Training Method, Device and Storage Medium for Network Alarm Event Recognition Model
By obtaining the historical correlation and topological correlation of network alarm events, the network alarm event recognition model is trained to generate, which solves the problem of low accuracy of network alarm events recognition in the prior art and achieves a higher recognition accuracy.
Patent Information
- Application Number
- CN202111676696.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-31
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2041-12-31
AI Technical Summary
The existing network alarm event recognition methods are clustered only based on time windows, resulting in a low accuracy of root cause event recognition.
By obtaining the historical correlation and topological correlation of network alarm events, training the event correlation of network alarm events, and using clustering algorithms and root cause recognition algorithms to generate network alarm event recognition models.
The accuracy of identification of network alarm events is improved, and more accurate clustering and root cause recognition is achieved by combining the event correlation generated by historical correlation and topological correlation.
Smart Images

Figure CN114358312B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of operation and maintenance technologies, and particularly to a method, device, and storage medium for training a network alarm event recognition model. Background Art
[0002] As the scale of the network system gradually increases, the frequency of failures is also getting higher and higher. To ensure the normal operation of the network system, it is necessary to identify the root cause events of the failures.
[0003] Currently, the existing network alarm event recognition method is to identify the root cause event based on the clustering result of alarm events. However, when clustering alarm events, only the time window clustering method is used, that is, clustering the alarm events that occur within a certain period of time.
[0004] Since clustering alarm events only based on the time window is affected by interference events, the accuracy of the clustering result is low, resulting in a low accuracy of root cause event recognition. Summary of the Invention
[0005] This application provides a method, device, and storage medium for training a network alarm event recognition model to solve the problem of low accuracy of network alarm event recognition.
[0006] In a first aspect, this application provides a method for training a network alarm event recognition model, including:
[0007] Obtain the network alarm events to be trained;
[0008] Determine the historical correlation of the network alarm events, where the historical correlation is the co-occurrence probability between network alarm events;
[0009] Determine the topological correlation of the network alarm events, where the topological correlation is the correlation of the network devices where the network alarm events occur;
[0010] Train the historical correlation and the topological correlation to obtain the event correlation of the network alarm events;
[0011] Cluster and identify the root cause of the event correlation to obtain a network alarm event recognition model.
[0012] In a second aspect, this application provides a training device for a network alarm event recognition model, including:
[0013] An obtaining module, configured to obtain the network alarm events to be trained;
[0014] A determining module, configured to determine the historical correlation of the network alarm events, where the historical correlation is the co-occurrence probability between network alarm events;
[0015] A determination module is further configured to determine the topological correlation of network alarm events, where the topological correlation is the correlation of network devices where network alarm events occur;
[0016] A training module is configured to train historical correlation and topological correlation;
[0017] An acquisition module is further configured to acquire the event correlation of network alarm events;
[0018] A clustering and root cause identification module is configured to cluster and identify the root cause of event correlation to obtain a network alarm event identification model.
[0019] In a third aspect, the present application provides a training device for a network alarm event identification model, including: a processor and a memory. Code is stored in the memory, and the processor runs the code stored in the memory to execute the training method for the network alarm event identification model according to any one of the first aspect.
[0020] In a fourth aspect, the present application provides a computer-readable storage medium, in which computer execution instructions are stored. When the computer execution instructions are executed by a processor, they are used to implement the training method for the network alarm event identification model according to any one of the first aspect.
[0021] A training method for a network alarm event identification model provided by the present application includes: acquiring network alarm events to be trained, determining the historical correlation and topological correlation of the network alarm events, where the historical correlation is the co-occurrence probability between network alarm events, and the topological correlation is the correlation of network devices where network alarm events occur. Training the historical correlation and topological correlation, acquiring the event correlation of the network alarm events, clustering and identifying the root cause of the event correlation to obtain a network alarm event identification model that can identify network alarm events. When it is necessary to identify the root cause event of a certain network alarm event, the network alarm event can be input into the network alarm event identification model, and the network alarm event identification model will output the root cause identification result of the network alarm event. Since the event correlation is jointly determined by the historical correlation and topological correlation, the accuracy of network alarm event clustering is improved, and thus the identification accuracy of network alarm events is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.
