CN107506252A - Information system error configurations detecting system and method based on configuration item incidence relation - Google Patents

Information system error configurations detecting system and method based on configuration item incidence relation Download PDF

Info

Publication number
CN107506252A
CN107506252A CN201710683438.8A CN201710683438A CN107506252A CN 107506252 A CN107506252 A CN 107506252A CN 201710683438 A CN201710683438 A CN 201710683438A CN 107506252 A CN107506252 A CN 107506252A
Authority
CN
China
Prior art keywords
configuration
configuration item
incidence relation
item
rule
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201710683438.8A
Other languages
Chinese (zh)
Inventor
向华伟
吕垚
张雪坚
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Information Center of Yunnan Power Grid Co Ltd
Original Assignee
Information Center of Yunnan Power Grid Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Information Center of Yunnan Power Grid Co Ltd filed Critical Information Center of Yunnan Power Grid Co Ltd
Priority to CN201710683438.8A priority Critical patent/CN107506252A/en
Publication of CN107506252A publication Critical patent/CN107506252A/en
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/07Responding to the occurrence of a fault, e.g. fault tolerance
    • G06F11/0703Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation
    • G06F11/0751Error or fault detection not based on redundancy
    • G06F11/0763Error or fault detection not based on redundancy by bit configuration check, e.g. of formats or tags
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/07Responding to the occurrence of a fault, e.g. fault tolerance
    • G06F11/0703Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation
    • G06F11/0793Remedial or corrective actions
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/30Monitoring
    • G06F11/32Monitoring with visual or acoustical indication of the functioning of the machine
    • G06F11/324Display of status information
    • G06F11/327Alarm or error message display
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0631Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/085Retrieval of network configuration; Tracking network configuration history
    • H04L41/0853Retrieval of network configuration; Tracking network configuration history by actively collecting configuration information or by backing up configuration information
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0866Checking the configuration

Abstract

The invention provides a kind of information system error configurations detecting system based on configuration item incidence relation, including configuration acquisition module;Configuration association relationship analysis module;Configure detected rule generation module;Arrangement abnormalities detection module;Related management module.A kind of information system error configurations detecting system and method based on configuration item incidence relation provided by the invention, based on information system configuration association relation, training is configured using given great amount of samples, form configuration item incidence relation and detected rule, by excavating the incidence relation between each component configuration item of information system and carrying out configuration item crosscheck using this association, it is capable of the error configurations of effective detection system.The present invention can prevent mistake, and be capable of the use of automatic detection error configurations by intellectual analysis, detection error configurations and it will be appreciated that the environment residing for software carries out automatically configuring abnormal detection simultaneously.The present invention is applied to analyze system configurations all at present.

