Fault positioning method, device, equipment, storage medium and product

By using a root cause prediction rule base and a pre-trained alarm association model in the communication network, and based on the association features and weight analysis of alarm data, alarm faults can be accurately located, solving the problem of low accuracy in alarm fault location in the communication network and improving the efficiency and accuracy of fault location.

CN115345324BActive Publication Date: 2026-05-01CHINA MOBILE COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE COMM GRP CO LTD
Filing Date
2021-05-11
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In existing communication networks, the accuracy of alarm fault location is low, especially when there is noise and incomplete information in the massive amount of alarm information, making it difficult to accurately identify the fault location and cause.

Method used

By acquiring alarm data to be processed, a root cause prediction rule base is used for prediction processing. The data is then input into a pre-trained alarm association model for model training. Alarm weights are determined based on association features, and the associated alarm pairs with the highest weights are taken as root cause alarms. These alarms are then located in conjunction with alarm network elements.

Benefits of technology

It improves the accuracy and efficiency of fault location, reduces the amount of target alarm data, and achieves rapid and accurate location of root cause alarms through model clustering and weight analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115345324B_ABST
    Figure CN115345324B_ABST
Patent Text Reader

Abstract

The application discloses a fault positioning method, comprising the following steps: performing root cause pre-judgment processing on to-be-processed alarm data based on a root cause pre-judgment rule base to obtain target alarm data; inputting the target alarm data into a pre-trained alarm correlation model to perform model training, so as to obtain a plurality of correlation alarm pairs based on a training result; determining alarm weights corresponding to each correlation alarm pair; taking a target correlation alarm pair corresponding to a maximum weight in each alarm weight as a root cause alarm, and taking an alarm network element corresponding to the target correlation alarm pair as a root cause network element. The application also discloses a fault positioning device, equipment, storage medium and product. Through root cause pre-judgment on alarm data, the application reduces the data amount of target alarm data, performs clustering on the target alarm data through a model, and performs secondary positioning on clustered correlation alarm pairs according to alarm weights to obtain a root cause alarm, thereby improving the accuracy and efficiency of fault positioning.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, and in particular to a fault location method, apparatus, device, storage medium, and product. Background Technology

[0002] Currently, various communication networks are vast in scale, complex in structure, and diverse in equipment, generating massive amounts of alarm information daily from various hardware devices and software. These alarms cover voice networks, data networks, transmission networks, signaling networks, intelligent networks, service networks, and more. When a fault alarm occurs in a telecommunications network, maintenance personnel are required to accurately determine the location, type, and cause of the network fault in the shortest possible time, and then take appropriate corrective measures promptly. However, in actual network operation, the occurrence of a fault often triggers multiple alarm events. Related equipment and service processes will issue related alarm sequences, and the numerous alarm sequences caused by multiple faults can overlap, thus drowning out the true alarm and making fault identification exceptionally difficult. Furthermore, with the continuous increase in the scale and complexity of networks, as well as the constant changes in network equipment, network services, and network structure, the types and number of alarms are increasing, including minor alarms, general alarms, serious alarms, major alarms, emergency alarms, missed alarms, false alarms, duplicate alarms, alarms with the same cause but different symptoms, alarms with the same symptoms but multiple causes, etc. As a result, a large number of noisy alarms or incomplete information are contained in the massive amount of alarm information. These factors further increase the difficulty of alarm correlation analysis and fault location.

[0003] Currently, alarm correlation analysis in communication networks mainly relies on alarm correlation rules compiled by experts. However, with the rapid construction of networks, the scale and structure of communication networks are becoming increasingly large and complex. Multiple new technologies and various network types of equipment are being applied to communication networks simultaneously. The accumulation speed of alarm correlation rules compiled by experts lags behind the speed of network technology changes, resulting in low accuracy in locating actual alarm faults.

[0004] The above content is only used to help understand the technical solution of the present invention and does not represent an admission that the above content is prior art. Summary of the Invention

[0005] The main objective of this invention is to provide a fault location method, apparatus, device, storage medium, and product, aiming to solve the technical problem of low accuracy in existing alarm fault location methods.

[0006] To achieve the above objectives, the present invention provides a fault location method, the fault location method comprising the following steps:

[0007] Acquire the alarm data to be processed, and perform root cause prediction processing on the alarm data to be processed based on the root cause prediction rule base to obtain the target alarm data;

[0008] The target alarm data is input into a pre-trained alarm association model for model training, so as to obtain multiple associated alarm pairs based on the training results;

[0009] Based on the multiple associated features of each associated alarm pair, determine the alarm weight corresponding to each associated alarm pair.

[0010] The target-related alarm pair corresponding to the highest weight among all alarm weights is taken as the root cause alarm, and the alarm network element corresponding to the target-related alarm pair is taken as the root cause network element.

[0011] Furthermore, the step of determining the alarm weight corresponding to each associated alarm pair based on multiple associated features includes:

[0012] Based on each of the aforementioned associated features, determine the associated feature weights for each associated alarm pair.

[0013] Based on the weights of each associated feature, the corresponding alarm weights for each associated alarm pair are determined.

[0014] Further, the correlation features include alarm occurrence time / alarm clearance time, alarm frequency, alarm level, alarm network element level, and alarm network element spacing. The step of determining the weight of each correlated alarm relative to its corresponding correlation feature based on each of the correlation features includes:

[0015] If there is a first associated alarm pair among all associated alarm pairs where both the alarm occurrence time and the alarm clearing time are earlier than those of other associated alarm pairs, then the associated feature weight of the first associated alarm pair will be increased by the first preset weight.

[0016] Obtain the second associated alarm pair corresponding to the alarm with the highest alarm frequency in the associated alarm pair, and increase the associated feature weight of the second associated alarm pair by the second preset weight.

[0017] Obtain the third associated alarm pair corresponding to the alarm with the highest alarm level in the associated alarm pair, and increase the associated feature weight of the third associated alarm pair by the third preset weight.

[0018] Obtain the fourth associated alarm pair corresponding to the alarm with the largest alarm element level in the associated alarm pair, and increase the associated feature weight of the fourth associated alarm pair by the fourth preset weight.

[0019] Obtain the sum of the network element distances between each alarm network element and other alarm network elements in the associated alarm pair. Obtain the fifth associated alarm pair corresponding to the alarm with the smallest sum of network element distances in the associated alarm pair. Increase the associated feature weight of the fifth associated alarm pair by the fifth preset weight.

[0020] Furthermore, the step of taking the associated alarm pair corresponding to the largest weight among the various alarm weights as the root cause alarm includes:

[0021] If the target associated alarm pair includes multiple pairs, then the priority of the associated feature weights corresponding to the target associated alarm is obtained;

[0022] The root cause alarm is determined based on the associated alarm pair corresponding to the associated feature weight with the highest priority.

[0023] Further, the step of inputting the target alarm data into a pre-trained alarm association model for model training, so as to obtain multiple associated alarm pairs based on the training results, includes:

[0024] The target alarm data is input into a pre-trained alarm association model for model training to obtain training results, wherein the training results include the first correlation degree between alarm pairs corresponding to the target alarm data;

[0025] The target alarm pair with a first correlation degree greater than a preset threshold is selected as the associated alarm pair.