[0023] Figure 1 FIG. is an application scenario diagram of a network alarm event identification model provided by an embodiment of the present application;
[0024] Figure 2Flow chart of a method for training a network alarm event recognition model provided by an embodiment of the present application Figure 1 ;
[0025] Figure 3 Flow chart of a method for training a network alarm event recognition model provided by an embodiment of the present application Figure 2 ;
[0026] Figure 4 Diagram of the distribution relationship model of OSPF down and interface down network alarm events provided by an embodiment of the present application;
[0027] Figure 5 Flow chart of a method for applying a network alarm event recognition model provided by an embodiment of the present application;
[0028] Figure 6 Schematic diagram of the architecture of a network alarm event recognition system provided by an embodiment of the present application Figure 1 ;
[0029] Figure 7 Schematic diagram of the clustering and root cause identification of network alarm events by an event clustering engine provided by an embodiment of the present application;
[0030] Figure 8 Schematic diagram of the architecture of a network alarm event recognition system provided by an embodiment of the present application Figure 2 ;
[0031] Figure 9 Schematic diagram of a training device for a network alarm event recognition model provided by an embodiment of the present application Figure 1 ;
[0032] Figure 10 Schematic diagram of a training device for a network alarm event recognition model provided by an embodiment of the present application Figure 2 .
[0033] Through the above-mentioned drawings, specific embodiments of the present application have been shown, and there will be more detailed descriptions hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. Detailed implementation manners
[0034] Here, exemplary embodiments will be described in detail, and examples thereof are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0035] The present application provides a training method for a network alarm event recognition model. First, obtain the network alarm events to be trained. Since the event correlation of network alarm events is related to historical correlation and is also affected by the magnitude of topological correlation of network alarm events, in order to improve the recognition efficiency of network alarm events, it is necessary to determine the historical correlation and topological correlation of network alarm events. By training the historical correlation and topological correlation, obtain the event correlation of network alarm events. Finally, cluster and identify the root cause of the event correlation to obtain a network alarm recognition model. When a network alarm event occurs, input the network alarm event to be recognized into the network alarm recognition model, and the network alarm event recognition model can output the clustering and root cause identification results of the network alarm event. Since the event correlation is jointly obtained through historical correlation and topological correlation, the accuracy of the event correlation can be improved, thereby improving the recognition accuracy of network alarm events.
[0036] Figure 1 FIG. is an application scenario diagram of a network alarm event recognition model provided by an embodiment of the present application. As Figure 1 shown, when a network alarm event occurs, the network alarm event can be input into the network alarm event recognition model, and the network alarm event recognition model recognizes the network alarm event and outputs the results of clustering and root cause identification of the network alarm event.
[0037] The following uses specific embodiments to detail the technical solutions of the present application and how the technical solutions of the present application solve the above technical problems. These specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The following will describe the embodiments of the present application in conjunction with the drawings.
[0038] Figure 2 FIG. is a flowchart of a training method for a network alarm event recognition model provided by an embodiment of the present application. Figure 1 The execution subject of this method can be a training device for a network alarm event recognition model. The training device for a network alarm event recognition model can be any device with data processing capabilities, such as a computer, etc. The method in this embodiment can be implemented by software, hardware, or a combination of software and hardware.
[0039] As Figure 2 shown, this method may include:
[0040] S201: Obtain the network alarm events to be trained.
[0041] When a network alarm event occurs, it indicates that a network failure has occurred. It should be noted that one network failure may include one or more network alarm events, and one of the network events is the root cause event of the network failure.
[0042] The network alarm events to be trained are the network alarm events that have occurred. The event types of network alarm events can be device - related, configuration - related, service - related, and protocol - related. Among them, device - related network alarm events are alarms caused by network device failures. Network devices are devices for network communication, including but not limited to servers, switches, routers, etc. Configuration - related alarm events are alarm events caused by network configuration errors. Service - related alarm events are alarm events that occur during the process of network services. Protocol - related network alarm events refer to alarm events where network protocols are incorrect. Network protocols can be TCP / IP protocol (Transport Control Protocol / Internet Protocol), NetBEUI (NetBios Enhanced User Interface) protocol, etc.
