Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

90 results about "Syslog" patented technology

In computing, syslog /ˈsɪslɒɡ/ is a standard for message logging. It allows separation of the software that generates messages, the system that stores them, and the software that reports and analyzes them. Each message is labeled with a facility code, indicating the software type generating the message, and assigned a severity level.

Log processing method and device, medium and product

The invention discloses a log processing method and device, a medium and a product, relates to the technical field of distributed system log management, and can be applied to the field of financial science and technology. The method comprises the following steps: sending a receiving node query request to a policy service, so that the policy service determines a target receiving node according to the receiving node query request; obtaining a target receiving node fed back by the policy service; based on the local system portrait model, processing the current system index data to obtain a business trough period window; determining an estimated transmission time length and a recommended transmission time period according to the data volume and the current available bandwidth of the to-be-transmitted log file and the service trough period window; sending a transmission decision request to a policy service; obtaining a target transmission time period and a fragment sequence fed back by the policy service; and transmitting a fragment sequence to the server through the target receiving node based on the target transmission time period, the fragment sequence comprising at least one log fragment. Through the technical scheme, the log processing efficiency can be improved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Block chain power abnormal data tracing method

The invention relates to the technical field of computers, in particular to a block chain power abnormal data tracing method. The method comprises the following steps: acquiring operation data and system logs of a power system, extracting model input, identifying exceptions and completing event source classification; for the abnormal generation differential change records, timestamps are extracted to construct chain records, and the chain records are serialized into traceable paths; performing cross-source alignment and sequence correction to form a consistent event sequence, classifying and sorting to obtain an event sequence structure, and verifying to generate a cross-system traceability path; and finally verifying a conclusion through a consensus mechanism, extracting a traceability report, and updating the anomaly detection model according to the traceability report. According to the method, the cross-source time sequence consistency and the evidence playback performance are improved, the conclusion credibility and the closed-loop iteration capability are enhanced, and the method is suitable for scenes such as data metering and equipment monitoring.
Owner:BEIJING FIBO XINDA TECHNOLOGY CO LTD

Enterprise informatization management integration platform based on big data

PendingCN121979873AAvoid inconsistent calibersReduce the risk of difficult reviewDatabase updatingFinanceInformatizationSystems engineering
The invention belongs to the technical field of enterprise informatization management and big data integration, and particularly relates to an enterprise informatization management integration platform based on big data. Comprising an auditing element unified structured acquisition module, a main body unique identifier analysis and failure closed loop module, a caliber version and field mapping version joint locking module and an evidence index binding and consistency verification packaging module. The platform reads interface and field mapping from a service system log according to a configuration table, normalizes the interface and field mapping and writes the interface and field mapping into an event account book collocation state; executing main body gating on the original entry record to generate a main body identifier and writing back the main body identifier; when failure occurs, the reason code is written and blocked, and the failure evidence index is returned; performing node analysis on the aperture script and generating an aperture chain fingerprint; and serializing the event segments, calculating abstracts, constructing batch abstract roots, positioning first inconsistent serial numbers when recalculation is inconsistent, and scheduling and supplementary collection, so as to output a recheckable audit evidence packet. According to the invention, aperture consistency and evidence traceability can be realized.
Owner:HUAIAN DONGCHUANGXINGKE TECHNOLOGY CO LTD

Router system service abnormity self-healing method based on cloud AI

The invention belongs to the technical field of communication, and particularly relates to a router system service exception self-healing method based on cloud AI, which comprises the following steps: deploying an exception detection module at a router end, collecting system logs and state data in real time and generating a standardized exception report; uploading the report to a cloud AI server through an encrypted MQTT protocol; the cloud calls a hybrid analysis model composed of a rule matching engine, a machine learning classifier and a reinforcement learning decision network to generate a self-healing strategy instruction packet; the router end receives and executes the strategy, completes service restart, configuration rollback or hotfix loading and other operations, and verifies the self-healing effect; when communication interruption exceeds a threshold value, an embedded loopback self-healing subsystem is automatically activated, and abnormity is independently handled based on a local strategy library. According to the technical scheme, millisecond-level abnormal response and high-success-rate autonomous recovery can be achieved, the network availability and the service continuity are remarkably improved, and the disaster recovery self-healing capacity is still achieved when the cloud end is disconnected.
Owner:CHENGDU VOLANS TECH CO LTD