[0026] Furthermore, the step of acquiring the alarm data to be processed includes:

[0027] Obtain the first alarm network element, the province information of the first alarm network element, and the transmission circuit information of the first alarm network element for each unrelated alarm in the unrelated alarm data;

[0028] Based on the first alarm network element, the province information of the first alarm network element, and the transmission circuit information of the first alarm network element, the unrelated alarm data is processed to obtain unrelated alarm information, and the unrelated alarm information is used to determine the alarm data to be processed.

[0029] Furthermore, the step of processing the unrelated alarm data based on the first alarm network element, the province information of the first alarm network element, and the transmission circuit information of the first alarm network element to obtain unrelated alarm information includes:

[0030] Based on the Viterbi algorithm, the name of the first target network element corresponding to the first alarm network element is determined in the hidden Markov model corresponding to the standard network element field;

[0031] Based on the data center information of the first alarm network element, the province information of the first alarm network element is corrected for errors, so as to obtain the first province information of the first alarm network element.

[0032] Based on the Viterbi algorithm, the first transmission circuit code corresponding to the transmission circuit information of the first alarm network element is determined in the hidden Markov model corresponding to the standard transmission circuit information.

[0033] Based on the first target network element name, the first province information, and the first transmission circuit code, the unassociated alarm information is determined.

[0034] Further, the step of determining the unassociated alarm information as the alarm data to be processed includes:

[0035] Based on the topological relationship between each first alarm network element in the unrelated alarm information, a first network topology map is generated;

[0036] Based on the first network topology diagram and the feature information of each first alarm network element, the feature vector corresponding to each first alarm network element is obtained, and the feature vector is used as the alarm data to be processed. The feature information includes alarm time, province information, manufacturer information, network element name, major, and equipment type.

[0037] Furthermore, before the step of acquiring the alarm data to be processed and performing root cause prediction processing on the alarm data to be processed based on the root cause prediction rule base to obtain the target alarm data, the fault location method further includes:

[0038] Obtain the historical feature vector corresponding to each historical alarm in the historical alarm data, and determine the historical alarm pair based on the historical feature vector;

[0039] The historical alarm pairs are input into the initial alarm association model for model training to obtain the trained alarm association model and the second association degree corresponding to each historical alarm pair;

[0040] Based on the second correlation degree, the true correlation degree corresponding to each historical alarm pair, and the trained alarm correlation model, the pre-trained alarm correlation model is determined.

[0041] Furthermore, the step of determining the pre-trained alarm association model based on the second correlation degree, the true correlation degree corresponding to each historical alarm pair, and the trained alarm association model includes:

[0042] Based on the second correlation degree and the corresponding true correlation degree of each historical alarm pair, the model training accuracy is determined.

[0043] Based on the training accuracy of the model and the trained alarm association model, the pre-trained alarm association model is determined.

[0044] Furthermore, the step of determining the pre-trained alarm association model based on the model training accuracy and the trained alarm association model includes:

[0045] If the training accuracy of the model is greater than or equal to the preset accuracy, then the trained alarm association model will be used as the pre-trained alarm association model.

[0046] If the model training accuracy is less than the preset accuracy, the trained alarm association model will be used as the initial alarm association model, and the process will return to the step of training the model by inputting the historical alarms to the initial alarm association model.

[0047] Furthermore, the step of obtaining the historical feature vector corresponding to each historical alarm in the historical alarm data includes:

[0048] Obtain the second alarm network element, the province information of the second alarm network element, and the transmission circuit information of the second alarm network element for each historical alarm in the historical alarm data;

[0049] Based on the second alarm network element, the province information of the second alarm network element, and the transmission circuit information of the second alarm network element, the historical alarm data is processed to obtain processed historical alarm data.

[0050] The historical feature vector is determined based on the processed historical alarm data.

[0051] Further, the step of processing the historical alarm data based on the second alarm network element, the province information of the second alarm network element, and the transmission circuit information of the second alarm network element to obtain processed historical alarm data includes:

[0052] Based on the Viterbi algorithm, the name of the second target network element corresponding to the second alarm network element is determined in the hidden Markov model corresponding to the standard network element field;

[0053] Based on the data center information of the second alarm network element, the province information of the second alarm network element is corrected for errors, so as to obtain the second province information of the second alarm network element;

[0054] Based on the Viterbi algorithm, the hidden Markov model corresponding to the transmission circuit information of the second alarm network element is used to determine the second transmission circuit code.

[0055] Based on the second target network element name, the second province information, and the second transmission circuit code, the processed historical alarm data is determined.

[0056] Furthermore, the step of determining the historical feature vector based on the processed historical alarm data includes:

[0057] Based on the topological relationships between each second alarm network element in the processed historical alarm data, a second network topology map is generated.

[0058] Based on the second network topology diagram and the feature information of each second alarm network element, the historical feature vector is obtained.

[0059] Furthermore, to achieve the above objectives, the present invention also provides a fault location device, the fault location device comprising:

[0060] The acquisition module is used to acquire alarm data to be processed and perform root cause prediction processing on the alarm data to be processed based on the root cause prediction rule base to obtain target alarm data.

[0061] The training module is used to input the target alarm data into a pre-trained alarm association model for model training, so as to obtain multiple associated alarm pairs based on the training results;

[0062] The determination module is used to determine the alarm weight of each associated alarm pair based on multiple associated features.

[0063] The positioning module is used to identify the target-related alarm pair with the highest weight among all alarm weights as the root cause alarm, and to identify the alarm network element corresponding to the target-related alarm pair as the root cause network element.

[0064] In addition, to achieve the above objectives, the present invention also provides a fault location device, the fault location device comprising: a memory, a processor, and a fault location program stored in the memory and executable on the processor, wherein the fault location program, when executed by the processor, implements the steps of the aforementioned fault location method.

[0065] In addition, to achieve the above objectives, the present invention also provides a storage medium storing a fault location program, which, when executed by a processor, implements the steps of the aforementioned fault location method.

[0066] In addition, to achieve the above objectives, the present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the aforementioned fault location method.

[0067] This invention acquires alarm data to be processed and performs root cause prediction processing on the alarm data based on a root cause prediction rule base to obtain target alarm data. Then, the target alarm data is input into a pre-trained alarm association model for model training to obtain multiple associated alarm pairs based on the training results. Next, based on multiple association features corresponding to each associated alarm pair, the alarm weight corresponding to each associated alarm pair is determined. Then, the target associated alarm pair with the highest weight among all alarm weights is taken as the root cause alarm, and the alarm network element corresponding to the target associated alarm pair is taken as the root cause network element. By performing root cause prediction on the alarm data, the amount of target alarm data is reduced. The target alarm data is clustered by the model, and the root cause alarm is obtained by secondary localization of the clustered associated alarm pairs based on the alarm weight, thereby improving the accuracy and efficiency of fault location. Attached Figure Description

[0068] Figure 1 This is a schematic diagram of the structure of a fault location device in the hardware operating environment involved in the embodiments of the present invention;

[0069] Figure 2 This is a flowchart illustrating the first embodiment of the fault location method of the present invention;

[0070] Figure 3 This is a functional module diagram of an embodiment of the fault location device of the present invention.

