Alarm behavior adaptive adjustment method, device, equipment and storage medium

By acquiring real-time bandwidth utilization and operational event logs, and combining multi-period time-series analysis and event impact attenuation models, alarm behavior is dynamically adjusted, solving the problems of high false alarm rate and low operation and maintenance efficiency of traditional alarm mechanisms in highly dynamic network environments, and achieving accurate identification and timely response to anomalies.

CN120856534BActive Publication Date: 2026-01-30SHENZHEN NOVA TECH DEV CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511333400.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-18
Publication Date
2026-01-30
Estimated Expiration
2045-09-18

AI Technical Summary

Technical Problem

Traditional alarm mechanisms suffer from high false alarm rates and low operational efficiency in highly dynamic network environments. They are unable to identify situations where bandwidth load is in a critical state for a long time or to detect periodic business fluctuations or temporary traffic adjustments, resulting in frequent triggering of invalid alarms and diverting the resources of operations and maintenance personnel.

Method used

By acquiring real-time bandwidth utilization data and operational event logs, traffic anomaly warning parameters are generated. A dynamic traffic baseline is constructed based on multi-period time series analysis and event impact attenuation model. The combination mode of visual warnings and acoustic alarms is adjusted to achieve adaptive adjustment of alarm behavior.

Benefits of technology

It effectively distinguishes between normal business fluctuations and real anomalies, reduces false alarm rates, improves the timeliness and accuracy of operation and maintenance work, and reduces the fatigue of operation and maintenance personnel.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120856534B_ABST
    Figure CN120856534B_ABST
Patent Text Reader

Abstract

This invention relates to the field of network operation and maintenance management technology, and particularly to a method, apparatus, device, and storage medium for adaptive adjustment of alarm behavior. This application collects real-time bandwidth occupancy data and operational event logs from network pathways, combines this with a dynamic baseline of historical traffic levels, and considers traffic fluctuations caused by specific types of operational events in the short term. Based on these two variables, the system adjusts relevant parameters for traffic anomaly warnings. The system performs multi-level classification judgments for primary alarms (bandwidth overload) and advanced alarms (continuous overload) according to the dynamically adjusted warning parameters, and adjusts the combination mode of visual warnings and acoustic alarms to match the actual anomaly level. This solution can effectively distinguish between normal business fluctuations and genuine anomalies, enabling the system to have adaptive tolerance for events within the operational maintenance plan, avoiding invalid alarms, preventing excessive interference with low-level anomalies, reducing ineffective responses from maintenance personnel, and significantly improving the timeliness and accuracy of maintenance work.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network operation and maintenance management technology, and in particular to a method, apparatus, device, and storage medium for adaptive adjustment of alarm behavior. Background Technology

[0002] With the rapid development of cloud computing, 5G, and the Industrial Internet, network scale is growing exponentially, and traffic patterns are becoming increasingly dynamic and complex. Enterprises' core businesses are becoming more reliant on network availability, and the impact of network anomalies has evolved from purely technical issues into direct economic losses and business risks. Against this backdrop, traditional monitoring methods based primarily on manual inspections and static rules are no longer sufficient to meet the real-time, resilience, and automation requirements of modern networks.

[0003] Current mainstream network monitoring systems generally adopt alarm strategies based on fixed thresholds. Although this mechanism is simple to implement, it cannot identify situations where the bandwidth load is in a critical state for a long time. In this case, alarms will persist without any actual fault. Secondly, the system cannot detect normal changes such as periodic business fluctuations or temporary traffic adjustments, frequently triggering invalid alarms. Operation and maintenance personnel have to spend a lot of time dealing with these quasi-abnormal states, which seriously distracts them from their ability to respond to real faults.

[0004] Therefore, how to solve the problem of high false alarm rate and low operation and maintenance efficiency of traditional alarm mechanisms in highly dynamic network environments has become a technical problem that urgently needs to be solved in this industry. Summary of the Invention

[0005] The main objective of this invention is to provide an adaptive adjustment method, apparatus, device, and storage medium for alarm behavior, aiming to solve the technical problems of high false alarm rate and low operation and maintenance efficiency of traditional alarm mechanisms in highly dynamic network environments.

[0006] To achieve the above objectives, the present invention provides an adaptive adjustment method for alarm behavior, the method comprising the following steps:

[0007] Obtain real-time bandwidth utilization data and operational event logs on the network path;

[0008] Based on the operational event logs, generate traffic anomaly warning parameters for the network path;

[0009] Based on the traffic anomaly warning parameters, the alarm behavior level under the real-time bandwidth utilization data is determined;

[0010] Based on the alarm behavior level, the combination mode of visual alerts and acoustic alarms is adjusted to achieve adaptive adjustment of alarm behavior.

[0011] Optionally, generating the network path traffic anomaly warning parameters based on the operational event log includes:

[0012] Based on the aforementioned operational event logs, determine the traffic fluctuation event gain;

[0013] Calculate the baseline traffic at the current moment based on the historical traffic data of the network path;

[0014] The network path's traffic anomaly warning parameters are generated based on the original values ​​of the traffic anomaly warning parameters, the traffic fluctuation event gain, and the baseline traffic at the current moment.

[0015] Optionally, determining the traffic fluctuation event gain based on the operational event log includes:

[0016] Based on the event type, occurrence time, and scope of impact fields in the operational event log, a raw event set with time sequence tags is obtained;

[0017] Based on the preset event type-traffic impact mapping table, calculate the initial impact score for each event in the original event set;

[0018] Based on the interval between the occurrence time of each event in the original event set and the current time, and the dynamic weighted decay function, the initial impact score is corrected to obtain the real-time impact factor;

[0019] The gain of the traffic fluctuation event is determined based on the real-time impact factor.

