CN110032490A - Method and device thereof for detection system exception - Google Patents

Method and device thereof for detection system exception Download PDF

Info

Publication number
CN110032490A
CN110032490A CN201811622495.6A CN201811622495A CN110032490A CN 110032490 A CN110032490 A CN 110032490A CN 201811622495 A CN201811622495 A CN 201811622495A CN 110032490 A CN110032490 A CN 110032490A
Authority
CN
China
Prior art keywords
monitor control
control index
length
value
index
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201811622495.6A
Other languages
Chinese (zh)
Inventor
蒋丹妮
何东杰
茅毓铭
张高磊
周雍恺
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Unionpay Co Ltd
Original Assignee
China Unionpay Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Unionpay Co Ltd filed Critical China Unionpay Co Ltd
Priority to CN201811622495.6A priority Critical patent/CN110032490A/en
Priority to PCT/CN2019/096274 priority patent/WO2020134032A1/en
Publication of CN110032490A publication Critical patent/CN110032490A/en
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/30Monitoring
    • G06F11/3065Monitoring arrangements determined by the means or processing involved in reporting the monitored data
    • G06F11/3072Monitoring arrangements determined by the means or processing involved in reporting the monitored data where the reporting involves data filtering, e.g. pattern matching, time or event triggered, adaptive or policy-based reporting
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/30Monitoring
    • G06F11/34Recording or statistical evaluation of computer activity, e.g. of down time, of input/output operation ; Recording or statistical evaluation of user activity, e.g. usability assessment
    • G06F11/3452Performance evaluation by statistical analysis
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F18/00Pattern recognition
    • G06F18/20Analysing
    • G06F18/23Clustering techniques
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06VIMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
    • G06V30/00Character recognition; Recognising digital ink; Document-oriented image-based pattern recognition
    • G06V30/10Character recognition
    • G06V30/19Recognition using electronic means
    • G06V30/192Recognition using electronic means using simultaneous comparisons or correlations of the image signals with a plurality of references
    • G06V30/194References adjustable by an adaptive method, e.g. learning

Abstract

The present invention relates to computer technologies, and in particular to for detection system exception method, realize this method device and computer readable storage medium.Comprise the steps of A according to the method for detection system exception of one aspect of the invention) determine monitor control index history value feature vector;And B) clustering is carried out to described eigenvector to obtain one or more frequent modes for judging whether system is abnormal, and the relevance between described eigenvector and the fluctuation of the monitor control index and the monitor control index is related.

