overlap at some evaluation points, the overlapping parts are overlaid. If there is no overlap, they are directly spliced together; for example, if A and B overlap at the 3rd evaluation point, the ideal occupancy value of the business processing unit can be obtained as 48+15=63; if B and C overlap at the 5th evaluation point, the value can be obtained as 20+10=30; other dimensions such as data temporary storage space occupancy, data flow throughput and information interaction throughput are also processed in the same way, thus forming an ideal business processing benchmark with four-dimensional linkage. To facilitate reproduction, the following simplified sandbox can be used; set the unified evaluation period to 5 minutes, and extract the corresponding historical curves within 4 consecutive periods, where the processing unit occupation and temporary storage space occupation sequences of task A are [42,50,46,30] and [20,25,24,18], respectively; The processing unit occupancy and temporary storage space occupancy sequences for Task B are [0,10,18,20] and [0,8,14,16], respectively; the processing unit occupancy and temporary storage space occupancy sequences for Task C are [0,0,5,12] and [0,0,4,9], respectively. Therefore, the processing unit occupancy in the ideal business processing benchmark can be [42,60,69,62], and the temporary storage space occupancy can be [20,33,42,43]. This benchmark is more consistent with the actual business chain than a simple average. As a fault-tolerance mechanism, if there are circular dependency records in the business flow sequence, such as the statistics module incorrectly outputting A→B→C→A, the system can first perform a cycle detection, temporarily disconnect a weak dependency edge in the cycle, or use the dependency version that was most recently manually approved to replace it; If the historical business throughput time series data has insufficient samples for a certain task segment, such as regulatory reporting only occurring on holidays, then the median curve of a small sample of the same type of business can be used as a substitute to avoid distortion of the ideal benchmark due to extreme single samples. After 22:00 at the end of the month, the payment clearing begins to perform calculations that reach the preset concurrency threshold. At 22:08, the refund verification begins to access the cleared transaction records. At 22:13, the regulatory reporting module generates a summary file. Based on this, the system reconstructs an ideal business processing benchmark with sequential and partial overlap characteristics, rather than simply superimposing the three over the entire time range. The purpose of this step is to restore the intrinsic rhythm of production operations by utilizing the order of business processes, thereby achieving a precise reconstruction of the ideal business processing benchmark and providing a more reliable data foundation for subsequent deviation extraction and scheduling judgment.
[0025] In a preferred embodiment of the present invention, the security operation and maintenance task management profile database records the interactive blocking characteristics of risk scanning tasks, the storage access characteristics of verification tasks, the processing exclusive characteristics of completeness verification tasks, and the channel crowding characteristics of information detection tasks; the profile characteristics include at least one of service dimension identifier, interference intensity, duration, start interval, repetition attribute, and peak occupancy. The feature injection calls the corresponding profile features from the security operation and maintenance task management profile library according to the security operation and maintenance task to be scheduled, and applies the interference of each business dimension to the time series position corresponding to the ideal business processing benchmark according to the expected processing time interval.
[0026] This embodiment provides a security operation and maintenance task profile modeling and feature injection mechanism; specifically, using the aforementioned clearing and settlement platform scenario, based on the ideal baseline that can be constructed according to the business flow sequence, it further solves the problem of different interference forms caused by different types of security operation and maintenance tasks to the platform; If only a single resource increment is configured for each type of security operation and maintenance task, such as adding an extra 10% load when performing log verification, the following technical defects will exist: different tasks have different impacts on the platform. Some are storage access intensive, some are computing resource intensive, and some are network bandwidth limited. If the dimensions of interference are not distinguished, it will be difficult to correctly differentiate between normal business fluctuations, operational disturbances and abnormal intrusions in subsequent consistency assessments. Therefore, in this embodiment, a differentiated profile is established for different task types in the security operation and maintenance task management profile library. Taking the clearing and settlement platform as an example, risk scanning tasks can be recorded as interactive blockage features, which mainly affect the information interaction throughput and introduce peak-type blockages at some assessment points. Verification tasks can be recorded as storage access characteristics, which mainly affect the data temporary storage space occupation and related I / O access rhythm; integrity verification tasks can be recorded as processing exclusive characteristics, which mainly affect the occupation of service processing units; information detection tasks can be recorded as channel crowding characteristics, which mainly affect data flow throughput and information interaction throughput. Each profile may include at least one of the following: business dimension identifier, interference intensity, duration, startup interval, repetitive attributes, and peak usage. For ease of explanation, the profile parameters of the log verification task are configured as follows: its impact dimensions are data temporary storage space occupation and information interaction throughput, with corresponding interference intensities of 0.15 and 0.08, respectively. The duration of the task is set to 4 evaluation points, the start interval is 1 evaluation point, and it has the attribute of single execution repetition, with peak usage reaching 12 and 6, respectively. If the data temporary storage space occupancy value at four evaluation points in the current ideal business