[0071] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0072] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0073] like Figure 1 As shown, Figure 1 This is a schematic diagram of the structure of a fault location device in the hardware operating environment involved in the embodiments of the present invention.

[0074] The fault location device in this invention embodiment can be a PC, or a smartphone, tablet computer, e-book reader, MP3 (Moving Picture Experts Group Audio Layer III) player, MP4 (Moving Picture Experts Group Audio Layer IV) player, portable computer, or other portable terminal device with display function.

[0075] like Figure 1As shown, the fault location device may include: a processor 1001, such as a CPU; a network interface 1004; a user interface 1003; a memory 1005; and a communication bus 1002. The communication bus 1002 is used to establish communication between these components. The user interface 1003 may include a display screen and an input unit such as a keyboard; optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 1005 may be high-speed RAM or non-volatile memory, such as a disk drive. Optionally, the memory 1005 may also be a storage device independent of the aforementioned processor 1001.

[0076] Optionally, the fault location device may also include a camera, RF (Radio Frequency) circuitry, sensors, audio circuitry, a WiFi module, and so on. These sensors may include, for example, light sensors, motion sensors, and other sensors. Of course, the fault location device may also be equipped with other sensors such as gyroscopes, barometers, hygrometers, thermometers, and infrared sensors, which will not be elaborated upon here.

[0077] Those skilled in the art will understand that Figure 1 The terminal structure shown does not constitute a limitation on the fault location device and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0078] like Figure 1 As shown, the memory 1005, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a fault location program.

[0079] exist Figure 1 In the terminal shown, the network interface 1004 is mainly used to connect to the backend server and communicate with the backend server; the user interface 1003 is mainly used to connect to the client (user terminal) and communicate with the client; and the processor 1001 can be used to call the fault location program stored in the memory 1005.

[0080] In this embodiment, the fault location device includes: a memory 1005, a processor 1001, and a fault location program stored in the memory 1005 and executable on the processor 1001. When the processor 1001 calls the fault location program stored in the memory 1005, it executes the steps of the fault location method in the following embodiments.

[0081] The present invention also provides a fault location method, referring to Figure 2 , Figure 2 This is a flowchart illustrating the first embodiment of the fault location method of the present invention.

[0082] In this embodiment, the fault location method includes the following steps:

[0083] Step S101: Obtain the alarm data to be processed, and perform root cause prediction processing on the alarm data to be processed based on the root cause prediction rule base to obtain the target alarm data;

[0084] In this embodiment, upon receiving a network anomaly, various network anomalies are first standardized to generate a real-time alarm stream, i.e., alarm data to be processed. Network anomalies include device hardware and software anomalies, device signaling anomalies, device performance index anomalies, and abnormal fluctuations in complaint volume. Furthermore, based on the operational experience of front-line experts, a root cause prediction rule base is established around typical fault scenarios to obtain the root cause prediction rule base according to the information corresponding to the root cause alarms of currently occurring or potentially occurring faults.

[0085] Specifically, in this embodiment, the root cause prediction rule base is used to perform root cause prediction processing on the alarm data to be processed, so as to delete / remove some minor alarms (non-root cause alarms) in the alarm data to be processed, so as to obtain target alarm data, thereby reducing the amount of target alarm data and improving the efficiency of fault location.

[0086] Step S102: Input the target alarm data into the pre-trained alarm association model for model training, and obtain multiple associated alarm pairs based on the training results;

[0087] In this embodiment, after obtaining the target alarm data, a pre-trained alarm association model is acquired. The target alarm data is input into the pre-trained alarm association model for model training to obtain the training result, which is the output data of the pre-trained alarm association model. Then, based on the training result, multiple associated alarm pairs are obtained. Specifically, the training result includes each alarm pair in the target alarm data and the first correlation degree corresponding to each alarm pair. Then, based on the first correlation degree, the associated alarm pairs in each alarm pair are determined, thereby realizing the clustering of the target alarm data.

[0088] Step S103: Determine the alarm weight corresponding to each associated alarm pair based on the multiple associated features corresponding to each associated alarm pair.

[0089] In this embodiment, after obtaining the associated alarm pairs, multiple associated features corresponding to each associated alarm pair are obtained, that is, the features of the two alarms in each associated alarm pair, and the alarm weights corresponding to each associated alarm pair are obtained. Specifically, the alarm weights corresponding to each associated alarm pair are determined according to preset rules. For example, the weights corresponding to each associated feature of the associated alarm pair are determined, and the sum of the weights corresponding to each associated feature is used as the alarm weight of the corresponding associated alarm pair.

[0090] Step S104: The target-related alarm pair corresponding to the largest weight among all alarm weights is taken as the root cause alarm, and the alarm network element corresponding to the target-related alarm pair is taken as the root cause network element.

[0091] In this embodiment, after obtaining the alarm weights corresponding to each associated alarm pair, the maximum weight among the alarm weights is determined, and the associated alarm pair corresponding to the maximum weight is obtained from each alarm weight to obtain the target associated alarm pair. The target associated alarm pair is the root cause alarm, and the alarm network element corresponding to the target associated alarm pair is the root cause network element. Since the two alarm network elements of the target associated alarm are associated alarm network elements, any one of the alarm network elements of the target associated alarm can be used as the root cause network element. Thus, the root cause network element can be accurately located according to the alarm weight of the associated alarm pair, so as to achieve accurate and rapid fault location.

[0092] The fault location method proposed in this embodiment acquires alarm data to be processed and performs root cause prediction processing on the alarm data based on a root cause prediction rule base to obtain target alarm data. Then, the target alarm data is input into a pre-trained alarm association model for model training to obtain multiple associated alarm pairs based on the training results. Next, based on multiple association features corresponding to each associated alarm pair, the alarm weights corresponding to each associated alarm pair are determined. The target associated alarm pair with the highest weight among all alarm weights is then taken as the root cause alarm, and the alarm network element corresponding to the target associated alarm pair is taken as the root cause network element. By performing root cause prediction on the alarm data, the amount of target alarm data is reduced. The model clusters the target alarm data, and secondary location is performed on the clustered associated alarm pairs based on the alarm weights to obtain the root cause alarm, thus improving the accuracy and efficiency of fault location. Simultaneously, fault location is performed through a pre-trained alarm association model, eliminating the need to rely on expert rules, thereby improving the accuracy of fault location.

[0093] Based on the first embodiment, a second embodiment of the fault location method of the present invention is proposed. In this embodiment, step S103 includes:

[0094] Step S201: Based on each of the associated features, determine the associated feature weights corresponding to each associated alarm pair;

[0095] Step S202: Determine the alarm weight corresponding to each associated alarm pair based on the weights of each associated feature.

[0096] In this embodiment, based on each associated feature, the associated feature weights corresponding to each associated alarm pair are determined to obtain the associated feature weights of the associated features of each associated alarm pair. Specifically, the associated feature weights of the associated features are determined according to preset rules, and then the sum of the associated feature weights corresponding to each associated feature is used as the alarm weight of the corresponding associated alarm pair.