Description

Method and device thereof for detection system exception
Technical field
The present invention relates to computer technologies, and in particular to for detection system exception method, realize this method device And computer readable storage medium.
Background technique
The technology of legacy system abnormality detection focuses on monitoring and discovery system exception, and common way is that basis is preset Rule the key index in system is monitored in real time, then alarm immediately if it find that abnormal.For example, if the pass of monitoring Key index has been more than that defined threshold value then triggers alarm.
Above system abnormality detection technology typically belongs to the medium-sized and subsequent type of thing, that is, alarms and take after noting abnormalities and remedy Measure.However, often pressure is excessive for system when an anomaly occurs, it is difficult to reach ideal effect adopting remedial measures Fruit, thus the influence even biggish loss caused by system.
In emerging dysgnosis detection field, current the relevant technologies are not yet mature, still in the rank explored and developed Section, the application in practical abnormality detection scene there is problems:
1. the generation of system exception failure and multiple indexs are interrelated in many cases, individually refer to
Target wave phenomenon is not enough to reflect the health status of system;
2. most of monitoring datas lack data label, the artificial work for marking training data set
It measures big and at high cost;
3. exceptional sample negligible amounts or covering surface be not complete.General System most time is in normal
State, exceptional sample is less, and needs to detect unknown new abnormal generation.
Being disclosed in the information of background parts of the present invention, it is only intended to increase understanding of the overall background of the invention, without answering When being considered as recognizing or imply that the information constitutes the prior art already known to those of ordinary skill in the art in any form.
Summary of the invention
It is an aspect of the invention to provide a kind of methods for detection system exception.
A kind of method for detection system exception according to one aspect of the present invention, wherein include the following steps:
A the feature vector of the history value of monitor control index) is determined;And
B clustering) is carried out to described eigenvector to obtain one or more frequent modes for judging whether system is different Often, the relevance between described eigenvector and the fluctuation of the monitor control index and the monitor control index is related.
Optionally, in the above-mentioned methods, the monitor control index includes one or more in following: different in the system Link number, handling capacity, queue length, response time and the success rate of type of service.
Optionally, in the above-mentioned methods, the step A) include:
The history value of the monitor control index is sampled according to mobile time window length and step-length, wherein the same time The history value of monitor control index in length of window constitutes a training sample;And
For each training sample, constructed using the statistical nature component of the history value of monitor control index therein corresponding special Levy vector.
Optionally, in the above-mentioned methods, its phase is determined after being normalized for each training sample again The statistical nature component answered.
Optionally, in the above-mentioned methods in step B), cluster point is carried out by the feature vector to the training sample Analysis is to obtain the frequent mode.
Optionally, in the above-mentioned methods, the statistical nature component includes one or more in following: maximum value, most Small value, average value, variance, the degree of bias, kurtosis, first-order difference feature and the maximum value and minimum value are in the training sample Position.
Optionally, in the above-mentioned methods, in clustering, dynamically change the weight of the statistical nature component, so that Belong to the training sample of same frequent mode distance be less than first threshold, and belong to different frequent modes training sample away from From greater than second threshold.
Optionally, in the above-mentioned methods, the time window length and step-length of the movement are determined according to practical business scene, Wherein, a variety of time window length and step-length can be used simultaneously.Optionally, in the above-mentioned methods, it is determined according to following manner Whether system is abnormal:
C1 the feature vector of current monitor index) is determined;And
C2) determine whether system is in abnormal based on the distance between the feature vector of current monitor index and the frequent mode State.
Optionally, in the above-mentioned methods, in step C2), if the feature vector of current monitor index and it is described frequently The distance between mode is less than the threshold value of setting, it is determined that system is in normal condition, otherwise, it is determined that system is in abnormal shape State.
The purpose of another aspect of the present invention is to provide a kind of abnormal detector of system.
A kind of abnormal detector of system of another aspect according to the invention comprising memory, processor and Store the computer program that can be run on a memory and on a processor, wherein the processor executes the computer journey The above-mentioned method for detection system exception is realized when sequence.
The purpose of another aspect of the invention is to provide a kind of computer readable storage medium.According to another aspect of the invention Computer readable storage medium stores computer program thereon, which realizes above-mentioned use when being executed by processor In the method for detection system exception.
The method for detection system exception according to an aspect of the present invention, in the timeliness side of system monitoring Face, the method for detection system exception of one aspect of the present invention are capable of detecting when the unusual fluctuations mode of monitor control index, It is alerted before system is abnormal, to improve the robustness of system.It is of the invention in terms of the accuracy of abnormality detection Association analysis of the method based on multidimensional monitoring index for detection system exception of one aspect is with identifying system exception feelings Condition is suitable for the practical O&M scenarios of complication system.
A variety of other features and advantage will be apparent from detailed further below and attached drawing.
Detailed description of the invention
Above-mentioned and/or other aspects and advantage of the invention will be become by the description of the various aspects below in conjunction with attached drawing It is more clear and is easier to understand, the same or similar unit, which is adopted, in attached drawing is indicated by the same numeral.Attached drawing includes:
Fig. 1 shows the flow chart of the method for detection system exception according to one embodiment of the invention.
Fig. 2 shows the flow charts of the method for determining frequent mode according to one embodiment of the invention.
Fig. 3 shows the schematic block diagram of the abnormal detector of the system according to one embodiment of the invention.