processing benchmark is [50, 54, 56, 52], then after feature injection, it can be formed as [58, 62, 64, 59]; if the original information interaction throughput is [40, 42, 43, 41], then it can be formed as [43, 45, 47, 44]. Furthermore, assuming the task to be scheduled is a completeness check, its profile indicates that an initial rising and then stabilizing disturbance sequence [6,8,8,7] is applied in the processing unit dimension, while only slight perturbations [1,1,0,0] are generated in other dimensions; If the processing unit occupancy in the current ideal benchmark is [55,58,60,57], then the processing unit occupancy in the theoretically interfered service state can be directly formed as [61,66,68,64]. If the task to be scheduled has repetitive attributes, such as initiating channel probing again every two evaluation points, then the interference sequence can be written into the corresponding time axis position in an interval-repetition mode during injection, instead of writing it only once. As a fault-tolerance mechanism, if the task to be scheduled cannot find a completely consistent task type in the profile library, it can be replaced by the closest known task profile. For example, the profile with the same impact dimension and the closest duration can be selected first. If a profile parameter is missing, such as missing peak usage, it can be filled in with the median value of the historical execution of the same type of task. If the expected processing time spans multiple business peak periods, the same profile can be split into multiple injection segments to avoid generating an unrealistic continuous high-occupancy platform in the theoretical state. When the record verification task is scheduled to be executed at 23:10 at the end of the month, the system retrieves the storage access characteristics of this type of task from the profile database and concludes that it will continue to increase the data temporary storage space usage and slightly increase the information exchange throughput in the next 4 evaluation points. The system applies this disturbance to the time series position corresponding to the ideal business processing benchmark according to the expected processing time interval, thereby obtaining the theoretical disturbed business state that can be compared later. The purpose of this mechanism is to solidify security operation and maintenance experience into a computable structured profile, so that the disturbances of different operation and maintenance tasks can be accurately injected according to dimension, intensity and time series position, thereby achieving more interpretable theoretical disturbance modeling. Furthermore, to maintain consistency in terminology between the preceding and following scenarios, in this embodiment, the aforementioned record verification task can be expanded and described using the log verification task as a specific business instance. In this embodiment, both refer to the same type of task profile, which is mainly based on storage access and related data verification, and both are subject to the injection logic of the storage access feature. When the above text uses log verification tasks as examples to illustrate interference sequences, duration, or peak usage, it is essentially an instantiation of the verification tasks recorded in the embodiments, rather than adding another different task type. Through this kind of corresponding explanation, the task category names in the profile library and the scenario example names can be kept semantically consistent, avoiding the misunderstanding of similar tasks as two different profile sources. Furthermore, in order to maintain a consistent correspondence between the task category name and the scenario example name in the entire text in this embodiment, in this embodiment, the aforementioned risk scanning task can be expanded and described by the vulnerability scanning task as a specific business instance. Both of them point to the same type of task profile for the purpose of identifying risks in business links, interface interactions or resource access, and both are applicable to the calling and injection logic of the interaction blocking feature. The aforementioned completeness verification task can be further explained by the integrity verification task as a specific business example. Both of them point to the same type of task profile that aims at verifying the completeness and consistency of data, files, configurations or results, and both are applicable to the call and injection logic of the exclusive processing feature. When other implementations use vulnerability scanning tasks or integrity verification tasks to describe business scenarios, it is an instantiation of the corresponding task category in this embodiment, rather than introducing a new profile category. This kind of correspondence description can keep the semantic boundaries of risk scanning / vulnerability scanning completeness verification / integrity verification record verification / log verification consistent throughout the text, avoiding ambiguity in understanding caused by name switching, such as multiple meanings of one word or multiple words with the same meaning.
[0027] In a preferred embodiment of the present invention, the actual deviation data is obtained by removing the ideal business processing benchmark from the real-time business load status data; the theoretical deviation data is obtained by removing the ideal business processing benchmark from the theoretically disturbed business status; the unified evaluation cycle is determined by the business monitoring granularity of the big data intelligent platform; the unified business dimension includes business processing unit occupancy, data temporary storage space occupancy, data flow throughput, and information interaction throughput; the actual deviation data and the theoretical deviation data are standardized according to the historical average and fluctuation range of each business dimension, or normalized according to the corresponding business capacity boundary.