[0043] The obtained network alarm events generally contain various information such as text information describing the network alarm events, the time when the network alarm events occur, and the devices where the network alarm events occur. The network alarm events that have occurred can be obtained from the servers corresponding to the network systems.
[0044] S202: Determine the historical correlation of network alarm events. The historical correlation is the co - occurrence probability between network alarm events.
[0045] The magnitude of historical correlation is one of the factors affecting the event correlation between network alarm events. The historical correlation is the co - occurrence probability between network alarm events. For example, within a certain period of time, when network alarm event A occurs, network alarm event B or multiple other network alarm events also occur subsequently.
[0046] In another implementation scenario, network alarm event A occurs twice, network alarm event B occurs three times, and network alarm event C occurs once.
[0047] Optionally, the historical correlation of network alarm events can be obtained based on a set time window.
[0048] Multiple different time windows can also be set to obtain the historical correlation of network alarm events under each time window, thereby improving the historical correlation of network alarm events.
[0049] S203: Determine the topological correlation of network alarm events. The topological correlation is the correlation of the network devices where network alarm events occur.
[0050] For communication to be achieved, there is a specific network structure layout among network devices. When a certain network device fails, it may cause other network devices to fail. For example, within a certain period of time, after a network alarm event occurs in Network Device 1, Network Device 2 or multiple other network devices also have network alarm events, indicating that there is a certain correlation among network devices. Therefore, the magnitude of topological correlation will affect the event correlation of network alarm events.
[0051] Optionally, the topological correlation of network alarm events can be obtained according to the networking architecture and network protocol configuration of network devices.
[0052] S204: Train the historical correlation and topological correlation to obtain the event correlation of network alarm events.
[0053] The event correlation of network alarm events is related to the historical correlation and topological correlation of network alarm events. Therefore, in this application, the historical correlation and topological correlation are used as the main factors to determine the event correlation. Optionally, the event correlation can be represented by the product of the historical correlation and the topological correlation, as follows:
[0054] Event correlation = Historical correlation * Topological correlation
[0055] The historical correlation and topological correlation can also be calculated and fused in other ways to obtain the event correlation.
[0056] S205: Cluster and identify the root cause of the event correlation to obtain a network alarm event recognition model.
[0057] In this application, clustering is performed on the event correlation to achieve the recognition of the event types of network alarm events. Based on clustering, root cause identification is further carried out to determine the causes of network alarm events.
[0058] Various clustering algorithms and root cause identification algorithms can be used to achieve this. For example, based on the event correlation, a probability distribution matrix of network alarm events can be generated. Each data in the probability distribution matrix represents the event correlation coefficient of the network alarm event.
[0059] Cluster and identify the root cause of the probability distribution matrix to obtain a network alarm event recognition model.
[0060] After the network alarm event recognition model is established, the established model can also be updated and optimized. For example, the updated network alarm events can be input into the network alarm event recognition model, and the results of clustering and root cause identification of the updated network alarm events can be output through the network alarm event recognition model.
[0061] An embodiment of the present application provides a training method for a network alarm event recognition model, which obtains network alarm events to be trained. Since the event correlation of network alarm events is related to historical correlation and topological correlation, it is necessary to determine the historical correlation and topological correlation of network alarm events. Train the historical correlation and topological correlation to obtain the event correlation of network alarm events. Cluster and root cause identify the event correlation, thereby obtaining a network alarm event recognition model. When it is necessary to identify network alarm events, the network alarm events can be input into the network alarm event recognition model, thereby outputting the results of clustering and root cause identification of network alarm events. Since the present application also determines the topological correlation affecting network alarm events on the basis of the historical correlation of network alarm events, the recognition accuracy of network alarm events is improved.
[0062] On the basis of the above embodiments, a specific embodiment is provided below to introduce in detail the training method of the network alarm event recognition model.
[0063] Figure 3 The following is a flowchart of a training method for a network alarm event recognition model provided by an embodiment of the present application Figure 2 as follows:
[0064] S301: Obtain network alarm events to be trained.