Power grid anti-bird multichannel twitter sound source positioning and intervention method

The invention provides a power grid anti-bird multichannel twitter sound source positioning and intervention method, which comprises the following steps: acquiring sound signals from a power grid area through a multichannel microphone array equipped with a laser radar calibration module, optimizing a separation threshold by adopting Fourier transform and combining a preset bird voiceprint feature library, separating twitter components and noise components, and performing interference on the twitter components and the noise components; pure birdsong signals are obtained; according to the pure birdsong signal, calculating the time difference between channels by adopting a time delay estimation method, dynamically correcting a preset threshold value by combining a real-time environment sensor, if the time difference exceeds the corrected threshold value, marking as an effective birdsong event, and adopting a centimeter-level differential GPS module to assist in determining the position coordinates of the birds; interference execution confirmation is received through an edge computing node and returned to a system log, a D-S evidence theory data fusion method is adopted to integrate the positioning coordinates and the risk level, if it is judged that the fusion result is consistent in a preset confidence interval, the bird damage monitoring model is updated based on an incremental learning algorithm, and real-time closed-loop feedback is obtained.
Owner:STATE GRID JIANGXI ELECTRIC POWER CO LTD +1

Safety assessment method and system for rail train, terminal equipment and medium

The invention belongs to the technical field of rail train driving, and provides a safety assessment method and system for a rail train, terminal equipment and a medium. The method comprises the following steps: acquiring original syslog log data of a plurality of vehicle-mounted devices in a rail train, and clustering the original syslog log data according to event keywords corresponding to each vehicle-mounted device to obtain a plurality of key syslog log data; and for each piece of key syslog log data, extracting data features of the key syslog log data, and inputting the data features into a pre-trained safety evaluation model to obtain a safety evaluation result of the rail train. According to the method, the abnormal event behavior of the vehicle-mounted equipment can be accurately identified, the consumption of operation resources is reduced, and the information safety problem of each vehicle-mounted equipment in the running process of the rail train is solved.
Owner:CRRC ZHUZHOU ELECTRIC LOCOMOTIVE RESEARCH INSTITUTE CO LTD

Power terminal access attack behavior detection method and system based on multi-modal data fusion

The invention discloses a multi-modal data fusion-based power terminal access attack behavior detection method and system, and the method comprises the steps: collecting data through a specific collection tool, and carrying out the collection of four key indexes, namely, a traffic mode, a system log, signal strength and network topology; and an access security assessment detection model is constructed based on a Transform model of multi-modal feature fusion, and abnormal behaviors of the access terminal of the power Internet of Things platform are accurately identified. A system constructed according to the method comprises a collection unit, a processing unit, a behavior detection unit, a trust evaluation unit and a blocking unit, a deep learning algorithm is utilized to analyze multi-modal features, terminal behaviors are evaluated in combination with a trust evaluation mechanism, and trust levels are divided. According to the invention, an intelligent blocking rule strategy is provided for different abnormal behaviors, and the access safety and reliability of the electric power Internet of Things terminal are improved.
Owner:GUANGDONG POWER GRID CO LTD +1

Abnormal information dump method of embedded multi-core operating system

The invention discloses an abnormal information dump method of an embedded multi-core operating system, which comprises the following steps of: in an initialization process of an abnormal dump module, creating an abnormal information annular buffer area, and configuring an abnormal information dump mode at the same time; on the premise that the system log information with the abnormal information is output to the abnormal information annular buffer area, the printk interface is re-hooked and defined; when a system is abnormal, an abnormal event is converted into an abnormal vector, an abnormal processing function is called, the output content of the abnormal processing function is transmitted through a printk interface, the abnormal information annular buffer area is output to a specified address or file according to a configured abnormal information unloading mode, and one-time abnormal information annular buffer area emptying operation is achieved. The problem that the system debugging information is difficult to obtain under the condition that no serial port exists in an actual application environment is solved.
Owner:EAST CHINA INST OF COMPUTING TECH