[0028] This embodiment provides a dual-track deviation extraction and scale unification mechanism; specifically, after obtaining the ideal business processing benchmark and the theoretically interfered business state, it further explains how to obtain directly comparable real deviation data and theoretical deviation data. In actual platforms, the dimensions and numerical ranges of the four business dimensions are usually different; the business processing unit occupancy may be expressed as a percentage, the data flow throughput may be expressed as the number of records per second, and the information interaction throughput may be expressed as the number of messages; if the original differences are directly compared, a defect will occur: dimensions with large numerical ranges will have too high weight in similarity calculation, while dimensions with small numerical ranges but significant business significance will be ignored due to their small weight. Therefore, in this embodiment, the three types of data are first aligned with a unified evaluation period, and then the differences are calculated separately. Assuming the monitoring granularity is 1 minute, all sequences fall on the same time axis with an evaluation point every 1 minute. The actual deviation data is obtained by subtracting the ideal business processing benchmark from the real-time business load status. The theoretical deviation data is obtained by subtracting the ideal business processing benchmark from the theoretically disturbed business status. Within a 4-minute window, the business processing unit occupancy in the ideal business processing baseline is [50,52,54,56], the real-time business load status is [54,55,58,60], and the theoretically interfered business status is [55,56,57,60]. Therefore, the actual deviation in the processing unit dimension is [4,3,4,4], and the theoretical deviation is [5,4,3,4]. In the data temporary storage space dimension, if the ideal baseline is [40,41,42,43], the real-time state is [50,49,52,51], and the theoretically disturbed state is [48,50,51,50], then the actual deviation is [10,8,10,8], and the theoretical deviation is [8,9,9,7]. Since the difference values in each dimension are inconsistent, the system needs to undergo further standardization or normalization processing. If standardization is adopted, it can be based on the historical average and fluctuation range of each business dimension; assuming that the historical average deviation of the data temporary storage space is 6 and the common fluctuation range is ±4, then the current actual deviation [10,8,10,8] can be converted to [(10-6) / 4,(8-6) / 4,(10-6) / 4,(8-6) / 4], that is, [1.0,0.5,1.0,0.5]; The theoretical deviation [8,9,9,7] can be converted to [0.5,0.75,0.75,0.25]; if normalization is used, it can be directly divided by the corresponding business capacity boundary; for example, if the data temporary storage space boundary is 80, then the actual deviation is normalized to [0.125,0.100,0.125,0.100], and the theoretical deviation is normalized to [0.100,0.113,0.113,0.088]; As a fault-tolerance mechanism, if the historical fluctuation range of a certain dimension is 0, that is, the dimension has been almost unchanged in history, the standardization process is prone to division by zero. At this time, it can be automatically switched to normalization processing according to capacity boundary. If the capacity boundary is also missing, the dimension is marked as a low confidence dimension and its weight is reduced or temporarily excluded from the subsequent similarity evaluation. If there are multiple data sampling times that are not uniform under a unified evaluation period, nearest neighbor alignment or linear interpolation can be used, but a maximum allowable offset should be set, for example, not exceeding half an evaluation period; if it exceeds this, the point is invalid. At 23:12 at the end of the month, the increase in the temporary storage space of the data collected in real time by the platform exceeded the ideal business processing benchmark and the difference was greater than the preset threshold, but the deviation of the business processing unit was less than the preset threshold. The system first calculates the actual deviation and the theoretical deviation separately, and then processes them according to a unified scale. After processing, the four-dimensional data with huge differences in dimensions are compressed into a comparable range, which can more stably enter the subsequent consistency evaluation stage. The purpose of this mechanism is to extract interpretable bias components from the actual business situation and eliminate the dimensional differences between different business dimensions through standardization or normalization, thereby achieving a more robust multidimensional impact matching. Furthermore, to maintain consistency between the terminology used in the embodiments and the examples, in this embodiment, both "eliminating the ideal business processing benchmark" and "subtracting the ideal business processing benchmark" refer to point-by-point subtraction processing after alignment under the same evaluation period and the same business dimension, and do not represent different algorithm steps. Actual deviation data always represents the sequence of differences between the real-time business load status and the ideal business processing benchmark, while theoretical deviation data always represents the sequence of differences between the theoretically disturbed business status and the ideal business processing benchmark. If expressions such as subtraction or elimination appear in the following text, they should be understood according to this unified meaning. This corresponding explanation can avoid different understandings of the deviation generation method caused by the switching of verbs, and ensure that the calculation methods before and after are consistent.
[0029] In a preferred embodiment of the present invention, the multidimensional business impact similarity results are generated through time-series path matching assessment or spatial vector matching assessment; when time-series path matching assessment is used, the degree of path deviation between the actual deviation data and the theoretical deviation data is converted and converted into a matching score. The general logic for converting to a consistency score is as follows: calculate the sum of the absolute differences between the actual deviation data and the theoretical deviation data in each business dimension within the evaluation window, divide the sum of the absolute differences by the preset maximum acceptable total deviation to obtain the deviation rate, subtract the deviation rate from the value 1 to obtain the consistency score of a single dimension, and perform a weighted summation of the single-dimensional consistency scores of all business dimensions to obtain the comprehensive consistency score. When spatial vector matching is used for evaluation, a matching score is directly generated. When the matching score reaches or exceeds the preset matching acceptance threshold that represents the maximum allowable deviation, the actual deviation data is determined to match the theoretical deviation data; otherwise, it is determined to be inconsistent.