[0065] Network alarm events can be abnormal events in the network, such as device alarms, abnormal logs, iFIT (In-situ Flow Information Telemetry) quality degradation events, etc. The obtained network alarm events contain information identifying the network alarm events, which can be key information such as alarm names, log names, alarm location information, and iFIT quality degradation information.
[0066] It should be noted that a network failure may include one or more network alarm events, and one of the network alarm events is the root cause event leading to the network failure.
[0067] S302: Obtain the historical correlation of network alarm events based on a set time window.
[0068] Within a period of time after a certain network alarm event A occurs, due to the influence of network alarm event A, network alarm event B also occurs. Therefore, there is historical correlation between network alarm events.
[0069] The time window can be adjusted according to the actual situation. It can be understood that the size of the time window will affect the correlation coefficient of historical correlation. Therefore, multiple time windows can be set to obtain the historical correlation of network alarm events.
[0070] In an implementation scenario, if the set time window is 200s, then taking each network alarm event as the center, analyze other network alarm events that occurred within 200s before and after it to obtain the historical correlation of network alarm events.
[0071] S303: Determine the topological location of the network device where the network alarm event occurred according to the networking architecture and network protocol configuration of the network device.
[0072] Among them, network devices include but are not limited to devices such as servers, switches, and routers.
[0073] The networking architecture of network devices is the organizational structure for network devices to achieve interconnection. For example, it can be a star structure or a ring structure, etc.
[0074] The network protocol is a set of communication rules between network devices. For example: TCP / IP protocol, NetBEUI protocol, etc.
[0075] The topological location of the network device where the network alarm event occurred can be the node location of the device in the network system.
[0076] S304: Calculate the topological distance between the network devices where the network alarm events occurred according to the topological location of the network devices where the network alarm events occurred.
[0077] Optionally, the topological distance can be the node distance of the nodes where the network devices where the network alarm events occurred. Determine the node distance according to the node location of the network devices where the network alarm events occurred. The node distance is the sum of the distances from two nodes to the nearest common device.
[0078] S305: Obtain the topological correlation of network alarm events according to the topological distance.
[0079] When the topological distance between the network devices where the network alarm events occurred is relatively close, it indicates that the topological correlation of the network alarm events is relatively large. When the historical correlations of the network alarm events are the same, the greater the topological correlation, the greater the event correlation of the network alarm time.
[0080] It can be understood that when the topological distance between the network devices where the network alarm events occurred is relatively far, the topological correlation of the network alarm events is relatively small.
[0081] S306: Train the network alarm events to generate the alarm propagation relationship between network alarm events.
[0082] Training is performed on a large number of historical network alarm events at a specific location to generate alarm propagation relationships. This alarm propagation relationship diagram allows for clustering and root cause inference of network alarm events. This approach eliminates the need for manual rule injection or a defined clustering time window. Instead, it analyzes the propagation relationships between network alarm events through probabilistic statistics of a large amount of historical network alarm event data, resulting in better generalization across locations.
[0083] A game point can represent a specific area.
[0084] S307: Based on the set time window, the network alarm propagation relationship is trained to obtain the event correlation of the network alarm event.
[0085] The propagation relationship between any two network alarm events can be a normal distribution relationship or a white noise distribution relationship. Different network alarm propagation relationships indicate different strengths of event correlation between network alarm events. For example, the two network alarm events OSPF down and interface down have a normal distribution relationship. OSPF down is likely to occur 3 seconds after the interface down. Although there may be protocol oscillation and interference from other interfaces, which may cause OSPF down to occur before the interface down, as the learning data increases, it will gradually converge to a normal distribution model, such as Figure 4 The figure shows that the two network alarm events, OSPF down and interface down, are highly correlated.
[0086] S308: Generate a probability distribution matrix of network alarm events based on event correlation.
[0087] By converting the event correlation into a matrix, we can obtain a probability distribution matrix that represents the magnitude of the network alarm event correlation. The data in the probability distribution matrix are the event correlation coefficients between network alarm events.
[0088] In one implementation scenario, if a site has 435 types of network alarm events, a probability distribution matrix of 435*435 is obtained.
[0089] S309: Clustering network alarm events according to the probability distribution matrix to generate alarm clusters.