Kubernetes-based GPU fault automatic monitoring method and system

The invention discloses a Kubernetes-based GPU fault automatic monitoring method and system, and relates to the technical field of computer monitoring, and the method comprises the steps: running a GPU detection program at each node; indexes are collected, wherein the indexes comprise XID and / or SXID error events in the system logs and the driving state and the equipment running state obtained based on the NVML; standardizing the indexes into an index data structure; generating a fault judgment result associated with the node identifier and the GPU equipment identifier according to a preset evaluation rule; and when the data is abnormal, the data is mapped as a Node Condition and / or reported to a Kubernetes Event, and a Prometheus acquisition interface is exposed to be pulled and stored. Through the technical scheme of the invention, GPU fault automatic identification and card level positioning are realized, cluster perceptibility and alarm traceability are enhanced, manual troubleshooting cost is reduced, and cluster stability is improved.
Owner:HANGZHOU HARMONYCLOUD TECH CO LTD

Multi-source fusion log compression method and device for anomaly detection

ActiveCN119420534BBridging the Semantic Gapreduce dependenceSecuring communicationDomain nameAlgorithm
This application discloses a multi-source fusion log compression method and apparatus for anomaly detection, belonging to the field of anomaly detection technology. The multi-source fusion log compression method for anomaly detection includes: generating an audit origination graph corresponding to the system audit log, an application origination graph corresponding to the application log, and a domain name origination graph corresponding to the domain name system log based on the system audit log corresponding to the electronic device, the application log corresponding to the target application in the electronic device, and the domain name system log corresponding to the electronic device; fusing the domain name origination graph into the application origination graph based on the domain name nodes in the application origination graph to obtain a sub-fused origination graph; fusing the audit origination graph into the sub-fused origination graph based on the event nodes in the audit origination graph to obtain a fused origination graph; and performing anomaly detection based on the fused origination graph. The multi-source fusion log compression method for anomaly detection in this application can alleviate the problems of semantic gap and dependency explosion.
Owner:INST OF ADVANCED TECH UNIV OF SCI & TECH OF CHINA

System and method for secure proactive activation of a disaster recovery system

A proactive activation system and method perform secure proactive activation of a disaster recovery system of a business. The proactive activation system comprises a log correlation system, a scoring system, and a disaster recovery activation system. The log correlation system collects logs from a computing device used in the business by a user, cross-correlates the collected logs, and determines a potential system failure as a disaster indicator. The scoring system assigns a score to the disaster indicator. In the case of the disaster indicator score being greater than a predetermined threshold, the disaster recovery activation system generates a control signal to activate the disaster recovery system. The method implements the proactive activation system.
Owner:SAUDI ARABIAN OIL CO

System log anomaly detection method based on Gimma model and medium

The invention discloses a system log anomaly detection method based on a Gimma model and a medium, and belongs to the field of log anomaly detection.The system log anomaly detection method comprises the steps that log messages are preprocessed to obtain a log message set; performing analysis processing by using a bidirectional parallel tree algorithm to obtain structured log data; a Gimma model is trained through the serialized log set, so that the model can predict subsequent logs according to a given log sequence; a log set containing normal and abnormal data is used for evaluating the effect of the model, and if an actual log key is in the first k keys predicted by the model, it is judged that the actual log key is normal; if the actual log key is not in the first k keys predicted by the model, judging that the log key is abnormal; through the LoRA low-rank fine tuning method, the time cost of model training is reduced. According to the method, various public log data sets can be supported, the anomaly detection task can be completed on log data of different structures, and the preprocessing precision and the anomaly detection precision can be effectively improved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Differentiated de-identification methods, systems, program products and devices for system logs