[0030] This embodiment provides an evaluation mechanism for the similarity of multi-dimensional business impacts; specifically, after the aforementioned deviation data has been standardized, it further explains how to convert the actual deviation and theoretical deviation into a feasible consistency score. If we only compare whether the absolute values at each time point are close, there are the following technical drawbacks: some interferences may have deviations in peak value, but their temporal change trajectories are consistent; some interferences may have similar total amounts, but the temporal characteristics of the peaks and troughs do not match. The former is more likely to represent the same type of operation and maintenance task or the same type of anomaly, while the latter should not be simply regarded as the same; therefore, this embodiment sets up two types of matching evaluation methods, one oriented towards time pattern and the other towards overall spatial distribution. When using time-series path matching assessment, the degree of deviation can be calculated for each business dimension's deviation path, and then the degree of deviation can be converted into a matching score. For a simplified calculation example, the actual deviation in the data temporary storage space dimension is [0.10, 0.14, 0.15, 0.12], and the theoretical deviation is [0.09, 0.13, 0.16, 0.11]; the sum of the absolute differences point by point is 0.04. If the maximum acceptable total deviation is preset to 0.20, then the consistency can be converted to 1-0.04 / 0.20=0.80; the other dimensions are calculated in the same way, and the total score can be obtained by weighted average; if the weights of the four dimensions are the same, the overall consistency is 0.83, and the threshold is set to 0.78, then it is judged as a match; When using spatial vector matching evaluation, the multidimensional deviations within the same window can be expanded into a single vector and compared directly. For example, by combining four points from each of the four dimensions into a 16-dimensional vector, the smaller the angle between the actual deviation vector and the theoretical deviation vector, the more consistent their directions are. To facilitate engineering implementation, the normalized inner product can also be used as an approximate score. Assuming the calculated result is 0.87, and the acceptance threshold is set to 0.80, then a match is still deemed appropriate. Furthermore, a dual threshold mechanism can be set; if the consistency reaches or exceeds 0.85, it is directly judged as a strong match; if it is between 0.75 (inclusive) and 0.85 (exclusive), it will proceed to manual review or be re-verified in conjunction with the capacity boundary; if it is below 0.75, it will be directly judged as a mismatch; this can avoid frequent jitter near the boundary value causing repeated instruction switching. As a fault-tolerance mechanism, if the absence of some evaluation points leads to an incomplete timing path, only the valid continuous segments can be evaluated, but the length of the continuous segments must not be less than the minimum window length, for example, not less than 3 evaluation points. If a zero bias occurs in the vector evaluation, that is, both the actual bias and the theoretical bias are close to zero, it means that there is basically no interference within the window. In this case, the fit can be set to a low priority matching state directly, rather than mechanically giving full marks, to prevent the absence of events from being mistaken for a high fit. At 23:14 at the end of the month, the platform prepares to determine whether the current real-time disturbance is consistent with the recorded verification task profile. The system first uses the time-series path method to find that both the data temporary storage space and the information interaction throughput paths show a synchronous slight increase, with a comprehensive consistency of 0.84. Since the preset threshold has been reached, the system determines that the current actual deviation is consistent with the theoretical deviation of this type of task, which can be used as a basis for scheduling interpretation or anomaly identification. The purpose of this mechanism is to transform multidimensional disturbance characteristics into a unified score, thereby enabling a quantifiable judgment of the source of real-world disturbances and avoiding misjudgments of complex business fluctuations by a single threshold method.
[0031] In a preferred embodiment of the present invention, the service capacity boundary includes at least one of the following: upper limit of service processing unit occupancy, upper limit of data temporary storage space occupancy, upper limit of data flow throughput, and upper limit of information interaction throughput. When verifying the predicted service load status based on the service capacity boundary in the service level agreement data, if the predicted service load status does not exceed the corresponding service capacity boundary in all service dimensions, the permitted execution instruction is output; if any service dimension exceeds the corresponding service capacity boundary, the deferred execution instruction is output.
[0032] This embodiment provides a scheduling release mechanism based on service capacity boundaries; specifically, after obtaining the predicted service load status, it is necessary to provide a scheduling result that can be directly executed, so as to implement the aforementioned benchmark reconstruction, feature injection and deviation matching into actual production control. If the decision to execute an operation and maintenance task is based solely on the degree of conformity, there will be shortcomings: even if the theoretical interference pattern of a certain type of task has been accurately identified, it may still cause a certain business dimension to exceed the service level agreement limit after being superimposed in the current window, which may lead to clearing delays, reporting blockages or message congestion; therefore, scheduling and release should also be combined with the business capacity boundary for final verification. In this embodiment, the service capacity boundary includes at least one of the following: the upper limit of service processing unit occupancy, the upper limit of data temporary storage space occupancy, the upper limit of data flow throughput, and the upper limit of information interaction throughput; after the system superimposes the theoretical deviation data onto the current real-time service load status, it obtains the predicted service load status and compares it with the capacity boundary dimension by dimension. For example, at four evaluation points, the current real-time business load status has a business processing unit occupancy of [60, 62, 61, 59], and the theoretical deviation of the task to be scheduled is [5, 4, 6, 5]. Then the predicted business processing unit occupancy is [65, 66, 67, 64]. If the upper limit of this dimension is 70, then this dimension can be passed. If the real-time value of the data temporary storage space is [68,69,70,72] and the theoretical deviation is [4,5,4,3], then the predicted value is [72,74,74,75]. If its upper limit is 75, then the first 3 points have not exceeded the limit, and the 4th point reaches the boundary but has not exceeded it, so it can still be considered as passing. If the predicted value of information interaction throughput is [61,64,66,67], and the upper limit of this dimension is 65, then since at least two evaluation points have exceeded the limit, a delay execution instruction should be output. In engineering implementation, a strict rule can be adopted that allows passage only if all dimensions and all points do not exceed the limits, or a flexible rule can be set that allows short-term edge contact but does not allow continuous over-limit. To illustrate the latter approach, suppose a certain dimension has a boundary of 80 and the predicted value is [78, 81, 79, 78]. If only one evaluation point exceeds the limit and the exceedance is less than 2, this situation can be handled by a buffer strategy, such as delaying the task start by one evaluation point or reducing the task concurrency, rather than immediately rejecting it completely. However, in stringent scenarios such as financial clearing and settlement, it is usually more prudent to adopt strict rules. As a fault-tolerance mechanism, if the service level agreement data lacks a capacity boundary for a certain business dimension, the 95th percentile of the windows of similar businesses in the past three months can be used as a temporary upper limit. If all boundaries are missing, the execution will be temporarily suspended based on the principle of conservatism. If the predicted business load status is close to the boundary in multiple dimensions, such as less than 5% away from the boundary, the maintenance task can be placed in a low priority queue even if it has not exceeded the limit, and wait for a better window. At 23:15 at the end of the month, the log verification task has completed theoretical injection and similarity assessment. After the system superimposes its theoretical deviation onto the real-time business load, it finds that the processing unit, temporary storage space and data flow throughput have not exceeded the service level agreement limit, but the information interaction throughput may exceed the limit at the next two assessment points. The system therefore outputs a delay execution instruction and postpones the task until the refund verification decreases before recalculating. The purpose of this mechanism is to ensure that the execution is based on clear business capacity boundary verification, thereby achieving controllable release for production scenarios and avoiding scheduling overreach caused by relying solely on similarity matching.