Specific embodiment
In the present specification, referring to which illustrates the attached drawings of illustrative examples of the present invention to more fully illustrate this hair It is bright.But the present invention can be realized by different form, and be not construed as being only limitted to each embodiment given herein.What is provided is each Embodiment is intended to make the disclosure of this paper comprehensively complete, and protection scope of the present invention is more fully communicated to art technology Personnel.
The term of such as "comprising" and " comprising " etc indicates have directly in addition to having in the specification and in the claims Other than the unit and step clearly stated, technical solution of the present invention is also not excluded for having its that do not stated directly or clearly The situation of its unit and step.The term of " first " and " second " etc is not offered as unit in time, space, size etc. The sequence of aspect and be only make distinguish each unit be used.
Below with reference to being retouched according to the method for the embodiment of the present invention with the flow chart of system explanation, block diagram and or flow chart State the present invention.It will be understood that these flow charts illustrate and/or each frame and flow chart of block diagram illustrate and/or the combination of block diagram It can be realized by computer program instructions.These computer program instructions can be supplied to general purpose computer, dedicated computing Machine or the processor of other programmable data processing devices are to constitute machine, so as to by computer or the processing of other programmable datas These instruction creations that the processor of equipment executes are for implementing these flow charts and/or frame and/or one or more flow chart elements Function/operation the component specified in figure.
These computer program instructions can be stored in computer-readable memory, these instructions can indicate to calculate Machine or other programmable processors realize function in a specific way, so as to these instructions being stored in computer-readable memory The production for constituting the function/operation instruction unit specified in one or more frames comprising implementation flow chart and/or block diagram produces Product.
These computer program instructions can be loaded on computer or other programmable data processors so that a system The operating procedure of column executes on computer or other programmable processors, to constitute computer implemented process, so that meter These instructions executed on calculation machine or other programmable data processors provide one for implementing this flowchart and or block diagram Or in multiple frames specify functions or operations the step of.It is further noted that in some alternative realizations, function/behaviour shown in frame Work can not be occurred by order shown in flow chart.For example, two frames successively shown actually can be executed essentially simultaneously Or these frames can execute in reverse order sometimes, be specifically dependent upon related function/operation.
Fig. 1 shows the flow chart of the method for detection system exception according to one embodiment of the invention.
In step 110, the training sample and feature vector of monitor control index are determined comprising following sub-step: according to finger Length of window of fixing time and step-length sample the monitor control index, wherein the monitoring data in same time window length Constitute a training sample;And it is directed to each training sample, it is constructed by extraction time window statistical nature corresponding Feature vector.For example, link number, handling capacity, queue length, response time and the success rate of system different service types, time Window statistical nature includes one or more in following: maximum value, minimum value, average value, variance, the degree of bias, kurtosis, a scale The position of score value and the maximum value and minimum value in the training sample.
Optionally, in step 110, usage history monitor control index is as sample training collection, with each training sample of determination Statistical nature to construct corresponding feature vector.Optionally, it is assumed that have the monitor control index of multiple dimensions, each index in system Both correspond to a period of time sequence.According to scheduled traveling time length of window and step-length, history monitor control index is divided into more The history value of a subsequence, all monitor control indexes in same time window constitutes a training sample.
Specifically, it is assumed that the monitoring data that the history value of monitor control index is one day in the past, timestamp are accurate to second grade, prison Controlling index is respectively to link three kinds of number (A), handling capacity (B) and queue length (C) monitor control indexes.From the foregoing, it will be observed that time series is long Degree is 86400 seconds, with 30 seconds for time window length, time series is divided into 17280 subsequences for sampling step length within 5 seconds (that is, being used as within 0 second to 30 seconds a subsequence, it is used as a subsequence within 5 seconds to 35 seconds, and so on).So i-th of training It include three sequence fragments of A, B, C in sample
[], wherein,,
After obtaining training sample, using link number, three kinds of monitor control indexes of handling capacity and queue length initial data, Time window statistical nature and the corresponding feature vector of first-order difference feature construction.It is first before the feature vector of building sample First initial data is normalized, i.e., to three subsequences of initial dataWithUse the side min-max Method does normalized, is stretched with eliminating data, influence of the deformation to Frequent Pattern Mining in following steps.Then, it unites respectively Count maximum value of three monitor control indexes in unit time length of window, minimum value, average value, variance, the degree of bias, kurtosis and most Big value and relative position of the minimum value in sequence fragment, while first-order difference operation is done to each subsequence, i.e.,, then the average value and variance of sequence after difference are calculated separately, the fluctuation of subsequence is measured with this.
After obtaining above-mentioned statistical nature component, respectively by initial dataWith, three index link numbers, The statistical nature of the time window of handling capacity and queue lengthWith And first-order difference average value and variance it is orderly be stitched together, to form the individual features vector of the sample, wherein max Indicating maximum value, min indicates minimum value, and avg indicates that average value, var indicate variance, and skew indicates the degree of bias, and kurt indicates kurtosis, And lt1 and lt2 respectively indicate the relative position of maximum value and minimum value in sequence fragment.Subsequently enter step 120.
In the step 120, clustering is carried out to obtain one or more frequent modes to features described above vector.It is optional Density-based algorithms can be used in ground, and the clustering architecture of arbitrary shape can be found in noisy data space, choosing Select the frequent mode that the algorithm excavates above-mentioned monitor control index in multidimensional feature space.Frequent mode is determined based on feature vector Specific method will be described in detail in Fig. 2.