[0090] The correlation between any two network alarm events can be determined according to the probability distribution matrix, and the two network alarm events with greater correlation can be clustered.
[0091] In one implementation scenario, if the statistical distribution between two network alarm events is a white noise distribution, it means that the alarm correlation between the network alarm events is very weak and they should not be clustered together.
[0092] In another implementation scenario, if the statistical distribution between two network alarm events is a normal distribution, indicating a strong correlation between the two network alarm events, then cluster these two network alarm events together.
[0093] S310: Initialize and assign the same weight to each alarm node in the probability distribution matrix.
[0094] Each row or each element in the probability distribution matrix represents an alarm node. Since it is necessary to determine the root cause network alarm event based on the weight of the alarm node, each alarm node needs to be initialized and the weights remain the same.
[0095] S311: Iteratively update the weight of each alarm node according to the alarm propagation relationship to obtain the root cause weight of the alarm node.
[0096] The iterative formula for iterating the weight of each alarm node is as follows:
[0097]
[0098] Among them, children(i) are all child nodes of the node in the association matrix, parents(j) are all parent nodes of the node in the association matrix, Prob(i, j) is the probability that j is a child node when i is the parent node, α is the default information value for each round of propagation, w is the root cause weight of each node, and k represents the set of all parent nodes of node j.
[0099] This formula can be understood as that the direct child nodes of each node will contribute a part of the weight to its parent node. After continuous iteration, the nodes closer to the root cause position will be more important, and their weights will become larger and larger. Finally, they can be sorted as the root cause coefficients.
[0100] In one implementation scenario, during the data collection process, there are situations where the front and back causality is inverted or local loops occur, resulting in weight explosion. On the basis of the above iterative formula, a random causality term is added.
[0101] Let represent the amount of information brought by child node j to parent node i, then the original iterative formula is updated to:
[0102] ω i =ω i +∑ j∈childen(i) (1 - d)*Δω (i,random(node)) +d*Δω (i,j)
[0103] Where d is the damping coefficient, which can be set to 0.8, indicating that there is a 0.8 probability of following the parent-child association relationship in the association matrix, and a 0.2 probability of randomly selecting a node as the child node, which can effectively prevent the coefficient explosion caused by local loops.
[0104] S312: Determine the root cause network alarm events of the alarm cluster according to the root cause weights.
[0105] As the amount of information obtained by iteration increases, the root cause weights of each node can be obtained based on multiple rounds of iteration. If there is still a two-way edge between two nodes, the edge with a lower weight pointing to a higher weight is removed, and finally a directed acyclic graph is formed. According to the directed acyclic graph and the root cause weights, the root cause network alarm events of each alarm cluster and the root cause network alarm events in a certain alarm sequence can be determined, and finally a network alarm event recognition model is generated.
[0106] The embodiment of the present application provides a training method for a network alarm event recognition model, which obtains the network alarm events to be trained, and obtains the historical correlation of the network alarm events based on a set time window. At the same time, determine the topological location and topological distance of the network alarm event occurrence device according to the network architecture and network protocol configuration of the network device, and determine the topological correlation of the network alarm event according to the topological distance. Train the network alarm events to generate the alarm propagation relationship between the network alarm events, and based on the set time window, train the network alarm propagation relationship to obtain the event correlation of the network alarm events. Generate a probability distribution matrix from the event correlation, cluster the network alarm events according to the probability distribution matrix to generate alarm clusters. Initialize and assign the same weight to each alarm node in the probability distribution matrix. According to the alarm propagation relationship, iteratively update the weight of each alarm node to obtain the root cause weight of the alarm node, and finally determine the root cause network alarm event to generate a network alarm event recognition model. Since the network alarm event recognition model in the embodiment of the present application performs root cause recognition based on the clustering result determined by the event correlation coefficient of the network alarm events, and the event correlation is jointly determined by the historical correlation and the topological correlation, the accuracy of network alarm event clustering is improved, and thus the recognition accuracy of network alarm events is improved.
[0107] Based on the above embodiments, an embodiment is provided below to describe the application process of the network alarm event recognition model in detail.