[0033] In a preferred embodiment of the present invention, in response to the service capacity warning, after generating abnormal intrusion theoretical deviation data by calling a preset abnormal behavior feature library, the method further includes: matching the actual deviation data with the abnormal intrusion theoretical deviation data using the consistency evaluation; when the consistency score reaches or exceeds a preset abnormal matching acceptance threshold, determining that the match is successful and outputting the forced termination instruction; otherwise, maintaining the operation of the current service task and outputting the postponement instruction.
[0034] This embodiment provides an abnormal intrusion identification mechanism triggered by a service capacity warning. Specifically, in addition to normal scheduling and release, it is also necessary to handle another more severe scenario, namely, the platform has experienced capacity overrun or abnormal deviation. The system needs to determine whether this is a normal business peak, a side effect of operation and maintenance tasks, or a potential abnormal intrusion behavior. If an anomaly is immediately identified and the task is terminated based solely on exceeding the limit in a single dimension, there will be obvious flaws. After special promotional activities, the month-end settlement platform may experience a transient increase in computing resources and data throughput due to refund verification and risk recalculation. This transient increase does not necessarily constitute an abnormal intrusion. Without further pattern recognition, it may lead to false alarms during peak business periods, causing abnormal interruptions to production tasks. Therefore, this embodiment specifies two types of triggering conditions; the first type is that the real-time business load status exceeds the corresponding business capacity boundary in at least one business dimension; the second type is that the actual deviation data exceeds the preset abnormal deviation threshold; the former is biased towards capacity exceeding the boundary, while the latter is biased towards abnormal deviation pattern even if it does not exceed the boundary; for example, after standardizing the actual deviation, if three consecutive evaluation points of a certain dimension are higher than 1.5, a business capacity warning can be triggered. In response to the business capacity warning, the system calls the abnormal behavior feature library to generate abnormal intrusion theoretical deviation data; and uses the same consistency evaluation method as mentioned above to match the actual deviation data with the abnormal intrusion theoretical deviation data one by one. In the abnormal behavior feature library, there is a pattern that shows a consistently high level of [0.18, 0.20, 0.22, 0.21] in the processing unit dimension and a slight synchronous increase of [0.05, 0.06, 0.05, 0.04] in the information interaction throughput dimension. If the actual deviation is normalized to obtain a similar path and the overall matching degree reaches 0.88, and the abnormal matching acceptance threshold is set to 0.82, then the matching is determined to be successful and a forced termination command is output. If the highest degree of agreement between the actual deviation and the theoretical deviation of the abnormal intrusion is only 0.61, which does not reach the threshold, it means that the current out-of-bounds is more likely to come from business fluctuations or unidentified disturbances. The system does not directly shut down the platform, but maintains the operation of the current business task and outputs a pause execution instruction to prevent the core settlement link from being interrupted due to false alarms. As a fault-tolerance mechanism, if the pattern is similar to multiple abnormal patterns at the same time, such as a 0.80% match with the continuous computation-intensive pattern and a 0.79% match with the periodic storage traversal pattern, while the threshold is 0.82, it can be determined as a suspected abnormality that has not been confirmed. In this case, production operations are maintained but new high-energy-consuming operation and maintenance tasks are restricted from entering. If the actual deviation continues to increase over multiple periods but never reaches the abnormal threshold, an incremental early warning mechanism can be activated. For example, the first period only records the data, the second period restricts scheduling, and the third period requires manual confirmation. At 23:18 at the end of the month, the platform's data throughput and business processing unit usage suddenly exceeded the limits simultaneously; the system first triggered a business capacity warning, and then compared the actual deviation with various abnormal intrusion patterns in the abnormal behavior feature database. The results showed that the current deviation trajectory was highly matched with a continuous computationally intensive anomaly pattern, with a match rate of 0.89, which exceeded the anomaly matching acceptance threshold. Therefore, the system no longer simply delayed scheduling, but switched to the forced termination process. The purpose of this mechanism is to upgrade the decision-making process after capacity warning from a simple out-of-bounds judgment to anomaly mode verification, thereby achieving more accurate identification of real security events and reducing false alarms to normal business peaks.
[0035] In a preferred embodiment of the present invention, the abnormal behavior feature library includes continuously computationally intensive features, continuously channel-occupying features, and periodically stored traversal features; The forced termination instruction is executed through the management and coordination module in the big data intelligent platform. It is used to suspend production business tasks other than scheduled security operation and maintenance tasks and security blocking and handling tasks, upgrade the handling level of the security blocking and handling tasks, and limit at least one target business capacity share among the processing clusters, logic units, execution links or business tasks that trigger business capacity warnings, data temporary storage space shares, data flow shares and information interaction shares.