In step 130, whether extremely frequent mode carrys out detection system based on one or more comprising following sub-step It is rapid: the feature vector of current monitor index is determined according to method described in above-mentioned steps 110 and step 120;And based on working as The distance between the feature vector of preceding monitor control index and the frequent mode determine whether system is in abnormality.If current The distance between the feature vector of monitor control index and the frequent mode are less than the threshold value of setting, it is determined that system is in normal shape State, otherwise, it is determined that system is in abnormality.Optionally, the distance can be Euclidean distance.
Specifically, based on traveling time window calculation current system monitor control index link number, handling capacity and queue length Feature vector, wherein time window length is consistent with the time window length that historical data samples.Using link number, handle up Amount and sample data of the nearest 30 seconds monitoring datas of queue length as abnormality detection, and time passage at any time refreshes in real time Detect sample.The feature vector that the detection sample is constructed according to above-mentioned steps 110 and step 120, calculate separately this feature to Amount is at a distance from each frequent mode.If current sample is not fallen in any existing frequent mode, it is considered as exception Occur, otherwise system is normal.
In above-mentioned steps, the accumulation to initial data is considered using the specimen sample method of traveling time window and is imitated It answers, using time window statistical nature and the corresponding feature vector of first-order difference feature construction, the phenomenon that filtering out single-point burr, Influence of the data noise to abnormal monitoring can be reduced.Meanwhile the outlier judgement based on frequent mode, it is capable of detecting when unknown Abnormal conditions.
Optionally, in above-mentioned steps, in addition to utilizing initial data, time window statistical nature and first-order difference feature, Other feature extracting method can also alternatively be used.Optionally, the time window length and step-length of the movement are based on abnormal The frequency of generation can dynamically adjust, and be determined according to practical business scene, wherein can be long using a variety of time windows simultaneously Degree and step-length.The method that a variety of time window length and arbitrary width can be used samples historical data, to increase The diversity of strong data, for detecting short-term or long-term Indexes Abnormality.
Fig. 2 shows the flow charts of the method for determining frequent mode according to one embodiment of the invention.In step 210 In, clustering is carried out to the feature vector of the history value of the monitor control index determined by the step in Fig. 1.Optionally, at this Density-based algorithms can be used in step, the tightness degree being distributed by sample in feature space divides sample For multiple clustering clusters, the i.e. maximum set of the connected point of high density.The specific implementation steps are as follows:
Definition training sample is ri;
It determines σ neighborhood, indicates the training sample riIn with mode rjDistance less than or equal to distance threshold σ sample collection It closes, that is,, wherein rjIndicate the kernel object of the mode;
If the mode rjThe σ neighborhood in include at least MinPts training samples, i.e., MinPts then defines the mode rjFor frequent mode.Wherein, it is in the neighborhood of σ that MinPts, which is defined as the distance of a certain sample, The threshold value of number of samples.
In a step 220, in process of cluster analysis, dynamic changes the weight of the statistical nature component of feature vector, makes The distance that the training sample of same frequent mode must be belonged to is less than first threshold, and belong to the training sample of different frequent modes Distance is greater than second threshold, and the sample in the history value of monitor control index before occurring extremely and during occurring is made to be to peel off Point (abnormality), to better discriminate between frequent mode and outlier.Wherein, first threshold and second threshold can be based on prisons The characteristics of controlling index and the significance level of system is predefined.Subsequently enter step 230.
In step 230, one or more frequent mode r are determined by clusteringj, frequent mould based on one or more Whether formula carrys out detection system abnormal.It is set if the distance between the feature vector of current monitor index and the frequent mode are less than Fixed threshold value, it is determined that system is in normal condition, otherwise, it is determined that system is in abnormality.Wherein, the distance can be with It is Euclidean distance or other distances, manhatton distance, Chebyshev's distance, mahalanobis distance etc..
Fig. 3 shows the schematic block diagram of the abnormal detector of the system according to one embodiment of the invention.The system it is different Normal detection device 30 includes memory 310, processor 320 and is stored on the memory and can be on the processor The computer program 330 of operation.It is above-mentioned abnormal for detection system to realize that the processor 320 runs described program 330 Method.
It is another aspect of this invention to provide that additionally providing a kind of computer readable storage medium, computer journey is stored thereon Sequence can realize the above-mentioned method for detection system exception when the program is executed by processor.
According to the method for the present invention and its device, sampling, feature extraction and the splicing of the history value based on more monitor control indexes, Can incidence relation in analysis system between the variation tendency and multiple monitor control indexes of multiple monitor control indexes, Mining Multidimensional monitoring The frequent mode of index, thus the abnormality in identifying system, in the case where not triggering system failure threshold alarm, in advance It was found that system exception to adopt remedial measures early.In addition, the present invention is suitable for a variety of in terms of the applicability of data model The time series data that system monitoring generates, without features such as the periodicity, the fluctuations that judges monitor control index, due to frequent mode digging Pick is based on unsupervised or semi-supervised training method, so being suitable for the training sample situation less without label or negative sample.
Embodiments and examples set forth herein is provided, to be best described by the reality according to this technology and its specific application Example is applied, and thus enables those skilled in the art to implement and using the present invention.But those skilled in the art will Know, provides above description and example only for the purposes of illustrating and illustrating.The description proposed is not intended to cover the present invention Various aspects or limit the invention to disclosed precise forms.
In view of the above, the scope of the present disclosure is determined by following claims.

