Key-indicator-based core network anomaly identification method and apparatus, and electronic device

By reducing the multi-dimensional index data of the core network to three-dimensional and using clustering algorithms, data redundancy and visualization difficulties in high-dimensional analysis are solved, efficient and accurate identification and positioning of the core network abnormality is achieved, and the stability and reliability of network operation are improved.

WO2025175917A1PCT designated stage Publication Date: 2025-08-28CHINA MOBILE GROUP DESIGN INST +1

Patent Information

Application Number
PCT/CN2024/142916
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-19
Filing Date
2024-12-26
Publication Date
2025-08-28

AI Technical Summary

Technical Problem

In the core network architecture, the analysis of high-dimensional indicators faces problems such as data redundancy and sparseness, difficulty in visualization, dimensional disasters, difficulty in feature selection and extraction, complex multi-dimensional correlation, loss of information and high time and energy costs, resulting in low efficiency of manual analysis and difficulty in quickly identifying abnormalities.

Method used

The neural network-based feature lossless dimensional compression algorithm (AE) and density-based clustering analysis algorithm (DBSCAN) are used to reduce the dimensions of multi-dimensional index data to three-dimensional, and cluster analysis is performed through the logical relationship of the pool group, abnormal targets are identified, three-dimensional clustering diagrams are generated, and abnormal information is output.

Benefits of technology

It realizes efficient and accurate core network abnormal identification, improves the efficiency and accuracy of multi-dimensional indicator analysis, reduces the need for manual intervention, and can quickly detect and locate abnormalities to ensure stable network operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024142916_28082025_PF_FP_ABST
    Figure CN2024142916_28082025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to the technical field of communication network operation and maintenance. Provided are a key-indicator-based core network anomaly identification method and apparatus, and an electronic device. By taking a network element type and a pool as an aggregation unit, dimensionality reduction is performed on multi-dimensional key indicators of network elements to obtain three-dimensional key indicators for easy visualization; and key indicators of all network elements in a network element pool are input on the basis of pool relationships, such that the capability of horizontal comparison of features across multiple network elements and multiple indicators can be provided, and anomaly analysis is then performed on three-dimensional data by means of a clustering algorithm, so as to find and obtain outliers representing anomalies, and thus, related information can be extracted from the outliers to generate a three-dimensional clustering view, and results such as an anomalous network element list, anomaly time, a complete KPI record and the clustering view are returned. The disclosure can realize quick locating of anomalies of a core network, and significantly improves the effect of multi-dimensional indicator analysis and the accuracy of anomaly detection, thereby facilitating early intervention and early troubleshooting of network problems, and thus ensuring stable and normal network operation.
Need to check novelty before this filing date? Find Prior Art

Description

Core network anomaly identification method, device and electronic equipment based on key indicators

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This disclosure is based on and claims the priority of Chinese patent application with application number 202410184995.5 and application date February 19, 2024. The entire content of the Chinese patent application is hereby incorporated into this disclosure by reference. Technical Field

[0003] The present disclosure relates to the field of communication network operation and maintenance technology, and in particular to a core network anomaly identification method, device, and electronic equipment based on key indicators. Background Art

[0004] As the basic infrastructure of the network, the core network undertakes important functions such as signaling transmission and user data transmission. Its stable operation is crucial to communication services. Real-time monitoring and analysis of multiple key performance indicators (hereinafter referred to as multi-dimensional indicators and KPI indicators in this disclosure) of core network network elements (such as AMF, SMF, UPF, CSCF, UDM, etc.) is one of the key methods of core network operation and maintenance. It enables operation and maintenance personnel to understand the operating status and performance of the core network in real time, thereby ensuring stable network operation, improving the quality of communication services, and meeting the growing needs of users.

[0005] Specifically, these KPI indicators are usually set according to the functional characteristics of the network element (for example, the main function of AMF is mobility management, and the main function of SMF is session management), and try to cover all key aspects of the network element function, such as signaling processing speed, user access delay, data transmission rate, etc. By monitoring these indicators through the monitoring system, setting static thresholds, comparing according to a certain time period, or making horizontal comparisons between network elements, operation and maintenance personnel can promptly discover potential problems, predict network congestion, failures, etc., and take corresponding optimization and maintenance measures to ensure network stability and reliability. In addition, multi-dimensional indicator monitoring can also help operation and maintenance personnel accurately locate problems, optimize network resource allocation, improve network performance and user experience, and avoid possible service interruptions or quality degradation. Summary of the Invention

[0006] In view of the above problems, the present disclosure is proposed. The present disclosure provides a method, device and electronic device for identifying core network anomalies based on key indicators, and correspondingly provides a computer-readable storage medium.

[0007] According to one aspect of the present disclosure, a method for identifying core network anomalies based on key indicators is provided, the method comprising:

[0008] Obtain multi-dimensional indicator data of core network elements and logical relationships between pool groups;

[0009] Compressing multi-dimensional indicator data into three-dimensional indicator data;

[0010] Based on the pool group logical relationship, cluster analysis is performed on the three-dimensional indicator data to generate a three-dimensional cluster graph and identify abnormal targets;

[0011] Based on the abnormal target, a list of abnormal network elements corresponding to the abnormal target, a timestamp indicating the abnormal time of the abnormal target, and an indicator data record of the abnormal target are output.