[0097] Specifically, in one embodiment, the associated features include alarm occurrence time / alarm clearance time, alarm frequency, alarm level, alarm network element level, and alarm network element spacing. Step S201 includes:

[0098] Step a1: If there is a first associated alarm pair among the associated alarm pairs where both the alarm occurrence time and the alarm clearing time are earlier than those of other associated alarm pairs, then increase the associated feature weight of the first associated alarm pair by the first preset weight.

[0099] Step a2: Obtain the second associated alarm pair corresponding to the alarm with the highest alarm frequency in the associated alarm pair, and increase the associated feature weight of the second associated alarm pair by the second preset weight.

[0100] Step a3: Obtain the third associated alarm pair corresponding to the alarm with the highest alarm level in the associated alarm pair, and increase the associated feature weight of the third associated alarm pair by the third preset weight.

[0101] Step a4: Obtain the fourth associated alarm pair corresponding to the alarm with the largest alarm element level in the associated alarm pair, and increase the associated feature weight of the fourth associated alarm pair by the fourth preset weight.

[0102] Step a5: Obtain the sum of the network element distances between the alarm network element and other alarm network elements of each alarm in the associated alarm pair; obtain the fifth associated alarm pair corresponding to the alarm with the smallest sum of network element distances in the associated alarm pair; and increase the associated feature weight of the fifth associated alarm pair by the fifth preset weight.

[0103] Specifically, first, obtain the alarm occurrence time and alarm clearance time of the two alarms in each associated alarm pair. Among all alarms, determine the alarm with the earliest occurrence time. Then, determine whether the alarm clearance time of the alarm with the earliest occurrence time is earlier than the alarm clearance time of other alarms. If so, the associated alarm pair corresponding to the alarm with the earliest occurrence time is the first associated alarm pair, and the associated feature weight of the first associated alarm pair is increased by a first preset weight. If not, the associated feature weight of each associated alarm pair is not increased, that is, the associated feature weight remains the initial weight.

[0104] The alarm frequency is obtained for each alarm in a related alarm pair. This alarm frequency is the number of times the alarm appears in the related alarm pair; that is, if the same alarm exists in multiple related alarm pairs, the number of related alarm pairs including that alarm is the alarm frequency. Then, the alarm with the highest alarm frequency is determined, and the second related alarm pair corresponding to this alarm with the highest alarm frequency is obtained. The association feature weight of the second related alarm pair is increased by a second preset weight. It is easy to understand that the alarm with the highest alarm frequency exists in multiple related alarm pairs. Therefore, all related alarm pairs including the alarm with the highest alarm frequency can be used as the second related alarm pair. Alternatively, the alarm frequency of another alarm in all related alarm pairs including the alarm with the highest alarm frequency can be obtained again, and the related alarm pair with the highest alarm frequency of that other alarm can be used as the second related alarm pair.

[0105] Obtain the alarm levels of the two alarms in the associated alarm pair, determine the alarm with the highest alarm level, take the associated alarm pair corresponding to the alarm with the highest alarm level as the third associated alarm pair, and increase the associated feature weight of the third associated alarm pair by the third preset weight. It should be noted that if the alarm with the highest alarm level corresponds to multiple associated alarm pairs, then all associated alarm pairs corresponding to the alarm with the highest alarm level can be considered as the third associated alarm pair. Alternatively, the associated alarm pair to which the alarm with the earliest occurrence time belongs among the multiple associated alarm pairs corresponding to the alarm with the highest alarm level belongs can be considered as the third associated alarm pair. If the alarm with the earliest occurrence time among the multiple associated alarm pairs corresponding to the alarm with the highest alarm level belongs to multiple undetermined associated alarm pairs, then the associated alarm pair to which the alarm with the earliest occurrence time belongs among the other alarms of the undetermined associated alarm pairs belongs can be considered as the third associated alarm. Alternatively, the associated alarm pair to which the alarm with the highest alarm frequency belongs among the multiple associated alarm pairs corresponding to the alarm with the highest alarm level belongs can be considered as the third associated alarm pair. If the alarm with the highest alarm frequency among the multiple associated alarm pairs corresponding to the alarm with the highest alarm level belongs to multiple undetermined associated alarm pairs, then the associated alarm pair to which the alarm with the highest alarm frequency belongs among the other alarms of the undetermined associated alarm pairs belongs can be considered as the third associated alarm.

[0106] Obtain the alarm element level of two alarms in a related alarm pair, determine the alarm with the highest alarm element level, and designate the related alarm pair corresponding to the alarm with the highest alarm element level as the fourth related alarm pair. Increase the association feature weight of the fourth related alarm pair by a fourth preset weight. It should be noted that if the related alarm pair corresponding to the alarm with the highest alarm element level includes multiple pairs, all related alarm pairs corresponding to the alarm with the highest alarm element level can be designated as the fourth related alarm pair. Alternatively, the related alarm pair to which the alarm with the earliest occurrence time belongs among the multiple related alarm pairs corresponding to the alarm with the highest alarm element level is designated as the third related alarm pair. If the alarm with the earliest occurrence time among the multiple related alarm pairs corresponding to the alarm with the highest alarm element level belongs to multiple undetermined related alarm pairs, then the undetermined related alarm pairs are... The alarm pair to which the earliest alarm occurred in another alarm pair is considered the third associated alarm; or, the alarm pair to which the alarm with the highest frequency in multiple associated alarm pairs corresponding to the alarm at the highest alarm element level is considered the third associated alarm pair. If the alarm with the highest frequency in multiple associated alarm pairs corresponding to the alarm at the highest alarm element level belongs to multiple undetermined associated alarm pairs, then the alarm pair to which the alarm with the highest frequency in another alarm of the undetermined associated alarm pair belongs is considered the third associated alarm.

[0107] Obtain the sum of the network element distances between each alarm network element and other alarm network elements in the associated alarm pair. Obtain the fifth associated alarm pair corresponding to the alarm with the smallest sum of network element distances in the associated alarm pair. Increase the associated feature weight of the fifth associated alarm pair by the fifth preset weight.

[0108] Further, in one embodiment, step S202 includes:

[0109] Step b1: If the target associated alarm pair includes multiple pairs, then obtain the priority of the associated feature weights corresponding to the target associated alarm.

[0110] Step b2: Determine the root cause alarm based on the associated alarm pair corresponding to the associated feature weight with the highest priority.

[0111] In this embodiment, if the target associated alarm pair includes multiple pairs, that is, the alarm weights of multiple associated alarm pairs are all the maximum weights, then the priority of the associated feature weights corresponding to the target associated alarm is obtained. The associated features include alarm occurrence time / alarm clearing time, alarm frequency, alarm level, alarm network element level, and alarm network element spacing. The priority of the associated features is preset. For example, the priority of each associated feature decreases in the order of alarm occurrence time / alarm clearing time, alarm frequency, alarm level, alarm network element level, and alarm network element spacing. The priority of the associated feature weight is the same as the priority of its corresponding associated feature.