This disclosure provides a differentiated de-identification method, system, program product, and apparatus for system logs. The method includes receiving log events and performing metadata completion and parsing to obtain structured fields and / or unstructured text fragments; identifying and classifying sensitive information in the structured fields and / or unstructured text fragments to generate a sensitivity mapping table containing the fields or fragments and their corresponding sensitivity types and levels; constructing an access context; based on the sensitivity mapping table and the access context, performing matching and decision-making according to a preset multi-dimensional strategy to generate a de-identification plan for each field or fragment; performing corresponding de-identification actions on the corresponding fields or fragments in the log events according to the de-identification plan to obtain de-identified log data; outputting the de-identified log data and generating an audit log containing strategy hit information and field-level action records.
Owner:HEBEI HAPPY CONSUMPTION FINANCE CO LTD

Project acceptance effect evaluation method and system based on data analysis

The invention discloses a project acceptance effect evaluation method and system based on data analysis, and relates to the technical field of data analysis, and the method comprises the steps: extracting acceptance contacts from a project acceptance conclusion, constructing an invertible path set corresponding to each contact, theoretically defining a process behavior record or data evidence which should be left when the invertible path set actually exists, and evaluating the project acceptance effect. And empirical verification is carried out based on data sources such as system logs, process records and document archiving. If it is found that the path is missing, incomplete or conflicted, the contact is marked as a structural support missing contact. The method further integrates the number and importance of the distortion contacts and the coverage range of the distortion contacts in the acceptance conclusion to form an authenticity evaluation result of the acceptance effect. According to the method, based on structural path inversion and support integrity judgment, a counterfeit acceptance conclusion lacking a process basis can be effectively identified, scientificity and credibility of acceptance work are improved, and the problem that an acceptance result is inconsistent with an actual project state and is difficult to identify is solved.
Owner:HEFEI XIANGFEI PRODUCTIVITY PROMOTION CENT CO LTD

Subway signal system log intelligent analysis method, device, equipment and medium

PendingCN121644207AAlarmsSecuring communicationData aggregatorNetwork Compartment
The invention relates to a subway signal system log intelligent analysis method, device and equipment and a medium. The method is realized by constructing a multi-stage security architecture of an internal security network-network isolation region DMZ-public network, firstly, log data preprocessing and encryption are carried out in the network isolation region DMZ, secondly, reverse communication is blocked through unidirectional transmission hardware, and then, accurate analysis is carried out by utilizing a large model association version demand and log keywords, so that the log data encryption is realized. And finally, establishing a global knowledge base to mine common hidden dangers. Compared with the prior art, the method has the advantages that on the premise that absolute safety of the core production network is ensured, log data aggregation of the whole road network is achieved, and intelligent real-time analysis and early warning are carried out.
Owner:CASCO SIGNAL LTD

APT attack behavior identification method and system based on causal sequence embedding

The invention provides an APT attack behavior identification method and system based on causal sequence embedding. The method comprises the following steps: generating a time sequence event stream sorted according to time for a multi-source system log; based on the generated time sequence event flow, constructing a directed causal traceability graph, extracting attack related sub-graphs through graph search, and abstractly combining nodes with isomorphic structures to obtain simplified attack sub-graphs; converting the simplified attack sub-graph into a triple sequence sorted according to time, and generating a time sequence attack event sequence; carrying out abstraction processing and sample balance on the time sequence attack event sequence, and inputting the time sequence attack event sequence into a Transform model for training to obtain an attack detection model; and predicting an input event sequence by using the attack detection model, and identifying an APT attack behavior. The method can improve the accuracy and interpretability of APT attack detection by fusing causal graph modeling and deep learning technologies, and is suitable for hidden attack behavior recognition tasks in a large-scale log environment.
Owner:CSG EHV POWER TRANSMISSION