[0020] Optionally, calculating the baseline traffic at the current moment based on the historical traffic data of the network path includes:

[0021] Based on the historical traffic data of the network path, a multi-period time series analysis is performed to obtain multiple periodic variation components, wherein the multiple periodic variation components include at least intraday periodic components, intraweek periodic components, and seasonal periodic components.

[0022] The baseline flow rate at the current moment is calculated based on the multiple periodic variation components.

[0023] Optionally, generating the traffic anomaly warning parameters for the network path based on the original value of the traffic anomaly warning parameters, the traffic fluctuation event gain, and the baseline traffic at the current moment includes:

[0024] Based on the original values ​​of the traffic anomaly warning parameters, determine the original values ​​of the alarm activation threshold and the alarm recovery threshold.

[0025] The time gain of traffic fluctuation is obtained based on the baseline traffic flow at the current moment;

[0026] The alarm activation threshold is determined based on the original values ​​of the traffic fluctuation event gain, the traffic fluctuation time gain, and the alarm activation threshold.

[0027] The alarm recovery threshold is determined based on the original values ​​of the traffic fluctuation event gain, the traffic fluctuation time gain, and the alarm recovery threshold.

[0028] The alarm activation threshold and the alarm recovery threshold are used as traffic anomaly warning parameters for the network path.

[0029] Optionally, the traffic anomaly warning parameters include an alarm activation threshold, an overload duration threshold, an overload total traffic threshold, and an alarm recovery threshold;

[0030] The determination of the alarm behavior level based on the traffic anomaly warning parameters under the real-time bandwidth utilization data includes:

[0031] When the real-time bandwidth utilization data exceeds the alarm activation threshold, a level 1 alarm is triggered.

[0032] In the first-level alarm state, the percentage of over-limit duration and the cumulative over-limit traffic within the preset time window are counted. If the percentage of over-limit duration is greater than the overload duration threshold, or the cumulative over-limit traffic is greater than the total overload traffic threshold, the alarm is upgraded to the second-level alarm state.

[0033] In the second-level alarm state, the average traffic within the time window is calculated based on a sliding window. If the average traffic falls below the degradation threshold, it will revert to the first-level alarm state.

[0034] In the first-level alarm state, the average flow rate within the time window is calculated based on a sliding window. If the average flow rate drops below the alarm recovery threshold, the alarm is completely deactivated.

[0035] Optionally, adjusting the combination mode of visual alerts and acoustic alarms according to the alarm behavior level includes:

[0036] In the first-level alarm state, the visual warning unit flashes yellow light at a fixed frequency and shuts down the acoustic alarm;

[0037] In the second-level alarm state, the control visual warning unit flashes red light at an alternating frequency and activates an intermittent buzzing acoustic alarm;

[0038] If the alarm remains in a level 2 alarm state for more than the preset duration, the acoustic alarm will be switched to a continuous buzzing mode and the flashing frequency of the visual warning unit will be increased simultaneously.

[0039] Furthermore, to achieve the above objectives, the present invention also proposes an alarm behavior adaptive adjustment device, the alarm behavior adaptive adjustment device comprising:

[0040] The data acquisition module is used to acquire real-time bandwidth utilization data and operational event logs on the network path;

[0041] The early warning analysis module is used to generate traffic anomaly early warning parameters for the network path based on the operational event logs.

[0042] The status assessment module is used to determine the alarm behavior level under the real-time bandwidth utilization data based on the traffic anomaly warning parameters.

[0043] The alarm execution module is used to adjust the combination mode of visual alerts and acoustic alarms according to the alarm behavior level, so as to achieve adaptive adjustment of alarm behavior.

[0044] Furthermore, to achieve the above objectives, the present invention also proposes an alarm behavior adaptive adjustment device, which includes: a memory, a processor, and an alarm behavior adaptive adjustment program stored in the memory and executable on the processor, wherein the alarm behavior adaptive adjustment program is configured to implement the steps of the alarm behavior adaptive adjustment method described above.

[0045] Furthermore, to achieve the above objectives, the present invention also proposes a storage medium storing an alarm behavior adaptive adjustment program, wherein when the alarm behavior adaptive adjustment program is executed by a processor, it implements the steps of the alarm behavior adaptive adjustment method described above.

[0046] The proposed technical solutions (one or more) have at least the following technical effects: First, a dynamic traffic baseline constructed based on multi-cycle time-series analysis and an event impact attenuation model effectively distinguishes between normal business fluctuations and genuine anomalies. Second, by dual-adjusting early warning parameters through event gain weighting and time attenuation factors, the system exhibits adaptive tolerance to traffic fluctuations caused by events within the maintenance plan, avoiding invalid alarms. Finally, the collaborative mechanism of multi-level alarms and multi-modal feedback, through a scientific combination of visual warning levels (yellow / red) and acoustic alarm modes (intermittent / continuous), ensures strong warning of major faults while avoiding excessive interference with low-level anomalies, and reduces operator fatigue. This solution effectively distinguishes between normal business fluctuations and genuine anomalies, enabling the system to exhibit adaptive tolerance to events within the maintenance plan, avoiding invalid alarms and excessive interference from low-level anomalies, reducing ineffective responses from maintenance personnel, and significantly improving the timeliness and accuracy of maintenance work. Attached Figure Description

[0047] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0048] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0049] Figure 1 This is a flowchart illustrating the first embodiment of the alarm behavior adaptive adjustment method of the present invention;

[0050] Figure 2 This is a flowchart illustrating the second embodiment of the alarm behavior adaptive adjustment method of the present invention;

[0051] Figure 3 This is a structural block diagram of the first embodiment of the alarm behavior adaptive adjustment device of the present invention;

[0052] Figure 4 This is a schematic diagram of the structure of the alarm behavior adaptive adjustment device of the hardware operating environment involved in the embodiment of the present invention.

[0053] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0054] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.

[0055] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.