[0036] This embodiment provides a mechanism for refining the abnormal behavior feature database and forcibly suspending execution. Specifically, after the aforementioned warning has confirmed the abnormal match, it is also necessary to clarify the abnormal type and the suspension action to avoid issuing an alarm without taking action, or having the action control granularity too large, which would affect the platform recovery. If forced shutdown is only manifested as unified shutdown control, the following technical defects exist: In the financial-grade clearing and settlement platform, some core security handling tasks and blocking tasks must continue to be executed, otherwise the abnormal propagation path cannot be cut off in time; at the same time, different abnormal modes have different characteristics of resource consumption. If relevant resources are restricted indiscriminately, it may cause unnecessary business impact, and it may also fail to restrict the affected resource domains in a targeted manner. Therefore, this embodiment refines the abnormal behavior feature library into at least three categories; the continuous computation-intensive feature is mainly characterized by the continuous high occupancy of the service processing unit with small fluctuations and continuity; the continuous channel occupancy feature is mainly characterized by long-term congestion of information exchange throughput and data flow throughput; Periodic storage traversal features are characterized by peak fluctuations in data temporary storage space access at fixed periods. To facilitate engineering implementation, each type of feature can save a standard deviation path and its tolerance range. For example, periodic storage traversal features can exhibit alternating fluctuations of [0.12, 0.03, 0.13, 0.04] at 4 evaluation points. The management and coordination module is responsible for controlling the forced termination of tasks; however, this module does not simply stop all tasks but rather implements tiered handling. The first step is to temporarily suspend all production operations tasks except for security maintenance and security disruption tasks, especially newly submitted batch processing tasks. The second step is to upgrade the handling level of the security blocking task, for example, from ordinary priority to the highest priority; the third step is to restrict the resource share corresponding to the processing cluster, logical unit, execution link or business task that triggers the warning. If the system identifies a persistent channel occupancy anomaly at 23:18, and the problem is concentrated between the reporting cluster and the external interface logic unit, the management and coordination module can reduce the information interaction share of the cluster from 100 to 40 and the data flow share from 100 to 50, while retaining the minimum resource share required for the security blocking and handling task. If an anomaly is identified as a continuous computationally intensive one, and the hotspot is concentrated in a certain anti-fraud backtracking execution stage, its business processing unit share can be restricted first, for example, reduced from 80 to 20, without having to excessively compress the storage space share at the same time. For ease of explanation, a simplified calculation example can be constructed; assume that the total resource share of a certain processing cluster is 100: under normal conditions, the processing unit share, temporary storage space share, data flow share, and information interaction share are all initially allocated to 100; After identifying a periodic storage traversal anomaly, the system reduces the temporary storage space share to 35, the data flow share to 60, and reserves the processing unit share to 70, so that the security blocking and handling task can continue to search for and cut off the anomaly source; this fine-grained limit is more conducive to the platform completing emergency handling under controlled conditions than a simple shutdown. As a fault-tolerance mechanism, if the source of the anomaly cannot be precisely located to the specific processing cluster or logical unit, restrictive measures can be taken at the business task level, such as suspending newly added reporting tasks and retaining the clearing results on disk. If even the business task level cannot be identified, the strategy can be reduced to a platform-wide rate limiting strategy, but the minimum resource guarantee for security blocking and handling tasks must still be maintained; if the capacity warning is not lifted after the forced termination, the resource share can be further tightened according to the preset escalation steps until manual takeover. After confirming the anomaly at 23:18 at the end of the month, the management and coordination module found that the anomaly characteristics were more consistent with the continuous channel occupancy type; the system then temporarily suspended the ordinary regulatory reporting and non-emergency refund recalculation tasks, only retaining the security blocking handling process and the necessary core clearing and closing tasks, and reduced the information exchange share of the logical unit where the external interface is located. This avoids both the continued occupation of communication channels by anomalies and the indiscriminate interruption of all platform capabilities. The purpose of this mechanism is to directly map the anomaly identification results into executable, tiered, and domain-limited resource management actions, thereby achieving more precise forced termination and more reliable emergency protection. Furthermore, to maintain consistency with the scope of forced termination, in this embodiment, the aforementioned necessary core clearing and closing tasks refer to the minimum necessary actions that have been pre-registered by the management and coordination module as security operation and maintenance tasks or security blocking tasks in the linkage and preservation process, such as state solidification, result sealing, auditing and recording, or security disking steps performed to prevent the spread of abnormalities, rather than the usual sense of continuing to allow ordinary production business tasks. After a forced termination command is issued, ordinary production business tasks are generally suspended. Only the necessary preservation and closure actions that are included in the security operation and maintenance handling link or the security blocking handling link can retain a minimum execution share. This limitation ensures that the scenario expression in the embodiment is consistent with the control boundary of suspending production business tasks other than security operation and maintenance handling tasks and security blocking handling tasks in the embodiment, thus avoiding ambiguity in the scope of forced termination.
[0037] In a preferred embodiment of the present invention, updating the task handling priority in subsequent management cycles includes the following processing: recording business feedback data after actual execution according to the permitted execution instruction; generating a business impact prediction deviation based on the difference between the business feedback data and the theoretically interfered business state; and correcting the corresponding profile features in the security operation and maintenance task management profile library based on the business impact prediction deviation. When the estimated deviation of the business impact does not exceed the preset deviation tolerance threshold, the processing priority of the corresponding task in the subsequent management cycle is increased; when the estimated deviation of the business impact exceeds the preset deviation tolerance threshold, the processing priority of the corresponding task in the subsequent management cycle is decreased.
