Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

166 results about "Syslog" patented technology

In computing, syslog /ˈsɪslɒɡ/ is a standard for message logging. It allows separation of the software that generates messages, the system that stores them, and the software that reports and analyzes them. Each message is labeled with a facility code, indicating the software type generating the message, and assigned a severity level.

Network traffic anomaly real-time detection method based on deep learning

The invention relates to the technical field of network flow detection, in particular to a real-time network flow anomaly detection method based on deep learning, and the system comprises the following steps: S1, carrying out the real-time collection and preprocessing of multi-modal data; s2, performing dynamic feature engineering and sliding window statistics; s3, carrying out online adaptive threshold initialization; s4, multi-modal deep learning model reasoning is carried out; s5, updating the adaptive threshold in real time; s6, abnormal decision making and confidence coefficient calibration; s7, generating interpretability analysis; and S8, performing real-time feedback and online learning. According to the scheme, the capability of detecting hidden and complex attacks is remarkably improved through multi-modal data fusion and dynamic feature engineering, network traffic, system logs, user behavior data and external threat intelligence are synchronously collected, and traffic statistical features, time sequence change features, frequency domain features and distribution features are extracted in real time by using a sliding window mechanism.
Owner:WUXI YUANSHUCHENG TECHNOLOGY CO LTD

Module identification method and device based on hybrid detection mechanism and storage medium

The invention discloses a module identification method and device based on a hybrid detection mechanism, and a storage medium, relates to the technical field of device management, and discloses a module identification method based on the hybrid detection mechanism, and the method comprises the steps: scanning a preset interface to obtain current equipment node information after a system is powered on, analyzing the system log to extract equipment event information; generating an initial module list based on the equipment node information and the equipment event information; in response to the hot plug event, executing the same scanning and system log analysis operation when the system is powered on, and obtaining a compensation scanning result; and generating an updated module list according to the initial module list and the compensation scanning result. Through a hybrid detection mechanism combining static scanning and dynamic event driving, the accuracy and real-time performance of module identification are effectively improved, system start initialization and operation period hot plug scenes are considered, and the problem of state inconsistency caused by event loss or equipment residue is avoided.
Owner:SHENZHEN SHENBAO ELECTRONIC METER CO LTD

Apparatuses for audit data generation and verification

It is provided an apparatus comprising interface circuitry, machine-readable instructions, and processing circuitry to execute the machine-readable instructions. The machine-readable instructions include instructions to receive data from a remote entity for handling by a computing system. The machine-readable instructions further include instructions to instantiate a first TEE and a second TEE. The machine-readable instructions further include instructions to generate log data corresponding to predefined activities of the computing system and to generate system record data of a system log of the computing system at predetermined times. The machine-readable instructions further include instructions to generate first audit data by the first TEE and second audit data by the second TEE. The machine-readable instructions further include instructions to transmit the first and the second audit data to a detection system for data aggregation and anomaly detection.
Owner:VAUGHN ROBERT +4

Log processing method and device, medium and product

The invention discloses a log processing method and device, a medium and a product, relates to the technical field of distributed system log management, and can be applied to the field of financial science and technology. The method comprises the following steps: sending a receiving node query request to a policy service, so that the policy service determines a target receiving node according to the receiving node query request; obtaining a target receiving node fed back by the policy service; based on the local system portrait model, processing the current system index data to obtain a business trough period window; determining an estimated transmission time length and a recommended transmission time period according to the data volume and the current available bandwidth of the to-be-transmitted log file and the service trough period window; sending a transmission decision request to a policy service; obtaining a target transmission time period and a fragment sequence fed back by the policy service; and transmitting a fragment sequence to the server through the target receiving node based on the target transmission time period, the fragment sequence comprising at least one log fragment. Through the technical scheme, the log processing efficiency can be improved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Block chain power abnormal data tracing method

The invention relates to the technical field of computers, in particular to a block chain power abnormal data tracing method. The method comprises the following steps: acquiring operation data and system logs of a power system, extracting model input, identifying exceptions and completing event source classification; for the abnormal generation differential change records, timestamps are extracted to construct chain records, and the chain records are serialized into traceable paths; performing cross-source alignment and sequence correction to form a consistent event sequence, classifying and sorting to obtain an event sequence structure, and verifying to generate a cross-system traceability path; and finally verifying a conclusion through a consensus mechanism, extracting a traceability report, and updating the anomaly detection model according to the traceability report. According to the method, the cross-source time sequence consistency and the evidence playback performance are improved, the conclusion credibility and the closed-loop iteration capability are enhanced, and the method is suitable for scenes such as data metering and equipment monitoring.
Owner:BEIJING FIBO XINDA TECHNOLOGY CO LTD