Description

Information system error configurations detecting system and method based on configuration item incidence relation
Technical field
The invention belongs to Internet video to play evaluation and test field, specifically a kind of information based on configuration item incidence relation System mistake configuration detecting system, while additionally provide the method that the system carries out error configurations detection.
Background technology
At present, as software system function becomes increasingly abundant, using more flexibly, its configuration becomes more complicated so that just True configuration software system turns into extremely complex work, and system configuration easily malfunctions(For example, MySQL server and The each software of Apache Server containing the configuration item of more than 200, can not ensure that this more than 200 configuration item configures Correctly), therefore because failure caused by error configurations just turns into a key issue, this failure would generally be brought more tight Economic loss, potential safety hazard and the functional fault of weight.
In addition, the diagnosis and reparation for failure caused by configuration item mistake need across software in itself and its operation ring Analyzed in border so that analysis process is difficult and expensive.For these reasons, it is reduced to be lost caused by configuration error It is minimum, it is necessary to automatic before application configuration check that one assembles and installs, find in advance it is potential mistake is set, repaiied in time It is multiple.But currently used most of configuration files lack abundant structurally and semantically information compared with programming language, it is difficult to straight Tap into the error analysis of row complexity.
The content of the invention
The technical problem to be solved in the present invention, it is to provide a kind of information system error configurations based on configuration item incidence relation Detecting system, the system are devised based on information system based on the incidence relation and its running environment that are implied between configuration item The configuration error detecting system technology of configuration association relation, training is configured using given great amount of samples, form configuration item association Relation and detected rule, by excavating the incidence relation between each component configuration item of information system and being matched somebody with somebody using this association Item crosscheck is put, is capable of the error configurations of effective detection system.
In order to solve the above technical problems, the technical solution used in the present invention is:
A kind of information system error configurations detecting system based on configuration item incidence relation, including:
Configure acquisition module:The original configuration information of software for gathering on-line system, and the configuration information collected is passed Give Command Line Parsing template and carry out parsing conversion, the configuration after conversion is recorded and is saved in and is locally configured in storehouse;
Configuration association relationship analysis module:The configuration item record of different software in storehouse is locally configured for reading, excavates and learns Incidence relation between configuration item;
Configure detected rule generation module:Closed using the association between the software configuration item of configuration association relationship analysis module generation System and data set training generation correlation rule;
Arrangement abnormalities detection module:It is complete in storehouse to being locally configured according to the correlation rule that configuration detected rule generation module generates Portion's configuration is detected, the abnormal generation alarm found to detection;
Related management module:For providing alarm displaying, detected rule and template types management, original configuration parsing template pipe Reason, configuration acquisition management and configuration search such as check at the function.
As the restriction to configuring acquisition module:It is described configuration acquisition module by client proxy, ssh orders execution, The modes such as configuration file parsing, SNMP gather original configuration information;Simultaneously by original configuration Information application Command Line Parsing template Parsed, the configuration for being converted to key-value forms is recorded and is saved in and is locally configured in storehouse.
As the restriction to configuration association relationship module:The configuration association relationship analysis module is primarily based on predefined Configuration Type template, match, learn and verify the type of each configuration item in repository;It is then based on the configuration item learnt Type, type identical software configuration item and system environments configuration item are established into preliminary incidence relation;
The configuration association analysis module is on the basis of the preliminary incidence relation based on type, the association rule mining of optimizing application Algorithm for Training correlation model, further excavate incidence relation between configuration item.
As the restriction to this configuration detected rule generation module:The configuration detected rule generation module is first according to pre- The content application parallel computing of matching is inserted the detected rule template by the detected rule template of setting, quick to form bag Containing effective regular and invalid regular detected rule superset;Then detected rule superset is directed to, with reference to repository, application configuration item The confidence level of value, the support of configuration association relation and configuration item value information entropy remove most of invalid rule, reduce wrong report Rate.
As the restriction to arrangement abnormalities detection module:The arrangement abnormalities detection module is configured according to being locally configured in storehouse List Names, configuration item type, the frequency of occurrences and value numbering frequency of configuration detected rule and Configuration Values carry out configuration key name Claim mistake, Configuration Values type error, associated errors and the detection of suspicious Configuration Values, form configuration item exception record.