[0012] In addition, the core network anomaly identification method based on key indicators according to one aspect of the present disclosure further includes outputting the three-dimensional clustering graph, wherein the abnormal target is marked in the three-dimensional clustering graph.

[0013] In addition, according to the core network anomaly identification method based on key indicators in one aspect of the present disclosure, compressing the multi-dimensional indicator data into three-dimensional indicator data includes:

[0014] Pre-train the dimension compression model with historical network element indicator data;

[0015] The trained dimension compression model is used to process the multidimensional indicator data into three-dimensional indicator data.

[0016] In addition, according to the core network anomaly identification method based on key indicators in one aspect of the present disclosure, the construction method of the dimensional compression model includes: using historical indicator data to train the autoencoder neural network model according to different network element types.

[0017] In addition, according to the core network anomaly identification method based on key indicators in one aspect of the present disclosure, the clustering analysis of the three-dimensional indicator data includes: clustering the three-dimensional indicator data in pool groups through a density-based clustering algorithm to identify outliers as abnormal targets.

[0018] In addition, according to the core network anomaly identification method based on key indicators in one aspect of the present disclosure, clustering the three-dimensional indicator data in pool groups using a density-based clustering algorithm includes:

[0019] Obtaining a data set consisting of multiple indicator sequences based on each of the three-dimensional indicator data;

[0020] Based on the spacing between data points in the dataset, set the parameters of the density-based clustering algorithm, including the neighborhood radius and the minimum number of indicator sequences within the neighborhood radius;

[0021] Determining core points in a data set based on the neighborhood radius and the minimum number of indicator sequences;

[0022] Performing recursive expansion based on the core point;

[0023] Repeat the above steps until clusters of indicator sequences are formed, and the indicator sequences that are not in any clusters are regarded as abnormal targets.

[0024] According to another aspect of the present disclosure, a core network anomaly identification device based on key indicators is provided, the identification device comprising:

[0025] The acquisition module is used to obtain multi-dimensional indicator data of core network elements and the logical relationship between pool groups;

[0026] Dimensionality reduction module, used to compress multi-dimensional indicator data into three-dimensional indicator data;

[0027] A clustering module, configured to perform cluster analysis on the three-dimensional indicator data based on the logical relationship of the pool groups, generate a three-dimensional cluster graph, and identify abnormal targets;

[0028] An output module is used to output, based on the abnormal target, a list of abnormal network elements corresponding to the abnormal target, a timestamp indicating the abnormal time of the abnormal target, an indicator data record of the abnormal target, and a three-dimensional clustering diagram.

[0029] In addition, according to the core network anomaly identification device based on key indicators in one aspect of the present disclosure, the output module is configured to: output the three-dimensional clustering graph, wherein the abnormal target is marked in the three-dimensional clustering graph.

[0030] In addition, according to the core network anomaly identification device based on key indicators in one aspect of the present disclosure, the clustering module is configured to: cluster the three-dimensional indicator data in pool groups through a density-based clustering algorithm to identify outliers as abnormal targets.

[0031] In addition, according to the core network anomaly identification device based on key indicators in one aspect of the present disclosure, the clustering module specifically includes:

[0032] A data set establishing unit, configured to obtain a data set consisting of a plurality of indicator sequences based on each of the three-dimensional indicator data;

[0033] A clustering parameter setting unit is used to set the parameters of the density-based clustering algorithm based on the spacing between data points in the data set, wherein the parameters include: a neighborhood radius and a minimum number of indicator sequences within the neighborhood radius;

[0034] a core point determination unit, configured to determine a core point in a data set according to the neighborhood radius and the minimum number of indicator sequences;

[0035] A cluster expansion unit, configured to perform recursive expansion based on the core point;

[0036] The cluster generation unit is used to control the data set establishment unit, the cluster parameter setting unit, the core point determination unit and the cluster expansion unit to repeat operations until clusters of indicator sequences are formed, and to treat indicator sequences that are not in any cluster as abnormal targets.

[0037] According to another aspect of the present disclosure, an electronic device is provided, including: a memory for storing computer-readable instructions; and a processor for executing the computer-readable instructions so that the electronic device executes the core network anomaly identification method based on key indicators as described above.

[0038] According to another aspect of the present disclosure, a non-transitory computer-readable storage medium is provided for storing computer-readable instructions. When the computer-readable instructions are executed by a processor, the processor executes the core network anomaly identification method based on key indicators as described above.

