Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

20 results about "Syslog" patented technology

In computing, syslog /ˈsɪslɒɡ/ is a standard for message logging. It allows separation of the software that generates messages, the system that stores them, and the software that reports and analyzes them. Each message is labeled with a facility code, indicating the software type generating the message, and assigned a severity level.

Safety assessment method and system for rail train, terminal equipment and medium

The invention belongs to the technical field of rail train driving, and provides a safety assessment method and system for a rail train, terminal equipment and a medium. The method comprises the following steps: acquiring original syslog log data of a plurality of vehicle-mounted devices in a rail train, and clustering the original syslog log data according to event keywords corresponding to each vehicle-mounted device to obtain a plurality of key syslog log data; and for each piece of key syslog log data, extracting data features of the key syslog log data, and inputting the data features into a pre-trained safety evaluation model to obtain a safety evaluation result of the rail train. According to the method, the abnormal event behavior of the vehicle-mounted equipment can be accurately identified, the consumption of operation resources is reduced, and the information safety problem of each vehicle-mounted equipment in the running process of the rail train is solved.
Owner:CRRC ZHUZHOU ELECTRIC LOCOMOTIVE RESEARCH INSTITUTE CO LTD

Differentiated de-identification methods, systems, program products and devices for system logs

This disclosure provides a differentiated de-identification method, system, program product, and apparatus for system logs. The method includes receiving log events and performing metadata completion and parsing to obtain structured fields and / or unstructured text fragments; identifying and classifying sensitive information in the structured fields and / or unstructured text fragments to generate a sensitivity mapping table containing the fields or fragments and their corresponding sensitivity types and levels; constructing an access context; based on the sensitivity mapping table and the access context, performing matching and decision-making according to a preset multi-dimensional strategy to generate a de-identification plan for each field or fragment; performing corresponding de-identification actions on the corresponding fields or fragments in the log events according to the de-identification plan to obtain de-identified log data; outputting the de-identified log data and generating an audit log containing strategy hit information and field-level action records.
Owner:HEBEI HAPPY CONSUMPTION FINANCE CO LTD

A block count-based CTC system log adaptive segmentation method

This invention discloses an adaptive segmentation method and system for system logs based on block counting, belonging to the field of data processing technology for rail transit signaling systems. Addressing the problems of easily corrupted logic, uneven segmentation sizes, low processing efficiency, and poor encoding compatibility caused by the special structure of CTC system logs ("text lines + hexadecimal lines"), this invention first defines and identifies the smallest logical block unit in the log; then, it performs adaptive parameter calculation based on block counting to determine the theoretical number of blocks each segmented file can hold; finally, it controls the writing process through dynamic threshold judgment, precisely controlling the size of individual files while ensuring the absolute integrity of logical blocks. This method and system effectively solve the core defects such as the splitting of logical units, excessive file size deviation, and excessive processing time, achieving high-fidelity and high-efficiency segmentation of logs at the 100GB level, providing a high-quality data foundation for subsequent fault tracing and intelligent operation and maintenance.
Owner:SIGNAL & COMM RES INST OF CHINA ACAD OF RAILWAY SCI +3

Identification of typosquat domain variations in passive domain name system (PDNS)

Various techniques for identification of typosquat variations in passive domain name systems (pDNS) are disclosed. In some embodiments, a system, a process, and / or a computer program product for identification of typosquat variations in pDNS includes generating a plurality of candidate typosquat domains using a virtual keyboard; automatically classifying a subset of the plurality of the candidate typosquat domains that each have been previously queried based on Domain Name System (DNS) logs to generate targeted candidate typosquat domains, wherein the classifying includes at least in part performing a Euclidean distance calculation using the virtual keyboard as a plane; and performing an action for one or more of the targeted candidate typosquat domains.
Owner:INFOBLOX INC

A log analysis method, system, smart cockpit, and electronic device.