As the restriction to other management modules:Other described management modules are detecting original configuration change or are passing through institute It is automatic to call arrangement abnormalities detection when stating the information system error configurations detecting system based on configuration item incidence relation and issuing configuration Module is detected, and prevents to issue the alarm of the diversified forms such as configuration or configuration change offer sound, light, short message to mistake, also Configuration change can be cancelled according to the action policy pre-seted.
Present invention also offers a kind of system is detected using the above-mentioned information system error configurations based on configuration item incidence relation The method that system carries out system mistake configuration detection, including the following steps carried out successively:
First, system software configuration collection:Acquisition is configured to the software merit rating of on-line system by configuring acquisition module, and will The information storage of acquisition is to being locally configured in storehouse;
2nd, configuration item incidence relation is analyzed:Read and analyzed by configuration relation association analysis module and difference in storehouse is locally configured A large amount of configuration items record of software, excavates and learns the incidence relation between configuration item;
3rd, incidence relation rule generation:Detected rule generation module is configured by the incidence relation in step 2, with reference to data set Training generation correlation rule, and the difficulty generated by the simplified correlation rule of application rule;
4th, configuration item abnormality detection:Arrangement abnormalities detection module is matched somebody with somebody to local according to training the correlation rule of generation in step 3 The whole configuration items put in storehouse carry out configuration item Name Error, configuration association mistake, Configuration Values type error and suspicious Configuration Values Detection, the abnormal generation alarm to discovery;
5th, configuration item error handle:Related management module by step 4 because the alarm generated extremely carries out alarm displaying, together When template is parsed to detected rule and template types, original configuration, configuration collection is managed pipe, and carry out configuring search and look into See.
As the restriction to step 1:Acquisition module is configured in the step 1 to hold by client proxy, ssh orders The modes such as row, configuration file parsing, SNMP gather original configuration information;Simultaneously by original configuration Information application Command Line Parsing mould Plate is parsed, and the configuration for being converted to key-value forms is recorded and is saved in and is locally configured in storehouse.
As the restriction to step 2:The step 2 includes the following steps carried out successively:
A1)Configuration association relationship analysis module is primarily based on predefined Configuration Type template, matches, learns and verifies repository In each configuration item type;
A2)Configuration association relationship analysis module is based on the configuration item type learnt, by type identical software configuration item with being System environment configurations item establishes preliminary incidence relation;
A3)Configuration association analysis module is on the basis of the preliminary incidence relation based on type, association rule mining algorithms instruction Practice correlation model, further excavate incidence relation between configuration item, form configuration item association relation model.
As the restriction to step 3:The step 3 includes the following steps carried out successively:
B1 detected rule generation module) is configured according to the detected rule template pre-seted, by the content application parallel computation of matching Technology inserts template, quick to be formed comprising effective regular and invalid regular detected rule superset;
B2 detected rule superset) is directed to, with reference to repository, confidence level, the support of configuration association relation of application configuration entry value And configuration item value information entropy removes most of invalid rule, reduces rate of false alarm, formed to comprising effective regular configuration detection Rule base;
As the restriction to step 4:Arrangement abnormalities detection module is according to being locally configured configuration item title in storehouse in the step 4 Inventory, configuration item type, configuration detected rule and the frequency of occurrences of Configuration Values and value numbering frequency etc. utilize and configure detected rule Effective rule in storehouse carries out configuration item Name Error, Configuration Values type error, associated errors and the detection of suspicious Configuration Values, and shape Into configuration item exception record.
As the restriction to step 5:Other management modules are detecting original configuration change or passed through in the step 5 It is automatic to call arrangement abnormalities inspection when the information system error configurations detecting system based on configuration item incidence relation issues configuration Survey module to be detected, prevent to issue the alarm of the diversified forms such as configuration or configuration change offer sound, light, short message to mistake, Configuration change can also be cancelled according to the action policy pre-seted.
As a result of above-mentioned technical scheme, compared with prior art, acquired technological progress is the present invention:
(1)It is the information system error configurations detecting system application software based on configuration item incidence relation of the present invention and software, soft Incidence relation between part and operating system environment information, operating system and physical environment, realize the intersection of configuration item validity Checking, to avoid the configuration of mistake;