A syslog log automatic parsing method

This invention discloses an automatic Syslog log parsing method, comprising: collecting Syslog log messages; removing header information and retaining the message body content, parsing it into a string set, and determining a delimiter; using the delimiter to segment the Syslog log message body content into a string array; confirming whether a key exists in the string array; classifying the strings, if a key exists, classifying the logs according to the key and data length; if no key exists, checking the data type and classifying the logs according to the array length and data type; automatically generating parsing templates for different log categories, using the parsing templates to extract the value corresponding to each field, and performing subsequent field mapping or transformation normalization processing. Using this invention, regular expression parsing of Syslog logs can be generated quickly, saving significant manpower.
Owner:HUANENG LANCANG RIVER HYDROPOWER CO LTD +1

Power generation side industrial control system network security intrusion detection data set updating and verification method

The invention discloses a method for updating and verifying a network security intrusion detection data set of a power generation side industrial control system. The method comprises the following steps: acquiring a target physical fault corresponding to key physical equipment to be protected in the power generation side industrial control system; based on the control logic, the operation characteristic and the safety interlocking rule of the key physical equipment, constructing a fault transmission model used for describing the causal relationship between the abnormal control signal and the target physical fault; by taking the target physical fault as an end point, according to the fault transfer model, calculating to obtain a multi-modal attack data sequence required for triggering the target physical fault; simulating the multi-modal attack data sequence based on the power generation process simulation model, detecting the state change of the key physical equipment in the simulation process, and when a target physical fault is successfully triggered, obtaining multi-modal simulation data including the network flow, the system log and the physical state parameter of the power generation side industrial control system, and adding the multi-modal simulation data to an intrusion detection data set as a marked effective intrusion sample.
Owner:HUANENG POWER INT INC +1

Log analysis method and system based on large language model and self-learning knowledge

The embodiment of the invention provides a log analysis method and system based on a large language model and self-learning knowledge, and relates to the technical field of log analysis. The analysis method comprises the following steps: obtaining a new log to be analyzed; judging whether the new log can be matched with a template in the cache tree or not; under the condition that the new log can be matched with the template in the cache tree, obtaining the template matched with the new log; analyzing the new log according to the matched template, and outputting an analysis result; when it is judged that the new log cannot be matched with the template in the cache tree, triggering the large language model to analyze the new log, and generating a new template; and storing the new template in the cache tree, and returning to the step of obtaining the new log to be analyzed. According to the method, under the condition that data labeling and manual rule maintenance are not needed, the log analysis efficiency is improved, efficient and extensible analysis and analysis of various system logs are achieved, and the effectiveness and practicability of downstream tasks such as anomaly detection and fault diagnosis are improved.
Owner:ANHUI NORMAL UNIV

A real-time abnormality sensing method for an automatic protection system of a high-speed train

This invention discloses a real-time anomaly detection method for a high-speed train automatic protection system (ATP). Using real-time operational data from all ATP sub-devices as the analysis object, it achieves the memorization of ATP system log sequences and correlation analysis of log information through an encoding / decoding network. A multi-head attention mechanism is introduced to process the operational data of each device in a hierarchical manner, addressing the concurrent data generation requirements of multiple devices. Finally, the data is systematically aggregated to accurately capture abnormal behavior of any sub-device in real time, comprehensively and promptly determining the specific fault location at the smallest granularity.
Owner:SIGNAL & COMM RES INST OF CHINA ACAD OF RAILWAY SCI +3

Service fault detection method and system

The invention provides a service fault detection method and system, and relates to the technical field of code fault detection, and the method comprises the steps: analyzing a system log, and obtaining log data related to an error; determining whether the error reporting event described by the log data is a candidate error reporting event of which the risk degree meets a preset requirement or not; in response to the fact that the error reporting event is a candidate error reporting event, acquiring system operation data in a specified time period; determining whether the candidate error reporting event is a target error reporting event representing service code defects in a system or not based on the log data and system operation data in a specified time period; in response to the fact that the error reporting event is a target error reporting event, preliminary fault positioning is carried out based on the log data and system operation data in a specified time period, and a preliminary fault positioning result is obtained; and performing secondary fault positioning in a service code data source at least based on the preliminary fault positioning result, and determining a target service code causing the target error reporting event.
Owner:CSC FINANCIAL CO LTD