Claims (12)

1. a kind of method for detection system exception, characterized in that it comprises the following steps:
A the feature vector of the history value of monitor control index) is determined;And
B clustering) is carried out to described eigenvector to obtain one or more frequent modes for judging whether system is different Often, the relevance between described eigenvector and the fluctuation of the monitor control index and the monitor control index is related.
2. the method for claim 1, wherein the monitor control index includes one or more in following: the system Link number, handling capacity, queue length, response time and the success rate of middle different service types.
3. the method for claim 1, wherein step A) include:
The history value of the monitor control index is sampled according to mobile time window length and step-length, wherein the same time The history value of monitor control index in length of window constitutes a training sample;And
For each training sample, constructed using the statistical nature component of the history value of monitor control index therein corresponding special Levy vector.
4. method as claimed in claim 3, wherein determined again after being normalized for each training sample Its corresponding statistical nature component.
5. method as claimed in claim 3, wherein in step B), carried out by the feature vector to the training sample Clustering is to obtain the frequent mode.
6. method as claimed in claim 3, wherein the statistical nature component includes one or more in following: maximum Value, minimum value, average value, variance, the degree of bias, kurtosis, first-order difference value and the maximum value and minimum value are in the trained sample Relative position in this.
7. method as claimed in claim 4, wherein in clustering, dynamically change the weight of the statistical nature component, So that the distance for belonging to the training sample of same frequent mode is less than first threshold, and belong to the training sample of different frequent modes Distance be greater than second threshold.
8. method as claimed in claim 3, wherein the time window length and step-length of the movement are according to practical business scene It determines, wherein a variety of time window length and step-length can be used simultaneously.
9. such as method described in any item of the claim 1 to 8, wherein determine whether system is abnormal according to following manner:
C1 the feature vector of current monitor index) is determined;And
C2) determine whether system is in abnormal based on the distance between the feature vector of current monitor index and the frequent mode State.
10. method as claimed in claim 9, wherein in step C2), if the feature vector of current monitor index and institute State the threshold value that the distance between frequent mode is less than setting, it is determined that system is in normal condition, otherwise, it is determined that system is in Abnormality.
11. a kind of abnormal detector of system comprising memory, processor and storage on a memory and can handled The computer program run on device, which is characterized in that the processor realized when executing the computer program claim 1 to The method of detection system exception is used for described in any one of 10.
12. a kind of computer-readable medium, is stored thereon with computer program, which is characterized in that the computer program is processed Device realizes the method that detection system exception is used for described in any one of claims 1 to 10 when executing.
CN201811622495.6A 2018-12-28 2018-12-28 Method and device thereof for detection system exception Pending CN110032490A (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN201811622495.6A CN110032490A (en) 2018-12-28 2018-12-28 Method and device thereof for detection system exception
PCT/CN2019/096274 WO2020134032A1 (en) 2018-12-28 2019-07-17 Method for detecting abnormality of service system, and apparatus therefor

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201811622495.6A CN110032490A (en) 2018-12-28 2018-12-28 Method and device thereof for detection system exception

Publications (1)

Publication Number Publication Date
CN110032490A true CN110032490A (en) 2019-07-19

Family

ID=67235430

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201811622495.6A Pending CN110032490A (en) 2018-12-28 2018-12-28 Method and device thereof for detection system exception