(2)Application configuration error detection rule template technology simplifies carries out detected rule based on data mining and machine learning techniques Computation complexity during generation so that the identification of configuration error detected rule and generation energy under the scene of more software magnanimity configuration items It is enough to complete to train and generate within the acceptable time;
(3)The information system error configurations detecting system based on configuration item incidence relation of the present invention supports real-time information technoloy equipment configuration Change monitoring and error detection, the configuration change carried out for the system included using the present invention can be prevented under error configurations Hair, it can cancel using the correct configuration of the last time for the error configurations carried out on information technoloy equipment, prop up simultaneously in real time The prompting of suspicious configuration change is held, error configurations recall rate reaches more than 90%, and maximizing reduces the exception caused by error configurations Downtime.
A kind of information system error configurations detecting system based on configuration item incidence relation provided by the invention in summary And method, based on information system configuration association relation, training is configured using given great amount of samples, forms configuration item incidence relation With detected rule, by excavate the incidence relation between each component configuration item of information system and utilize it is this association carry out configuration item Crosscheck, it is capable of the error configurations of effective detection system.The present invention passes through intellectual analysis, detection error configurations and energy simultaneously Enough understand that the environment residing for software carries out automatically configuring abnormal detection, can prevent mistake, and can automatic detection mistake match somebody with somebody The use put.
The present invention is applied to analyze system configurations all at present.
The present invention is described in further detail below in conjunction with specific embodiment.
Brief description of the drawings
Fig. 1 is the theory diagram of the embodiment of the present invention 1.
Embodiment
A kind of information system error configurations detecting system based on configuration item incidence relation of embodiment 1
A kind of information system error configurations detecting system based on configuration item incidence relation is present embodiments provided, as shown in figure 1, It includes:
Configure acquisition module:The original configuration information of software for gathering on-line system, and the configuration information collected is passed Give Command Line Parsing template and carry out parsing conversion, the configuration after conversion is recorded and is saved in and is locally configured in storehouse.
Acquisition module is configured in the present embodiment and passes through client proxy, ssh orders execution, configuration file parsing, SNMP etc. Mode gathers original configuration information;Original configuration Information application Command Line Parsing template is parsed simultaneously, is converted to key- The configuration of value forms is recorded and is saved in and is locally configured in storehouse.
And the acquisition target of the present embodiment includes the network equipment, server, intermediate file, database, safety means etc. respectively Kind software systems.
Configuration association relationship analysis module:The configuration item record of different software in storehouse is locally configured for reading, excavates simultaneously Learn the incidence relation between configuration item.
Configuration association relationship analysis module in the present embodiment is operated based on following principles:It is primarily based on predefined Configuration Type template, match, learn and verify the type of each configuration item in repository.It is then based on the configuration learnt Item type, type identical software configuration item and system environments configuration item are established into preliminary incidence relation;
Last configuration association analysis module is on the basis of the preliminary incidence relation based on type, the association rule mining of optimizing application Algorithm(Apriori and FP-Growth)Correlation model is trained, further excavates incidence relation between configuration item.
Wherein, the predefined Configuration Type template of configuration association relationship module in the present embodiment, matches, learns and verify to match somebody with somebody The mode for putting the type of each configuration item in storehouse is carried out according to table 1:
Configure detected rule generation module:Closed using the association between the software configuration item of configuration association relationship analysis module generation System and data set training generation correlation rule.
Correlation rule in the present embodiment is generated as:First should by the content of matching according to the detected rule template pre-seted The detected rule template is inserted with parallel computing, quick formed surpasses comprising effective regular and invalid regular detected rule Collection;Then detected rule superset is directed to, with reference to repository, confidence level, the support of configuration association relation of application configuration entry value And configuration item value information entropy removes most of invalid rule, reduces rate of false alarm.
The detected rule superset formed in the present embodiment is as shown in table 2
Arrangement abnormalities detection module:It is complete in storehouse to being locally configured according to the correlation rule that configuration detected rule generation module generates Portion's configuration is detected, the abnormal generation alarm found to detection.
It is the step of abnormality detection in the present embodiment:According to be locally configured configuration item List Names in storehouse, configuration item type, Configure detected rule and Configuration Values the frequency of occurrences and value numbering frequency progress configuration item Name Error, Configuration Values type error, Associated errors and the detection of suspicious Configuration Values, form configuration item exception record.