A method for detecting log anomalies in a power dispatch automation system

This invention relates to the field of electrical digital data processing technology and discloses a method for detecting log anomalies in power dispatch automation systems. The method includes: constructing a fixed-depth parse tree using historical log data and extracting log templates based on word segmentation similarity; converting power dispatch domain knowledge into vectors and storing them in a knowledge base; retrieving knowledge related to the log templates from the knowledge base, inputting it into a large model for anomaly detection, and labeling the templates; after real-time log preprocessing, inheriting template labels by matching the template library with the parse tree and using an adaptive threshold strategy, triggering online template updates for unmatched logs; aggregating the context and high-frequency parameters of the abnormal logs, constructing dynamic prompt words based on the retrieval results and template feature weights, inputting them into a large model for multi-dimensional root cause analysis, and optimizing the template mechanism based on the prompt words. This method solves the problems of difficult manual maintenance, weak generalization ability, and slow detection speed in existing technologies, achieving efficient detection, high accuracy, and adaptability.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD QUZHOU POWER SUPPLY CO

A malicious attack behavior detection method based on a transformer and a GNN

This invention provides a method for detecting malicious attacks based on Transformer and GNN, comprising: acquiring system log data to be detected, and constructing a source graph based on the system log data to obtain a source graph; performing word embedding generation processing on the source graph to obtain word embeddings; and inputting the source graph and the word embeddings into a pre-trained malicious attack detection model to obtain detection results; wherein the malicious attack detection model is a Transformer and GNN-based model. This invention can capture local and global graph features in the source graph, effectively improving the accuracy and real-time performance of APT attack detection, enhancing the adaptability and scalability of the system, and has significant practical value.
Owner:BEIJING JIAOTONG UNIV

A block count-based CTC system log adaptive segmentation method

This invention discloses an adaptive segmentation method and system for system logs based on block counting, belonging to the field of data processing technology for rail transit signaling systems. Addressing the problems of easily corrupted logic, uneven segmentation sizes, low processing efficiency, and poor encoding compatibility caused by the special structure of CTC system logs ("text lines + hexadecimal lines"), this invention first defines and identifies the smallest logical block unit in the log; then, it performs adaptive parameter calculation based on block counting to determine the theoretical number of blocks each segmented file can hold; finally, it controls the writing process through dynamic threshold judgment, precisely controlling the size of individual files while ensuring the absolute integrity of logical blocks. This method and system effectively solve the core defects such as the splitting of logical units, excessive file size deviation, and excessive processing time, achieving high-fidelity and high-efficiency segmentation of logs at the 100GB level, providing a high-quality data foundation for subsequent fault tracing and intelligent operation and maintenance.
Owner:SIGNAL & COMM RES INST OF CHINA ACAD OF RAILWAY SCI +3

SOC serial port log storage method, system and device and storage medium

The embodiment of the invention relates to the technical field of automobile communication, and discloses an SOC serial port log storage method, system and device and a storage medium, and the method comprises the steps: starting an MCU, and executing serial port RX receiving initialization; the MCU controls the SOC to start; after the SOC is started, all IP cores in the SOC respectively output log data to a serial port TX of the SOC, and a syslog service of an ARM operating system is started; the MCU receives log data output by the SOC through the serial port TX through the serial port RX and caches the log data to the RAM; the MCU and the ARM core of the SOC perform handshake to verify a syslog service state; and the MCU sends the log data cached in the RAM to an ARM core of the SOC through the Ethernet, and stores the log data in the SOC through a syslog service. The MCU receives the log data, sent by the serial port TX of the SOC, of all the heterogeneous cores through the serial port RX, then transmits the log data to the ARM core of the SOC through the Ethernet, and finally stores the log data through the syslog service, so that the ARM core obtains the log data of all the heterogeneous cores through the external peripheral, and stores the log data through the syslog service.
Owner:HUIZHOU DESAY SV AUTOMOTIVE