[0039] As will be described in detail below, the core network anomaly identification method, device, electronic device, and computer-readable storage medium based on key indicators according to the embodiments of the present disclosure are mainly based on the concept of reducing the dimensionality of the multi-dimensional key indicators of network elements to three dimensions for easy visualization, using network element type and pool as the collection unit. Based on the Pool relationship, the key indicators of all network elements in the network element pool are input to provide the ability to compare the characteristics of multiple network elements and multiple indicators horizontally. Then, anomaly analysis is performed on the three-dimensional data using a clustering algorithm to discover and obtain outliers that represent anomalies. From this, relevant information can be extracted to generate a three-dimensional cluster view, and results such as a list of abnormal network elements, anomaly time, complete KPI records, and cluster views are returned. The present disclosure can quickly locate core network anomalies, has the advantage of improving the efficiency of core network operation diagnosis and optimization, significantly improves the effect of multi-dimensional indicator analysis and the accuracy of anomaly detection, and reduces the possibility of omissions, thereby facilitating early intervention and early troubleshooting of network problems, eliminating potential faults in the bud, and ensuring the smooth and normal operation of the network.

[0040] In particular, the present disclosure also introduces a neural network-based feature lossless dimensionality compression algorithm (Auto-encoder, AE) and a density-based clustering analysis algorithm (Density-Based Spatial Clustering of Applications with Noise, DBSCAN). Therefore, the dimensionality compression and clustering analysis proposed in the previous article can be a fully unsupervised automated multi-dimensional indicator analysis method, so that in the core network multi-dimensional indicator monitoring scenario, it can realize unsupervised learning and summarize the rules and correlations of the above-mentioned multi-dimensional indicators, and achieve fully automatic analysis without human intervention and the effect of discovering anomalies in multi-dimensional indicators.

[0041] It is to be understood that both the foregoing general description and the following detailed description are exemplary, and are intended to provide further explanation of the technology as claimed. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] The above and other purposes, features, and advantages of the present disclosure will become more apparent through a more detailed description of the embodiments of the present disclosure in conjunction with the accompanying drawings. The accompanying drawings are intended to provide a further understanding of the embodiments of the present disclosure and constitute a part of the specification. Together with the embodiments of the present disclosure, they are used to explain the present disclosure and are not intended to limit the present disclosure. In the drawings, the same reference numerals generally represent the same components or steps.

[0043] FIG1 is a schematic diagram illustrating the main process of a method for identifying core network anomalies based on key indicators according to an embodiment of the present disclosure.

[0044] FIG2 is a schematic flow chart illustrating a density clustering method according to an embodiment of the present disclosure.

[0045] FIG3 is a functional block diagram illustrating a core network anomaly identification device based on key indicators according to an embodiment of the present disclosure.

[0046] FIG4 is a hardware block diagram illustrating an electronic device according to an embodiment of the present disclosure.

[0047] FIG5 is a schematic diagram illustrating a computer-readable storage medium according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0048] In order to make the purpose, technical solutions and advantages of the present disclosure more apparent, the following will describe in detail exemplary embodiments of the present disclosure with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments of the present disclosure, and it should be understood that the present disclosure is not limited to the exemplary embodiments described herein.

[0049] As the basic infrastructure of the network, the core network undertakes important functions such as signaling transmission and user data transmission. Its stable operation is crucial to communication services. Real-time monitoring and analysis of multiple key performance indicators (hereinafter referred to as multi-dimensional indicators and KPI indicators in this disclosure) of core network network elements (such as AMF, SMF, UPF, CSCF, UDM, etc.) is one of the key methods of core network operation and maintenance. It enables operation and maintenance personnel to understand the operating status and performance of the core network in real time, thereby ensuring stable network operation, improving the quality of communication services, and meeting the growing needs of users.

[0050] Specifically, these KPI indicators are usually set according to the functional characteristics of the network element (for example, the main function of AMF is mobility management, and the main function of SMF is session management), and try to cover all key aspects of the network element function, such as signaling processing speed, user access delay, data transmission rate, etc. By monitoring these indicators through the monitoring system, setting static thresholds, comparing according to a certain time period, or making horizontal comparisons between network elements, operation and maintenance personnel can promptly discover potential problems, predict network congestion, failures, etc., and take corresponding optimization and maintenance measures to ensure network stability and reliability. In addition, multi-dimensional indicator monitoring can also help operation and maintenance personnel accurately locate problems, optimize network resource allocation, improve network performance and user experience, and avoid possible service interruptions or quality degradation.

[0051] However, as core network architecture evolves towards flatter and cloud-based architecture, the number of key indicators (i.e., dimensions) for core network elements has increased significantly, with a single element type ranging from dozens to hundreds, and the interrelationships between multi-dimensional indicators are becoming increasingly complex. Analyzing high-dimensional indicators presents numerous challenges and difficulties, including:

[0052] First, data redundancy and sparsity: High-dimensional data often contains a large amount of redundant information and sparsity, that is, the values ​​of most indicators are zero or similar, which makes it difficult for manual analysis to capture the overall patterns and regularities of the data.

[0053] Second, visualization is difficult: High-dimensional data is difficult to visualize directly because the human visual system can only perceive space in three dimensions or less. In high-dimensional space, it is difficult to intuitively visualize and observe data, which limits the effectiveness of manual analysis.