Related management module:For providing alarm displaying, detected rule and template types management, original configuration parsing template Management, configuration acquisition management and configuration search such as check at the function.
The function of other management modules is in the present embodiment:Detecting original configuration change or by described based on configuration It is automatic to call arrangement abnormalities detection module to be examined when the information system error configurations detecting system of item incidence relation issues configuration Survey, prevent to issue the alarm of the diversified forms such as configuration or configuration change offer sound, light, short message to mistake, can also be according to default The action policy revocation configuration change put.
A kind of information system error configurations detection method based on configuration item incidence relation of embodiment 2
A kind of information system error configurations detection method based on configuration item incidence relation is present embodiments provided, based on embodiment A kind of 1 information system error configurations detecting system based on configuration item incidence relation is completed, and it is following including what is carried out successively Step:
First, system software configuration collection:Acquisition is configured to the software merit rating of on-line system by configuring acquisition module, and will The information storage of acquisition is to being locally configured in storehouse.
Acquisition module is configured in this step and passes through the side such as client proxy, ssh orders execution, configuration file parsing, SNMP Formula gathers original configuration information;Original configuration Information application Command Line Parsing template is parsed simultaneously, is converted to key- The configuration of value forms is recorded and is saved in and is locally configured in storehouse.
2nd, configuration item incidence relation is analyzed:Read and analyze by configuration relation association analysis module and be locally configured in storehouse A large amount of configuration items record of different software, excavates and learns the incidence relation between configuration item.
This step includes the following steps carried out successively:
Step 2 includes the following steps carried out successively:
A1)Configuration association relationship analysis module is primarily based on predefined Configuration Type template, matches, learns and verifies repository In each configuration item type(Type in this step is carried out also according to the table 1 in embodiment 1);
A2)Configuration association relationship analysis module is based on the configuration item type learnt, by type identical software configuration item with being System environment configurations item establishes preliminary incidence relation;
A3)Configuration association analysis module is on the basis of the preliminary incidence relation based on type, association rule mining algorithms (Apriori and FP-Growth)Correlation model is trained, further excavates incidence relation between configuration item, configuration item association is formed and closes It is model.
3rd, incidence relation rule generation:Configuration detected rule generation module passes through the incidence relation in step 2, binding number Generation correlation rule is trained according to collection, and passes through the regular difficulty for simplifying correlation rule and generating of application.
This step includes the following steps carried out successively:
B1 detected rule generation module) is configured according to the detected rule template pre-seted, by the content application parallel computation of matching Technology inserts template, quick to be formed comprising effective regular and invalid regular detected rule superset(The detection formed in this step Regular superset is carried out according to the table 2 in embodiment 1);
B2 detected rule superset) is directed to, with reference to repository, confidence level, the support of configuration association relation of application configuration entry value And configuration item value information entropy removes most of invalid rule, reduces rate of false alarm, formed to comprising effective regular configuration detection Rule base;
4th, configuration item abnormality detection:Arrangement abnormalities detection module is matched somebody with somebody to local according to training the correlation rule of generation in step 3 The whole configuration items put in storehouse carry out configuration item Name Error, configuration association mistake, Configuration Values type error and suspicious Configuration Values Detection, the abnormal generation alarm to discovery.
Arrangement abnormalities detection module is according to being locally configured configuration item List Names in storehouse, configuration item type, match somebody with somebody in this step The frequency of occurrences and value numbering frequency of detected rule and Configuration Values etc. is put to carry out using the effective rule configured in detected rule storehouse Configuration item Name Error, Configuration Values type error, associated errors and the detection of suspicious Configuration Values, and form configuration item exception record.
5th, configuration item error handle:Related management module by step 4 because the alarm generated extremely carries out alarm exhibition Show, while are managed by pipe, and carries out configuration and searches for detected rule and template types, original configuration parsing template, configuration collection Rope is checked.
Other management modules are detecting original configuration change or are being based on configuration item incidence relation by described in this step Information system error configurations detecting system when issuing configuration, it is automatic to call arrangement abnormalities detection module to be detected, under prevention It is transported to the alarm of the diversified forms such as the configuration change offer sound, light, short message put or to mistake, additionally it is possible to according to the action pre-seted Strategy revocation configuration change.