Enterprise informatization management integration platform based on big data

PendingCN121979873AAvoid inconsistent calibersReduce the risk of difficult reviewDatabase updatingFinanceInformatizationSystems engineering
The invention belongs to the technical field of enterprise informatization management and big data integration, and particularly relates to an enterprise informatization management integration platform based on big data. Comprising an auditing element unified structured acquisition module, a main body unique identifier analysis and failure closed loop module, a caliber version and field mapping version joint locking module and an evidence index binding and consistency verification packaging module. The platform reads interface and field mapping from a service system log according to a configuration table, normalizes the interface and field mapping and writes the interface and field mapping into an event account book collocation state; executing main body gating on the original entry record to generate a main body identifier and writing back the main body identifier; when failure occurs, the reason code is written and blocked, and the failure evidence index is returned; performing node analysis on the aperture script and generating an aperture chain fingerprint; and serializing the event segments, calculating abstracts, constructing batch abstract roots, positioning first inconsistent serial numbers when recalculation is inconsistent, and scheduling and supplementary collection, so as to output a recheckable audit evidence packet. According to the invention, aperture consistency and evidence traceability can be realized.
Owner:HUAIAN DONGCHUANGXINGKE TECHNOLOGY CO LTD

Dynamic routing method and device based on Nginx and Lua, equipment and storage medium

The invention discloses a dynamic routing method and device based on Nginx and Lua, equipment and a storage medium, and belongs to the technical field of network communication, and the method comprises the steps: receiving a user request, obtaining a tenant number and an expression, constructing a recognition model, inputting the expression into the recognition model, outputting a classification label and a first confidence value, and introducing the first confidence value for judgment, and selecting an optimal path from the candidate path set given by the permission mapping table according to the path score, performing permission judgment on the optimal path, when the access permission of the optimal path exists, sending a user request to a back-end module corresponding to the optimal path, constructing a state record item, and pushing the record item to a system log. According to the method, a dynamic path scheduling mode taking expression semantics and tenant context as cores is constructed, so that closed-loop capabilities of identity recognition, content understanding, path control and behavior tracing are formed, and the method has relatively high deployment universality and service adaptability.
Owner:GUANGZHOU SIYUN DATA TECH CO LTD

Automatic testing method, system and equipment based on protocol configuration table and medium

The invention discloses an automatic testing method, system and equipment based on a protocol configuration table and a medium. The method specifically comprises the following steps: capturing a communication data packet between a game client and a game server; analyzing the communication data packet by using a protocol format reasoning algorithm based on a hidden Markov model to generate a protocol configuration table; constructing an automatic test robot, and simulating player behaviors based on the protocol configuration table to execute a protocol-level test; based on the protocol configuration table and the execution state of the test robot, preferentially exploring a high-risk branch path, and dynamically adjusting the test sequence; and constructing a defect root cause analysis engine according to a protocol level test result and a multi-modal detection result, and automatically positioning and outputting a problem root in combination with protocol data, game state data and a system log. According to the method, the whole process of game automatic testing is realized, the game problem is accurately and efficiently detected, the source is positioned, the manual testing cost and error are reduced, and the game testing quality and efficiency are improved.
Owner:广州三七极耀网络科技有限公司

Router system service abnormity self-healing method based on cloud AI

The invention belongs to the technical field of communication, and particularly relates to a router system service exception self-healing method based on cloud AI, which comprises the following steps: deploying an exception detection module at a router end, collecting system logs and state data in real time and generating a standardized exception report; uploading the report to a cloud AI server through an encrypted MQTT protocol; the cloud calls a hybrid analysis model composed of a rule matching engine, a machine learning classifier and a reinforcement learning decision network to generate a self-healing strategy instruction packet; the router end receives and executes the strategy, completes service restart, configuration rollback or hotfix loading and other operations, and verifies the self-healing effect; when communication interruption exceeds a threshold value, an embedded loopback self-healing subsystem is automatically activated, and abnormity is independently handled based on a local strategy library. According to the technical scheme, millisecond-level abnormal response and high-success-rate autonomous recovery can be achieved, the network availability and the service continuity are remarkably improved, and the disaster recovery self-healing capacity is still achieved when the cloud end is disconnected.
Owner:CHENGDU VOLANS TECH CO LTD