[0054] Third, the curse of dimensionality: High-dimensional data sets bring huge complexity in computing and storage, also known as the curse of dimensionality. Traditional manual analysis methods are inefficient on high-dimensional data and have difficulty processing large-scale high-dimensional data sets.

[0055] Fourth, feature selection and extraction: In high-dimensional data, there are often a large number of features, but only some of them are useful for problem solving or pattern discovery, making manual selection and extraction of effective features extremely difficult and requiring a lot of time and expertise.

[0056] Fifth, multi-dimensional correlation: In high-dimensional data, there may be complex multi-dimensional correlations between different indicators, and manual analysis is difficult to fully understand and capture these complex relationships.

[0057] Sixth, information loss: In order to reduce the dimension for manual analysis, dimensionality reduction processing is often required, which may lead to information loss and data deformation, affecting the accuracy of the analysis results.

[0058] Seventh, time and energy cost: The analysis of high-dimensional data requires more time and energy, and manual analysis is difficult to efficiently cope with the processing and analysis needs of large-scale high-dimensional data.

[0059] In view of the above problems, the present disclosure is proposed. The present disclosure provides a method, device and electronic device for identifying core network anomalies based on key indicators, and correspondingly provides a computer-readable storage medium.

[0060] First, a method for identifying core network anomalies based on key indicators according to an embodiment of the present disclosure will be described with reference to Figures 1 and 2. Figure 1 is a schematic diagram illustrating the main flow of the method for identifying core network anomalies based on key indicators according to an embodiment of the present disclosure. Figure 2 is a schematic diagram further illustrating the flow of a density clustering method according to an embodiment of the present disclosure.

[0061] The core network anomaly identification method based on key indicators according to an embodiment of the present disclosure will be described in detail with reference to FIG1 and FIG2 , including:

[0062] Step S1: Acquire multi-dimensional indicator data of core network elements and pool group (Pool) logical relationships;

[0063] The indicator data mentioned here may include but is not limited to CPU utilization, memory utilization, beam utilization, and other key indicators closely related to the operating status of core network elements. The Pool logical relationship between network elements can represent the pool group affiliation of different network elements. The emphasis on pool group affiliation information in this disclosure is based on the following considerations:

[0064] By inputting the key indicators of all network elements in the pool based on the pool logical relationship, it is possible to compare and analyze the characteristics of multiple network elements and multiple indicators. Multi-indicator dimensionality reduction clustering provides the ability to compare network elements horizontally within the pool, increasing the methods and efficiency of determining network element anomalies. The pool-based dimensionality reduction clustering method has at least the following advantages over anomaly identification based on individual network elements:

[0065] 1. Improved data understanding: Pool-based anomaly identification provides richer contextual information. By analyzing the feature differences between network elements within a pool group, we can better understand the characteristics and influencing factors of abnormal network elements, thereby more accurately locating the cause of the anomaly and taking appropriate measures to address it.

[0066] 2. Discovery of characteristic differences: By grouping network elements into their respective pool groups, the characteristic differences between different pool groups can be better compared and analyzed. This helps to identify network elements that are significantly different from other network elements and better understand the reasons for these differences.

[0067] 3. Improved efficiency and scalability: Compared with anomaly identification of individual network elements, dimensionality reduction clustering based on pools can reduce large amounts of indicator data to lower dimensions, thereby reducing data complexity and improving the efficiency and scalability of the algorithm. Specifically, by grouping network elements into pools, the amount of computation and storage requirements can be reduced while improving the speed and scalability of the algorithm.

[0068] Specifically in actual operation, the multi-dimensional indicators (KPI) of the core network elements and the Pool relationship of the network elements can be received in Json format by opening the Restful API interface, which is not limited in this disclosure.

[0069] Step S2: compressing the multi-dimensional index data into three-dimensional index data;

[0070] Specifically, the historical KPI data of network elements can be obtained in advance to train a dimensional compression model. Therefore, when processing multi-dimensional KPIs in real time, the trained dimensional compression model can be used to output three-dimensional indicator data, which can be represented in a visual way as multiple indicator data of each core network element at a certain timestamp are compressed into points with three-dimensional coordinate information.

[0071] Based on this concept, in some preferred embodiments of the present disclosure, the specific construction of the aforementioned dimensional compression model can be based on the above-mentioned historical KPI data, training an autoencoder neural network model, thereby achieving dimensional compression of multidimensional KPI indicators to three dimensions, thereby ensuring that the multidimensional indicators are compressed to three dimensions without losing data features, so that the multidimensional indicators are visualized. In actual operation, the training of the dimensional compression model can be carried out according to different network element types, specifically including two processes, Encoder and Decoder, where Code is a three-dimensional feature, and the Decoder process can restore the Code after dimensionality reduction and compression. In the model training process, the Input and Output can use the MSE variance as the loss function, and the deviation is controlled within the range of 0.003. Finally, the training obtains the conversion relationship between multidimensional indicator data and Code.

[0072] The specific implementation can be referred to as follows:

[0073] (1) Model construction:

[0074] Construct an Autoencoder model (Auto-Encoder, AE), which consists of two parts: an encoder and a decoder. The encoder maps the input data to a latent representation space, and the decoder maps the latent representation back to the original data dimension.