[0108] Figure 5 It is a flowchart of a method for applying a network alarm event recognition model provided by an embodiment of the present application. Since the network alarm events are sequential streaming data during the actual network use, the network alarm event recognition model also needs to adapt to the characteristics of the streaming data. As shown in the figure, the method is as follows:
[0109] S501: Receive network alarm event e.
[0110] The one that sends network alarm event e can be other modules in the network alarm event recognition system in the above embodiments. Network alarm event e can be device alarm, exception log, iFIT poor quality event, etc.
[0111] S502: Determine whether the fault set SituationPool is empty. If the fault set is empty, execute step S503; otherwise, execute steps S504 - S505.
[0112] The fault set is a set of network alarm events received from other modules. The fault set can contain multiple fault situations, and each fault can contain one or more network alarm events. When the fault set is empty, it indicates that the existing network alarm events have been processed, and there are no other pending network alarm events.
[0113] S503: Create a fault Situation with network alarm event e, set network alarm event e as the root cause event of this fault, and finally add this fault to the fault set and end the process.
[0114] Since a network fault can contain one or more network alarm events, and one of the network events is the root cause event of the network fault. When the fault set is empty, it indicates that the root cause event of this network fault is network alarm event e.
[0115] S504: Determine the fault most relevant to network alarm event e according to the probability distribution matrix, denoted as s.
[0116] According to the probability distribution matrix provided in the above embodiments, the network alarm event with a relatively large correlation coefficient with network alarm event e can be determined, so as to determine the fault most relevant to network alarm event e.
[0117] S505: Determine whether the event correlation between network alarm event e and s is greater than the set threshold. If it is greater, execute S506; otherwise, return to S503.
[0118] The set threshold can be represented by the following formula:
[0119] σ(rootRate)·HyperParameters.confidenceThreshold
[0120] In the formula, HyperParameters.confidenceThreshold is a dynamic threshold calculated by a sigmoid function. where e is a constant and rootRate is the root cause coefficient.
[0121] S506: Cluster the network alarm event e into s, complete root cause identification at the same time, and end the process.
[0122] If the event correlation between the network alarm event e and s is greater than the set threshold, it indicates that the network alarm event e is a network alarm event causing the fault s. Therefore, associate e with s, perform root cause identification on all network alarm events in s, and obtain the root cause event causing the fault.
[0123] The embodiment of the present application provides a method for applying a network alarm event recognition model, which receives a network alarm event e and determines whether the fault set is empty. If the fault set is empty, create a new fault with the network alarm event e, set e as the root cause event of the fault, and finally add the fault to the fault set and end the process. When the fault set is not empty, according to the probability distribution matrix, determine the fault most relevant to e, and judge whether the event correlation between the network alarm event e and the fault is greater than the set threshold. If it is greater than the set threshold, the network alarm event recognition model clusters the network alarm event e into s and completes root cause identification at the same time. The method for applying the network alarm event recognition model provided by the embodiment of the present application can cluster network alarm events and identify the root cause network alarm events causing the faults. Since the network alarm event recognition model is based on the event correlation of network alarm events, that is, the probability distribution matrix, the recognition accuracy of network alarm events is relatively high.
[0124] Based on the above embodiments, an embodiment is provided below to describe the network alarm event recognition system in detail.
[0125] Figure 6 Schematic diagram of a network alarm event recognition system architecture provided by an embodiment of the present application Figure 1 As Figure 6 shown, the system event cluster engine (Event Cluster Engine) provided by the embodiment of the present application includes an event cluster engine super (Event Cluster Engine Super) module 601 and multiple event cluster engine in-domain (Event ClusterEngineDomain) modules 602. The schematic diagram of the event cluster engine clustering and root cause identifying network alarm events is as Figure 7 shown.
[0126] Specifically, the structures of the event cluster engine super module 601 and the event cluster engine in-domain module 602 are as Figure 8 shown.
[0127] As Figure 8As shown in the figure, the event cluster engine super module 601 includes a clustering model aggregation module 6011 and a clustering model synchronization module 6012. Among them, the clustering model aggregation module 6011 can aggregate data from multiple in-domain modules 602 of the event cluster engine. The aggregated data can be the probability distribution matrix of network alarm events.