[0056] The main solution of this application embodiment is: to obtain real-time bandwidth utilization data and operation event logs in the network channel; to generate traffic anomaly warning parameters for the network channel based on the operation event logs; to determine the alarm behavior level under the real-time bandwidth utilization data based on the traffic anomaly warning parameters; and to adjust the combination mode of visual warning and acoustic alarm according to the alarm behavior level to achieve adaptive adjustment of alarm behavior.

[0057] Currently, mainstream network monitoring systems generally adopt alarm strategies based on fixed thresholds. While this mechanism is simple to implement, it cannot identify situations where bandwidth load is consistently at a critical level. In such cases, alarms persist without any actual fault. Secondly, the system cannot detect normal changes such as periodic service fluctuations or temporary traffic adjustments, frequently triggering invalid alarms. Maintenance personnel must spend a significant amount of time dealing with these near-abnormal states, severely hindering their ability to respond to genuine faults. Therefore, the high false alarm rate and low operational efficiency of traditional alarm mechanisms in highly dynamic network environments are pressing technical problems that need to be addressed.

[0058] This application effectively distinguishes between normal business fluctuations and genuine anomalies by constructing a dynamic traffic baseline based on multi-cycle time-series analysis and an event impact attenuation model. Secondly, by dual-adjusting early warning parameters through event gain weighting and time decay factors, the system exhibits adaptive tolerance for traffic fluctuations caused by events within the maintenance plan, avoiding invalid alarms. Finally, the collaborative mechanism of multi-level alarms and multi-modal feedback, through a scientific combination of visual warning levels (yellow / red) and acoustic alarm modes (intermittent / continuous), ensures strong warnings of major faults while avoiding excessive interference with low-level anomalies, and reduces operator fatigue. This solution effectively distinguishes between normal business fluctuations and genuine anomalies, enabling the system to exhibit adaptive tolerance for events within the maintenance plan, avoiding invalid alarms and excessive interference from low-level anomalies, reducing ineffective responses from maintenance personnel, and significantly improving the timeliness and accuracy of maintenance work.

[0059] It should be noted that the executing entity of this invention can be an alarm behavior adaptive adjustment device, or a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, or mobile phone, or a thermal management device capable of implementing the above-mentioned functions of an alarm behavior adaptive adjustment device, etc. This embodiment does not specifically limit it in this way. The following uses an alarm behavior adaptive adjustment device as the executing entity as an example to describe this embodiment and the following embodiments.

[0060] Based on this, embodiments of this application provide an adaptive adjustment method for alarm behavior, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the alarm behavior adaptive adjustment method of this application.

[0061] In this embodiment, the alarm behavior adaptive adjustment method includes steps S10 to S40:

[0062] Step S10: Obtain real-time bandwidth utilization data and operational event logs on the network path.

[0063] It should be noted that real-time bandwidth utilization data refers to the current traffic load percentage of a network path, typically collected from devices such as switches and routers. Operational event logs refer to records related to business changes and maintenance operations, which directly affect network traffic patterns. Generally, they fall into two categories: the first is hardware maintenance, such as switch port replacement or fiber optic splicing, and configuration changes, such as routing policy adjustments or QoS policy updates. These can cause short-term network outages, sudden drops in traffic, or redistribution on some ports, easily triggering static traffic monitoring rules. The second category is enterprise project launches, such as new business releases, e-commerce promotions, live video streaming events, or data migration / backup, such as cross-data center synchronization. These can cause sustained surges or periodic peaks in traffic on some ports, also easily triggering static traffic monitoring rules.

[0064] Understandably, real-time bandwidth data reflects the current state of the network and is the direct basis for triggering alarms. The role of operation logs is to provide business background and help distinguish between real anomalies and human operations in subsequent steps, such as avoiding false alarms during planned maintenance.

[0065] Step S20: Generate traffic anomaly warning parameters for the network path based on the operation event log.

[0066] It should be noted that traffic anomaly warning parameters refer to relevant parameters set for monitoring traffic within the channel, such as alarm activation threshold, overload duration threshold, total overload traffic threshold, and alarm recovery threshold. The alarm activation threshold is used to determine whether network traffic has entered an abnormal state. It is usually a percentage (e.g., bandwidth usage exceeding 80%) or an absolute value (e.g., traffic per second > 1Gbps). When real-time traffic exceeds this value, the system triggers a primary alarm, notifying operations personnel of potential network congestion, attacks, or service surges. The overload duration threshold distinguishes between momentary jitter and sustained overload, usually set in time units. For example, exceeding 80% bandwidth for 5 consecutive minutes is considered exceeding the limit. If traffic exceeds the alarm activation threshold and remains above this time limit, it is escalated to a critical alarm to avoid overreacting to short-term fluctuations. The total overload traffic threshold limits the allowed accumulation of abnormal traffic. This threshold prevents occasional high loads from being mistaken for faults, such as data backups. The alarm recovery threshold is used to determine whether traffic has returned to normal.

[0067] Understandably, the system automatically relaxes alarm thresholds (e.g., from 80% to 90%) within known pre-planned event time windows by linking schedule data from the operations management platform, or sets alarm activation thresholds to gradually return to their original levels after a certain period. Secondly, it dynamically adjusts detection strategies based on event type, for example, allowing longer periods of exceeding limits within the time window of operational events. Finally, it tags and filters traffic from specific source IPs, such as internal operations nodes or marketing campaign servers, to ensure that the alarm engine only focuses on truly suspicious abnormal behavior.

[0068] It should be understood that this adaptive mechanism retains security protection capabilities while avoiding invalid alarm interference during periods of high business load, thus achieving a balance between security policies and business continuity.

[0069] Step S30: Based on the traffic anomaly warning parameters, determine the alarm behavior level under the real-time bandwidth occupancy data.