Country Status (2)

Country Link
CN (1) CN110032490A (en)
WO (1) WO2020134032A1 (en)

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110427278A (en) * 2019-07-31 2019-11-08 中国工商银行股份有限公司 Method for detecting abnormality and device
CN110995508A (en) * 2019-12-23 2020-04-10 中国人民解放军国防科技大学 KPI mutation-based self-adaptive unsupervised online network anomaly detection method
CN111368681A (en) * 2020-02-27 2020-07-03 深圳数联天下智能科技有限公司 Live body discrimination method, device and equipment based on multipoint positioning and storage medium
CN111859056A (en) * 2020-07-31 2020-10-30 中国工商银行股份有限公司 Data processing method, device, electronic equipment and medium
CN113515554A (en) * 2020-04-09 2021-10-19 华晨宝马汽车有限公司 Anomaly detection method and system for irregularly sampled time series

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112329517B (en) * 2020-09-17 2022-11-29 中国南方电网有限责任公司超高压输电公司南宁监控中心 Transformer substation disconnecting link confirmation video image analysis method and system
CN112286951A (en) * 2020-11-26 2021-01-29 杭州数梦工场科技有限公司 Data detection method and device
CN113568819B (en) * 2021-01-31 2024-04-16 腾讯科技(深圳)有限公司 Abnormal data detection method, device, computer readable medium and electronic equipment
CN113672467A (en) * 2021-08-24 2021-11-19 中国电信股份有限公司 Operation and maintenance early warning method and device, electronic equipment and storage medium
CN114095081B (en) * 2021-11-02 2023-02-17 中国联合网络通信集团有限公司 Method and device for determining health degree of optical module and computer readable storage medium
CN115499246B (en) * 2022-11-15 2023-04-07 阿里云计算有限公司 Abnormal event processing and detecting method and processing system

Citations (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2012039232A1 (en) * 2010-09-24 2012-03-29 株式会社日立ソリューションズ Operational risk analysis server and operational risk analysis system
CN105205113A (en) * 2015-09-01 2015-12-30 西安交通大学 System and method for excavating abnormal change process of time series data
CN105847302A (en) * 2016-05-31 2016-08-10 北京奇艺世纪科技有限公司 Abnormity detection method and device
CN106126391A (en) * 2016-06-28 2016-11-16 北京百度网讯科技有限公司 System monitoring method and apparatus
CN106649050A (en) * 2016-09-09 2017-05-10 西安交通大学 Multi-parameter running situation graphic representation method for time sequential system
CN106649438A (en) * 2016-09-09 2017-05-10 西安交通大学 Time series data unexpected fault detection method
CN108053095A (en) * 2017-11-22 2018-05-18 全球能源互联网研究院有限公司 A kind of electrical energy power quality disturbance affair character extracting method and system
CN108089962A (en) * 2017-11-13 2018-05-29 北京奇艺世纪科技有限公司 A kind of method for detecting abnormality, device and electronic equipment
CN108234524A (en) * 2018-04-02 2018-06-29 广州广电研究院有限公司 Method, apparatus, equipment and the storage medium of network data abnormality detection
CN108509979A (en) * 2018-02-28 2018-09-07 努比亚技术有限公司 A kind of method for detecting abnormality, server and computer readable storage medium
CN108880841A (en) * 2017-05-11 2018-11-23 上海宏时数据系统有限公司 A kind of threshold values setting, abnormality detection system and the method for service monitoring system

Patent Citations (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2012039232A1 (en) * 2010-09-24 2012-03-29 株式会社日立ソリューションズ Operational risk analysis server and operational risk analysis system
CN105205113A (en) * 2015-09-01 2015-12-30 西安交通大学 System and method for excavating abnormal change process of time series data
CN105847302A (en) * 2016-05-31 2016-08-10 北京奇艺世纪科技有限公司 Abnormity detection method and device
CN106126391A (en) * 2016-06-28 2016-11-16 北京百度网讯科技有限公司 System monitoring method and apparatus
CN106649050A (en) * 2016-09-09 2017-05-10 西安交通大学 Multi-parameter running situation graphic representation method for time sequential system
CN106649438A (en) * 2016-09-09 2017-05-10 西安交通大学 Time series data unexpected fault detection method
CN108880841A (en) * 2017-05-11 2018-11-23 上海宏时数据系统有限公司 A kind of threshold values setting, abnormality detection system and the method for service monitoring system
CN108089962A (en) * 2017-11-13 2018-05-29 北京奇艺世纪科技有限公司 A kind of method for detecting abnormality, device and electronic equipment
CN108053095A (en) * 2017-11-22 2018-05-18 全球能源互联网研究院有限公司 A kind of electrical energy power quality disturbance affair character extracting method and system
CN108509979A (en) * 2018-02-28 2018-09-07 努比亚技术有限公司 A kind of method for detecting abnormality, server and computer readable storage medium
CN108234524A (en) * 2018-04-02 2018-06-29 广州广电研究院有限公司 Method, apparatus, equipment and the storage medium of network data abnormality detection