[0038] This embodiment provides a task profile self-correction and subsequent handling priority update mechanism; specifically, after the aforementioned scheduling execution and anomaly handling form a closed loop, the system also needs to continuously correct the profile library based on the actual execution effect, otherwise the actual impact changes of the same type of operation and maintenance task in different versions, different clusters or different months will not be absorbed in time. If the profile database remains unchanged for a long time, a flaw will be exposed: the platform architecture, storage medium, task concurrency and business model are all changing, and the task profiles established in the early stage may gradually deviate from the actual situation; in this case, even if the aforementioned comparison process is complete, the theoretically disturbed business state may become more and more inaccurate, ultimately affecting the reliability of scheduling. Therefore, in this embodiment, after each execution permission instruction is output and the task is completed, the actual business feedback data after execution is recorded and compared with the theoretically affected business state generated before execution to generate the business impact prediction deviation. For ease of explanation, suppose a log verification task theoretically expects to increase the data temporary storage space usage by [8,10,9,7], but the actual feedback shows an increase of [6,8,8,6]. Then the deviation in the estimated impact of this business can be recorded as [-2,-2,-1,-1]. If calculated using the mean absolute deviation, the result is 1.5. Assuming a deviation tolerance threshold of 2, it indicates that the prediction is relatively accurate. When the deviation does not exceed the preset threshold, the system can increase the priority of the corresponding task in the subsequent management cycle. This increase can be manifested as: prioritizing its participation in the scheduling in an earlier time window next time, or moving it forward among multiple candidate security operation and maintenance tasks; for example, if the original priority is level 3, it can be increased to level 2. This does not mean that it is forced to be executed immediately, but that it is easier to obtain the opportunity to be allowed to execute in the future window. Conversely, if a completeness check task is theoretically expected to increase processing unit usage by only [5,6,5,4], but actually increases to [11,12,10,9], the average absolute deviation can reach more than 5, significantly exceeding the tolerance threshold. In this case, the system will lower the priority of subsequent processing on the one hand, and correct the corresponding profile features on the other hand, such as increasing the interference intensity in the processing exclusive feature, lengthening the duration, and updating the peak usage. After correction, the next time theoretical injection is performed, a more realistic theoretical interference business state can be obtained. To prevent significant data shifts caused by a single accidental fluctuation, a smooth update can be used. The interference intensity in the original profile was 0.15, and it was corrected to 0.22 based on feedback. The system can then update it to 0.171 in a 7:3 ratio, which preserves the stability of the old value while absorbing the information of the new value. If three consecutive feedbacks point to a higher impact, the profile can be gradually adjusted to the new level. As a fault-tolerance mechanism, if the actual business feedback data after execution is incomplete, for example, if two evaluation points are missing due to data collection failure, the estimated deviation will only be calculated on the valid points, but the minimum number of valid points must be met; if it is insufficient, the profile will not be updated or the priority will not be adjusted this time. If the feedback differences for the same type of task are large over a long period of time on different clusters, the original single profile can be split into cluster-level profiles, such as maintaining a clearing cluster log verification profile and a reporting cluster log verification profile respectively. At 23:20 at the end of the month, the platform successfully executed a log verification task without affecting the clearing time limit. Subsequent statistics showed that the actual increase in data storage space and information exchange throughput caused by the task was slightly lower than previously estimated, and the deviation in the business impact prediction was within the tolerance threshold. The system therefore appropriately increases the processing priority of such tasks in subsequent management cycles, and simultaneously fine-tunes the peak occupancy in the profile to be closer to reality; conversely, if the processing unit monopoly caused by a subsequent completeness check is much higher than expected, the system will lower its priority to prevent it from being inserted too early again during future peak periods. The purpose of this mechanism is to allow task profiles and scheduling priorities to continuously evolve with actual execution feedback, thereby achieving adaptive adaptation to changes in the platform environment and improving the stability and accuracy of subsequent scheduling decisions.
[0039] The foregoing has provided a detailed description of one embodiment of the present invention, but this description is merely a preferred embodiment and should not be construed as limiting the scope of the invention. All equivalent variations and modifications made within the scope of the claims of this invention should still fall within the patent coverage of this invention.
Claims
1. A method for scheduling security operation and maintenance tasks for big data intelligent platforms, characterized in that, Includes the following steps: The business statistics module in the big data intelligent platform collects business task dependency data, service level agreement data including business capacity boundaries, historical business throughput time series data, and real-time business load status data, and obtains the occupancy and consumption characteristic data of the security operation and maintenance tasks to be scheduled from the preset security operation and maintenance task management profile library. Based on the business task dependency data, the service level agreement data, and the historical business throughput time series data, an ideal business processing benchmark is constructed under a state of no maintenance interference. Based on the occupancy and consumption characteristic data, the ideal service processing benchmark is characterized and injected to generate the theoretically interfered service state; The real-time business load status data, the ideal business processing benchmark, and the theoretically disturbed business status are aligned according to the unified evaluation cycle and unified business dimension determined by the business monitoring granularity of the big data intelligent platform to generate actual deviation data and theoretical deviation data. The actual deviation data and the theoretical deviation data are evaluated for their consistency to generate a multi-dimensional business impact similarity result. The theoretical deviation data is then superimposed on the real-time business load status data to generate a predicted business load status. When the predicted service load status does not exceed the corresponding service capacity boundary across all service dimensions, an execution permission instruction is output; otherwise, a deferred execution instruction is output. When the real-time business load status data exceeds the corresponding business capacity boundary in at least one business dimension or the actual deviation data exceeds the preset abnormal deviation threshold, a business capacity warning is triggered, and in response to the business capacity warning, a preset abnormal behavior feature library is called to generate abnormal intrusion theoretical deviation data. When the actual deviation data matches the abnormal intrusion theoretical deviation data, a forced termination command is output; Update the task handling priority for subsequent management cycles based on the business feedback data after actual execution.