[0075] (2) Define the loss function:

[0076] The goal of the Auto-Encoder is to minimize the difference between the input data and the reconstructed data, so a loss function is defined to measure the reconstruction error. The loss function used in some embodiments of the present disclosure is the mean square error (MSE), which is the square difference between the input data and the decoder output.

[0077] Among them, n represents the number of input data, y i represents the input data, and Representation and input data y i The corresponding decoder output.

[0078] (3) Training process:

[0079] The Autoencoder model is trained using the historical KPIs obtained. During the training process, the model parameters are adjusted using the backpropagation algorithm to minimize the loss function. Each training epoch includes the following steps:

[0080] a) Randomly select a batch from the training data.

[0081] b) Feed the batch of data into the encoder to obtain the latent representation.

[0082] c) Feed the latent representation into the decoder to obtain the reconstructed data.

[0083] d) Calculate the loss between the reconstructed data and the original data.

[0084] e) Use backpropagation to update the model parameters to reduce the loss.

[0085] (4) Hyperparameter adjustment:

[0086] During training, it's necessary to select appropriate hyperparameters, such as the learning rate, batch size, and number of hidden layer nodes. These hyperparameters affect training effectiveness and need to be adjusted based on experimental results. In practice, training and tuning can be performed using a large number of core network multi-dimensional KPI indicators to identify a well-suited set of hyperparameter settings.

[0087] (5) Training termination:

[0088] If the number of training iterations set in the hyperparameters and the threshold range after comparing the MSE loss function between the input and output are met, the training process is terminated and the AE model used for subsequent dimensional compression inference is output (that is, the mapping relationship from sample data input to abstract feature code is learned).

[0089] Combined with the description of the training process, it can be seen that the three-dimensional index after dimensionality compression here is actually the feature (code) in the training process. As mentioned above, this feature (code) can also be restored through the Decoder process and the MSE of the original multidimensional index of the input is guaranteed to be within 0.003, that is, the dimensionality compression process does not lose the original multidimensional data features.

[0090] Step S3: performing cluster analysis on the three-dimensional indicator data based on the pool group logical relationship to identify abnormal targets;

[0091] Because network elements in the same pool are located close together and have similar KPI indicators, high-density areas and outlier noise points within clusters can be discovered and a three-dimensional cluster map can be generated. Therefore, by clustering the compressed data results using a density-based clustering algorithm, outliers can be automatically and efficiently identified and identified as anomalies.

[0092] Specifically, the compressed three-dimensional core network element indicators obtained in the previous step can be clustered and analyzed by pool using the density-based spatial clustering of applications with noise (DBSCAN). Core network elements are typically organized into pools for load sharing and mutual backup and disaster recovery. Because multiple elements within a pool cover the same geographic area, meaning they serve users with similar behavioral characteristics, their multi-dimensional indicators are similar. Therefore, the density-based clustering algorithm can identify outliers, which are actually abnormal points.

[0093] Regarding the algorithm mechanism of the DBSCAN clustering method mentioned here, the overall framework can be referred to as follows: calculating the distance between data points, selecting algorithm parameters (including the neighborhood radius (ε) and the minimum number of neighbors (MinPts)), identifying core points, boundary points, and noise points, recursively expanding clusters from core points, and repeatedly iterating to form the final cluster cluster, so that abnormal outliers can be detected.

[0094] Therefore, in conjunction with FIG2 , the density clustering implementation process in the present disclosure scenario can be expanded as follows:

[0095] Step S31: obtaining a data set consisting of several indicator sequences based on the three-dimensional indicator data;

[0096] The compressed three-dimensional KPI sequences (hereinafter referred to as indicator sequences) of different network elements are organized into a data set, where each indicator sequence represents a data point in the data set, and the distance between indicator sequences can be calculated using metrics such as Euclidean distance:

[0097] Among them, N represents the dimension of the indicator sequence, x 1i 、x 2i Represent the components of two data points in the i-th dimension respectively.

[0098] Step S32: setting parameters of a density-based clustering algorithm based on the spacing between data points in the data set, the parameters including: neighborhood radius and the minimum number of indicator sequences within the neighborhood radius;

[0099] Select parameters for the density clustering algorithm, namely the neighborhood radius (ε) and the minimum number of neighbors (MinPts), where ε defines the neighborhood range of a point (all other points within the neighborhood radius of the point are neighbors of the point), and MinPts represents the minimum number of indicator sequences within ε.

[0100] Step S33: Determine core points in the data set based on the neighborhood radius and the minimum number of indicator sequences:

[0101] Specifically, the number of indicator sequences within the ε neighborhood of each indicator sequence can be calculated. If the number of indicator sequences within the ε neighborhood of this indicator sequence is greater than or equal to MinPts, the indicator sequence is marked as a core point. Then, based on the core point and its neighborhood radius, the border points are determined in the data set.