[0070] It should be noted that alarm behavior levels are usually divided into mild (alert), moderate (warning), and severe (serious warning), and the level is dynamically classified based on the intensity of the traffic exceeding the limit, the duration of the exceeding the limit, and the type of related event, such as DDoS attack or business outbreak.

[0071] Understandably, this step is crucial for refined alarm management, avoiding a single alarm mode and ensuring that different levels of abnormal traffic trigger matching response strategies, thereby reducing false alarm interference and enabling rapid response in the event of a truly high threat.

[0072] In a feasible embodiment, determining the alarm behavior level based on the traffic anomaly warning parameters under the real-time bandwidth utilization data includes: triggering a level one alarm when the real-time bandwidth utilization data is greater than the alarm activation threshold; under the level one alarm state, calculating the proportion of over-limit duration and the cumulative over-limit traffic within a preset time window; if the proportion of over-limit duration is greater than the overload duration threshold, or the cumulative over-limit traffic is greater than the total overload traffic threshold, then escalating to a level two alarm; under the level two alarm state, calculating the average traffic within the time window based on a sliding window; if the average traffic falls below the downgrade threshold, then reverting to a level one alarm; under the level one alarm state, calculating the average traffic within the time window based on a sliding window; if the average traffic drops below the alarm recovery threshold, then completely deactivating the alarm behavior.

[0073] It should be noted that when the real-time bandwidth utilization exceeds the preset alarm trigger threshold, the system immediately enters a Level 1 alarm state. Level 1 alarms are typically low-level alerts, such as log recordings, slight interface color changes, and infrequent notifications. This design aims to avoid directly triggering high-level responses due to instantaneous traffic fluctuations, reducing operational fatigue. In the Level 1 alarm state, the percentage of time exceeding limits or the cumulative amount of traffic exceeding limits is assessed to determine whether to escalate to a Level 2 alarm. Then, in the Level 2 alarm state, the average traffic is calculated using a sliding window to determine whether to revert to a Level 1 alarm. If alarm downgrading occurs, in the Level 1 alarm state, the average traffic is calculated based on a sliding window to determine whether to completely clear the alarm.

[0074] Step S40: Adjust the combination mode of visual alerts and acoustic alarms according to the alarm behavior level to achieve adaptive adjustment of alarm behavior.

[0075] It should be noted that the combination modes of visual alerts and acoustic alarms include: mild alarm (visual cues only, such as yellow flashing), moderate alarm (visual + low-frequency sound cues), and severe alarm (red full-screen flashing + high-frequency alarm sound + SMS notification). The adjustment is based on the alarm behavior level obtained in the aforementioned steps.

[0076] Understandably, this step improves alarm perception efficiency through multi-sensory linkage, ensuring that operations and maintenance personnel can quickly identify and respond to alarms at different levels of urgency, reducing attention to non-critical alarms.

[0077] In a feasible embodiment, adjusting the combination mode of visual warning and acoustic alarm according to the alarm behavior level includes: in the first-level alarm state, controlling the visual warning unit to flash yellow light at a fixed frequency and turning off the acoustic alarm; in the second-level alarm state, controlling the visual warning unit to flash red light at an alternating frequency and activating the intermittent buzzing acoustic alarm; when the second-level alarm state is continuously maintained for more than a preset duration, adjusting the acoustic alarm to a continuous buzzing mode and simultaneously increasing the flashing frequency of the visual warning unit.

[0078] This embodiment effectively distinguishes between normal business fluctuations and real anomalies by constructing a dynamic traffic baseline based on multi-cycle time-series analysis and an event impact attenuation model. Secondly, by adjusting the early warning parameters through event gain weighting and time attenuation factor, the system has an adaptive tolerance for traffic fluctuations caused by events within the operation and maintenance plan, avoiding invalid alarms. Finally, the collaborative mechanism of multi-level alarms and multi-modal feedback, through the scientific combination of visual warning levels (yellow / red) and acoustic alarm modes (intermittent / continuous), ensures strong warning of major faults while avoiding excessive interference with low-level anomalies, and at the same time reduces operator fatigue.

[0079] In summary, this technical solution can effectively distinguish between normal business fluctuations and real anomalies, enabling the system to have adaptive tolerance for events within the operation and maintenance plan, avoiding excessive interference from invalid alarms and low-level anomalies, reducing invalid responses from operation and maintenance personnel, and significantly improving the timeliness and accuracy of operation and maintenance work.

[0080] Based on the first embodiment of this application, in the second embodiment of this application, the content that is the same as or similar to that in the first embodiment described above can be referred to the above description, and will not be repeated hereafter. Based on this, please refer to... Figure 2 Step S20 in the alarm behavior adaptive adjustment method includes steps S201 to S203:

[0081] Step S201: Determine the traffic fluctuation event gain based on the operation event log.

[0082] It should be noted that certain operational events can directly impact traffic fluctuations within the channel. These include planned system upgrades, large-scale data migrations, e-commerce promotions, and online event pre-launch activities. These factors can all lead to a significant increase in bandwidth utilization over a certain period. To prevent such normal business fluctuations from being misjudged as abnormal traffic and triggering alarms, the system needs to intelligently adapt by combining operational event logs and using methods such as whitelisting or adjusting warning indicators.

[0083] Understandably, different events have different impacts and characteristics on traffic fluctuations. For example, system upgrades / data migrations typically manifest as a sharp increase in bandwidth in the short term, but the traffic pattern is relatively regular, usually a constant high load. Therefore, the traffic fluctuation event gain generated by such events can be set to a fixed value, such as 1.2 times the baseline traffic. On the other hand, e-commerce promotional activities have obvious time-period characteristics, related to the promotion date or activity period, and are accompanied by a surge in traffic peaks, such as the instantaneous impact of flash sales. A dynamic load gain model should be used to link the gain with the time period weight and peak amplification factor. If the event type is online activity preheating, it may show a gradual increase, so a time decay factor needs to be introduced to smooth the gain.