[0128] The clustering model synchronization module 6012 in the event cluster engine super module 601 and the clustering model synchronization module 6024 in the in-domain module 602 of the event cluster engine implement data synchronization. The data that needs to be synchronized is the probability distribution matrix of network alarm events.
[0129] The in-domain module 602 of the event cluster engine includes a network event receiving module 6021 that receives network alarm events, a clustering and root cause identification module 6022 that clusters and identifies the root cause of network alarm events, and a result sending module 6023 that outputs the clustering and root cause identification results.
[0130] Among them, the result sending module 6023 can send the clustering and root cause identification results to a terminal device for presentation. The terminal device can be a mobile phone, a tablet computer, a PC device, etc.
[0131] The in-domain module 602 of the event cluster engine also includes a clustering model online incremental learning module 6025. After clustering and root cause identification of updated network alarm events are completed, based on online incremental learning and federated learning, the updated network alarm events to be trained are trained to improve the accuracy of network alarm event identification.
[0132] Other modules are used to transmit network alarm events to the network event receiving module 6021, and can be devices such as routers and servers.
[0133] After a network alarm event occurs, other modules transmit it to the network event receiving module 6021. The network event receiving module 6021 sends the network alarm event to the clustering and root cause identification module 6022 for clustering and root cause identification, and the clustering and root cause identification results are sent to the terminal device through the result sending module 6023.
[0134] The embodiment of the present application provides a network alarm event recognition system, including an event cluster engine super module and multiple in-domain modules of the event cluster engine. After a network alarm event occurs, other modules send the network alarm event to the network event receiving module. The clustering and root cause identification module clusters and identifies the root cause of the received network alarm event, and sends the clustering and root cause identification results to a terminal device that can present the results through the result sending module, realizing the root cause identification of network alarm events. The system provided by the embodiment of the present application can also train updated network alarm events through the clustering model online incremental learning module, improving the accuracy of network alarm event recognition.
[0135] Figure 9 Schematic diagram of a training device for a network alarm event recognition model provided by an embodiment of the present application Figure 1 As Figure 9 shown in the figure, the training device 900 for the network alarm event recognition model provided by the present application may include: an acquisition module 901, a determination module 902, a training module 903, and a clustering and root cause identification module 904.
[0136] The acquisition module 901 is configured to acquire network alarm events to be trained;
[0137] The determination module 902 is configured to determine the historical correlation of network alarm events, and the historical correlation is the co-occurrence probability between network alarm events;
[0138] The determination module 902 is further configured to determine the topological correlation of network alarm events, and the topological correlation is the correlation of network devices where network alarm events occur;
[0139] The training module 903 is configured to train the historical correlation and the topological correlation;
[0140] The acquisition module 901 is further configured to acquire the event correlation of network alarm events;
[0141] The clustering and root cause identification module 904 is configured to cluster and identify the root cause of the event correlation to obtain a network alarm event recognition model.
[0142] Figure 10 Schematic diagram of a training device for a network alarm event recognition model provided by an embodiment of the present application Figure 2 As Figure 10 shown in the figure, a training device 1000 for a network alarm event recognition model provided by an embodiment of the present application includes a processor 1001 and a memory 1002, where the processor 1001 and the memory 1002 are connected through a bus 1003.
[0143] In a specific implementation process, code is stored in the memory 1002, and the processor 1001 runs the code stored in the memory 1002 to execute the training method of the network alarm event recognition model in the above method embodiment.
[0144] For the specific implementation process of the processor 1001, reference may be made to the above method embodiment, and its implementation principle and technical effects are similar, which will not be elaborated here in this embodiment.
[0145] In the above Figure 10In the illustrated embodiments, it should be understood that the processor 1001 may be a central processing unit (CPU for short), or may also be other general-purpose processors, digital signal processors (DSP for short), application specific integrated circuits (ASIC for short), etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed in combination with the invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules in the processor.
[0146] The memory 1002 may include high-speed RAM memory and may also include non-volatile storage NVM, such as at least one disk memory.
[0147] The bus 1003 may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus 1003 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus 1003 in the drawings of this application is not limited to only one bus or one type of bus.