Method for detecting log abnormity of power dispatching automation system

The invention relates to the technical field of electric digital data processing, and discloses a method for detecting log abnormity of an electric power dispatching automation system, which comprises the following steps of: constructing a fixed depth analysis tree through historical log data, and extracting a log template based on word segmentation similarity; converting knowledge in the power dispatching field into vectors and storing the vectors into a knowledge base; retrieving knowledge base associated domain knowledge of the log template, inputting the large model to carry out abnormity judgment and marking a template label; after real-time log preprocessing, a template label is inherited through a parse tree matching template library and a self-adaptive threshold strategy, and online template updating is triggered for unmatched logs; and the context and high-frequency parameters of the abnormal log are aggregated, a dynamic cue word is constructed in combination with a retrieval result and a template feature weight, a large model is input for multi-dimensional root cause analysis, and template mechanism optimization is driven based on the cue word. The problems that in the prior art, manual maintenance is difficult, the generalization ability is weak, and the detection speed is low are solved, and the purposes of efficient detection, high accuracy and self-adaption are achieved.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD QUZHOU POWER SUPPLY CO

Automated threat hunting

Embodiments perform automated threat hunting in computing environments. A threat hunt plan is obtained to guide collection of candidate evidence items from evidence sources. Portions of candidate evidence items are discarded based on relevance scores, and evidence items are determined from non-discarded portions. Threat indicators associated with the evidence items are identified based on criteria in the threat hunt plan. Threat profiles are obtained based on the evidence items and threat indicators such that threat profiles include threat assessment metrics and are included in a report. Collection agents may interface with system logs, network traffic captures, endpoints, databases, email services, or user activity records to gather evidence items based on time ranges, filtering criteria, or sampling rates.
Owner:DROPZONE AI INC

Power grid anti-bird multichannel twitter sound source positioning and intervention method

The invention provides a power grid anti-bird multichannel twitter sound source positioning and intervention method, which comprises the following steps: acquiring sound signals from a power grid area through a multichannel microphone array equipped with a laser radar calibration module, optimizing a separation threshold by adopting Fourier transform and combining a preset bird voiceprint feature library, separating twitter components and noise components, and performing interference on the twitter components and the noise components; pure birdsong signals are obtained; according to the pure birdsong signal, calculating the time difference between channels by adopting a time delay estimation method, dynamically correcting a preset threshold value by combining a real-time environment sensor, if the time difference exceeds the corrected threshold value, marking as an effective birdsong event, and adopting a centimeter-level differential GPS module to assist in determining the position coordinates of the birds; interference execution confirmation is received through an edge computing node and returned to a system log, a D-S evidence theory data fusion method is adopted to integrate the positioning coordinates and the risk level, if it is judged that the fusion result is consistent in a preset confidence interval, the bird damage monitoring model is updated based on an incremental learning algorithm, and real-time closed-loop feedback is obtained.
Owner:STATE GRID JIANGXI ELECTRIC POWER CO LTD +1

Safety assessment method and system for rail train, terminal equipment and medium

The invention belongs to the technical field of rail train driving, and provides a safety assessment method and system for a rail train, terminal equipment and a medium. The method comprises the following steps: acquiring original syslog log data of a plurality of vehicle-mounted devices in a rail train, and clustering the original syslog log data according to event keywords corresponding to each vehicle-mounted device to obtain a plurality of key syslog log data; and for each piece of key syslog log data, extracting data features of the key syslog log data, and inputting the data features into a pre-trained safety evaluation model to obtain a safety evaluation result of the rail train. According to the method, the abnormal event behavior of the vehicle-mounted equipment can be accurately identified, the consumption of operation resources is reduced, and the information safety problem of each vehicle-mounted equipment in the running process of the rail train is solved.
Owner:CRRC ZHUZHOU ELECTRIC LOCOMOTIVE RESEARCH INSTITUTE CO LTD

Linkage banning method and device for network security threats, computer equipment, storage medium and program product

The invention relates to a linkage forbidding method and device for network security threats, equipment, a storage medium and a program product, and relates to the technical field of network security. According to the invention, the efficiency and accuracy of network security protection can be improved. The method comprises the following steps: carrying out multi-dimensional monitoring on a target network and collecting multi-source monitoring data; performing feature extraction on the multi-source monitoring data to obtain a traffic feature corresponding to the network traffic data, a log feature corresponding to the system log information, a user behavior feature corresponding to the user behavior data and a potential security vulnerability corresponding to the vulnerability scanning information; according to the flow characteristics, the log characteristics, the user behavior characteristics and the potential security vulnerabilities, performing threat analysis through a machine learning algorithm to identify potential network security threats, and determining threat levels of the network security threats by adopting an analytic hierarchy process; and formulating a forbidding strategy according to the network security threat and the threat level, and executing the forbidding strategy for the network security threat.
Owner:SHUOHUANG RAILWAY DEV +1