[0112] The root cause alarm is determined based on the associated alarm pair corresponding to the highest priority associated feature weight. For example, if both associated alarm pairs A and B are target associated alarm pairs, then the priority of the associated feature weights of associated alarm pairs A and B is obtained. For example, the associated feature weights of A include alarm occurrence time / alarm clearing time weight, alarm level weight, and alarm network element level weight; the associated feature weights of B include alarm frequency weight, alarm level weight, alarm network element level weight, and alarm network element spacing weight. Therefore, the associated feature weight with the highest priority is the alarm occurrence time / alarm clearing time weight. The time weight is used to determine the root cause alarm. If the associated feature weights of A include alarm occurrence time / alarm clearing time weight and alarm frequency weight, and the associated feature weights of B include alarm occurrence time / alarm clearing time weight, alarm level weight, alarm network element level weight, and alarm network element spacing weight, then the associated feature weight with the highest priority is the alarm occurrence time / alarm clearing time weight. However, since this weight exists in both A and B, the weight with the second highest priority is determined, which is the alarm frequency weight. Therefore, A is taken as the root cause alarm.

[0113] The fault location method proposed in this embodiment determines the associated feature weights of each associated alarm pair based on the associated features; then, based on the associated feature weights, it determines the alarm weights of each associated alarm pair. This method can accurately obtain the alarm weights of associated alarm pairs based on the associated feature weights, further improving the accuracy of root cause element location.

[0114] Based on the first embodiment, a third embodiment of the fault location method of the present invention is proposed. In this embodiment, step S102 includes:

[0115] Step S301: Input the target alarm data into a pre-trained alarm association model for model training to obtain training results, wherein the training results include the first correlation degree between alarm pairs corresponding to the target alarm data;

[0116] Step S302: Select the target alarm pair with a first correlation degree greater than a preset threshold from the alarm pairs corresponding to the target alarm data as the associated alarm pair.

[0117] In this embodiment, the target alarm data is input into a pre-trained alarm association model for model training to obtain the training result. The output of the pre-trained alarm association model is used as the training result. The training result includes the first correlation degree between the alarm pairs corresponding to the target alarm data. The alarm pairs corresponding to the target alarm data refer to the alarm pairs formed between each pair of alarms in the target alarm data.

[0118] Then, the first correlation degree of the alarm pair corresponding to the target alarm data is compared with a preset threshold to determine the target alarm pair with a first correlation degree greater than the preset threshold, and the target alarm pair is taken as the associated alarm pair to accurately obtain the associated alarm pair.

[0119] It should be noted that the preset threshold can be set reasonably, for example, the preset threshold is 0.5, 0.55, 0.6, 0.7, etc.

[0120] The fault location method proposed in this embodiment trains the target alarm data into a pre-trained alarm association model to obtain training results, wherein the training results include a first correlation degree between alarm pairs corresponding to the target alarm data. Then, the target alarm pairs with a first correlation degree greater than a preset threshold are selected as the associated alarm pairs. Based on the first correlation degree obtained by model training, associated alarm pairs can be accurately determined among the alarm pairs corresponding to the target alarm data. This achieves clustering of target alarm data through model training, further improving the accuracy and efficiency of fault location.

[0121] Based on the first embodiment, a fourth embodiment of the fault location method of the present invention is proposed. In this embodiment, step S101 includes:

[0122] Step S401: Obtain the first alarm network element, the province information of the first alarm network element, and the transmission circuit information of the first alarm network element for each unrelated alarm in the unrelated alarm data;

[0123] Step S402: Based on the first alarm network element, the province information of the first alarm network element, and the transmission circuit information of the first alarm network element, perform data processing on the unrelated alarm data to obtain unrelated alarm information, and use the unrelated alarm information to determine the alarm data to be processed.

[0124] In this embodiment, when alarm access is performed, abnormal data (unrelated alarm data) corresponding to network anomalies are received. Various abnormal data are standardized to generate a real-time alarm stream, i.e., alarm data to be processed. Specifically, the first alarm network element, the province information of the first alarm network element, and the transmission circuit information of the first alarm network element are obtained for each unrelated alarm in the unrelated alarm data. That is, the first alarm network element, the province information of the first alarm network element, and the transmission circuit information of the first alarm network element are obtained for each alarm in the unrelated alarm data. Then, based on the first alarm network element, the province information of the first alarm network element, and the transmission circuit information of the first alarm network element, the unrelated alarm data is processed to achieve standardization of the unrelated alarm data. The unrelated alarm data is processed to standardize, ensure consistency, and improve accuracy. The resulting unrelated alarm information determines the alarm data to be processed.

[0125] Specifically, in one embodiment, step S402 includes:

[0126] Step c1: Based on the Viterbi algorithm, determine the name of the first target network element corresponding to the first alarm network element in the hidden Markov model corresponding to the standard network element field;

[0127] Step c2: Based on the data center information of the first alarm network element, correct the incorrect province information of the first alarm network element to obtain the first province information of the first alarm network element;

[0128] Step c3: Based on the Viterbi algorithm, determine the first transmission circuit code corresponding to the transmission circuit information of the first alarm network element in the hidden Markov model corresponding to the standard transmission circuit information.

[0129] Step c4: Based on the first target network element name, the first province information, and the first transmission circuit code, determine the unassociated alarm information.

[0130] In this embodiment, due to the inconsistency between the network element names in the unassociated alarm data and the standard network element fields, a Hidden Markov Model (HMM) is pre-established based on the standard network element fields. After obtaining the unassociated alarm data, the first target network element name corresponding to the first alarm network element is determined in the HMM corresponding to the standard network element fields using the Viterbi algorithm. This yields the standard network element name corresponding to the network element name of each alarm in the unassociated alarm data. For example, if the network element name of the alarm in the unassociated alarm data is Yibin (Chengdu Phase 6), its corresponding standard network element name is Yibin (Chengdu Direction Phase 6). If the network element name of the alarm in the unassociated alarm data is Hohhot AR04, its corresponding standard network element name is Hohhot AR4.

[0131] Simultaneously, based on the data center information to which the first alarm network element belongs, the province information of the first alarm network element is corrected for errors to obtain the first province information of the first alarm network element. Specifically, the data center province information corresponding to the data center information to which the first alarm network element belongs is obtained through a digital map, and the data center province information is used as the first province information of the first alarm network element.

[0132] Furthermore, a hidden Markov model is pre-established based on standard transmission circuit information. After obtaining unassociated alarm data, the first transmission circuit code corresponding to the transmission circuit information of the first alarm network element is determined in the hidden Markov model corresponding to the standard transmission circuit information based on the Viterbi algorithm.

[0133] Finally, based on the first target network element name, the first province information, and the first transmission circuit code, the unassociated alarm information is determined. Specifically, the network element name of the first alarm network element in the unassociated alarm data is replaced with the corresponding first target network element name, the province information of the first alarm network element is replaced with the corresponding first province information, and the transmission circuit information of the first alarm network element is replaced with the corresponding first transmission circuit code to obtain the unassociated alarm information.

[0134] In another embodiment, step S402 includes:

[0135] Step d1: Generate a first network topology map based on the topological relationship between each first alarm network element in the unassociated alarm information;

[0136] Step d2: Based on the first network topology map and the feature information of each first alarm network element, obtain the feature vector corresponding to each first alarm network element, and use the feature vector as the alarm data to be processed. The feature information includes alarm time, province information, manufacturer information, network element name, major, and equipment type.