[0084] In one feasible embodiment, determining the traffic fluctuation event gain based on the operational event log includes steps A10 to A40.

[0085] Step A10: Based on the event type, occurrence time and scope of impact fields in the operation event log, obtain the original event set with time sequence tags.

[0086] It should be noted that the original event set not only includes the basic information of the events (such as event type and occurrence time), but also needs to dynamically label their timeliness based on the current time. For single events such as database upgrades, it is necessary to mark their effective time window, and for continuous events, it is necessary to mark their periodic stages, such as warm-up period, peak period, and decline period, so that the weights can be adjusted according to time decay later.

[0087] Step A20: Calculate the initial impact score of each event in the original event set according to the preset event type-traffic impact mapping table.

[0088] Understandably, the system analyzes the typical impact of various events on bandwidth utilization based on historical data and constructs a preset event type-traffic impact mapping table. This mapping table is used to quantify the typical impact of different operational events on network traffic, providing the system with a standardized calculation basis to achieve dynamic adjustment of alarm thresholds. In specific operations, the preset basic impact score and correction coefficient are quickly obtained according to the event type. Then, combined with variables such as event scope (global / local) and time decay, an initial impact score containing only event gain is generated.

[0089] Step A30: Based on the interval between the occurrence time of each event in the original event set and the current time, and the dynamic weighted decay function, the initial influence score is corrected to obtain the real-time influence factor.

[0090] It should be noted that the impact of operational events is not constant, but changes dynamically over time. For immediate events, a stepped decay is generally used, which means that the traffic fluctuation gain generated by the event is reduced to zero within a certain time window. For periodic events, an exponential decay is used. This embodiment uses a dynamic weighted decay function to adjust the time sensitivity of the impact of operational events on traffic, ensuring that the system can be closer to the real scenario and avoid misjudgment caused by static weights.

[0091] Step A40: Determine the gain of the traffic fluctuation event based on the real-time impact factor.

[0092] It should be understood that the real-time impact factor refers to the actual impact of each effective time period on the current channel's flow fluctuations. The gain of the flow fluctuation event can be calculated by combining it with the proportional coefficient of each event.

[0093] Step S202: Calculate the baseline traffic at the current moment based on the historical traffic data of the network path.

[0094] It should be noted that, due to long-term operation, traffic exhibits certain periodic characteristics at every moment. During typical daytime cycles, traffic bandwidth shows obvious peaks and troughs. In addition, there are weekly periodic components (capturing traffic differences between weekdays and weekends) and seasonal periodic components (identifying long-term seasonal trends or the impact of special holidays). By weighting and fusing these periodic components and combining them with time series prediction algorithms, the system can accurately calculate the baseline traffic value at the current moment, providing a dynamic benchmark for subsequent traffic anomaly detection.

[0095] In a feasible embodiment, calculating the baseline traffic at the current moment based on the historical traffic data of the network path includes: performing multi-period time-series analysis on the historical traffic data of the network path to obtain multiple periodic variation components, wherein the multiple periodic variation components include at least intraday periodic components, intraweekly periodic components, and seasonal periodic components; and calculating the baseline traffic at the current moment based on the multiple periodic variation components.

[0096] Step S203: Generate the network path's traffic anomaly warning parameters based on the original values ​​of the traffic anomaly warning parameters, the traffic fluctuation event gain, and the baseline traffic at the current moment.

[0097] It should be noted that by integrating the original values ​​of the traffic anomaly warning parameters, the traffic fluctuation event gain, and the baseline traffic at the current moment, the system can dynamically adjust the accurate traffic anomaly warning parameters suitable for removing external interference factors in the current network path.

[0098] Understandably, its core implementation logic involves first decoupling and separating the baseline values ​​of the alarm activation threshold and alarm recovery threshold based on the original warning parameters (such as statically configured initial thresholds); then, combining the baseline traffic data at the current moment, calculating the traffic fluctuation time gain that reflects the time cycle characteristics; subsequently, applying the traffic fluctuation event gain and time gain synchronously to the original thresholds, and generating dynamically adjusted alarm activation and recovery thresholds through weighted or function mapping methods, such as linear superposition or exponential smoothing. Ultimately, these two dynamic thresholds constitute complete traffic anomaly warning parameters, ensuring that the alarm triggering mechanism can adapt to sudden business scenarios while maintaining sensitivity to real anomalies.

[0099] In a feasible embodiment, generating the traffic anomaly warning parameters for the network path based on the original values ​​of the traffic anomaly warning parameters, the traffic fluctuation event gain, and the baseline traffic at the current moment includes: determining the original values ​​of the alarm activation threshold and the alarm recovery threshold based on the original values ​​of the traffic anomaly warning parameters; obtaining the traffic fluctuation time gain based on the baseline traffic at the current moment; determining the alarm activation threshold based on the original values ​​of the traffic fluctuation event gain, the traffic fluctuation time gain, and the alarm activation threshold; determining the alarm recovery threshold based on the original values ​​of the traffic fluctuation event gain, the traffic fluctuation time gain, and the alarm recovery threshold; and using the alarm activation threshold and the alarm recovery threshold as the traffic anomaly warning parameters for the network path.

[0100] It is understood that in this embodiment, the generated traffic anomaly warning parameters include at least an alarm activation threshold, an overload duration threshold, an overload total traffic threshold, and an alarm recovery threshold. The functions of these data items are as follows: The alarm activation threshold is used to determine whether network traffic has entered an abnormal state. It is usually a percentage (e.g., bandwidth usage exceeding 80%) or an absolute value (e.g., traffic per second > 1Gbps). When real-time traffic exceeds this value, the system triggers a primary alarm to notify maintenance personnel that there may be network congestion, attacks, or a surge in business. The overload duration threshold is used to distinguish between instantaneous jitter and continuous overload. It is usually set in time units. For example, exceeding 80% bandwidth for 5 consecutive minutes is considered an over-limit. If the traffic exceeds the alarm activation threshold and remains above this time limit, it is upgraded to a critical alarm to avoid over-responding to short-term fluctuations. The overload total traffic threshold limits the allowed scale of abnormal traffic accumulation. This threshold can prevent occasional high loads from being misjudged as faults, such as data backups. The alarm recovery threshold is used to determine whether traffic has returned to normal.