[0102] For other data points (indicator sequences) in the dataset that are not marked as core points, if they are within the ε neighborhood of a core point, then the indicator sequence is marked as a boundary point. Therefore, after the above traversal marking, those data points (indicator sequences) that are neither marked as core points nor marked as boundary points can be marked as noise points.

[0103] Step S34: recursively expand based on the core point;

[0104] Starting from a core point, recursively traverse the indicator sequences in its ε neighborhood and add the indicator sequences in the neighborhood to the cluster. During the clustering process, if an indicator sequence in the neighborhood is a core point, then continue to recursively add the indicator sequences in its neighborhood to the cluster.

[0105] Step S35: Repeat the above process until clusters of indicator sequences are formed, and treat indicator sequences that are not in any cluster as abnormal targets.

[0106] Repeat the above process until all core points and boundary points are assigned to clusters. At this point, it is easy to identify all indicator sequences that do not belong to any cluster, that is, discrete data points. Through this process, the density-based clustering algorithm can find clusters with high density in the three-dimensional indicator sequence and lock on to abnormal indicator sequences.

[0107] Step S4: Based on the abnormal target, output a list of abnormal network elements corresponding to the abnormal target, a timestamp indicating the abnormal time of the abnormal target, and an indicator data record.

[0108] Finally, relevant information about the outliers (i.e., abnormal points), such as the name of the network element (i.e., abnormal network element) corresponding to the outlier and the time of the abnormality, is extracted to form a list and time information. This information is then sent to the operation and maintenance personnel along with the complete KPI record and the corresponding generated three-dimensional cluster view, enabling accurate identification of abnormal issues and targeted subsequent maintenance work. The abnormal time refers to the time when the outlier occurred.

[0109] In addition, in addition to the list of abnormal network elements corresponding to the above-mentioned abnormal targets, the timestamp indicating the abnormal time of the abnormal targets, and the indicator data records, a three-dimensional clustering map can also be output, in which the abnormal targets are marked, thereby effectively realizing the visualization of the abnormal targets.

[0110] The above describes a method for identifying core network anomalies based on key indicators according to an embodiment of the present disclosure. Below, a device for identifying core network anomalies based on key indicators, used to implement the above control method, will be further described. Figure 3 is a functional block diagram illustrating the device for identifying core network anomalies based on key indicators according to an embodiment of the present disclosure.

[0111] As shown in FIG3 , a core network anomaly identification device 300 based on key indicators according to an embodiment of the present disclosure includes:

[0112] The collection module 301 is used to obtain multi-dimensional indicator data of core network elements and pool group logical relationships;

[0113] Dimensionality reduction module 302, used to compress multi-dimensional indicator data into three-dimensional indicator data;

[0114] A clustering module 303 is configured to perform cluster analysis on the three-dimensional indicator data based on the pool group logical relationship to identify abnormal targets;

[0115] The output module 304 is configured to output, based on the abnormal target, a list of abnormal network elements corresponding to the abnormal target, a timestamp indicating the abnormal time of the abnormal target, and an indicator data record of the abnormal target.

[0116] Furthermore, the clustering module 303 is further configured to generate a three-dimensional clustering graph based on cluster analysis of the three-dimensional indicator data, and the output module is further configured to output the three-dimensional clustering graph, wherein the abnormal targets are marked in the three-dimensional clustering graph.

[0117] Furthermore, the clustering module is configured to: perform cluster analysis on the three-dimensional indicator data in pool groups by using a density-based clustering algorithm, and identify outliers that are abnormal targets.

[0118] Furthermore, the clustering module specifically includes:

[0119] A data set establishing unit, configured to obtain a data set consisting of a plurality of indicator sequences based on each of the three-dimensional indicator data;

[0120] A clustering parameter setting unit is used to set the parameters of the density-based clustering algorithm based on the spacing between data points in the data set. The parameters include: neighborhood radius and the minimum number of indicator sequences within the neighborhood radius;

[0121] a core point determination unit, configured to determine a core point in a data set according to the neighborhood radius and the minimum number of indicator sequences;

[0122] A cluster expansion unit, configured to perform recursive expansion based on the core point;

[0123] The cluster generation unit is used to control the data set establishment unit, the cluster parameter setting unit, the core point determination unit and the cluster expansion unit to repeat operations until clusters of indicator sequences are formed, and to treat indicator sequences that are not in any cluster as abnormal targets.

[0124] Figure 4 is a hardware block diagram illustrating an electronic device 600 according to an embodiment of the present disclosure. The electronic device according to an embodiment of the present disclosure includes at least a processor and a memory for storing computer-readable instructions. When the computer-readable instructions are loaded and executed by the processor, the processor executes the core network anomaly identification method based on key indicators as described above.

[0125] The electronic device 600 shown in Figure 4 specifically includes: a central processing unit (CPU) 601, a graphics processing unit (GPU) 602, and a main memory 603. These units are interconnected via a bus 604. The central processing unit (CPU) 601 and / or the graphics processing unit (GPU) 602 can be used as the above-mentioned processor, and the main memory 603 can be used as the above-mentioned memory for storing computer-readable instructions. In addition, the electronic device 600 may also include a communication unit 605, a storage unit 606, an output unit 607, an input unit 608, and an external device 609, which are also connected to the bus 604.