[0137] In this embodiment, after obtaining unassociated alarm information, the topological relationship between each first alarm network element in the unassociated alarm information is obtained, and a first network topology graph is generated based on the topological relationship. For example, the first network topology graph G = (V, E), where V = {v1, v2, ... vn} is the set of first alarm network elements, which includes the full set of network elements of various specialties such as core network, bearer, CMNET, transmission, and NFV. E = {eij} is the set of edges, where eij represents a directed edge with weight wij between the vi-th network element and the vj-th network element. The edges here include physical connections, such as a direct optical cable connection between vi and vj, as well as logical connections, such as two network elements belonging to the same POOL, or the CMNET network element and the transmission network element being associated through the transmission circuit code. They may even include weak connections, such as two network elements belonging to the same data center / city / province. The larger the range, the lower the wij. The weight wij represents the reliability of the connection relationship between the two network elements. Here, wij is physical connection > logical connection > weak connection.

[0138] Then, based on the first network topology diagram and the feature information of each first alarm network element, the feature vector corresponding to each first alarm network element is obtained, and the feature vector is used as the alarm data to be processed. The feature information includes at least the alarm time, province information, manufacturer information, network element name, specialty, and equipment type. By using the network topology diagram, the vector representation of the first alarm network elements for each specialty is completed, realizing cross-specialty association of alarm network elements.

[0139] For complex cross-disciplinary fault scenarios, cross-disciplinary associations can be achieved through network topology diagrams, which can accurately locate cross-disciplinary faults, thereby greatly reducing the number of work orders dispatched, improving the efficiency and timeliness of fault verification, and thus improving network maintenance efficiency.

[0140] The fault location method proposed in this embodiment obtains the first alarm network element, the province information of the first alarm network element, and the transmission circuit information of the first alarm network element for each unrelated alarm in the unrelated alarm data. Then, based on the first alarm network element, the province information of the first alarm network element, and the transmission circuit information of the first alarm network element, the unrelated alarm data is processed to obtain unrelated alarm information. The unrelated alarm information is then used to determine the alarm data to be processed. By processing the unrelated alarm data to obtain the alarm data to be processed, the alarm data to be processed meets the format requirements of model training, thereby further improving the efficiency of fault location.

[0141] Based on the above embodiments, a fifth embodiment of the fault location method of the present invention is proposed. In this embodiment, before step S101, the fault location method further includes:

[0142] Step S501: Obtain the historical feature vector corresponding to each historical alarm in the historical alarm data, and determine the historical alarm pair based on the historical feature vector;

[0143] Step S502: Train the historical alarm pairs into the initial alarm association model to obtain the trained alarm association model and the second association degree corresponding to each historical alarm pair.

[0144] Step S503: Based on the second correlation degree, the true correlation degree corresponding to each historical alarm pair, and the trained alarm correlation model, determine the pre-trained alarm correlation model.

[0145] In this embodiment, the alarm association model needs to be trained in advance. Specifically, the historical feature vectors corresponding to the historical alarms are obtained first, and the historical alarm pairs are determined based on the historical feature vectors. That is, the historical feature vectors are combined only in pairs to obtain the historical feature vectors of each historical alarm pair.

[0146] Then, the historical alarm pairs are used to train the initial alarm association model to obtain the trained alarm association model, and the model output is used as the second association degree corresponding to each historical alarm pair.

[0147] Then, based on the second correlation degree, the true correlation degree corresponding to each historical alarm pair, and the trained alarm correlation model, a pre-trained alarm correlation model is determined. Specifically, based on the second correlation degree and the true correlation degree corresponding to each historical alarm pair, the accuracy of model training is determined, and based on the accuracy and the trained alarm correlation model, a pre-trained alarm correlation model is determined.

[0148] The fault location method proposed in this embodiment obtains the historical feature vectors corresponding to each historical alarm in the historical alarm data, and determines historical alarm pairs based on the historical feature vectors. Then, the historical alarm pairs are input into the initial alarm association model for model training to obtain the trained alarm association model and the second correlation degree corresponding to each historical alarm pair. Then, based on the second correlation degree, the true correlation degree corresponding to each historical alarm pair, and the trained alarm association model, a pre-trained alarm association model is determined. This realizes the training of the initial alarm association model based on historical alarm data, improves the accuracy of the pre-trained alarm association model, and thus improves the accuracy of fault location.

[0149] Based on the fifth embodiment, a sixth embodiment of the fault location method of the present invention is proposed. In this embodiment, step S503 includes:

[0150] Step S601: Determine the model training accuracy based on the second correlation degree and the corresponding true correlation degree of each historical alarm pair;

[0151] Step S602: Based on the model training accuracy and the trained alarm association model, determine the pre-trained alarm association model.

[0152] In this embodiment, the model training accuracy is first calculated based on the second correlation degree and the corresponding true correlation degree of each historical alarm pair, and then the pre-trained alarm correlation model is determined based on the model training accuracy. Specifically, step S602 includes:

[0153] Step e1: If the training accuracy of the model is greater than or equal to the preset accuracy, then the trained alarm association model is used as the pre-trained alarm association model.

[0154] Step e2: If the model training accuracy is less than the preset accuracy, the trained alarm association model is used as the initial alarm association model, and the process returns to the step of training the model by inputting the historical alarms to the initial alarm association model.

[0155] In this embodiment, after obtaining the model training accuracy, it is determined whether the model training accuracy is greater than or equal to the preset accuracy. If so, the trained alarm association model is directly used as the pre-trained alarm association model. Otherwise, the trained alarm association model is used as the initial alarm association model, and the step of training the input initial alarm association model with the historical alarms is returned to perform iterative optimization of the initial alarm association model until the model training accuracy is greater than or equal to the preset accuracy.

[0156] It should be noted that the preset accuracy rate can be set reasonably, for example, the preset accuracy rate is 80%, 90%, 95%, etc.

[0157] The fault location method proposed in this embodiment determines the model training accuracy based on the second correlation degree and the corresponding true correlation degree of each historical alarm pair. Then, based on the model training accuracy and the trained alarm correlation model, a pre-trained alarm correlation model is determined. The pre-trained alarm correlation model is accurately determined through the model training accuracy, thereby improving the accuracy of the pre-trained alarm correlation model and further enhancing the accuracy of fault location.

[0158] Based on the fifth embodiment, a seventh embodiment of the fault location method of the present invention is proposed. In this embodiment, step S501 includes:

[0159] Step S701: Obtain the second alarm network element, the province information of the second alarm network element, and the transmission circuit information of the second alarm network element for each historical alarm in the historical alarm data.

[0160] Step S702: Based on the second alarm network element, the province information of the second alarm network element, and the transmission circuit information of the second alarm network element, perform data processing on the historical alarm data to obtain processed historical alarm data.

[0161] Step S703: Determine the historical feature vector based on the processed historical alarm data.