[0101] It should be understood that this method, through the linkage of parameters in three dimensions—basic configuration, real-time baseline, and event gain—reduces the false alarm rate while ensuring the system's ability to respond quickly to potential risks.

[0102] In this embodiment, the operation event logs are first parsed to generate a set of original events with time-sensitive tags according to event type, occurrence time, and impact scope. Then, an initial impact score is assigned using an event-traffic mapping table, and a real-time impact factor is calculated using a stepped or exponential decay function to obtain the traffic fluctuation event gain. At the same time, the historical traffic of the channel is decomposed into multiple periods of time series, and intraday, intraweek, and seasonal components are integrated to output the current baseline traffic in real time. Finally, based on the original static threshold, the event gain and the baseline fluctuation time gain are superimposed to dynamically generate four thresholds: alarm activation, overload duration, total overload traffic, and alarm recovery. These thresholds can be automatically relaxed or tightened according to the event stage.

[0103] In summary, this embodiment avoids false alarms triggered by planned business operations by introducing an event gain mechanism. It also enhances the ability to distinguish between sudden traffic surges by accurately matching the timeliness of event impacts through a dynamic weighted attenuation function. Furthermore, it reduces misjudgments caused by periodic peak traffic by employing multi-period time-series analysis to model baseline traffic. Finally, it dynamically adjusts alarm-related data indicators to ensure sensitivity while avoiding frequent alarms. This solution significantly reduces the false alarm rate, improves operational efficiency, and ensures rapid detection and handling of real risks such as DDoS attacks and link failures, providing intelligent protection for network stability.

[0104] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the adaptive adjustment method of alarm behavior in this application. Any simple modifications based on this technical concept are within the protection scope of this application.

[0105] This application also provides an alarm behavior adaptive adjustment device, please refer to... Figure 3 The alarm behavior adaptive adjustment device includes:

[0106] The data acquisition module 10 is used to acquire real-time bandwidth utilization data and operational event logs in the network path;

[0107] The early warning analysis module 20 is used to generate traffic anomaly early warning parameters for the network path based on the operation event log;

[0108] The status assessment module 30 is used to determine the alarm behavior level under the real-time bandwidth utilization data based on the traffic anomaly warning parameters.

[0109] The alarm execution module 40 is used to adjust the combination mode of visual warning and acoustic alarm according to the alarm behavior level, so as to achieve adaptive adjustment of alarm behavior.

[0110] In one embodiment, the early warning analysis module 20 is further configured to determine the traffic fluctuation event gain based on the operation event log; calculate the baseline traffic at the current moment based on the historical traffic data of the network path; and generate the traffic anomaly early warning parameters of the network path based on the original value of the traffic anomaly early warning parameters, the traffic fluctuation event gain, and the baseline traffic at the current moment.

[0111] In one embodiment, the early warning analysis module 20 is further configured to: obtain a set of original events with time-series markers based on the event type, occurrence time, and impact range fields in the operation event log; calculate the initial impact score of each event in the original event set based on a preset event type-traffic impact mapping table; correct the initial impact score based on the interval between the occurrence time of each event in the original event set and the current time, and a dynamic weighted attenuation function, to obtain a real-time impact factor; and determine the traffic fluctuation event gain based on the real-time impact factor.

[0112] In one embodiment, the early warning analysis module 20 is further configured to perform multi-period time-series analysis based on the historical traffic data of the network path to obtain multiple periodic variation components, wherein the multiple periodic variation components include at least intraday periodic components, intraweekly periodic components, and seasonal periodic components; and calculate the baseline traffic at the current moment based on the multiple periodic variation components.

[0113] In one embodiment, the early warning analysis module 20 is further configured to: determine the original values ​​of the alarm activation threshold and the alarm recovery threshold based on the original values ​​of the traffic anomaly early warning parameters; obtain the traffic fluctuation time gain based on the baseline traffic at the current time; determine the alarm activation threshold based on the traffic fluctuation event gain, the traffic fluctuation time gain, and the original values ​​of the alarm activation threshold; determine the alarm recovery threshold based on the original values ​​of the traffic fluctuation event gain, the traffic fluctuation time gain, and the alarm recovery threshold; and use the alarm activation threshold and the alarm recovery threshold as the traffic anomaly early warning parameters of the network path.

[0114] In one embodiment, the state assessment module 30 is further configured to trigger a level one alarm when the real-time bandwidth occupancy data exceeds the alarm activation threshold; in the level one alarm state, the module calculates the percentage of over-limit duration and the cumulative over-limit traffic within a preset time window; if the percentage of over-limit duration exceeds the overload duration threshold, or the cumulative over-limit traffic exceeds the total overload traffic threshold, the alarm is upgraded to a level two alarm; in the level two alarm state, the module calculates the average traffic within the time window based on a sliding window; if the average traffic falls below the downgrade threshold, the alarm is reverted to a level one alarm; in the level one alarm state, the module calculates the average traffic within the time window based on a sliding window; if the average traffic drops below the alarm recovery threshold, the alarm is completely deactivated.