Claims (12)

1. a kind of information system error configurations detecting system based on configuration item incidence relation, it is characterised in that it includes:
Configure acquisition module:The original configuration information of software for gathering on-line system, and the configuration information collected is passed Give Command Line Parsing template and carry out parsing conversion, the configuration after conversion is recorded and is saved in and is locally configured in storehouse;
Configuration association relationship analysis module:The configuration item record of different software in storehouse is locally configured for reading, excavates and learns Incidence relation between configuration item;
Configure detected rule generation module:Closed using the association between the software configuration item of configuration association relationship analysis module generation System and data set training generation correlation rule;
Arrangement abnormalities detection module:It is complete in storehouse to being locally configured according to the correlation rule that configuration detected rule generation module generates Portion's configuration is detected, the abnormal generation alarm found to detection;
Related management module:For providing alarm displaying, detected rule and template types management, original configuration parsing template pipe Reason, configuration acquisition management and configuration search such as check at the function.
2. a kind of information system error configurations detecting system based on configuration item incidence relation according to claim 1, its It is characterised by:The configuration acquisition module is adopted by modes such as client proxy, ssh orders execution, configuration file parsing, SNMP Collect original configuration information;Original configuration Information application Command Line Parsing template is parsed simultaneously, is converted to key-value lattice The configuration of formula is recorded and is saved in and is locally configured in storehouse.
3. a kind of information system error configurations detecting system based on configuration item incidence relation according to claim 1 or 2, It is characterized in that:The configuration association relationship analysis module is primarily based on predefined Configuration Type template, matches, learns and tests Demonstrate,prove the type of each configuration item in repository;The configuration item type learnt is then based on, by type identical software merit rating Item establishes preliminary incidence relation with system environments configuration item;
The configuration association analysis module is on the basis of the preliminary incidence relation based on type, the association rule mining of optimizing application Algorithm for Training correlation model, further excavate incidence relation between configuration item.
4. a kind of information system error configurations detecting system based on configuration item incidence relation according to claim 1 or 2, It is characterized in that:The configuration detected rule generation module first should by the content of matching according to the detected rule template pre-seted The detected rule template is inserted with parallel computing, quick formed surpasses comprising effective regular and invalid regular detected rule Collection;Then detected rule superset is directed to, with reference to repository, confidence level, the support of configuration association relation of application configuration entry value And configuration item value information entropy removes most of invalid rule, reduces rate of false alarm.
5. a kind of information system error configurations detecting system based on configuration item incidence relation according to claim 1 or 2, It is characterized in that:The arrangement abnormalities detection module according to be locally configured configuration item List Names in storehouse, configuration item type, configuration Detected rule carries out configuration item Name Error, Configuration Values type error with value numbering frequency with the frequency of occurrences of Configuration Values, associated Mistake and the detection of suspicious Configuration Values, form configuration item exception record.
6. a kind of information system error configurations detecting system based on configuration item incidence relation according to claim 5, its It is characterised by:Other described management modules detect original configuration change or by the letter based on configuration item incidence relation It is automatic to call arrangement abnormalities detection module to be detected when breath system mistake configuration detecting system issues configuration, it is transported under prevention Put or the configuration change offer sound to mistake, the alarm of light, the diversified forms such as short message, can also be removed according to the action policy pre-seted Sell configuration change.
A kind of 7. information system error configurations detection method based on configuration item incidence relation, based on any in claim 1 to 6 Information system error configurations detecting system based on configuration item incidence relation described in one is completed, it is characterised in that including according to The following steps of secondary progress:
First, system software configuration collection:Acquisition is configured to the software merit rating of on-line system by configuring acquisition module, and will The information storage of acquisition is to being locally configured in storehouse;
2nd, configuration item incidence relation is analyzed:Read and analyzed by configuration relation association analysis module and difference in storehouse is locally configured A large amount of configuration items record of software, excavates and learns the incidence relation between configuration item;
3rd, incidence relation rule generation:Detected rule generation module is configured by the incidence relation in step 2, with reference to configuration item Data set training generation correlation rule, and the difficulty generated by the simplified correlation rule of application rule;
4th, configuration item abnormality detection:Arrangement abnormalities detection module is matched somebody with somebody to local according to training the correlation rule of generation in step 3 The whole configuration items put in storehouse carry out configuration item Name Error, configuration association mistake, Configuration Values type error and suspicious Configuration Values Detection, the abnormal generation alarm to discovery;
5th, configuration item error handle:Related management module by step 4 because the alarm generated extremely carries out alarm displaying, together When template is parsed to detected rule and template types, original configuration, configuration collection is managed, and carry out configuring search and check.
8. a kind of information system error configurations detection method based on configuration item incidence relation according to claim 7, its It is characterised by:Acquisition module is configured in the step 1 and passes through client proxy, ssh orders execution, configuration file parsing, SNMP Original configuration information is gathered etc. mode;Original configuration Information application Command Line Parsing template is parsed simultaneously, is converted to The configuration of key-value forms is recorded and is saved in and is locally configured in storehouse.
9. a kind of information system error configurations detection method based on configuration item incidence relation according to claim 8, its It is characterised by:The step 2 includes the following steps carried out successively:
A1)Configuration association relationship analysis module is primarily based on predefined Configuration Type template, matches, learns and verifies repository In each configuration item type;
A2)Configuration association relationship analysis module is based on the configuration item type learnt, by type identical software configuration item with being System environment configurations item establishes preliminary incidence relation;
A3)Configuration association analysis module is on the basis of the preliminary incidence relation based on type, association rule mining algorithms instruction Practice correlation model, further excavate incidence relation between configuration item, form configuration item association relation model.
10. a kind of information system error configurations detection method based on configuration item incidence relation according to claim 9, its It is characterised by:The step 3 includes the following steps carried out successively:
B1 detected rule generation module) is configured according to the detected rule template pre-seted, by the content application parallel computation of matching Technology inserts template, quick to be formed comprising effective regular and invalid regular detected rule superset;
B2 detected rule superset) is directed to, with reference to repository, confidence level, the support of configuration association relation of application configuration entry value And configuration item value information entropy removes most of invalid rule, reduces rate of false alarm, formed to comprising effective regular configuration detection Rule base.
11. a kind of information system error configurations detection method based on configuration item incidence relation according to claim 10, It is characterized in that:Arrangement abnormalities detection module is according to being locally configured configuration item List Names, configuration item in storehouse in the step 4 Type, configuration detected rule and the frequency of occurrences of Configuration Values and value numbering frequency etc. utilize the effective rule configured in detected rule storehouse Configuration item Name Error, Configuration Values type error, associated errors and the detection of suspicious Configuration Values are then carried out, and forms configuration item exception Record.
12. a kind of information system error configurations detection method based on configuration item incidence relation according to claim 11, It is characterized in that:Other management modules are being detected original configuration change or closed by described based on configuration item in the step 5 It is automatic to call arrangement abnormalities detection module to be detected when the information system error configurations detecting system of connection relation issues configuration, Prevent to issue configuration or the configuration change offer sound to mistake, the alarm of light, the diversified forms such as short message, additionally it is possible to according to pre-seting Action policy revocation configuration change.
CN201710683438.8A 2017-08-11 2017-08-11 Information system error configurations detecting system and method based on configuration item incidence relation Pending CN107506252A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201710683438.8A CN107506252A (en) 2017-08-11 2017-08-11 Information system error configurations detecting system and method based on configuration item incidence relation