2. The security operation and maintenance task scheduling method for big data intelligent platforms according to claim 1, characterized in that, The business task depends on the business flow sequence relationship output by the business statistics module. The ideal business processing benchmark determines the predicted time interval of each business task according to the logical order of the business flow sequence, and extracts the corresponding business capacity occupancy curve from the historical business throughput time series data and then splices or superimposes it according to the predicted time interval to generate the curve. The ideal business processing benchmark includes data occupied by business processing units, data occupied by temporary data storage space, data flow throughput, and information interaction throughput.
3. The security operation and maintenance task scheduling method for big data intelligent platforms according to claim 1, characterized in that, The security operation and maintenance task management profile database records the interactive blocking characteristics of risk scanning tasks, the storage access characteristics of verification tasks, the processing exclusive characteristics of completeness verification tasks, and the channel crowding characteristics of information detection tasks. Profile features include at least one of the following: business dimension identifier, interference intensity, duration, startup interval, repetitive attributes, and peak usage. The feature injection calls the corresponding profile features from the security operation and maintenance task management profile library according to the security operation and maintenance task to be scheduled, and applies the interference of each business dimension to the time series position corresponding to the ideal business processing benchmark according to the expected processing time interval.
4. The security operation and maintenance task scheduling method for big data intelligent platforms according to claim 1, characterized in that, The actual deviation data is obtained by removing the ideal business processing benchmark from the real-time business load status data; The theoretical deviation data is obtained by removing the ideal service processing benchmark from the theoretical interfered service state; The unified evaluation cycle is determined by the business monitoring granularity of the big data intelligent platform; the unified business dimension includes business processing unit occupancy, data temporary storage space occupancy, data flow throughput, and information interaction throughput. The actual deviation data and the theoretical deviation data are standardized according to the historical average and fluctuation range of each business dimension, or normalized according to the corresponding business capacity boundary.
5. The security operation and maintenance task scheduling method for big data intelligent platforms according to claim 1, characterized in that, The multidimensional business impact similarity results are generated through temporal path matching evaluation or spatial vector matching evaluation. When using time-series path matching assessment, the degree of path deviation between the actual deviation data and the theoretical deviation data is converted and converted into a matching score; when using spatial vector matching assessment, a matching score is directly generated. When the matching score reaches or exceeds the preset matching acceptance threshold representing the maximum allowable total deviation, the actual deviation data is determined to match the theoretical deviation data; otherwise, it is determined not to match.
6. The security operation and maintenance task scheduling method for big data intelligent platforms according to claim 1, characterized in that, The business capacity boundary includes at least one of the following: the upper limit of business processing unit occupancy, the upper limit of data temporary storage space occupancy, the upper limit of data flow throughput, and the upper limit of information interaction throughput. When verifying the predicted service load status based on the service capacity boundaries in the service level agreement data, if the predicted service load status does not exceed the corresponding service capacity boundaries across all service dimensions, the execution permission instruction is output; if any service dimension exceeds the corresponding service capacity boundary, the execution delay instruction is output.
7. The security operation and maintenance task scheduling method for big data intelligent platforms according to claim 5, characterized in that, In response to the business capacity warning, after generating abnormal intrusion theoretical deviation data by calling the preset abnormal behavior feature library, the method further includes: matching the actual deviation data with the abnormal intrusion theoretical deviation data using the consistency evaluation; when the consistency score reaches or exceeds the preset abnormal matching acceptance threshold, determining that the match is successful and outputting the forced termination instruction; otherwise, maintaining the operation of the current business task and outputting the postponement instruction.
8. The security operation and maintenance task scheduling method for big data intelligent platforms according to claim 7, characterized in that, The abnormal behavior feature library includes features of continuous computationally intensive behavior, features of continuous channel occupancy, and features of periodic storage traversal. The forced termination instruction is executed through the management and coordination module in the big data intelligent platform. It is used to suspend production business tasks other than scheduled security operation and maintenance tasks and security blocking and handling tasks, upgrade the handling level of the security blocking and handling tasks, and limit at least one target business capacity share among the processing clusters, logic units, execution links or business tasks that trigger business capacity warnings, data temporary storage space shares, data flow shares and information interaction shares.
9. The method for scheduling security operation and maintenance tasks for big data intelligent platforms according to claim 1 or 3, characterized in that, The priority of task handling within the subsequent management cycle includes the following processing: recording business feedback data after actual execution based on the permitted execution instruction; The business impact prediction deviation is generated based on the difference between the business feedback data and the theoretically affected business status, and the corresponding profile features in the security operation and maintenance task management profile library are corrected based on the business impact prediction deviation. When the estimated deviation of the business impact does not exceed the preset deviation tolerance threshold, the processing priority of the corresponding task in the subsequent management cycle is increased; when the estimated deviation of the business impact exceeds the preset deviation tolerance threshold, the processing priority of the corresponding task in the subsequent management cycle is decreased.