ActiveCN118861265BData integrityIn vehicle
This invention discloses a log analysis method, system, smart cockpit, and electronic device. The method includes the following steps: deploying a log analysis system in an in-vehicle terminal, the log analysis system being configured to interact with the cloud for data exchange; the log analysis system receiving a log analysis model from the cloud, acquiring and filtering log data generated by the in-vehicle terminal, generating corresponding analysis reports from the processed log data and packaging them, and uploading the packaged log data to the cloud; the cloud receiving the packaged log data, analyzing, processing, and storing it. This invention can solve the problems of consuming large amounts of storage space due to uploading large amounts of logs, and the inability to process log data in real time. By preprocessing and filtering logs, it effectively reduces storage costs while ensuring data integrity and traceability.
Owner:CHINA FAW CO LTD +1

A data analysis method and device, electronic equipment and storage medium

This application provides a data analysis method, apparatus, electronic device, and storage medium, comprising: extracting access data corresponding to users from system logs of a target operating system; the access data including quantitative access data and qualitative access data; preprocessing the quantitative and qualitative access data respectively to obtain quantitative access data to be analyzed and qualitative access data to be analyzed; performing quantitative analysis on the quantitative access data to be analyzed to obtain quantitative analysis results; performing qualitative analysis on the qualitative access data to be analyzed to obtain qualitative analysis results; and performing hybrid theoretical analysis on the quantitative and qualitative analysis results to determine the target behavior profile corresponding to the users. By performing hybrid quantitative and qualitative analysis on user system logs, a deep analysis of user-generated system logs is achieved, improving the accuracy of user behavior analysis while avoiding waste of log resources.
Owner:RICHFIT INFORMATION TECH +1

Metaverse Network Threat Event Inference Method

ActiveCN116915484BOvercome the problem of attackComprehensive aggressionSecuring communicationAttackEngineering
This invention discloses a method for estimating threat events in a metaverse network, primarily addressing the problems of existing threat detection methods failing to fully reflect the dynamics of the system, lacking the ability to detect real-time network attacks, and lacking the capability to reconstruct attack scenarios. The implementation scheme involves: monitoring changes in virtual resource parameters within the metaverse virtual environment and issuing warnings about the current virtual boundary status of the user; constructing a source map using system log data collected from the user's device and network space anchor entity information; compressing the source map to obtain a compressed source map, which is then visualized in the Neo4j database; setting attack stage labels for entity matching in the compressed source map, and performing forward and reverse searches on the compressed source map to extract the attack map of metaverse security boundary attacks. This invention can detect attacks in the metaverse network in real time, has a wider range of applications, enhances the ability to proactively respond to metaverse network threats, and can be used for network security.
Owner:XIDIAN UNIV

Communication device detection method and system, electronic device, and storage medium

PendingCN122457509AInformation resourceEmbedded system
The present disclosure provides a detection method and system of a communication device, an electronic device and a storage medium. The method comprises: in response to receiving a physical examination instruction or a routine inspection instruction from a user, performing fault detection, resource detection and security detection. The fault detection comprises: verifying the consistency of reading and writing of the exchange chip register, verifying the consistency of reading and writing of the unused area of the Flash chip, detecting hardware connectivity, detecting the consistency of service and configuration, detecting the kernel module loading state and scanning error information in the system log. The resource detection comprises: periodically collecting a plurality of resource indicators, and determining the resource running condition according to the plurality of resource indicators collected periodically. The security detection comprises: vulnerability detection, account and command behavior detection, executable file directory integrity detection and scanning of abnormal login behavior in the log. The present disclosure realizes the all-round system physical examination of the communication device through the three dimensions of fault detection, resource detection and security detection.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Monitoring ports to map devices for streaming measurement

In one example, a method is described. The method includes receiving, from an information presentation device, a sequence of pings. The sequence of pings includes a first ping at a first port number, a second ping at a second port number, and a third ping at a third port number at a streaming meter. The method further includes updating, a system log of the streaming meter, to show the first ping at the first port number, the second ping at the second port number, and the third ping at the third port number; comparing the sequence of pings to a key configuration stored in the streaming meter; and generating, in response to the comparing, a status event. The status event includes device information. The method further includes transmitting, over a network, the status event to a server associated with an audience measurement entity.
Owner:THE NIELSEN CO (US) LLC