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201710683438.8A CN107506252A (en) 2017-08-11 2017-08-11 Information system error configurations detecting system and method based on configuration item incidence relation

Publications (1)

Publication Number Publication Date
CN107506252A true CN107506252A (en) 2017-12-22

Family

ID=60690527

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201710683438.8A Pending CN107506252A (en) 2017-08-11 2017-08-11 Information system error configurations detecting system and method based on configuration item incidence relation

Country Status (1)

Country Link
CN (1) CN107506252A (en)

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109409748A (en) * 2018-10-29 2019-03-01 广东友元国土信息工程有限公司 A kind of check method and system of Evaluation for cultivated-land index relevance
CN112088364A (en) * 2018-06-29 2020-12-15 国际商业机器公司 Using a machine learning module to determine whether to perform error checking of a memory cell
WO2021104270A1 (en) * 2019-11-26 2021-06-03 中兴通讯股份有限公司 Configuration anomaly detection method, server and storage medium
CN113810235A (en) * 2021-09-22 2021-12-17 国网吉林省电力有限公司 CMDB automatic operation and maintenance management method and system based on configuration intelligent discovery
CN114327668A (en) * 2021-11-25 2022-04-12 中国电子科技集团公司第十五研究所 Intelligent parameter configuration method and device based on association mining