[0126] FIG5 is a schematic diagram illustrating a computer-readable storage medium according to an embodiment of the present disclosure. As shown in FIG5 , a computer-readable storage medium 700 according to an embodiment of the present disclosure has computer-readable instructions 701 stored thereon. When the computer-readable instructions 701 are executed by a processor, the core network anomaly identification method based on key indicators according to an embodiment of the present disclosure described with reference to the above figures is executed. The computer-readable storage medium includes, but is not limited to, for example, volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM) and / or cache memory (cache), etc. The non-volatile memory may, for example, include read-only memory (ROM), a hard disk, a flash memory, an optical disk, a magnetic disk, etc.

[0127] The above describes, with reference to the accompanying drawings, a core network anomaly identification method, apparatus, electronic device, and computer-readable storage medium based on key indicators according to embodiments of the present disclosure. The main concept is to reduce the dimensionality of multi-dimensional key indicators of network elements to three dimensions for easy visualization, using network element type and pool as the collection unit. Based on the Pool relationship, inputting the key indicators of all network elements in the network element pool can provide the ability to compare the characteristics of multiple network elements and multiple indicators horizontally. Then, anomaly analysis is performed on the three-dimensional data using a clustering algorithm to discover and obtain outliers that represent anomalies. From this, relevant information can be extracted to generate a three-dimensional cluster view, and results such as a list of abnormal network elements, anomaly time, complete KPI records, and cluster views are returned. The present disclosure can quickly locate core network anomalies, has the advantage of improving the efficiency of core network operation diagnosis and optimization, significantly improves the effect of multi-dimensional indicator analysis and the accuracy of anomaly discovery, and reduces the possibility of omissions, thereby facilitating early intervention and early troubleshooting of network problems, eliminating potential faults in the bud, and ensuring the smooth and normal operation of the network.

[0128] In particular, the present disclosure also introduces a neural network-based feature lossless dimensionality compression algorithm (Auto-encoder, AE) and a density-based clustering analysis algorithm (Density-Based Spatial Clustering of Applications with Noise, DBSCAN). Therefore, the dimensionality compression and clustering analysis proposed in the previous article can be a fully unsupervised automated multi-dimensional indicator analysis method, so that in the core network multi-dimensional indicator monitoring scenario, it can realize unsupervised learning and summarize the rules and correlations of the above-mentioned multi-dimensional indicators, and achieve fully automatic analysis without human intervention and the effect of discovering anomalies in multi-dimensional indicators.

[0129] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.

[0130] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, strengths, and effects mentioned in this disclosure are merely illustrative and not restrictive, and should not be construed as necessarily possessed by each embodiment of the present disclosure. Furthermore, the specific details disclosed above are provided for illustrative purposes and to facilitate understanding, rather than as limitations. These details do not limit the present disclosure to necessarily being implemented using these specific details.

[0131] The block diagrams of the devices, devices, equipment, and systems involved in this disclosure are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As will be appreciated by those skilled in the art, these devices, devices, equipment, and systems can be connected, arranged, or configured in any manner. Words such as "include," "comprise," "have," and the like are open-ended words, meaning "including but not limited to," and can be used interchangeably therewith. The words "or" and "and" used herein refer to the words "and / or" and can be used interchangeably therewith, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to," and can be used interchangeably therewith.

[0132] Additionally, as used herein, "or" used in a list of items beginning with "at least one" indicates a separate list, so that, for example, a list of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word "exemplary" does not mean that the example described is preferred or better than other examples.

[0133] It should also be noted that in the system and method of the present disclosure, each component or each step can be decomposed and / or recombined. Such decomposition and / or recombination should be regarded as equivalent solutions of the present disclosure.

[0134] Various changes, substitutions, and modifications may be made to the technology described herein without departing from the teachings defined by the appended claims. Moreover, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of things, means, methods, and actions described above. Currently existing or later developed processes, machines, manufactures, compositions of things, means, methods, or actions that perform substantially the same function or achieve substantially the same results as the corresponding aspects described herein may be utilized. Accordingly, the appended claims include within their scope such processes, machines, manufactures, compositions of things, means, methods, or actions.

[0135] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the aspects shown herein, but rather to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0136] All embodiments of the present disclosure may be implemented individually or in combination with other embodiments, and are all considered to be within the scope of protection claimed by the present disclosure.

[0137] The above description has been provided for the purpose of illustration and description. In addition, this description is not intended to limit the embodiments of the present disclosure to the forms disclosed herein. Although a number of example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.

Claims

1. A method for identifying core network anomalies based on key indicators, the method comprising: Obtain multi-dimensional indicator data of core network elements and logical relationships between pool groups; compressing the multidimensional indicator data into three-dimensional indicator data; Based on the logical relationship of the pool groups, cluster analysis is performed on the three-dimensional indicator data to identify abnormal targets; Based on the abnormal target, a list of abnormal network elements corresponding to the abnormal target, a timestamp indicating the abnormal time of the abnormal target, and an indicator data record of the abnormal target are output.