[0115] In one embodiment, the alarm execution module 40 is further configured to control the visual warning unit to flash yellow light at a fixed frequency and turn off the acoustic alarm in the first-level alarm state; control the visual warning unit to flash red light at an alternating frequency and activate the intermittent buzzing acoustic alarm in the second-level alarm state; and when the second-level alarm state is continuously maintained for more than a preset time, adjust the acoustic alarm to a continuous buzzing mode and simultaneously increase the flashing frequency of the visual warning unit.

[0116] This embodiment effectively distinguishes between normal business fluctuations and genuine anomalies by constructing a dynamic traffic baseline based on multi-cycle time-series analysis and an event impact attenuation model. Secondly, by dual-adjusting early warning parameters through event gain weighting and time attenuation factors, the system exhibits adaptive tolerance for traffic fluctuations caused by events within the maintenance plan, avoiding invalid alarms. Finally, the collaborative mechanism of multi-level alarms and multi-modal feedback, through a scientific combination of visual warning levels (yellow / red) and acoustic alarm modes (intermittent / continuous), ensures strong warnings of major faults while avoiding excessive interference with low-level anomalies, thus reducing operator fatigue. This solution effectively distinguishes between normal business fluctuations and genuine anomalies, enabling the system to exhibit adaptive tolerance for events within the maintenance plan, avoiding invalid alarms and excessive interference from low-level anomalies, reducing ineffective responses from maintenance personnel, and significantly improving the timeliness and accuracy of maintenance work.

[0117] The alarm behavior adaptive adjustment device provided in this application, employing the alarm behavior adaptive adjustment method in the above embodiments, can solve the technical problems of high false alarm rate and low operation and maintenance efficiency of traditional alarm mechanisms in highly dynamic network environments. Compared with the prior art, the beneficial effects of the alarm behavior adaptive adjustment device provided in this application are the same as those of the alarm behavior adaptive adjustment method provided in the above embodiments, and other technical features in the alarm behavior adaptive adjustment device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.

[0118] This application provides an alarm behavior adaptive adjustment device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the alarm behavior adaptive adjustment method in the above embodiment 1.

[0119] The following is for reference. Figure 4The diagram illustrates a structural schematic suitable for implementing an alarm behavior adaptive adjustment device according to embodiments of this application. The alarm behavior adaptive adjustment device in embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 4 The alarm behavior adaptive adjustment device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0120] like Figure 4 As shown, the alarm behavior adaptive adjustment device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.) that can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM) 1004. The RAM 1004 also stores various programs and data required for the operation of the alarm behavior adaptive adjustment device. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 1003 including, for example, magnetic tape, hard disk, etc.; and communication devices 1009. Communication device 1009 allows the alarm behavior adaptive adjustment device to communicate wirelessly or wiredly with other devices to exchange data. While the figures show alarm behavior adaptive adjustment devices with various systems, it should be understood that implementation or possession of all the systems shown is not required. More or fewer systems may be implemented alternatively.

[0121] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.

[0122] The alarm behavior adaptive adjustment device provided in this application, employing the alarm behavior adaptive adjustment method in the above embodiments, can solve the technical problems of high false alarm rate and low operation and maintenance efficiency of traditional alarm mechanisms in highly dynamic network environments. Compared with the prior art, the beneficial effects of the alarm behavior adaptive adjustment device provided in this application are the same as those of the alarm behavior adaptive adjustment method provided in the above embodiments, and other technical features in this alarm behavior adaptive adjustment device are the same as those disclosed in the previous embodiment method, and will not be repeated here.

[0123] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.

[0124] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0125] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, the computer-readable program instructions being used to execute the alarm behavior adaptive adjustment method in the above embodiments.

[0126] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.

[0127] The aforementioned computer-readable storage medium may be included in the alarm behavior adaptive adjustment device; or it may exist independently and not assembled into the alarm behavior adaptive adjustment device.

[0128] The aforementioned computer-readable storage medium carries one or more programs. When the aforementioned one or more programs are executed by the alarm behavior adaptive adjustment device, the alarm behavior adaptive adjustment device causes the device to: acquire real-time bandwidth utilization data and operation event logs in the network path; generate traffic anomaly warning parameters for the network path based on the operation event logs; determine the alarm behavior level under the real-time bandwidth utilization data based on the traffic anomaly warning parameters; and adjust the combination mode of visual warning and acoustic alarm according to the alarm behavior level to achieve adaptive adjustment of alarm behavior.

[0129] Computer program code for performing the operations of this application can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0130] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0131] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.

[0132] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described adaptive adjustment method for alarm behavior. This solves the technical problems of high false alarm rates and low operational efficiency in traditional alarm mechanisms under highly dynamic network environments. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the adaptive adjustment method for alarm behavior provided in the above embodiments, and will not be elaborated upon here.

[0133] The computer program product provided in this application can solve the technical problem of adaptive adjustment of alarm behavior. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as the beneficial effects of the adaptive adjustment method of alarm behavior provided in the above embodiments, and will not be repeated here.

[0134] The above description is only a part of the embodiments of this application and does not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.