Cited By (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112088364A (en) * 2018-06-29 2020-12-15 国际商业机器公司 Using a machine learning module to determine whether to perform error checking of a memory cell
CN109409748A (en) * 2018-10-29 2019-03-01 广东友元国土信息工程有限公司 A kind of check method and system of Evaluation for cultivated-land index relevance
CN109409748B (en) * 2018-10-29 2021-07-20 广东友元国土信息工程有限公司 Checking method and system for farmland quality evaluation index relevance
WO2021104270A1 (en) * 2019-11-26 2021-06-03 中兴通讯股份有限公司 Configuration anomaly detection method, server and storage medium
CN112953737A (en) * 2019-11-26 2021-06-11 中兴通讯股份有限公司 Configuration abnormality detection method, server, and storage medium
EP4060942A4 (en) * 2019-11-26 2023-01-04 ZTE Corporation Configuration anomaly detection method, server and storage medium
CN113810235A (en) * 2021-09-22 2021-12-17 国网吉林省电力有限公司 CMDB automatic operation and maintenance management method and system based on configuration intelligent discovery
CN113810235B (en) * 2021-09-22 2024-02-23 国网吉林省电力有限公司 CMDB automatic operation and maintenance management method and system based on configuration intelligent discovery
CN114327668A (en) * 2021-11-25 2022-04-12 中国电子科技集团公司第十五研究所 Intelligent parameter configuration method and device based on association mining

Similar Documents

Publication Publication Date Title
CN107506252A (en) Information system error configurations detecting system and method based on configuration item incidence relation
US10901727B2 (en) Monitoring code sensitivity to cause software build breaks during software project development
US20190361759A1 (en) System and method to identify failed points of network impacts in real time
US11316875B2 (en) Method and system for analyzing cybersecurity threats and improving defensive intelligence
US10310968B2 (en) Developing software project plans based on developer sensitivity ratings detected from monitoring developer error patterns
CN103809499B (en) remote monitoring system and method
CN104506484B (en) A kind of proprietary protocol analysis and recognition methods
CN109343395B (en) Abnormity detection system and method for DCS operation log of nuclear power plant
CN105975604B (en) The iterative data processor abnormality detection of one kind distribution and diagnostic method
CN107124289B (en) Weblog time alignment method, device and host
CN104407977B (en) Based on the automatization uniting and adjustment testing method of the task system stage by stage of model inspection
Krishnamurthy et al. Scalable anomaly detection and isolation in cyber-physical systems using bayesian networks
WO2012104488A1 (en) Arrangement and method for model-based testing
CN105740140A (en) Software system failure diagnosis method, server and system
CN107066370A (en) A kind of automatic monitoring and the instrument and method for collecting faulty hard disk daily record
EP3663919A1 (en) System and method of automated fault correction in a network environment
CN110245077A (en) A kind of response method and equipment of program exception
CN111913824B (en) Method for determining data link fault cause and related equipment
KR101425868B1 (en) System and Method for processing of large scale data based rule set
CN117055502A (en) Intelligent control system based on Internet of things and big data analysis
CN104794013B (en) Alignment system running status, the method and device for establishing system running state model
CN105099816B (en) A kind of aviation mission electronic system general comprehensive detection device and detection method
Jia et al. Machine deserves better logging: A log enhancement approach for automatic fault diagnosis
CN112147974B (en) Alarm root cause diagnosis method based on chemical process knowledge automation
CN105913226B (en) Nuclear power plant's operation support system based on intelligent voice prompt

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
WD01 Invention patent application deemed withdrawn after publication

Application publication date: 20171222

WD01 Invention patent application deemed withdrawn after publication