A system fault diagnosis method, device, equipment and storage medium

Embodiments of the present application relate to the technical field of computer, in particular to a system fault diagnosis method, device and equipment and storage medium, aiming at quickly diagnosing and positioning the cause of system fault. The method comprises: classifying and extracting fault data from system log data to obtain multiple different types of fault data; obtaining component state information of all fault components according to the multiple different types of fault data; respectively performing fault correlation analysis on different types of fault components through corresponding fault diagnosis modules according to the component state information of the fault components to obtain multiple fault causes; and comprehensively analyzing the multiple fault causes based on a two-line solidification rule to obtain a final fault cause.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Advertisement creation failure reason diagnosis method, system, equipment and medium

The invention discloses an advertisement creation failure reason diagnosis method, system and device and a medium. The method specifically comprises the steps of collecting multi-source data in an advertisement creation process; constructing a knowledge graph of the advertisement creation process based on the multi-source data; node embedding and relation reasoning are carried out on the knowledge graph through a graph neural network, and associated features in the advertisement creation process are extracted; based on the association features, performing cross-modal alignment and fusion on the text description, the system log and the user operation video by using a Transform model, and generating a fine-grained reason diagnosis result of the failed task; and constructing a success rate prediction model according to historical data and real-time features based on the associated features and the fine-grained reason diagnosis result, and dynamically adjusting advertisement budget allocation based on a prediction result of the success rate prediction model. According to the method, automatic and intelligent diagnosis of the advertisement creation failure reason is realized, the efficiency and accuracy of advertisement creation success rate analysis and optimization are improved, and advertisement putting decision scientization is facilitated.
Owner:ANHUI SANQI JIYU NETWORK TECH CO LTD

Visualization Of System Logs Using Time Curves

A computer-implemented method is presented for visualizing log data captured in a computer system. The method includes: receiving a plurality of log records, where each log record includes a severity indicator; grouping log records in the plurality of log records into groups of log records, such that log records in a given group of records are chronological; for each group of log records, extracting one or more templates from a given group of log records, where each template is comprised of a text string representing log records in the given group of log records; for each group of log records, computing a similarity measure between a given group of log records and the remaining groups of log records; and visualizing the groups of log records by projecting each group of log records onto a multi-dimensional plane based on the similarity measures for the groups of log records and connecting projections for the groups of log records in chronological order using a line.
Owner:DYNATRACE LLC

Attack identification method and system of operating system, computer equipment and medium

The invention provides an attack recognition method and system of an operating system, computer equipment and a medium, and belongs to the technical field of network security, the method comprises the following steps: collecting system logs from the operating system, an application program and network equipment, after preprocessing, generating a log text high-dimensional semantic vector by using a pre-training unsupervised semantic coding model, and storing the log text high-dimensional semantic vector in a database; the features are reduced into low-dimensional features through an auto-encoder; mapping system entities into nodes, mapping log interaction relationships into directed edges, and constructing a system traceability graph in combination with low-dimensional features; then, node high-dimensional representation is learned by using an enhanced graph attention network (EGAT), a bidirectional gating loop unit is input after time sequence serialization to capture behavior time sequence dependence, and a node anomaly classification probability is output; and finally, the federated server generates a global model to realize multi-system collaborative detection under privacy protection. According to the method, the complex attack chain can be accurately identified, the detection precision and the data privacy are considered, and the real-time intrusion detection and security response requirements of a large-scale network environment are met.
Owner:SHANDONG UNIV OF TECH

Utilization of contextual metadata for identifying network operational data telemetry and events

Techniques and mechanisms for utilization of contextual metadata for identifying network operation telemetry and events are provided. Contextual metadata is applied to router resource objects associated with network resources operating via network routers to and from user computing devices or systems. Telemetry data associated with operation of the network resources is streamed to a telemetry collector. Event logs including the contextual metadata may be stored locally with the user's devices or systems for viewing or may be sent remotely to a remote syslog server. At the telemetry collector or the syslog server, the contextual metadata is used to separate telemetry data and / or event logs on network resource identity basis so that operation of the network resources may be analyzed and reported.
Owner:CISCO TECHNOLOGY INC