[0162] In this embodiment, after obtaining historical alarm data, the second alarm network element, the province information of the second alarm network element, and the transmission circuit information of the second alarm network element for each historical alarm are obtained. That is, the second alarm network element, the province information of the second alarm network element, and the transmission circuit information of the second alarm network element for each historical alarm are obtained. Then, based on the second alarm network element, the province information of the second alarm network element, and the transmission circuit information of the second alarm network element, the historical alarm data is processed to achieve standardization of the historical alarm data. The historical alarm data is standardized, consistent, and accurate to obtain processed historical alarm data, and the historical feature vector is determined based on the processed historical alarm data.

[0163] Specifically, in one embodiment, step S702 includes:

[0164] Step f1: Based on the Viterbi algorithm, determine the name of the second target network element corresponding to the second alarm network element in the hidden Markov model corresponding to the standard network element field;

[0165] Step f2: Based on the data center information of the second alarm network element, correct the incorrect province information of the second alarm network element to obtain the second province information of the second alarm network element;

[0166] Step f3: Based on the Viterbi algorithm, determine the second transmission circuit code corresponding to the transmission circuit information of the second alarm network element in the hidden Markov model corresponding to the standard transmission circuit information;

[0167] Step f4: Based on the network element name corresponding to the second alarm network element, the second province information, and the second transmission circuit code, determine the processed historical alarm data.

[0168] In this embodiment, after obtaining historical alarm data, the second target network element name corresponding to the second alarm network element is determined in the hidden Markov model corresponding to the standard network element field based on the Viterbi algorithm, that is, the standard network element name corresponding to the network element name of each historical alarm in the historical alarm data is obtained.

[0169] Simultaneously, based on the data center information to which the second alarm network element belongs, the province information of the second alarm network element is corrected for errors to obtain the second province information of the second alarm network element. Specifically, the data center province information corresponding to the data center information to which the second alarm network element belongs is obtained through a digital map, and this data center province information is used as the second province information of the second alarm network element.

[0170] Furthermore, based on the Viterbi algorithm, the hidden Markov model corresponding to the transmission circuit information of the second alarm network element is used to determine the second transmission circuit code.

[0171] Finally, based on the second target network element name, the second province information, and the second transmission circuit code, the processed historical alarm data is determined. Specifically, the network element name of the second alarm network element in the historical alarm data is replaced with the corresponding second target network element name, the province information of the second alarm network element is replaced with the corresponding second province information, and the transmission circuit information of the second alarm network element is replaced with the corresponding second transmission circuit code to obtain the processed historical alarm data.

[0172] In another embodiment, step S703 includes:

[0173] Step g1: Generate a second network topology map based on the topological relationships between each second alarm network element in the processed historical alarm data;

[0174] Step g2: Based on the second network topology map and the feature information of each second alarm network element, obtain the historical feature vector.

[0175] In this embodiment, after obtaining processed historical alarm data, the topological relationships between various second alarm network elements in the processed historical alarm data are obtained, and a second network topology map is generated based on these topological relationships. Then, based on the second network topology map and the feature information of each second alarm network element, the historical feature vector corresponding to each second alarm network element is obtained. This feature information includes at least alarm time, province information, manufacturer information, network element name, specialty, and equipment type. By using the network topology map, the vector representation of second alarm network elements for each specialty is completed, realizing cross-specialty association of alarm network elements.

[0176] The fault location method proposed in this embodiment obtains the second alarm network element, the province information of the second alarm network element, and the transmission circuit information of the second alarm network element for each historical alarm in the historical alarm data. Then, based on the second alarm network element, the province information of the second alarm network element, and the transmission circuit information of the second alarm network element, the historical alarm data is processed to obtain processed historical alarm data. Then, the historical feature vector is determined based on the processed historical alarm data. By standardizing the historical alarm data, the historical feature vector is obtained from the standardized data, so that the standardized data meets the format requirements of model training, improving the efficiency of model training and further improving the efficiency of fault location.

[0177] The present invention also provides a fault location device, with reference to Figure 3 The fault location device includes:

[0178] The acquisition module 10 is used to acquire alarm data to be processed and perform root cause prediction processing on the alarm data to be processed based on the root cause prediction rule base to obtain target alarm data.

[0179] Training module 20 is used to input the target alarm data into a pre-trained alarm association model for model training, so as to obtain multiple associated alarm pairs based on the training results;

[0180] The determination module 30 is used to determine the alarm weight corresponding to each associated alarm pair based on multiple associated features corresponding to each associated alarm pair.

[0181] The positioning module 40 is used to take the target associated alarm pair corresponding to the largest weight among the various alarm weights as the root cause alarm, and take the alarm network element corresponding to the target associated alarm pair as the root cause network element.

[0182] The methods executed by the above-mentioned program units can be referred to in the various embodiments of the fault location method of the present invention, and will not be repeated here.

[0183] The present invention also provides a storage medium, namely a computer-readable storage medium. The storage medium stores a fault location program, which, when executed by a processor, implements the steps of the fault location method described above.

[0184] The method implemented when the fault location program running on the processor is executed can be referred to in various embodiments of the fault location method of the present invention, and will not be repeated here.

[0185] Furthermore, this embodiment of the invention also proposes a computer program product, which includes a fault location program. When the fault location program is executed by a processor, it implements the steps of the fault location method as described above.

[0186] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.

[0187] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0188] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0189] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.

Claims

1. A fault location method, characterized in that, The fault location method includes the following steps: Acquire the alarm data to be processed, and perform root cause prediction processing on the alarm data to be processed based on the root cause prediction rule base to delete / remove non-root cause alarms in the alarm data to be processed, so as to obtain the target alarm data. The target alarm data is input into a pre-trained alarm association model for model training, so as to obtain multiple associated alarm pairs based on the training results. The training results include each alarm pair in the target alarm data and the first correlation degree corresponding to each alarm pair. The target alarm pairs with a first correlation degree greater than a preset threshold are taken as the associated alarm pairs. Based on the multiple associated features of each associated alarm pair, determine the alarm weight corresponding to each associated alarm pair. The target-related alarm pair corresponding to the highest weight among all alarm weights is taken as the root cause alarm, and the alarm network element corresponding to the target-related alarm pair is taken as the root cause network element.

2. The fault location method as described in claim 1, characterized in that, The step of determining the alarm weight corresponding to each associated alarm pair based on multiple associated features includes: Based on each of the aforementioned associated features, determine the associated feature weights for each associated alarm pair. Based on the weights of each associated feature, the corresponding alarm weights for each associated alarm pair are determined.

3. The fault location method as described in claim 2, characterized in that, The correlation features include alarm occurrence time / alarm clearance time, alarm frequency, alarm level, alarm network element level, and alarm network element spacing. The step of determining the weight of each correlated alarm on the corresponding correlation feature based on each of the correlation features includes: If there is a first associated alarm pair among all associated alarm pairs where both the alarm occurrence time and the alarm clearing time are earlier than those of other associated alarm pairs, then the associated feature weight of the first associated alarm pair will be increased by the first preset weight. Obtain the second associated alarm pair corresponding to the alarm with the highest alarm frequency in the associated alarm pair, and increase the associated feature weight of the second associated alarm pair by the second preset weight. Obtain the third associated alarm pair corresponding to the alarm with the highest alarm level in the associated alarm pair, and increase the associated feature weight of the third associated alarm pair by the third preset weight. Obtain the fourth associated alarm pair corresponding to the alarm with the largest alarm element level in the associated alarm pair, and increase the associated feature weight of the fourth associated alarm pair by the fourth preset weight. Obtain the sum of the network element distances between each alarm network element and other alarm network elements in the associated alarm pair. Obtain the fifth associated alarm pair corresponding to the alarm with the smallest sum of network element distances in the associated alarm pair. Increase the associated feature weight of the fifth associated alarm pair by the fifth preset weight.