[0148] The embodiments of this application provide a computer-readable storage medium. Computer-executable instructions are stored in the computer-readable storage medium. When the computer-executable instructions are executed by a processor, they are used to implement the training method of the network alarm event recognition model in the above method embodiments.
[0149] The above computer-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a disk, or an optical disc. The readable storage medium can be any available medium accessible by a general-purpose or special-purpose computer.
[0150] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an Application Specific Integrated Circuit (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in a device.
[0151] An embodiment of the present application provides a computer program product, including a computer program, which when executed by a processor, implements the training method of the network alarm event recognition model provided in any of the above embodiments of the present application.
[0152] Those skilled in the art will readily conceive of other embodiments of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include known common knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and the embodiments are only regarded as exemplary, and the true scope and spirit of the present application are pointed out by the following claims.
[0153] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.
Claims
1. A training method for a network alarm event recognition model, characterized in that, including: Obtain network alarm events to be trained; Determine the historical correlation of the network alarm events, where the historical correlation is the co-occurrence probability between the network alarm events; Determine the topological correlation of the network alarm events, where the topological correlation is the correlation of the network devices where the network alarm events occur; According to the historical correlation and the topological correlation, perform probability statistical training on the network alarm events to generate the alarm propagation relationship between the network alarm events; Based on a set time window, train the alarm propagation relationship to obtain the event correlation of the network alarm events; Determine the probability distribution matrix according to the event correlation; Cluster the network alarm events according to the probability distribution matrix to generate alarm clusters; Initialize and assign the same weight to each alarm node in the probability distribution matrix; According to the alarm propagation relationship, iteratively update the weights of each alarm node to obtain the root cause weights of the alarm nodes; Determine the root cause network alarm event recognition model of the alarm cluster according to the root cause weights; 2. The method according to claim 1, wherein The obtaining the topological correlation of the network alarm events includes: Obtain the topological correlation of the network alarm events according to the networking architecture and network protocol configuration of the network devices; 3. The method according to claim 2, wherein The obtaining the topological correlation of the network alarm events according to the networking architecture and network protocol configuration of the network devices includes: Determine the topological location of the device where the network alarm event occurs according to the networking architecture and network protocol configuration of the network devices; Calculate the topological distance between the devices where the network alarm events occur according to the topological location of the network devices where the network alarm events occur; Obtain the topological correlation of the network alarm events according to the topological distance; 4. The method according to claim 1, wherein The determining the historical correlation of the network alarm events includes: Obtain the historical correlation of the network alarm events based on a set time window; 5. The method according to claim 1, characterized in that, The method further includes: Based on online incremental learning and federated learning, train the updated network alarm events to be trained to improve the accuracy of network alarm event recognition; 6. A training device for a network alarm event recognition model, characterized in that, including: An obtaining module, configured to obtain network alarm events to be trained; A determining module, configured to determine the historical correlation of the network alarm events, where the historical correlation is the co-occurrence probability between the network alarm events; The determining module is further configured to determine the topological correlation of the network alarm events, where the topological correlation is the correlation of the network devices where the network alarm events occur; A training module, configured to perform probability statistical training on the network alarm events according to the historical correlation and the topological correlation to generate the alarm propagation relationship between the network alarm events; The obtaining module is further configured to train the alarm propagation relationship based on a set time window to obtain the event correlation of the network alarm events; The determining module is further configured to determine a probability distribution matrix according to the event correlation; cluster the network alarm events according to the probability distribution matrix to generate alarm clusters; initialize and assign the same weight to each alarm node in the probability distribution matrix; and iteratively update the weight of each alarm node according to the alarm propagation relationship to obtain the root cause weight of the alarm node. Determine the root cause network alarm event recognition model of the alarm cluster according to the root cause weight.
7. A training device for a network alarm event recognition model, characterized in that, It includes: A processor and a memory. Code is stored in the memory, and the processor runs the code stored in the memory to execute the training method of the network alarm event recognition model according to any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, Computer-executable instructions are stored in the computer-readable storage medium, and when the computer-executable instructions are executed by a processor, they are used to implement the training method of the network alarm event recognition model according to any one of claims 1 to 5.
Citation Information
Patent Citations
Fault root cause analysis method and device
CN110609759A
Data processing method and device and storage medium
CN111756560A