Computer performance degradation prediction and anomaly detection method based on multi-source data fusion

PendingCN122152652AHardware monitoringKnowledge based modelsPersonalizationComputer performance
The present application belongs to the technical field of computer performance detection, and discloses a computer performance degradation prediction and anomaly detection method based on multi-source data fusion, and the specific steps are as follows: S1. Multi-source data acquisition: collect hardware sensor data, software performance counter data, and user behavior and system log data of the computer. By fusing hardware, software and system log multi-source data, the one-sidedness of a single data source is avoided, the computer performance is accurately and comprehensively reflected, the detection accuracy is improved, and the false alarm and missed alarm rates are reduced; based on the historical data of the health state, a personalized model is trained to build a health region, which is adapted to different user habits, solves the drawbacks of fixed threshold one-size-fits-all, and enhances adaptability; the health degree trend is predicted through the LSTM model, the change from "post-detection" to "pre-prediction" is realized, and the user is helped to carry out preventive maintenance in advance; with the help of the SHAP method, the abnormal root cause is located, the fault diagnosis and repair time is shortened, and the operation and maintenance efficiency is improved.
Owner:NOAH TESTING & CERTIFICATION (BEIJING) CO LTD

Disaster recovery processing method and apparatus for CDN live streaming, device, and medium

PendingUS20260181036A1TransmissionQuality dataEdge node
The present disclosure provides a disaster recovery processing method and a disaster recovery processing apparatus for CDN live streaming, a device, and a medium, which relates to the field of cloud computing technologies, and in particular, to CDN (content delivery network) live streaming field. A specific implementation is: a streaming quality analysis platform acquires quality data of an edge node and a central node from a system log, and determines a fault node and a fault type thereof using a fault identification model or threshold ranges of the quality data. The identified fault node information is sent to a node configuration platform, to generate configuration blocks including filters and processing. The configuration blocks are issued to respective nodes. The node determines, based on streaming information, whether a filter is hit, and performs a corresponding disaster recovery processing when it is hit.
Owner:BEIJING BAIDU NETCOM SCI & TECH CO LTD

A method for upgrading based on a kernel vulnerability of a kylin system

The application discloses a kind of based on kirin system kernel vulnerability upgrade method, it is related to operating system technical field, the application includes the following steps: whether it is x86_64, non then error termination process;Query current kernel package version, if matching vulnerability repair target version is prompted to complete and terminates;Determine SP version to match upgrade package, not support then error termination;Backup GRUB configuration according to start mode, record default kernel start item, pause key service and generate system state snapshot;Select the kernel package of corresponding SP version and execute installation, installation fails then trigger automatic rollback;Restart server, and the starting state is monitored by BMC, timeout / failure triggers hardware recovery, success then confirm kernel version;Verify kernel, service, system log etc., then complete upgrade;Failure then automatically rollback and verify rollback result.The application integrates automatic backup and rollback mechanism in kirin system kernel upgrade process, improves the security and reliability of system update.
Owner:BEIJING HUANENG XINRUI CONTROL TECH

Applying subscriber-id based security, equipment-id based security, and / or network slice-id based security with user-id and syslog messages in mobile networks

Techniques for applying subscriber-ID based security, equipment-ID based security, and / or network slice-ID based security with user-ID and syslog messages in mobile networks are disclosed. In some embodiments, a system / process / computer program product for applying subscriber-ID based security, equipment-ID based security, and / or network slice-ID based security with user-ID and syslog messages in mobile networks includes monitoring network traffic on a mobile network at a security platform to identify a new session; extracting a plurality of parameters by parsing syslog messages with a user-ID agent at the security platform; and enforcing a security policy on the new session at the security platform based on one or more of the plurality of parameters including one or more of a subscriber-ID, equipment-ID, and network slice-ID to apply context-based security in the mobile network.
Owner:PALO ALTO NETWORKS INC

Dormancy wake-up processing method and apparatus, electronic device, and storage medium