2. The method for identifying core network anomalies based on key indicators according to claim 1, further comprising: Based on the cluster analysis of the three-dimensional indicator data, a three-dimensional cluster diagram is generated, and The three-dimensional cluster map is output, wherein the abnormal target is marked in the three-dimensional cluster map.

3. The method for identifying core network anomalies based on key indicators according to claim 1 or 2, wherein compressing multi-dimensional indicator data into three-dimensional indicator data comprises: Pre-train the dimension compression model with historical network element indicator data; The trained dimension compression model is used to process the multidimensional indicator data into three-dimensional indicator data.

4. In the method for identifying core network anomalies based on key indicators according to claim 3, the dimension compression model is constructed by: According to different network element types, historical indicator data is used to train the autoencoder neural network model.

5. The method for identifying core network anomalies based on key indicators according to any one of claims 1 to 4, wherein the cluster analysis of the three-dimensional indicator data comprises: The three-dimensional indicator data is clustered and analyzed in pool groups using a density-based clustering algorithm to identify outliers that are abnormal targets.

6. The method for identifying core network anomalies based on key indicators according to claim 5, wherein clustering analysis of the three-dimensional indicator data in pool groups using a density-based clustering algorithm comprises: Obtaining a data set consisting of multiple indicator sequences based on each of the three-dimensional indicator data; Setting parameters of the density-based clustering algorithm based on the spacing between data points in the data set, wherein the parameters include: a neighborhood radius and a minimum number of indicator sequences within the neighborhood radius; Determining core points in the data set according to the neighborhood radius and the minimum number of indicator sequences; Performing recursive expansion based on the core point; The above steps are repeated until clusters of indicator sequences are formed, and the indicator sequences that are not in any clusters are regarded as the abnormal targets.

7. A core network anomaly identification device based on key indicators, the identification device comprising: The acquisition module is used to obtain multi-dimensional indicator data of core network elements and the logical relationship between pool groups; Dimensionality reduction module, used to compress multi-dimensional indicator data into three-dimensional indicator data; A clustering module, configured to perform cluster analysis on the three-dimensional indicator data based on the logical relationship of the pool groups to identify abnormal targets; An output module is used to output, based on the abnormal target, a list of abnormal network elements corresponding to the abnormal target, a timestamp indicating the abnormal time of the abnormal target, and an indicator data record of the abnormal target.

8. The core network anomaly identification device based on key indicators according to claim 7, The clustering module is further used to generate a three-dimensional clustering graph based on cluster analysis of the three-dimensional indicator data, and the output module is further used to output the three-dimensional clustering graph, wherein the abnormal target is marked in the three-dimensional clustering graph.

9. The core network anomaly identification device based on key indicators as described in claim 7 or 8, wherein the clustering module is configured to: cluster the three-dimensional indicator data in pool groups through a density-based clustering algorithm to identify outliers that are the abnormal targets.

10. The core network anomaly identification device based on key indicators according to claim 9, wherein the clustering module specifically comprises: A data set establishing unit, configured to obtain a data set consisting of a plurality of indicator sequences based on each of the three-dimensional indicator data; a clustering parameter setting unit, configured to set parameters of a density-based clustering algorithm based on the spacing between data points in the data set, wherein the parameters include: a neighborhood radius and a minimum number of indicator sequences within the neighborhood radius; a core point determination unit, configured to determine a core point in the data set according to the neighborhood radius and the minimum number of indicator sequences; A cluster expansion unit, configured to perform recursive expansion based on the core point; The cluster generation unit is used to control the data set establishment unit, the cluster parameter setting unit, the core point determination unit and the cluster expansion unit to repeat operations until clusters of indicator sequences are formed, and to use indicator sequences that are not in any cluster as the abnormal targets.

11. An electronic device comprising: a memory for storing computer-readable instructions; as well as A processor is configured to run the computer-readable instructions so that the electronic device executes the core network anomaly identification method based on key indicators as described in any one of claims 1 to 6.

12. A non-transitory computer-readable storage medium for storing computer-readable instructions, which, when executed by a processor, causes the processor to execute the core network anomaly identification method based on key indicators according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Method for detecting link state of network equipment, device thereof and equipment

    CN113891385A

  • Cell abnormal state detection method and equipment

    CN114079957A

  • Cell abnormal index detection method and device

    CN115209458A

  • Core network anomaly identification method and device based on key indexes and electronic equipment

    CN118803998A

  • KPI anomaly detection for radio access networks

    US20210243623A1

Cited By

  • Energy storage lithium ion battery capacity abnormity identification method, system and equipment

    CN120870897A

  • Concentrator intelligent fusion terminal with equipment running state monitoring function

    CN121071376A

  • Data quality management method and platform based on converter station equipment

    CN121658467A

  • Comprehensive energy management method and platform based on energy consumption digitization

    CN121881220A

  • Data storage method and equipment for mass transaction information

    CN122137750A