4. The fault location method as described in claim 2, characterized in that, The step of taking the associated alarm pair corresponding to the largest weight among all alarm weights as the root cause alarm includes: If the target associated alarm pair includes multiple pairs, then the priority of the associated feature weights corresponding to the target associated alarm is obtained; The root cause alarm is determined based on the associated alarm pair corresponding to the associated feature weight with the highest priority.

5. The fault location method as described in claim 1, characterized in that, The steps for obtaining alarm data to be processed include: Obtain the first alarm network element, the province information of the first alarm network element, and the transmission circuit information of the first alarm network element for each unrelated alarm in the unrelated alarm data; Based on the first alarm network element, the province information of the first alarm network element, and the transmission circuit information of the first alarm network element, the unrelated alarm data is processed to obtain unrelated alarm information, and the unrelated alarm information is used to determine the alarm data to be processed.

6. The fault location method as described in claim 5, characterized in that, The step of processing the unrelated alarm data based on the first alarm network element, the province information of the first alarm network element, and the transmission circuit information of the first alarm network element to obtain unrelated alarm information includes: Based on the Viterbi algorithm, the name of the first target network element corresponding to the first alarm network element is determined in the hidden Markov model corresponding to the standard network element field; Based on the data center information of the first alarm network element, the province information of the first alarm network element is corrected for errors, so as to obtain the first province information of the first alarm network element. Based on the Viterbi algorithm, the first transmission circuit code corresponding to the transmission circuit information of the first alarm network element is determined in the hidden Markov model corresponding to the standard transmission circuit information. Based on the first target network element name, the first province information, and the first transmission circuit code, the unassociated alarm information is determined.

7. The fault location method as described in claim 5, characterized in that, The step of determining the unassociated alarm information as the alarm data to be processed includes: Based on the topological relationship between each first alarm network element in the unrelated alarm information, a first network topology map is generated; Based on the first network topology diagram and the feature information of each first alarm network element, the feature vector corresponding to each first alarm network element is obtained, and the feature vector is used as the alarm data to be processed. The feature information includes alarm time, province information, manufacturer information, network element name, major, and equipment type.

8. The fault location method according to any one of claims 1 to 7, characterized in that, Before the step of acquiring the alarm data to be processed and performing root cause prediction processing on the alarm data to be processed based on the root cause prediction rule base to obtain the target alarm data, the fault location method further includes: Obtain the historical feature vector corresponding to each historical alarm in the historical alarm data, and determine the historical alarm pair based on the historical feature vector; The historical alarm pairs are input into the initial alarm association model for model training to obtain the trained alarm association model and the second association degree corresponding to each historical alarm pair; Based on the second correlation degree, the true correlation degree corresponding to each historical alarm pair, and the trained alarm correlation model, the pre-trained alarm correlation model is determined.

9. The fault location method as described in claim 8, characterized in that, The step of determining the pre-trained alarm association model based on the second correlation degree, the true correlation degree corresponding to each historical alarm pair, and the trained alarm association model includes: Based on the second correlation degree and the corresponding true correlation degree of each historical alarm pair, the model training accuracy is determined. Based on the training accuracy of the model and the trained alarm association model, the pre-trained alarm association model is determined.

10. The fault location method as described in claim 9, characterized in that, The step of determining the pre-trained alarm association model based on the model training accuracy and the trained alarm association model includes: If the training accuracy of the model is greater than or equal to the preset accuracy, then the trained alarm association model will be used as the pre-trained alarm association model. If the model training accuracy is less than the preset accuracy, the trained alarm association model will be used as the initial alarm association model, and the process will return to the step of training the model by inputting the historical alarms to the initial alarm association model.

11. The fault location method as described in claim 8, characterized in that, The step of obtaining the historical feature vector corresponding to each historical alarm in the historical alarm data includes: Obtain the second alarm network element, the province information of the second alarm network element, and the transmission circuit information of the second alarm network element for each historical alarm in the historical alarm data; Based on the second alarm network element, the province information of the second alarm network element, and the transmission circuit information of the second alarm network element, the historical alarm data is processed to obtain processed historical alarm data. The historical feature vector is determined based on the processed historical alarm data.

12. The fault location method as described in claim 11, characterized in that, The step of processing the historical alarm data based on the second alarm network element, the province information of the second alarm network element, and the transmission circuit information of the second alarm network element to obtain processed historical alarm data includes: Based on the Viterbi algorithm, the name of the second target network element corresponding to the second alarm network element is determined in the hidden Markov model corresponding to the standard network element field; Based on the data center information of the second alarm network element, the province information of the second alarm network element is corrected for errors, so as to obtain the second province information of the second alarm network element; Based on the Viterbi algorithm, the hidden Markov model corresponding to the transmission circuit information of the second alarm network element is used to determine the second transmission circuit code. Based on the second target network element name, the second province information, and the second transmission circuit code, the processed historical alarm data is determined.

13. The fault location method as described in claim 11, characterized in that, The step of determining the historical feature vector based on the processed historical alarm data includes: Based on the topological relationships between each second alarm network element in the processed historical alarm data, a second network topology map is generated. Based on the second network topology diagram and the feature information of each second alarm network element, the historical feature vector is obtained.

14. A fault location device, characterized in that, The fault location device includes: The acquisition module is used to acquire alarm data to be processed and perform root cause prediction processing on the alarm data to be processed based on the root cause prediction rule base to delete / remove non-root cause alarms in the alarm data to be processed in order to obtain target alarm data. The training module is used to input the target alarm data into a pre-trained alarm association model for model training, so as to obtain multiple associated alarm pairs based on the training results. The training results include each alarm pair in the target alarm data and the first correlation degree corresponding to each alarm pair. The target alarm pairs with a first correlation degree greater than a preset threshold are taken as the associated alarm pairs. The determination module is used to determine the alarm weight of each associated alarm pair based on multiple associated features. The positioning module is used to identify the target-related alarm pair with the highest weight among all alarm weights as the root cause alarm, and to identify the alarm network element corresponding to the target-related alarm pair as the root cause network element.

15. A fault location device, characterized in that, The fault location device includes: a memory, a processor, and a fault location program stored in the memory and executable on the processor, wherein the fault location program, when executed by the processor, implements the steps of the fault location method as described in any one of claims 1 to 13.

16. A storage medium, characterized in that, The storage medium stores a fault location program, which, when executed by a processor, implements the steps of the fault location method as described in any one of claims 1 to 13.

17. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the fault location method as described in any one of claims 1 to 13.

Citation Information

Patent Citations

  • Operation and maintenance fault root cause identification method and device, computer equipment and storage medium

    CN111897673A

  • Method and device for constructing clouded network alarm root cause relationship tree model

    CN112580678A