Claims

1. A method for adaptive adjustment of alarming behavior, characterized in that, The adaptive adjustment method of the alarm behavior comprises: obtaining real-time bandwidth occupancy data and operation event logs of a network path; generating a traffic anomaly early warning parameter of the network path according to the operation event logs; the generating of the traffic anomaly early warning parameter of the network path according to the operation event logs comprises: determining a traffic fluctuation event gain according to the operation event logs; calculating a baseline traffic at a current time according to historical traffic data of the network path; generating the traffic anomaly early warning parameter of the network path according to an original value of the traffic anomaly early warning parameter, the traffic fluctuation event gain and the baseline traffic at the current time; the determining of the traffic fluctuation event gain according to the operation event logs comprises: obtaining an original event set with time sequence labels according to an event type, a time of occurrence and an impact range field in the operation event logs; calculating an initial impact score of each event in the original event set according to a preset event type-traffic impact mapping table; correcting the initial impact score according to an interval between a time of occurrence of each event in the original event set and a current time and a dynamic weighted decay function to obtain a real-time impact factor; determining the traffic fluctuation event gain according to the real-time impact factor; the generating of the traffic anomaly early warning parameter of the network path according to the original value of the traffic anomaly early warning parameter, the traffic fluctuation event gain and the baseline traffic at the current time comprises: determining an original value of an alarm start threshold and an original value of an alarm recovery threshold according to the original value of the traffic anomaly early warning parameter; obtaining a traffic fluctuation time gain according to the baseline traffic at the current time; determining the alarm start threshold according to the traffic fluctuation event gain, the traffic fluctuation time gain and the original value of the alarm start threshold; determining the alarm recovery threshold according to the traffic fluctuation event gain, the traffic fluctuation time gain and the original value of the alarm recovery threshold; taking the alarm start threshold and the alarm recovery threshold as the traffic anomaly early warning parameter of the network path; determining an alarm behavior level under the real-time bandwidth occupancy data based on the traffic anomaly early warning parameter; adjusting a combination mode of visual warning and acoustic alarm according to the alarm behavior level to realize adaptive adjustment of the alarm behavior.

2. The method of claim 1, wherein, the calculating of the baseline traffic at the current time according to the historical traffic data of the network path comprises: performing multi-period time sequence analysis on the historical traffic data of the network path to obtain a plurality of periodic change components, wherein the plurality of periodic change components at least comprise an intraday periodic component, a weekly periodic component and a seasonal periodic component; calculating the baseline traffic at the current time according to the plurality of periodic change components.

3. The method of claim 1, wherein, the traffic anomaly early warning parameter comprises an alarm start threshold, an overload duration threshold, an overload total traffic threshold and an alarm recovery threshold; the determining of the alarm behavior level under the real-time bandwidth occupancy data based on the traffic anomaly early warning parameter comprises: triggering a first-level alarm when the real-time bandwidth occupancy data is greater than the alarm start threshold; In the first level alarm state, the proportion of the over-limit duration and the cumulative over-limit flow in a preset time window are counted, if the proportion of the over-limit duration is greater than an overload duration threshold, or the cumulative over-limit flow is greater than an overload total flow threshold, the alarm state is upgraded to the second level alarm state; In the second level alarm state, the average flow in a time window is calculated based on a sliding window, if the average flow falls below a downgrade threshold, the alarm state is downgraded to the first level alarm state; In the first level alarm state, the average flow in a time window is calculated based on a sliding window, if the average flow falls below an alarm recovery threshold, the alarm state is completely removed.

4. The method of claim 1, wherein, The combination mode of the visual warning and the acoustic alarm is adjusted according to the alarm behavior level, including: In the first level alarm state, the visual warning unit is controlled to flash yellow light at a fixed frequency and the acoustic alarm is turned off; In the second level alarm state, the visual warning unit is controlled to flash red light at an alternating frequency, and the intermittent beeping acoustic alarm is activated; When the second level alarm state lasts for more than a preset time, the acoustic alarm is adjusted to a continuous beeping mode and the flashing frequency of the visual warning unit is simultaneously increased.

5. An apparatus for adaptive adjustment of alarming behavior, characterized in that The alarm behavior adaptive adjustment device includes: A data collection module is configured to acquire real-time bandwidth occupancy data and operation event logs of a network path; A pre-warning analysis module is configured to generate a flow anomaly pre-warning parameter of the network path according to the operation event logs; The pre-warning analysis module is further configured to determine a flow fluctuation event gain according to the operation event logs, calculate a baseline flow at a current time according to historical flow data of the network path, and generate the flow anomaly pre-warning parameter of the network path according to an original value of the flow anomaly pre-warning parameter, the flow fluctuation event gain, and the baseline flow at the current time; The pre-warning analysis module is further configured to obtain an original event set with time sequence labels according to an event type, a time of occurrence, and an impact range field in the operation event logs, calculate an initial impact score of each event in the original event set according to a preset event type-flow impact mapping table, correct the initial impact score according to an interval between the time of occurrence of each event in the original event set and a current time and a dynamic weighted decay function, and obtain a real-time impact factor according to the real-time impact factor, and determine a flow fluctuation event gain; The pre-warning analysis module is further configured to determine an original value of an alarm start threshold and an original value of an alarm recovery threshold according to an original value of the flow anomaly pre-warning parameter, obtain a flow fluctuation time gain according to a baseline flow at a current time, determine an alarm start threshold according to the flow fluctuation event gain, the flow fluctuation time gain, and the original value of the alarm start threshold, determine an alarm recovery threshold according to the flow fluctuation event gain, the flow fluctuation time gain, and the original value of the alarm recovery threshold, and take the alarm start threshold and the alarm recovery threshold as the flow anomaly pre-warning parameter of the network path; A state evaluation module is configured to determine an alarm behavior level under the real-time bandwidth occupancy data based on the flow anomaly pre-warning parameter. The alarm execution module is configured to adjust a combination mode of the visual warning and the acoustic alarm according to the alarm behavior level, so as to realize adaptive adjustment of the alarm behavior.

6. An apparatus for adaptive adjustment of alarming behavior, characterized by The alarm behavior adaptive adjustment device comprises a memory, a processor, and an alarm behavior adaptive adjustment program stored in the memory and executable on the processor, and the alarm behavior adaptive adjustment program is configured to implement the steps of the alarm behavior adaptive adjustment method according to any one of claims 1 to 4.

7. A storage medium, characterized by The storage medium stores an alarm behavior adaptive adjustment program, and the alarm behavior adaptive adjustment program, when executed by the processor, implements the steps of the alarm behavior adaptive adjustment method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Intelligent task alarm rule self-learning method and system based on support priority

    CN119441832A

  • Intelligent alarm preprocessing method of self-adaptive rule engine

    CN120321102A