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
吕光明: "《宏观经济统计分析》", 31 December 2016 *
涂新辉: "《智能信息处理与知识服务丛书 基于概念的信息检索方法》", 30 April 2015 *

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110427278A (en) * 2019-07-31 2019-11-08 中国工商银行股份有限公司 Method for detecting abnormality and device
CN110995508A (en) * 2019-12-23 2020-04-10 中国人民解放军国防科技大学 KPI mutation-based self-adaptive unsupervised online network anomaly detection method
CN110995508B (en) * 2019-12-23 2022-11-11 中国人民解放军国防科技大学 KPI mutation-based adaptive unsupervised online network anomaly detection method
CN111368681A (en) * 2020-02-27 2020-07-03 深圳数联天下智能科技有限公司 Live body discrimination method, device and equipment based on multipoint positioning and storage medium
CN111368681B (en) * 2020-02-27 2023-09-01 深圳数联天下智能科技有限公司 Living body screening method, device, equipment and storage medium based on multi-point positioning
CN113515554A (en) * 2020-04-09 2021-10-19 华晨宝马汽车有限公司 Anomaly detection method and system for irregularly sampled time series
CN111859056A (en) * 2020-07-31 2020-10-30 中国工商银行股份有限公司 Data processing method, device, electronic equipment and medium
CN111859056B (en) * 2020-07-31 2023-08-29 中国工商银行股份有限公司 Data processing method, device, electronic equipment and medium

Also Published As

Publication number Publication date
WO2020134032A1 (en) 2020-07-02

Similar Documents

Publication Publication Date Title
CN110032490A (en) Method and device thereof for detection system exception
US10896080B2 (en) S.M.A.R.T. threshold optimization method used for disk failure detection
Qahtan et al. A pca-based change detection framework for multidimensional data streams: Change detection in multidimensional data streams
AU2016286280B2 (en) Combined method for detecting anomalies in a water distribution system
US10373065B2 (en) Generating database cluster health alerts using machine learning
CN113518011B (en) Abnormality detection method and apparatus, electronic device, and computer-readable storage medium
US10719774B2 (en) Method and system for health monitoring and fault signature identification
CN113255848B (en) Water turbine cavitation sound signal identification method based on big data learning
CN108319981A (en) A kind of time series data method for detecting abnormality and device based on density
CA2471013A1 (en) Method and system for analyzing and predicting the behavior of systems
JP2004531815A (en) Diagnostic system and method for predictive condition monitoring
CN104915568A (en) Satellite telemetry data abnormity detection method based on DTW
US20200143292A1 (en) Signature enhancement for deviation measurement-based classification of a detected anomaly in an industrial asset
GB2491564A (en) Method of system monitoring
CN111538311B (en) Flexible multi-state self-adaptive early warning method and device for mechanical equipment based on data mining
US20170249559A1 (en) Apparatus and method for ensembles of kernel regression models
CN108956111B (en) Abnormal state detection method and detection system for mechanical part
US20090043536A1 (en) Use of Sequential Clustering for Instance Selection in Machine Condition Monitoring
JPWO2019244203A1 (en) Diagnostic device, diagnostic method and program
Anderka et al. Automatic ATM Fraud Detection as a Sequence-based Anomaly Detection Problem.
US10976731B2 (en) Abnormality diagnostic system
CN114610572A (en) Service abnormity detection method, device, computer equipment and storage medium
CN114065627A (en) Temperature abnormality detection method, temperature abnormality detection device, electronic apparatus, and medium
KR102059112B1 (en) IoT STREAM DATA QUALITY MEASUREMENT INDICATORS AND PROFILING METHOD FOR INTERNET OF THINGS AND SYSTEM THEREFORE
JP2018028845A (en) Abnormality sign detection system and abnormality sign detection method

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination