A method and apparatus for generating an alarm root cause location model
By analyzing the historical alarm data and topological relationship of the virtual network, an alarm positioning model is generated, which solves the problem of low alarm efficiency in the virtual network, and achieves fast and accurate fault positioning and repair.
Patent Information
- Application Number
- CN202111148552.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-28
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2041-09-28
AI Technical Summary
In virtual networks, the inefficiency of positioning root alarms leads to failure analysis that relies on manual experience and is prone to errors, delaying network repair and may lead to the expansion of failures.
By obtaining the historical alarm data of the virtual network and the topological relationship between network element, analyzing the association and causal relationship between type alarms, generating an alarm positioning model, and using frequency mining algorithms and Markov chain algorithms to determine the root cause alarm.
Improve the positioning efficiency and accuracy of root cause alarms, reduce manpower investment, and quickly identify and repair virtual network failures.
Smart Images

Figure CN115883324B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communications, and in particular, to a method and apparatus for generating an alarm root cause location model. Background Art
[0002] In a virtual network, alarms may be triggered by network element failures. Since the network elements in a virtual network are interconnected, a failure of one network element often causes related network elements to also fail and issue alarms. In the case of multiple alarms occurring in a virtual network, technicians often need to analyze the topological relationship between multiple network elements in the virtual network, and then, based on technical experience, analyze and determine which alarms issued by network elements are the root cause alarms that trigger other alarms, also known as root cause alarms. However, the topological relationship of network elements in a virtual network often changes, and the efficiency of manually analyzing root cause alarms is low. Moreover, since the analysis of root cause alarms depends on the experience of technicians, there may also be cases of incorrect analysis, thereby delaying the timeliness of network repair and possibly further causing the expansion of faults.
[0003] How to efficiently locate the root cause alarms in a virtual network is the technical problem to be solved by this application. Summary of the Invention
[0004] The purpose of the embodiments of this application is to provide a method and apparatus for generating an alarm root cause location model to solve the problem of low efficiency in locating the root cause alarms in a virtual network.
[0005] In a first aspect, a method for generating an alarm root cause location model is provided, including:
[0006] Obtain historical alarm data of the virtual network and the network element topological relationship of the virtual network, where the historical alarm data includes the types of alarms triggered by network elements in the virtual network in an abnormal state and the timestamps when the alarms are triggered;
[0007] Determine the correlation relationship between type alarms according to the historical alarm data, where the correlation relationship between a first type alarm and a second type alarm represents the probability of occurrence of the first type alarm and the second type alarm within a first preset period and / or the probability of the first type alarm and the second type alarm occurring successively within a second preset period;
[0008] Determine the causal relationship between type alarms according to the correlation relationship between type alarms;
[0009] Generate an alarm location model according to the causal relationship between type alarms and the network element topological relationship of the virtual network. The alarm location model includes the causal relationship between type alarms occurring at each network element in the virtual network, and the alarm location model is used to locate the root cause alarm in at least one target alarm according to the data of at least one target alarm occurring in the virtual network.
[0010] In a second aspect, a device for generating an alarm root cause location model is provided, including:
[0011] An acquisition module that acquires historical alarm data of a virtual network and the network element topology relationship of the virtual network. The historical alarm data includes the types of alarms triggered by network elements in the virtual network in an abnormal state and the timestamps when the alarms are triggered;
[0012] A first determination module that determines the association relationship between type alarms according to the historical alarm data. Among them, the association relationship between a first type alarm and a second type alarm represents the probability of the first type alarm and the second type alarm occurring within a first preset time period and / or the probability of the first type alarm and the second type alarm occurring successively within a second preset time period;
[0013] A second determination module that determines the causal relationship between type alarms according to the association relationship between type alarms;
[0014] A generation module that generates an alarm location model according to the causal relationship between type alarms and the network element topology relationship of the virtual network. The alarm location model includes the causal relationship between type alarms occurring at each network element in the virtual network, and the alarm location model is used to locate the root cause alarm in at least one target alarm according to the data of at least one target alarm that occurs in the virtual network.
[0015] In a third aspect, an electronic device is provided. The electronic device includes a processor, a memory, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, the steps of the method in the first aspect are implemented.
[0016] In a fourth aspect, a computer-readable storage medium is provided. A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the method in the first aspect are implemented.
[0017] In the embodiments of the present application, by obtaining the historical alarm data of the virtual network and the network element topology relationship of the virtual network, the historical alarm data includes the type of alarm triggered by the network element in the virtual network in an abnormal state and the timestamp of the triggered alarm; determining the correlation relationship between the type alarms according to the historical alarm data, wherein the correlation relationship between the first type alarm and the second type alarm represents the probability of the first type alarm and the second type alarm occurring within the first preset period and / or the probability of the first type alarm and the second type alarm occurring successively within the second preset period; determining the causal relationship between the type alarms according to the correlation relationship between the type alarms; generating an alarm location model according to the causal relationship between the type alarms and the network element topology relationship of the virtual network, the alarm location model includes the causal relationship between the type alarms occurring at each network element in the virtual network, and the alarm location model is used to locate the root cause alarm in at least one target alarm according to the data of at least one target alarm occurring in the virtual network. The solution of the embodiments of the present invention can efficiently determine the correlation between various types of alarms, and the generated alarm location model can determine the root cause alarm according to the alarm data, which is beneficial to quickly eliminate virtual network faults. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The drawings described herein are used to provide a further understanding of the present invention, and constitute a part of the present invention. The illustrative embodiments of the present invention and their descriptions are used to explain the present invention, and do not constitute an improper limitation of the present invention. In the drawings:
[0019] Figure 1a is one of the flow diagrams of a method for generating an alarm root cause location model according to an embodiment of the present invention;
[0020] Figure 1b is the application flow diagram of a method for generating an alarm root cause location model online and offline according to an embodiment of the present invention;
[0021] Figure 2 is the second flow diagram of a method for generating an alarm root cause location model according to an embodiment of the present invention;
[0022] Figure 3 is the third flow diagram of a method for generating an alarm root cause location model according to an embodiment of the present invention;
[0023] Figure 4 is the fourth flow diagram of a method for generating an alarm root cause location model according to an embodiment of the present invention;
[0024] Figure 5 is the fifth flow diagram of a method for generating an alarm root cause location model according to an embodiment of the present invention;
[0025] Figure 6aIt is the sixth flowchart of a method for generating an alarm root cause location model according to an embodiment of the present invention;
[0026] Figure 6b It is the result output by the alarm location model generated by a method for generating an alarm root cause location model according to an embodiment of the present invention;
[0027] Figure 7 It is the seventh flowchart of a method for generating an alarm root cause location model according to an embodiment of the present invention;
[0028] Figure 8 It is the structural schematic diagram of a device for generating an alarm root cause location model according to an embodiment of the present invention. Specific embodiments
[0029] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention. In this application, the accompanying drawing numbers are only used to distinguish each step in the solution and are not used to limit the execution order of each step. The specific execution order shall be subject to the description in the specification.
[0030] In the field of communication technology, with the rise of 5G services, the network structure has become increasingly complex. Technologies such as software-defined network, network function orchestration, virtualization, and containerization have made network fault analysis and processing extremely complex. The reasons for the current increase in network operation and maintenance complexity include, for example: the complexity brought by the dynamic change of the network architecture, the complexity brought by hierarchical decoupling to fault location, the complexity brought by real-time network resource allocation, and the complexity brought by network high reliability. Due to the above increase in network operation and maintenance complexity, the business pain points faced by current operation and maintenance include: a large number of derivative alarms and homologous alarms when a fault occurs make it impossible for operation and maintenance personnel to start, the association rules need to be sorted out by domain experts, the rules are old, and there is a lack of fault prediction ability, and the operation and maintenance work is like walking on thin ice.
[0031] For network fault monitoring and maintenance, a passive monitoring method is often adopted. This method requires a large number of maintenance personnel for operation and maintenance. However, the alarms and logs of IT (Information Technology) devices have increased exponentially. With the decoupling of the three layers of the network physical layer, virtual layer, and VNF layer, the monitoring not only targets network devices but also needs to monitor and process various objects such as hosts, storage, and virtual machines. If only the passive method is used, a large number of personnel need to be added, which requires a lot of manpower and time.
[0032] Among them, the means for analyzing virtual networks often involve manually formulating association rules for certain alarms, without delving into the mining of massive alarm data. During the root cause analysis process, it is difficult to analyze cross-layer network relationships and discover some fault problems with external connections. Additionally, presenting faults based on topology cannot achieve intelligent topology generation. Often, a topology diagram needs to be manually drawn, and it is difficult to have an automatic topology generation mechanism based on internal association relationships.
[0033] To solve the problems existing in the prior art, an embodiment of the present application provides a method for generating an alarm root cause location model, as Figure 1a shown, including:
[0034] S11: Obtain historical alarm data of the virtual network and the network element topology relationship of the virtual network. The historical alarm data includes the types of alarms triggered by network elements in the virtual network in an abnormal state and the timestamps when the alarms are triggered.
[0035] The above historical alarm data can be data of each network element device in the virtual network during a historical period, including the types of alarms triggered by network elements in an abnormal state and the timestamps when the alarms are triggered. Among them, the historical alarm data can also include the operation data of network elements in a normal state.
[0036] The above network element topology relationship represents the connection relationship between each network element in the virtual network. When a network element triggers an alarm in an abnormal state, the network elements directly or indirectly connected to this network element may also be affected by the abnormality of this network element and trigger alarms successively. The network element topology relationship can be displayed through a dot-line diagram, where the dots correspond to the network elements in the virtual network, and the connecting lines between the dots represent the connection relationship between the connected network elements. Further, the above network element topology relationship can also highlight the network elements that trigger alarms by changing the colors of the dots and lines and marking numerical values. The dot-line diagram representing the network element topology relationship can be presented to technicians to efficiently view the connection relationship of each network element and improve the efficiency of repairing abnormal network elements.
[0037] S12: Determine the association relationship between type alarms according to the historical alarm data. Among them, the association relationship between the first type alarm and the second type alarm represents the probability of the first type alarm and the second type alarm occurring within the first preset period and / or the probability of the first type alarm and the second type alarm occurring successively within the second preset period.
[0038] Among them, the historical alarm data often includes various types of alarms. This step is used to determine the association relationship between each type of alarm. Specifically, the association relationship can represent which types of alarms are associated with each other, and can also represent the degree of association tightness between type alarms.
[0039] The time length of the second preset period can be greater than that of the first preset period. For example, the second preset period can be 24 hours, which can be a fault correlation analysis interval period. This alarm correlation time interval period is used to determine the fault root cause analysis associated alarm pool. The alarm timestamps of the alarm data included in the alarm pool all belong to the above second preset period, and all alarm analyses are carried out within this interval period.
[0040] The first preset period can be 5 minutes, for example. The shorter the time length of the first preset period is set, the closer the correlation degree between the type alarms with a correlation relationship is determined. In practical applications, the time length of the first preset period can also be set according to factors such as the length of the second preset period and the processing performance of the processing device.
[0041] S13: Determine the causal relationship between the type alarms according to the correlation relationship between the type alarms.
[0042] In this step, the causal relationship is determined according to the correlation relationship between the type alarms. Among them, the causal relationship can specifically include the causal trigger relationship between the type alarms with a correlation relationship.
[0043] This causal relationship can, for example, represent that the trigger of the first type of alarm will trigger the second type of alarm, that is, the first type of alarm is the cause of the second type of alarm. Then, when both the first type of alarm and the second type of alarm are triggered, the first type of alarm is the root cause alarm.
[0044] S14: Generate an alarm location model according to the causal relationship between the type alarms and the network element topology relationship of the virtual network. The alarm location model includes the causal relationship between the type alarms occurring at each network element in the virtual network. The alarm location model is used to locate the root cause alarm in at least one target alarm according to the data of at least one target alarm occurring in the virtual network.
[0045] The above correlation relationship and causal relationship can be determined based on the frequency mining algorithm. This algorithm is based on factors such as frequent itemsets, support, and confidence. It can use the first preset period as the granularity and perform frequency item statistics on the data within the second preset period with a sliding window. Using Spark for calculation, perform support and confidence analysis and calculation on the data within the second preset period, and generate an alarm location model according to a certain threshold (such as the support is greater than 80%). This alarm location model can associate the triggered alarms with the performance of the virtual network.
[0046] Specifically, the alarm location model may include multiple root cause rules. Each root cause rule includes multiple type alarms with an associated relationship, as well as the root cause alarm among these type alarms. That is, a root cause rule may include at least one first type of alarm that can trigger a second type of alarm, or may include at least one second type of alarm that can be triggered by a first type of alarm. Moreover, the above alarm location model may specifically be stored in the form of an analysis rule library, that is, multiple root cause rules are stored in the analysis rule library, and there may be a certain association between the multiple root cause rules. For example, the first root cause rule is that type A alarm can trigger type B alarm, and the second root cause rule is that type B alarm can trigger type C alarm. Then, when type A, type B, and type C alarms all occur, according to the above first root cause rule and second root cause rule, it can be determined that the root cause alarm is type A alarm.
[0047] In addition, the alarm location model in the solution provided by the embodiments of the present application is generated based on the network element topology relationship. The above alarm location model can generate multiple associated root cause rules based on the network element topology relationship, and each root cause rule is associated with a network element in the virtual network.
[0048] The solution provided by the embodiments of the present application can associate the alarms triggered by abnormal network elements with the performance data of the abnormal network elements, thereby determining the association relationship and causal relationship between type alarms, and then generating an alarm location model. In practical applications, the real-time data collected in the virtual network can be input into the alarm location model, and the root cause alarm can be determined by matching the real-time data with the alarm location model, and the abnormal network element and the root cause of the abnormal network element can be determined.
[0049] For example, the solution provided by the embodiments of the present application can be applied to an alarm system. The overall architecture of this alarm system is divided into three layers, namely: the data access layer, the real-time processing layer, and the application display layer.
[0050] (1) Data access layer: Access virtualized alarm events, performance monitoring data, work order data, log data, etc. through Kafka, IBM MQ, socket, ftp, etc., and can obtain the historical alarm data of the virtual network and the network element topology relationship of the virtual network.
[0051] (2) Real-time processing layer: Real-time process various types of data in the data access layer, and use rules, models, and domain algorithms to analyze the data, and can implement services such as fault management and capacity prediction. Generate an alarm location model for operation and maintenance through methods such as manual sorting and data mining to provide atomic capabilities for the real-time processing process. In order to optimize the quality of the alarm location model, a fault root cause intelligent analysis system can also be built on the Spark and Flink platforms based on artificial intelligence and big data computing technologies, using data preprocessing, feature engineering, data mining, statistical machine learning, and deep machine learning algorithms.
[0052] (3) Application display layer: including real-time alarm monitoring, network health assessment, work order tracking, etc., in order to display the root cause alarm analysis results to the technical staff, and can also be used to receive the instructions triggered by the technical staff to perform further repair operations on the network elements related to the root cause alarm.
[0053] Further, such as Figure 1b The solution provided in the embodiment of the present application can be performed offline, and after the alarm location model is generated, it can be applied to real-time root cause analysis of the online virtual network.
[0054] The solution provided by the embodiment of the present application first accesses alarm or log data from the virtual network system as the historical alarm data of the virtual network, and then performs pre-processing operations such as key attribute extraction and data cleaning on the historical alarm data to improve the quality of the historical alarm data. Next, the standardized historical alarm data is input into the algorithm model for alarm correlation analysis and root cause discovery, and the analysis results are output. The analysis results may include multiple root cause rules, and then generate an association rule analysis library as an alarm location model.
[0055] After the alarm location model is generated, the alarm location model can be applied to the online virtual network. The virtual network system calls the above alarm location model to match the alarm in real time and outputs the root alarm to guide the subsequent fault handling process. If the rule corresponding to the real-time data is matched in the analysis rule library, the root cause alarm is output, and the specific data of the root cause alarm can be obtained through real-time alarm monitoring, so that the technicians can repair the abnormal network elements of the virtual network.
[0056] The solution provided by the embodiment of the present application can effectively improve the efficiency of locating the root cause alarm and avoid wasting too much manpower and time. In this solution, by analyzing the correlation and causal relationship between the types of alarms and generating an alarm location model, the accuracy of determining the root cause alarm can be effectively improved, and the root cause alarm can be located from multiple alarms in the virtual network, which is conducive to fundamentally solving multiple alarms, thereby improving the efficiency of network element abnormality repair.
[0057] Based on the solution provided in the above embodiment, optionally, Figure 2 As shown, the above step S12 includes:
[0058] S21: Generate a complete set of alarm data according to a preset duration and historical alarm data, wherein the complete set of alarm data includes a plurality of alarm data subsets obtained by dividing the historical alarm data at intervals of the preset duration.
[0059] The time length of the first preset period described above may be the preset duration described in this step. For example, the preset duration may be 5 minutes. In this step, a time window with a time length of 5 minutes can be set, and the historical alarm data is segmented by "sliding" this time window on the historical alarm data. The alarm data with timestamps within the above time window is divided into alarm data subsets, thereby obtaining multiple alarm data subsets. It should be understood that the above alarm data subsets may overlap with each other, that is, different alarm data subsets may include a part of the same historical alarm data.
[0060] S22: Determine the association relationship between type alarms according to multiple alarm data subsets in the alarm data set.
[0061] The solution provided by the embodiment of the present application divides the historical alarm data into an alarm data set with a preset duration. The alarm data subsets in the alarm data set include alarm data with close timestamps. The association relationship between type alarms is determined according to the alarm data with close trigger times, which can improve the accuracy of the determined association relationship.
[0062] Based on the solution provided by the above embodiment, optionally, as Figure 3 shown, the above step S22 includes:
[0063] S31: Determine the probability of the occurrence of the first type of alarm and the second type of alarm within the first preset period according to the ratio of the number of alarm data subsets that contain both the first type of alarm and the second type of alarm to the number of alarm data subsets in the alarm data set.
[0064] Assume that the alarm data set is U, and the alarm data set U includes type alarm A and type alarm B. For the convenience of description, the probability calculated in step S31 of the present application is hereinafter referred to as support degree. In this step, the support degree of type alarm A and type alarm B can be determined by the following formula (1-1):
[0065]
[0066] Among them, support_count(A∩B) is the subset that contains type A alarm and type B alarm, and U is the complete set. The support degree reflects the probability that alarms of types A and B occur simultaneously within the same time window. Further, if the calculated support degree meets the preset support degree rule, it is determined that there is an association relationship between type alarm A and type alarm B, and then the causal relationship between alarms of types A and B is determined in the subsequent steps and used to generate an alarm location model. For example, the preset support degree rule is greater than 80%. Then, the type alarms with a support degree greater than 80% are determined as alarms with an association relationship, and the causal relationship between the alarms with an association relationship is continued to be determined and an alarm location model is generated.
[0067] Based on the solution provided in the above embodiments, optionally, as Figure 4 shown, the above step S22 includes:
[0068] S41: Determine the probability that the first type of alarm and the second type of alarm occur successively within the second preset time period according to the ratio of the number of alarm data subsets that contain both the first type of alarm and the second type of alarm to the number of alarm data subsets that contain the first type of alarm.
[0069] For the sake of convenience of explanation, the probability calculated in step S41 of this application will be referred to as confidence below. In this step, the confidence of type alarm A and type alarm B can be determined by the following formula (1-2):
[0070]
[0071] Where support_count(A) is a subset that contains only A or both type A alarms and type B alarms. The confidence reflects the probability that type B alarms occur when type A alarms occur. Further, if the calculated confidence meets the preset confidence rule, it is determined that there is an association relationship between type alarm A and type alarm B, and then the causal relationship between type A and type B alarms is determined in the subsequent steps and used to generate an alarm location model. For example, if the preset confidence rule is greater than 80%, then the type alarms with a confidence greater than 80% are determined as alarms with an association relationship, and the causal relationship between the alarms with an association relationship is continued to be determined and an alarm location model is generated.
[0072] Further, the association relationship between type alarms can also be determined by combining the above confidence and support degree, that is, when the preset confidence rule is satisfied and the preset support degree rule is satisfied, it is determined that there is an association relationship between type alarms.
[0073] Through the solution provided by the embodiments of this application, the association relationship between type alarms can be determined through confidence or support degree, and this association relationship can characterize which type alarms are related, and then be used to improve the accuracy of determining the causal relationship in the subsequent step of determining the causal relationship.
[0074] Based on the solution provided in the above embodiments, optionally, as Figure 5 shown, the above step S13 includes:
[0075] S51: If the probability that the first type of alarm and the second type of alarm occur within the first preset time period is greater than the first preset probability, or the probability that the first type of alarm and the second type of alarm occur successively within the second preset time period is greater than the second preset probability, then it is determined that the first type of alarm and the second type of alarm are associated.
[0076] Specifically, the above-mentioned first preset probability may be the preset support degree in the preset support degree rule, and the above-mentioned second preset probability may be the preset confidence degree in the preset confidence degree rule. If the support degree of the first type of alarm and the second type of alarm is greater than the preset support degree (for example, 80%), or the confidence degree of the first type of alarm and the second type of alarm is greater than the preset confidence degree (for example, 80%), it can be determined that there is a correlation between the first type of alarm and the second type of alarm.
[0077] The associated type alarms in this step can be presented in tabular form. The table may include parameters characterizing the correlation between type alarms, as shown in the following table:
[0078] Alarm A - NE Name Alarm A - Alarm Title Alarm B - NE Name Alarm B - Alarm Title Number of Times When Alarms A and B Occur Together Number of Times Alarm A Occurs Probability of Alarm B Occurring after Alarm A NJAMF02AZX Abnormal Alarm of Virtual Machine Detection Agent NJAMF02AZX Module Abnormal Alarm 15231 17843 85 NJNRF02AZX Abnormal Alarm of Virtual Machine Detection Agent NJNRF02AZX Module Abnormal Alarm 10322 14409 71 NJUDMAUSF03AZX BFD Session Down NJAMF02AZX SCCU and SC TIPC Link Down 4462 8730 51 NJSMF4AHW PFCP Link Failure NJSMF4AHW PFCP Peer Node Unreachable 170 233 72 NJAMF2AHW NG-RAN Link Failure NJAMF2AHW NG-RAN Node Unreachable 155 184 84 NJAMF4AHW NG-RAN Link Failure NJAMF4AHW NG-RAN Node Unreachable 145 186 77 NJAMF02AZX Interface Layer 2 Protocol State Down NJAMF02AZX Interface IPv4 Protocol State Down 80 88 90 NJAMF03AZX NGAP Received Couple Disconnection Indication NJAMF02AZX SCCU and SC TIPC Link Down 68 109 62
[0079] S52: Determine the causal relationship between type alarms according to the occurrence time of the associated type alarms.
[0080] In this step, the occurrence time of the above-mentioned type alarm can be determined according to the time stamp that triggers the type alarm.
[0081] Through the solution provided by the embodiments of the present application, it is possible to determine which type alarms are correlated, and further determine the causal relationship between the correlated type alarms. There is no need to further analyze the type alarms that are not correlated, which can effectively reduce the data processing load and improve the accuracy of determining the causal relationship.
[0082] Based on the solution provided by the above embodiments, optionally, as Figure 6a shown, determining the causal relationship between type alarms according to the occurrence time of the associated type alarms includes:
[0083] S61: Generate a Markov chain P(X n+1 =x|X1, X2,..., X n ) = P(X n+1 =x|X n ), where n is a positive integer, n represents the order of occurrence of alarms based on time, and X1, X2,..., X n , X n+1 represent the associated type alarms;
[0084] S62: Determine the causal relationship between type alarms according to the Markov chain. The causal relationship includes the probability of the second type of alarm occurring after the first type of alarm occurs.
[0085] In the embodiments provided by the present application, the triggered alarms and the historical process of the logs are used as time series samples for model modeling, and time series algorithms are used for modeling to analyze the causal relationship between alarm events. Among them, different alarms represent different states of network element devices. The change of state can be called a transition, and the probability associated with different state changes can be called a transition probability.
[0086] For example: To study what alarms a certain network element will have in the future, if the alarm state at the current moment is known, then the alarm state at a future moment has nothing to do with the alarm state at any moment before the current moment.
[0087] A Markov chain is a sequence of random variables X1, X2, X3…, X n . The range of these variables, that is, the set of all possible values they can take, can be called the "state space", and the value of X n is the state at time n. If the conditional probability distribution of X n+1 for the past state depends only on X n , it can be expressed as the following formula (2-1):
[0088] P(X n+1 =x|X1, X2,…, X n ) = P(X n+1 =x|X n ) (2-1)
[0089] Here, x is a certain state in the process, which refers to a specific alarm in the analysis of alarm root causes. The value of n in formula (2-1) can be freely set in the analysis of alarm root causes. For example, if the value is 3, it means that the current alarm is only related to the previous 3 alarms. The above identity (2-1) can be regarded as the Markov property.
[0090] A Markov chain is a stochastic process that satisfies the following two assumptions:
[0091] (1) The probability distribution of the system state at time t + l depends only on the state at time t and is independent of the state before time t. In the embodiments of the present application, t takes the value of 3.
[0092] (2) The state transition from time t to time t + l is independent of the value of t. A Markov chain model can be represented as (S, P, Q).
[0093] Among them, S is a non-empty set of states composed of all possible states of the system. Sometimes it is also called the state space of the system. It can be a finite, countable set or any non-empty set. In the embodiments of the present application, it is assumed that S is a countable set (that is, finite or countable). For the convenience of explanation, lowercase letters i, j (or Si, Sj, etc.) are used to represent states.
[0094] P = [P ij is the state transition probability matrix of the system, where P ij represents the probability that the system is in state i at time t and in state j at the next time t + 1. N is the number of all possible states of the system. For any i ∈ s, there is
[0095] Q = [q1, q2…q n is the initial probability distribution of the system, and q i is the probability that the system is in state i at the initial time, satisfying
[0096] The solution provided by the embodiments of the present application makes up for the deficiency of difficult discovery of root cause relationships in the communication field based on time series algorithms. Through the solution provided by the embodiments of the present application, the root cause relationship can be output. Among them, the transition probability of the Markov chain algorithm fully considers the sequence of occurrence of alarms, and an analysis model is established based on time series. Moreover, the root cause rules of alarms are weighted and calculated based on the time distance between the occurrences of alarms, and the generated alarm location model can accurately describe the strength of the root cause rules. In addition, the number of times each alarm participates in the calculation in this solution is only related to the order of the Markov chain, improving the engineering calculation performance.
[0097] Through the solution provided by the embodiments of the present application, the alarm information of the network element set where the fault occurs can be efficiently and intuitively located. For example, the result output by the alarm location model can be as Figure 6b shown, where the output result can specifically include the root cause alarm network element, the alarm name, and the association relationship.
[0098] Based on the solution provided by the above embodiments, optionally, as Figure 7 shown, after the above step S13, the following further includes:
[0099] S71: Update the network element topology relationship of the virtual network according to the association relationship between the type alarms;
[0100] Among them, the above step S14 includes:
[0101] S72: Generate an alarm location model according to the causal relationship between the type alarms and the updated network element topology relationship of the virtual network.
[0102] In the communication field, if the network element topology relationship is manually maintained, there are often delays and errors. In the process of continuous addition, deletion, and update of network elements, due to the lag of resource update and the instability of manual maintenance, the resource topology will deteriorate. This solution updates the network element topology relationship according to the causal relationship, ensuring the real-time accuracy of the network element topology relationship and also improving the accuracy of locating the root cause of faults in the subsequent steps.
[0103] Through the solution provided by the embodiments of the present application, the topological relationship between related network elements can be further automatically supplemented and drawn according to the association relationship between type alarms.
[0104] For example, the 5G resource model can be divided into three layers, namely the VNF (Virtualized Network Function) layer, the VIM (Visual editor improved) layer, and the PIM (Platform Independent Model) layer. These three types of resources in the acquisition environment are parsed to draw a three-layer topology diagram, presenting the VNF, VM, physical resources, and three-layer associated topology. When the resources in the VIM layer and the PIM layer are not updated in a timely manner or there are resource errors, the topological connection relationship is missing, which will cause the topology between network element A in the VIM layer and network element B in the PIM layer to be disconnected.
[0105] Through the association relationship determined in the solution provided by the embodiments of the present application, the information of network element A in the VIM layer can be found, and the association relationship between network elements can be determined according to the association relationship between the type alarms of the network elements represented by the association relationship, so as to supplement the topological information of the network elements in the VIM layer and the PIM layer and repair the topological resources.
[0106] Through the solution provided by the embodiments of the present application, an alarm location model can be automatically generated according to historical alarm data to efficiently and automatically identify the root cause alarms in the virtual network. Moreover, the association relationship and causal relationship in this embodiment can also be used to intelligently expand topological resources and realize automatic update of topological relationships. The solution provided by the embodiments of the present application has the advantages of high efficiency, accuracy, and high automation. In addition, through historical alarm data preprocessing, feature engineering, and technologies based on data mining and artificial intelligence, the root cause of the fault is intelligently mined, and an alarm location model is generated more effectively. The alarm location model can match the root cause of the fault in real time according to the input virtual network data.
[0107] To solve the problems existing in the prior art, the embodiments of the present application further provide a generating device 80 for an alarm root cause location model, as Figure 8 shown, including:
[0108] An obtaining module 81, which obtains the historical alarm data of the virtual network and the network element topology relationship of the virtual network. The historical alarm data includes the type of alarm triggered by the network element in the virtual network in the abnormal state and the time stamp when the alarm is triggered;
[0109] A first determining module 82, which determines the association relationship between type alarms according to the historical alarm data. Among them, the association relationship between the first type alarm and the second type alarm represents the probability that the first type alarm and the second type alarm occur within the first preset time period and / or the probability that the first type alarm and the second type alarm occur successively within the second preset time period;
[0110] A second determination module 83 determines the causal relationship between type alarms according to the association relationship between type alarms;
[0111] A generation module 84 generates an alarm location model according to the causal relationship between type alarms and the network element topology relationship of the virtual network. The alarm location model includes the causal relationship between type alarms occurring at each network element in the virtual network, and the alarm location model is used to locate the root cause alarm in at least one target alarm according to the data of at least one target alarm occurring in the virtual network.
[0112] The device provided by the embodiment of the present application obtains the historical alarm data of the virtual network and the network element topology relationship of the virtual network. The historical alarm data includes the type of alarm triggered by the network element in the virtual network in the abnormal state and the time stamp when the alarm is triggered; determines the association relationship between type alarms according to the historical alarm data, where the association relationship between the first type alarm and the second type alarm represents the probability of the first type alarm and the second type alarm occurring within the first preset period and / or the probability of the first type alarm and the second type alarm occurring successively within the second preset period; determines the causal relationship between type alarms according to the association relationship between type alarms; generates an alarm location model according to the causal relationship between type alarms and the network element topology relationship of the virtual network. The alarm location model includes the causal relationship between type alarms occurring at each network element in the virtual network, and the alarm location model is used to locate the root cause alarm in at least one target alarm according to the data of at least one target alarm occurring in the virtual network. The solution of the embodiment of the present invention can efficiently determine the association between various types of alarms, and the generated alarm location model can determine the root cause alarm according to the alarm data, which is beneficial to quickly eliminate virtual network faults.
[0113] Preferably, the embodiment of the present invention also provides an electronic device, including a processor, a memory, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, it implements each process of the above-mentioned embodiment of the method for generating an alarm root cause location model, and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0114] The embodiment of the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by the processor, it implements each process of the above-mentioned embodiment of the method for generating an alarm root cause location model, and can achieve the same technical effect. To avoid repetition, it will not be elaborated here. Among them, the computer-readable storage medium, such as a read-only memory (ROM for short), a random access memory (RAM for short), a magnetic disk or an optical disc, etc.
[0115] It should be noted that in this article, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent in such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including such element.
[0116] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions for causing a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods of the various embodiments of the present invention.
[0117] The embodiments of the present invention have been described above in conjunction with the accompanying drawings. However, the present invention is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present invention, those of ordinary skill in the art can also make many forms without departing from the spirit and scope protected by the claims of the present invention, and all of them belong to the protection scope of the present invention.
Claims
1. A method for generating an alarm root cause location model, characterized in that include: Obtaining historical alarm data of the virtual network and the network element topology relationship of the virtual network, the historical alarm data including the type of alarm triggered by the network element in the virtual network in an abnormal state and the timestamp of the alarm triggering; Determine the correlation between the types of alarms according to the historical alarm data, wherein the correlation between the first type of alarm and the second type of alarm represents the probability of the first type of alarm and the second type of alarm occurring within a first preset time period and / or the probability of the first type of alarm and the second type of alarm occurring successively within a second preset time period; Determine the causal relationship between type alarms based on the correlation between type alarms; An alarm location model is generated based on the causal relationship between type alarms and the network element topology relationship of the virtual network. The alarm location model includes the causal relationship between type alarms occurring at each network element in the virtual network. The alarm location model is used to locate the root cause alarm in at least one target alarm based on the data of at least one target alarm occurring in the virtual network, wherein the alarm location model includes an analysis rule base, wherein the analysis rule base stores multiple root cause rules, and any one of the root cause rules includes multiple type alarms with associated relationships and root cause alarms among the type alarms with associated relationships.
2. The method according to claim 1, wherein Determine the correlation between different alarm types based on historical alarm data, including: Generate a full set of alarm data according to a preset duration and historical alarm data, wherein the full set of alarm data includes a plurality of alarm data subsets obtained by dividing the historical alarm data at intervals of the preset duration; The association relationship between the types of alarms is determined according to multiple alarm data subsets in the full alarm data set.
3. The method according to claim 2, characterized in that, Determine the association between types of alarms based on multiple alarm data subsets in the full alarm data set, including: The probability of the first type of alarm and the second type of alarm occurring within the first preset time period is determined according to the ratio of the number of alarm data subsets containing both the first type of alarm and the second type of alarm to the number of alarm data subsets in the entire alarm data set.
4. The method according to claim 2, wherein Determine the association between types of alarms based on multiple alarm data subsets in the full alarm data set, including: The probability of the first type of alarm and the second type of alarm occurring successively within the second preset time period is determined according to the ratio of the number of alarm data subsets containing both the first type of alarm and the second type of alarm to the number of alarm data subsets containing the first type of alarm.
5. The method according to claim 3 or 4, characterized in that, The causal relationship between type alarms is determined based on the association relationship between type alarms, including: If the probability that the first type of alarm and the second type of alarm occur within the first preset time period is greater than the first preset probability, or the probability that the first type of alarm and the second type of alarm occur successively within the second preset time period is greater than the second preset probability, then it is determined that the first type of alarm is associated with the second type of alarm; The causal relationship between the type alarms is determined according to the occurrence time of the associated type alarms.
6. The method according to claim 5, characterized in that, The causal relationship between the type alarms is determined based on the occurrence time of the associated type alarms, including: Generate a Markov chain P(X n+1 = x|X1, X2, …, X n ) = P(X n+1 = x|X n ), where n is a positive integer, n represents the order of occurrence of the alarm based on time, and X1, X2, …, X n , X n+1 represent the associated type of alarm; The causal relationship between the types of alarms is determined according to the Markov chain, and the causal relationship includes the probability of the second type of alarm occurring after the first type of alarm occurs.
7. The method according to claim 6, wherein After determining the causal relationship between type alarms according to the association relationship between type alarms, it further includes: Updating the network element topology relationship of the virtual network according to the association relationship between type alarms; Among them, generating an alarm location model according to the causal relationship between type alarms and the network element topology relationship of the virtual network includes: Generating an alarm location model according to the causal relationship between type alarms and the updated network element topology relationship of the virtual network.
8. An apparatus for generating an alarm root cause location model, characterized in that, It includes: An acquisition module that acquires the historical alarm data of the virtual network and the network element topology relationship of the virtual network. The historical alarm data includes the types of alarms triggered by network elements in the virtual network in an abnormal state and the timestamps of the triggered alarms; A first determination module that determines the association relationship between type alarms according to the historical alarm data. Among them, the association relationship between the first type alarm and the second type alarm represents the probability of occurrence of the first type alarm and the second type alarm within the first preset time period and / or the probability of the first type alarm and the second type alarm occurring successively within the second preset time period; A second determination module that determines the causal relationship between type alarms according to the association relationship between type alarms; A generation module that generates an alarm location model according to the causal relationship between type alarms and the network element topology relationship of the virtual network. The alarm location model includes the causal relationship between type alarms occurring at each network element in the virtual network. The alarm location model is used to locate the root cause alarm in at least one target alarm according to the data of at least one target alarm that occurs in the virtual network. Among them, the alarm location model includes an analysis rule library, and multiple root cause rules are stored in the analysis rule library. Any one of the root cause rules includes multiple type alarms with an association relationship and the root cause alarm among the type alarms with an association relationship.
9. An electronic device, characterized in that, It includes: A memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, A computer program is stored on a computer-readable storage medium. When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Network alarm analysis model creation method, alarm analysis method and device
CN111125268A
System fault root cause positioning method and device, storage medium and electronic device
CN113254254A