ActiveCN115437859BDetecting faulty computer hardwareStart timeTerminal time
The present disclosure relates to a hibernation wake-up processing method and device, electronic equipment and storage medium, wherein the method comprises: obtaining a system time when a preset function of a first device in a system on chip (SOC) is called as a first start time, wherein the preset function is a hibernation function or a wake-up function; obtaining a system time when the calling of the preset function ends as a first end time; and in a case where a difference between the first end time and the first start time is greater than a preset threshold, writing device information of the first device into a system log. Through the scheme of the present disclosure, only when the time consumption of hibernation or wake-up of a device exceeds the preset threshold, the device information of the device is written into the system log, thereby avoiding the influence of the time consumption of recording the device information of each device on the performance of SOC hibernation and wake-up.
Owner:BEIJING CO WHEELS TECH CO LTD

Data processing methods, apparatuses, electronic devices, storage media, and software products

This application discloses a data processing method, apparatus, electronic device, storage medium, and program product, belonging to the field of industrial vision. The data processing method includes: processing an initial log based on a preset log format to obtain a standardized log; the preset log format includes at least one of: timestamp, thread number, log level, log content, and code location; wherein the log content includes an action or result field and a parameter field; and outputting the standardized log. This application's data processing method, by outputting standardized logs with a consistent structure based on a preset log format, reduces the complexity of system log content, enabling users to more directly understand the causes of anomalies and handle corresponding anomalies, thereby improving the efficiency of equipment fault diagnosis.
Owner:苏州凌云光工业智能技术有限公司 +1

Data processing method, system, apparatus, and storage medium

This application discloses a data processing method, system, apparatus, and storage medium. Relating to the field of Internet technology, the method includes: upon receiving a target instruction, determining the target script corresponding to the target business type indicated in the target instruction from multiple preset scripts; using the target script, extracting the request content of the target business request from the system log of the source system based on string recognition, wherein the system log records the request content of multiple business types received by the source system, and the request content of the target business request is used to perform business testing on the target system, where the target system is the system to which the business migration from the source system is directed. This application solves the problem of high labor costs associated with related technologies in business migration scenarios between old and new systems, where production test cases are manually extracted from the old system for testing the new system based on these production test cases.
Owner:TRAVELSKY TECHNOLOGY LIMITED

Log information transmission method and device, and storage medium

ActiveCN119071281BTransmissionInformation typeInformation transmission
The present disclosure provides a log information transmission method and device and a storage medium, relates to the technical field of communication, and solves the technical problem that in the prior art, when the log information demand of a log information application device changes, it is difficult to change the reported log information content in time according to the log information demand of the log application device by using the syslog protocol to report the log information. The method comprises the following steps: receiving a first POST request; generating a log information subscription identifier based on the identifier of the log information application device and the log information type requested to be obtained; sending a response message to the log information application device; the response message is used to instruct the log information application device to establish a server push event (SSE) long connection based on the log information subscription identifier; and the SSE long connection is used to send log information to the log information application device. The present disclosure is used for a log information reporting scene.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Industrial log anomaly judgment method and system based on end-to-end large model

PendingCN122286476ALanguage understandingIndustrial systems
This invention provides a method and system for anomaly detection in industrial logs based on an end-to-end large-scale model. The method includes: acquiring raw industrial system log data; preprocessing the raw industrial system log data to obtain preprocessed industrial system log data; embedding the preprocessed industrial system log data into a preset prompt word template, and constructing a training set based on the prompt word template; inputting the training set into a pre-trained large-scale language model, and fine-tuning the large-scale language model using a low-rank matrix LoRA to obtain a fine-tuned large-scale language model; inputting the industrial system log data to be detected into the trained large-scale language model, and outputting the anomaly category identification result. This invention can fully stimulate the language understanding ability of the large-scale language model, achieve highly robust anomaly identification of unstructured and semantically inconsistent log content, and greatly improve the application efficiency of the large-scale language model in multi-source heterogeneous environments.
Owner:WUHAN UNIV OF TECH