Power terminal access attack behavior detection method and system based on multi-modal data fusion

The invention discloses a multi-modal data fusion-based power terminal access attack behavior detection method and system, and the method comprises the steps: collecting data through a specific collection tool, and carrying out the collection of four key indexes, namely, a traffic mode, a system log, signal strength and network topology; and an access security assessment detection model is constructed based on a Transform model of multi-modal feature fusion, and abnormal behaviors of the access terminal of the power Internet of Things platform are accurately identified. A system constructed according to the method comprises a collection unit, a processing unit, a behavior detection unit, a trust evaluation unit and a blocking unit, a deep learning algorithm is utilized to analyze multi-modal features, terminal behaviors are evaluated in combination with a trust evaluation mechanism, and trust levels are divided. According to the invention, an intelligent blocking rule strategy is provided for different abnormal behaviors, and the access safety and reliability of the electric power Internet of Things terminal are improved.
Owner:GUANGDONG POWER GRID CO LTD +1

Abnormal information dump method of embedded multi-core operating system

The invention discloses an abnormal information dump method of an embedded multi-core operating system, which comprises the following steps of: in an initialization process of an abnormal dump module, creating an abnormal information annular buffer area, and configuring an abnormal information dump mode at the same time; on the premise that the system log information with the abnormal information is output to the abnormal information annular buffer area, the printk interface is re-hooked and defined; when a system is abnormal, an abnormal event is converted into an abnormal vector, an abnormal processing function is called, the output content of the abnormal processing function is transmitted through a printk interface, the abnormal information annular buffer area is output to a specified address or file according to a configured abnormal information unloading mode, and one-time abnormal information annular buffer area emptying operation is achieved. The problem that the system debugging information is difficult to obtain under the condition that no serial port exists in an actual application environment is solved.
Owner:EAST CHINA INST OF COMPUTING TECH

Kubernetes-based GPU fault automatic monitoring method and system

The invention discloses a Kubernetes-based GPU fault automatic monitoring method and system, and relates to the technical field of computer monitoring, and the method comprises the steps: running a GPU detection program at each node; indexes are collected, wherein the indexes comprise XID and / or SXID error events in the system logs and the driving state and the equipment running state obtained based on the NVML; standardizing the indexes into an index data structure; generating a fault judgment result associated with the node identifier and the GPU equipment identifier according to a preset evaluation rule; and when the data is abnormal, the data is mapped as a Node Condition and / or reported to a Kubernetes Event, and a Prometheus acquisition interface is exposed to be pulled and stored. Through the technical scheme of the invention, GPU fault automatic identification and card level positioning are realized, cluster perceptibility and alarm traceability are enhanced, manual troubleshooting cost is reduced, and cluster stability is improved.
Owner:HANGZHOU HARMONYCLOUD TECH CO LTD

Role based syslog record access

Method and apparatus for providing users role-based system log entry access are described. This can be implemented using a data controller that can read and implement a policy that determines what portion of the total system log certain users (or user groups) are permitted to access. In turn, it may curate a redacted system log and present it to the user that sent the request for the system log. The data controller may act as an intermediate layer between a user wishing to view a system log, the system log itself.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Multi-source fusion log compression method and device for anomaly detection

ActiveCN119420534BBridging the Semantic Gapreduce dependenceSecuring communicationDomain nameAlgorithm
This application discloses a multi-source fusion log compression method and apparatus for anomaly detection, belonging to the field of anomaly detection technology. The multi-source fusion log compression method for anomaly detection includes: generating an audit origination graph corresponding to the system audit log, an application origination graph corresponding to the application log, and a domain name origination graph corresponding to the domain name system log based on the system audit log corresponding to the electronic device, the application log corresponding to the target application in the electronic device, and the domain name system log corresponding to the electronic device; fusing the domain name origination graph into the application origination graph based on the domain name nodes in the application origination graph to obtain a sub-fused origination graph; fusing the audit origination graph into the sub-fused origination graph based on the event nodes in the audit origination graph to obtain a fused origination graph; and performing anomaly detection based on the fused origination graph. The multi-source fusion log compression method for anomaly detection in this application can alleviate the problems of semantic gap and dependency explosion.
Owner:INST OF ADVANCED TECH UNIV OF SCI & TECH OF CHINA

Embedded device log management method and system

The invention relates to the technical field of embedded system log management, and relates to an embedded device log management method and system, and the method comprises the steps: S1, scanning a log stream line by line, analyzing each line of logs, and filtering the logs according to a routing rule; s2a, splitting the log routed to the local storage into a plurality of independent files, and monitoring and writing the independent files in real time; and S2b, for the log routed to the temporary buffer area, if the number of times of occurrence of the same predefined prefix label in a predetermined time exceeds a threshold value, generating a temporary routing rule and adding the temporary routing rule to a routing table. By implementing the scheme, (1) the log management efficiency and the system reliability are improved; (2) efficient storage, resource optimization and fault self-diagnosis of embedded system logs are realized, and the service life of hardware is prolonged; and (3) the log time continuity is ensured, the efficiency of troubleshooting and system analysis is greatly improved, the data security is ensured, convenient access is provided for authorized users, and a complete operation auditing capability is provided.
Owner:Shenzhen Jinying Tuolian Technology Co., Ltd.

System and method for secure proactive activation of a disaster recovery system

A proactive activation system and method perform secure proactive activation of a disaster recovery system of a business. The proactive activation system comprises a log correlation system, a scoring system, and a disaster recovery activation system. The log correlation system collects logs from a computing device used in the business by a user, cross-correlates the collected logs, and determines a potential system failure as a disaster indicator. The scoring system assigns a score to the disaster indicator. In the case of the disaster indicator score being greater than a predetermined threshold, the disaster recovery activation system generates a control signal to activate the disaster recovery system. The method implements the proactive activation system.
Owner:SAUDI ARABIAN OIL CO

FTA fault tree-based operating system fault diagnosis method, apparatus and device

The invention provides an operating system fault diagnosis method, device and equipment based on an FTA fault tree, and relates to the technical field of operating system fault diagnosis, and the method comprises the steps: carrying out the FTA fault tree building of a target operating system based on the architecture dimension of the target operating system, and obtaining the FTA fault tree corresponding to the target operating system; obtaining a to-be-analyzed system log corresponding to a target operating system uploaded by a user and a target fault corresponding to the target operating system; according to the to-be-analyzed system log, the target fault and an FTA fault tree corresponding to the target operating system, performing matching analysis on the to-be-analyzed system log to obtain a plurality of fault nodes; generating a diagnosis result corresponding to the target fault according to the plurality of fault nodes; the diagnosis result at least comprises a fault node position and processing information corresponding to the fault node; the problems of low diagnosis efficiency, inaccurate positioning, high cost and the like in the prior art can be effectively solved.
Owner:THUNDERSOFT (NANJING) CO LTD

Systems and methods for machine interpretation of security data via dynamic constraint specification matrix

The present invention encompasses systems, computer program products, and methods for machine interpretation of security data. It identifies various data sources providing metrics and parameters, which include system logs, network traffic data, user activity records, and application logs. The system retrieves these metrics and parameters through an application programming interface and transforms them from unstructured to structured data. This structured data is then featured and stored. A dynamic consolidated matrix, known as the Constraint Specification Matrix (CSM), is generated from these features. A machine learning model is trained to discern correlations and patterns within the CSM's features. Lastly, the system transmits instructions to present these correlations and patterns via a user interface on a user device, allowing for user-friendly visualization and interpretation of the analyzed security data.
Owner:BANK OF AMERICA CORP

Blockchain-based mass interface call log evidence storage and traceability method and system

The application discloses a mass interface call log storage and tracing method and system based on a blockchain, belongs to the technical field of the blockchain, and aims to solve the problems of mass interface call log storage difficulty and data sharing tracing difficulty in a data sharing mode. A service gateway pushes a call log to a Kafka cluster; the Kafka cluster consumes the call log and stores the consumed call log in batches to an ES system through logstash; a log collection system uploads a total hash value corresponding to the batch call log to the blockchain, the blockchain returns a transaction hash value to the log collection system, the log collection system returns the transaction hash value to the ES system and associates the transaction hash value with the corresponding batch call log; a trusted third party calculates a total hash value of the corresponding batch call log, compares the obtained total hash value with the total hash value queried from the blockchain, and determines that the call log is trusted if the total hash values are consistent.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Content recognition method, network device, and computer-readable storage medium

The application provides a content identification method, network equipment and a computer readable storage medium. The method comprises: identifying user access records corresponding to suggestive content according to collected domain name system (DNS) logs; the suggestive content is suspected flow diversion content; determining whether external addresses in the user access records have flow diversion behavior according to the user access records; if it is determined that the external addresses have flow diversion behavior, sending target external addresses having flow diversion behavior to a second device for content review; the second device is a device having a subscription relationship with a first device; and receiving review results sent by the second device. The first device of the application provides flow diversion behavior discovery capability, the second device reviews target external addresses having flow diversion behavior, and through interaction between the first device and the second device, multi-party collaborative governance of bad flow diversion behavior is realized, and the efficiency and accuracy of identifying bad content can be improved.
Owner:CHINA MOBILE COMM LTD RES INST +1

System log anomaly detection method based on Gimma model and medium

The invention discloses a system log anomaly detection method based on a Gimma model and a medium, and belongs to the field of log anomaly detection.The system log anomaly detection method comprises the steps that log messages are preprocessed to obtain a log message set; performing analysis processing by using a bidirectional parallel tree algorithm to obtain structured log data; a Gimma model is trained through the serialized log set, so that the model can predict subsequent logs according to a given log sequence; a log set containing normal and abnormal data is used for evaluating the effect of the model, and if an actual log key is in the first k keys predicted by the model, it is judged that the actual log key is normal; if the actual log key is not in the first k keys predicted by the model, judging that the log key is abnormal; through the LoRA low-rank fine tuning method, the time cost of model training is reduced. According to the method, various public log data sets can be supported, the anomaly detection task can be completed on log data of different structures, and the preprocessing precision and the anomaly detection precision can be effectively improved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Differentiated de-identification methods, systems, program products and devices for system logs

This disclosure provides a differentiated de-identification method, system, program product, and apparatus for system logs. The method includes receiving log events and performing metadata completion and parsing to obtain structured fields and / or unstructured text fragments; identifying and classifying sensitive information in the structured fields and / or unstructured text fragments to generate a sensitivity mapping table containing the fields or fragments and their corresponding sensitivity types and levels; constructing an access context; based on the sensitivity mapping table and the access context, performing matching and decision-making according to a preset multi-dimensional strategy to generate a de-identification plan for each field or fragment; performing corresponding de-identification actions on the corresponding fields or fragments in the log events according to the de-identification plan to obtain de-identified log data; outputting the de-identified log data and generating an audit log containing strategy hit information and field-level action records.
Owner:HEBEI HAPPY CONSUMPTION FINANCE CO LTD

Project acceptance effect evaluation method and system based on data analysis

The invention discloses a project acceptance effect evaluation method and system based on data analysis, and relates to the technical field of data analysis, and the method comprises the steps: extracting acceptance contacts from a project acceptance conclusion, constructing an invertible path set corresponding to each contact, theoretically defining a process behavior record or data evidence which should be left when the invertible path set actually exists, and evaluating the project acceptance effect. And empirical verification is carried out based on data sources such as system logs, process records and document archiving. If it is found that the path is missing, incomplete or conflicted, the contact is marked as a structural support missing contact. The method further integrates the number and importance of the distortion contacts and the coverage range of the distortion contacts in the acceptance conclusion to form an authenticity evaluation result of the acceptance effect. According to the method, based on structural path inversion and support integrity judgment, a counterfeit acceptance conclusion lacking a process basis can be effectively identified, scientificity and credibility of acceptance work are improved, and the problem that an acceptance result is inconsistent with an actual project state and is difficult to identify is solved.
Owner:HEFEI XIANGFEI PRODUCTIVITY PROMOTION CENT CO LTD

Subway signal system log intelligent analysis method, device, equipment and medium

PendingCN121644207AAlarmsSecuring communicationData aggregatorNetwork Compartment
The invention relates to a subway signal system log intelligent analysis method, device and equipment and a medium. The method is realized by constructing a multi-stage security architecture of an internal security network-network isolation region DMZ-public network, firstly, log data preprocessing and encryption are carried out in the network isolation region DMZ, secondly, reverse communication is blocked through unidirectional transmission hardware, and then, accurate analysis is carried out by utilizing a large model association version demand and log keywords, so that the log data encryption is realized. And finally, establishing a global knowledge base to mine common hidden dangers. Compared with the prior art, the method has the advantages that on the premise that absolute safety of the core production network is ensured, log data aggregation of the whole road network is achieved, and intelligent real-time analysis and early warning are carried out.
Owner:CASCO SIGNAL LTD