Hidden danger mining method and device, equipment and storage medium
By acquiring multi-dimensional operation and maintenance data for data fusion and anomaly detection, the problem of low efficiency in manual sorting in existing technologies has been solved, realizing automated network vulnerability investigation and discovery, improving efficiency and avoiding resource waste.
Patent Information
- Application Number
- CN202111230382.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-21
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2041-10-21
AI Technical Summary
The current method of identifying network vulnerabilities mainly relies on manual screening, resulting in a small number of isolated cases, significant delays, excessive resource waste, and low efficiency.
Acquire multi-dimensional operational and maintenance vulnerability data, including equipment alarm data, performance index data, fault work order data, and customer complaint data, perform data fusion processing, generate feature matrices of different granularity slices, and identify vulnerable network elements through anomaly detection.
It has achieved comprehensive automated troubleshooting, avoiding resource waste, improving the efficiency of network troubleshooting and discovery, and enabling early detection of major/important faults.
Smart Images

Figure CN116010473B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication and computer technology, and in particular to a method, apparatus, device and storage medium for identifying potential hazards. Background Technology
[0002] With the widespread development of mobile networks, identifying or uncovering network vulnerabilities before major / critical failures is an urgent issue.
[0003] Currently, potential hazards are primarily identified through manual review, which includes the following two aspects: 1) Based on the handling of recent major / significant failures, manually review whether similar hazards still exist. For example, if a certain software version of a device has a bug, the software version of all similar devices needs to be upgraded simultaneously. 2) Manually verify the operational status of each type of device and its backup network elements.
[0004] Relying on manual screening and discovery of potential risks results in a small number of risks being discovered, which are often of limited variety. This leads to significant delays and resource waste, meaning that current methods for identifying and uncovering network vulnerabilities suffer from inefficiency. Summary of the Invention
[0005] The main purpose of this application is to provide a method, apparatus, equipment and storage medium for identifying potential network vulnerabilities, aiming to solve the technical problem of low efficiency in the existing network vulnerability investigation or discovery.
[0006] To achieve the above objectives, this application provides a method for identifying potential hazards, the method comprising:
[0007] Obtain multi-dimensional operational and maintenance potential data, wherein the multi-dimensional operational and maintenance potential data includes at least several items from equipment alarm data, performance indicator data, fault work order data, and customer complaint data;
[0008] The operation and maintenance risk data are fused to obtain feature matrices of slices with different granularities;
[0009] Anomaly detection is performed on the feature matrices of the slices at different granularities to obtain the network elements with potential operational risks pointed to by the operational risk data.
[0010] Optionally, before the step of performing data fusion processing on the maintenance vulnerability data to obtain feature matrices of different granularity slices, the method includes:
[0011] Extract one or more of the following from the device alarm data: alarm data of the first quantity type, alarm data of the first duration type, alarm data of the second duration type, and alarm data of the first frequency type;
[0012] And / or extract one or more of the following from the performance index data: risk index type data, index anomaly threshold data, and index rule parameter data;
[0013] And / or extract one or more of the following from the fault work order data: second frequency type work order data, third duration type work order data, and second quantity type work order data;
[0014] And / or extract one or more of the third frequency type complaint data and the fourth duration type complaint data from the customer complaint data.
[0015] Optionally, the maintenance vulnerability data includes equipment alarm data and performance indicator data, wherein the equipment alarm data is used for vulnerability mining at the network element granularity and / or alarm title granularity.
[0016] The step of performing data fusion processing on the maintenance vulnerability data to obtain feature matrices of different granularity slices includes:
[0017] According to the network element granularity and the alarm title granularity, the first active alarm quantity and the other second active alarm quantity in other second slice times are extracted from the device alarm data, respectively. The other second slice times can be multiple times.
[0018] A first alarm quantity matrix is generated based on the first active alarm quantity, and a second alarm quantity matrix is generated based on the second active alarm quantity.
[0019] The first alarm quantity matrix and the second alarm quantity matrix are further grouped by network element type to obtain the data of each group. Based on the group data under each network element type group and the performance index data, a first performance index matrix and a second performance index matrix are generated.
[0020] By concatenating the first alarm quantity matrix and the first performance index matrix, the first slice feature matrix is obtained;
[0021] By concatenating the second alarm quantity matrix and the second performance index matrix, a second slice feature matrix is obtained.
[0022] Optionally, the step of concatenating the first alarm quantity matrix and the first performance index matrix to obtain the first time feature matrix includes:
[0023] Extract alarm data of the first quantity type, alarm data of the first duration type, alarm data of the second duration type, and alarm data of the first frequency type from the device alarm data;
[0024] Determine the percentages of the first quantity type alarm data, the first duration type alarm data, the second duration type alarm data, and the first frequency type alarm data relative to the corresponding anomaly indicators of all network elements of the same network element type;
[0025] Based on the percentage, a first reference feature matrix is determined;
[0026] The first reference feature matrix, the first alarm quantity matrix, and the first performance index matrix are concatenated to obtain the first slice feature matrix.
[0027] Optionally, the step of concatenating the first reference feature matrix, the first alarm quantity matrix, and the first performance index matrix to obtain the first slice feature matrix includes:
[0028] Extract second frequency type work order data, third duration type work order data, and second quantity type work order data from the fault work order data;
[0029] Based on the second frequency type work order data, the third duration type work order data, and the second quantity type work order data, determine the second reference feature matrix within a preset time period before the first slice time.
[0030] The first reference feature matrix, the second reference feature matrix, the first alarm quantity matrix, and the first performance index matrix are concatenated to obtain the first slice feature matrix.
[0031] Optionally, the step of performing anomaly detection on the feature matrices of the different granularity slices to obtain the hidden network elements pointed to by the operation and maintenance hidden danger data includes:
[0032] By utilizing multiple integrated preset machine learning anomaly detection algorithms, anomaly detection is performed on the feature matrices of the slices at different granularities, and the abnormal network elements and their time locations are output according to a voting mechanism.
[0033] And / or determine the first mining network element corresponding to the device alarm data;
[0034] And / or determine the second mining network element corresponding to the performance index data;
[0035] And / or determine the third mining network element corresponding to the fault work order data;
[0036] And / or determine the fourth mining network element corresponding to each of the customer complaint data;
[0037] Based on the abnormal network element under the same date, the time location, and the abnormal confidence interval of different slice granularities, and / or the first mining network element, and / or the second mining network element, and / or the third mining network element, and / or the fourth mining network element, the hidden network element pointed to by the operation and maintenance hidden danger data is determined.
[0038] Optionally, after the step of performing anomaly detection on the feature matrices of the different granularity slices to obtain the hidden network elements pointed to by the operation and maintenance hidden danger data, the method includes:
[0039] Based on the hidden danger network element and the device alarm data, determine the alarm title whose anomaly ranking is within a preset range;
[0040] Determine the number of first title alarms in the first slice time and other second slice time periods, and determine the number of second title alarms corresponding to the alarm title in the device alarm data;
[0041] Based on the alarm volume of the first title and the alarm volume of the second title, determine the associated alarm information.
[0042] This application also provides a hazard excavation device, the hazard excavation device comprising:
[0043] The acquisition module is used to acquire multi-dimensional operation and maintenance potential data, wherein the multi-dimensional operation and maintenance potential data includes at least several items from equipment alarm data, performance index data, fault work order data, and customer complaint data.
[0044] The fusion module is used to perform data fusion processing on the operation and maintenance hidden danger data to obtain feature matrices of slices with different granularities;
[0045] The detection module is used to perform anomaly detection on the feature matrix of the slices at different granularities to obtain the network elements with hidden dangers pointed to by the operation and maintenance hidden danger data.
[0046] This application also provides a hidden danger discovery device, which is a physical node device. The hidden danger discovery device includes: a memory, a processor, and a program of the hidden danger discovery method stored in the memory and executable on the processor. When the program of the hidden danger discovery method is executed by the processor, it can implement the steps of the hidden danger discovery method as described above.
[0047] This application also provides a storage medium storing a program that implements the above-described hazard discovery method. When the program is executed by a processor, it implements the steps of the hazard discovery method as described above.
[0048] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the aforementioned hidden danger discovery method.
[0049] This application provides a method, apparatus, device, and storage medium for identifying potential network vulnerabilities. Compared to existing methods that rely on manual sorting, resulting in a small and limited number of vulnerabilities discovered, significant delays, and substantial resource waste, leading to low efficiency in network vulnerability investigation or discovery, this application acquires multi-dimensional operational vulnerability data. This multi-dimensional operational vulnerability data includes at least several items from equipment alarm data, performance indicator data, fault work order data, and customer complaint data. The operational vulnerability data is then fused to obtain feature matrices of different granularities. Anomaly detection is performed on the feature matrices of the different granularities to obtain the network elements with vulnerabilities identified by the operational vulnerability data. This application comprehensively utilizes and automatically acquires multi-dimensional operational and maintenance (O&M) vulnerability data, including multiple data sources such as equipment alarm data, performance indicator data, fault work order data, and customer complaint data. It then automatically performs data fusion processing on this O&M vulnerability data to obtain feature matrices of different granularities, enabling comprehensive and automatic anomaly detection and identifying the vulnerable network elements pointed to by the O&M vulnerability data. It can be understood that this application prioritizes comprehensive investigation of network vulnerabilities before major / important faults, avoiding situations where the number of vulnerabilities discovered is small and singular. Furthermore, this application employs automatic investigation rather than manual investigation, thus avoiding investigation delays and resource waste, and improving the efficiency of network vulnerability investigation or discovery. Attached Figure Description
[0050] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0051] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0052] Figure 1 This is a flowchart illustrating the first embodiment of the hazard discovery method of this application;
[0053] Figure 2 This is a flowchart illustrating the process prior to step S20 in the hazard identification method of this application.
[0054] Figure 3 This is a schematic diagram of the device structure of the hardware operating environment involved in the embodiments of this application.
[0055] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0056] It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit this application.
[0057] This application provides a method for identifying potential hazards. In the first embodiment of this method, refer to... Figure 1 The method for identifying potential hazards includes:
[0058] Step S10: Obtain multi-dimensional operation and maintenance potential data, wherein the multi-dimensional operation and maintenance potential data includes at least several items from equipment alarm data, performance index data, fault work order data, and customer complaint data.
[0059] Step S20: Perform data fusion processing on the operation and maintenance hidden danger data to obtain feature matrices of slices with different granularities;
[0060] Step S30: Perform anomaly detection on the feature matrices of the slices at different granularities to obtain the network elements with hidden dangers pointed to by the operation and maintenance hidden danger data.
[0061] The specific steps are as follows:
[0062] Step S10: Obtain multi-dimensional operation and maintenance potential data, wherein the multi-dimensional operation and maintenance potential data includes at least several items from equipment alarm data, performance index data, fault work order data, and customer complaint data.
[0063] In this embodiment, it should be noted that the hazard excavation method can be applied to a hazard excavation device, which belongs to a hazard excavation system, and the hazard excavation system is subordinate to hazard excavation equipment.
[0064] In this embodiment, the hidden danger mining is based on the operation and maintenance hidden danger data, which includes data under different dimensions. The specific different dimensions can be obtained by setting the hidden danger mining system, or the specific different dimensions can be fixed or determined.
[0065] In this embodiment, the sources of the maintenance vulnerability data include:
[0066] Source 1: Data on potential maintenance risks proactively reported by various devices;
[0067] Source 2: Data on potential operational and maintenance risks collected manually;
[0068] Source 3: After setting up the hidden danger, it triggers the reporting of operation and maintenance hidden danger data from various devices.
[0069] In this embodiment, the multi-dimensional operation and maintenance risk data includes at least several of the following: equipment alarm data, performance index data, fault work order data, and customer complaint data.
[0070] Specifically, the multi-dimensional operation and maintenance risk data includes at least two of the following: equipment alarm data, performance indicator data, fault work order data, and customer complaint data.
[0071] In this embodiment, potential hazards are identified based on multi-dimensional operational hazard data, rather than on single-dimensional operational hazard data. Therefore, a comprehensive hazard identification process can be conducted, improving the efficiency of hazard investigation.
[0072] In this embodiment, the multi-dimensional operation and maintenance vulnerability data includes at least software vulnerability data and hardware vulnerability data.
[0073] Because vulnerability discovery is based on both software and hardware vulnerability data, it improves the efficiency of vulnerability identification by exploring vulnerabilities from both hardware and software perspectives.
[0074] In this embodiment, for each dimension of data, such as device alarm data, performance index data, fault work order data, and customer complaint data, at least the different subdivisions are included.
[0075] Specifically, for the device alarm data dimension, it includes at least one or more of the following: first quantity type alarm data (excessive alarm data), first duration type alarm data (excessively long alarm data), second duration type alarm data (excessively short alarm data), and first frequency type alarm data (high-frequency alarm data);
[0076] For performance indicator data, it should include at least one or more of the following: risk indicator type data (indicators representing network risks), indicator anomaly threshold data, and indicator rule parameter data.
[0077] For fault work order data, it includes at least one or more of the following: second frequency type work order data (high frequency work order data), third duration type work order data (extra long work order data), and second quantity type work order data (excessive quantity work order data);
[0078] For customer complaint data, it should include at least one or more of the following: third frequency type complaint data (high-frequency complaint data) and fourth duration type complaint data (overtime complaint data).
[0079] Step S20: Perform data fusion processing on the operation and maintenance hidden danger data to obtain feature matrices of slices with different granularities;
[0080] In this embodiment, after obtaining the operational and maintenance risk data in various dimensions, the operational and maintenance risk data in each dimension are normalized and then fused to obtain feature matrices of different granularity slices.
[0081] The data fusion processing of the aforementioned operational and maintenance vulnerability data yields feature matrices of different granularity slices, including:
[0082] The operation and maintenance hidden danger data is vectorized and normalized in each dimension. Then, the data is fused to obtain feature matrices of different granularity slices.
[0083] The operation and maintenance risk data is subjected to matrix transformation processing, and the operation and maintenance risk data of each dimension is normalized. Then, the data is fused to obtain feature matrices of different granularity slices.
[0084] Among them, reference Figure 2 Before the step of performing data fusion processing on the maintenance vulnerability data to obtain feature matrices of different granularity slices, the method includes:
[0085] Step S01: Extract one or more of the following from the device alarm data: alarm data of the first quantity type, alarm data of the first duration type, alarm data of the second duration type, and alarm data of the first frequency type.
[0086] In this embodiment, one or more of the following are extracted from the device alarm data: first quantity type alarm data (excessive alarm data), first duration type alarm data (excessively long alarm data), second duration type alarm data (excessively short alarm data), and first frequency type alarm data (high-frequency alarm data), i.e., potential hazards are identified based on the device alarm data.
[0087] The specific details of identifying potential hazards based on equipment alarm data are as follows:
[0088] First, extract the alarm data reported by the device according to the parameters in Table 1. Specifically, the "Is it an engineering project" field indicates whether the alarm is caused by network engineering commissioning. After excluding engineering alarm data from the reported alarm data based on this field, the device alarm data is obtained.
[0089]
[0090] Table 1
[0091] After obtaining the device alarm data, the alarm data is statistically analyzed according to the following four formats.
[0092] Before compiling alarm data according to the following four formats, first run the corresponding potentially problematic device. After running, mark the items that meet the abnormal conditions as abnormal items according to the default parameters (alarm default parameters). Determine whether the proportion of network elements included in the abnormal items is within the preset threshold P1% (e.g., within 5%) of the total number of such network elements in the entire network. If it is not within the preset threshold P1%, adjust (increase / decrease) the default parameters of each network element type and run again until the proportion of network elements included in each type of output abnormal item is within the preset threshold P1% (e.g., 5%) of the total number of such network elements in the entire network.
[0093] In this embodiment, the requirement that the percentage of network elements included in each type of output anomaly item be within a preset threshold P1% (e.g., 5%) of the total number of network elements of that type in the entire network is intended to avoid low alarm efficiency caused by excessive alarms and excessive resource waste.
[0094] Specifically, alarm data is compiled according to the following four formats:
[0095] First type of format: First quantity type of alarm data (excessive alarm data), the number of alarms per day in a single network exceeds M1, or the number of alarms per month in a single network exceeds N1;
[0096] For different specialties and network element types, different M1 and N1 can be set. The default settings are M1 = the average daily alarm volume of the specialty and network element type in the past month * 3, and N1 = the average monthly alarm volume of the specialty and network element type in the past six months * 3.
[0097] In this embodiment, the granularity for hazard mining of the first quantity type of alarm data is: network element.
[0098] Output examples are shown in Table 2:
[0099] major province Equipment manufacturers Network element types Network element name date Alarm quantity
[0100] Table 2
[0101] The second type of format is alarm data of the first duration type (excessive alarm data). Among them, level 1 alarms lasting more than X1 hours, level 2 alarms lasting more than Y1 hours, and level 3 alarms lasting more than Z1 hours are considered excessive alarms. The duration is equal to the alarm clearing time minus the alarm occurrence time.
[0102] Condition description: Different durations can be set for different professions, network element types, and alarm levels. The default settings are X1=4, Y1=24, and Z1=120.
[0103] In this embodiment, the granularity for hazard discovery of alarm data of the first duration type is: network element + alarm title.
[0104] Output examples are shown in Table 3:
[0105]
[0106] Table 3
[0107] The third type of format, the second duration type of alarm data (ultra-short alarm data), is alarms with a duration of less than X2 minutes, where the duration = alarm clearing time - alarm occurrence time;
[0108] Condition description: Different durations can be set for different professions, network element types, and alarm levels. The default setting is X2=1.
[0109] In this embodiment, the granularity for identifying potential hazards in the second duration type alarm data is: network element + alarm title.
[0110] Output examples are shown in Table 4:
[0111]
[0112] Table 4
[0113] The fourth format, the first frequency type of alarm data (high-frequency alarm data), is when a single network element reports the same alarm more than X3 times per day.
[0114] Condition description: Different alarm counts can be set for different specialties, network element types, and alarm levels. The default setting is X3 = 20.
[0115] The granularity of the first frequency type alarm data (high-frequency alarm data) is: network element + alarm title.
[0116] Output examples are shown in Table 5:
[0117]
[0118] Table 5
[0119] In this embodiment, after statistically analyzing alarm data according to the above four formats, a list of the top P1% of network elements for each type of anomaly (anomalies in alarm data for each format) is output.
[0120] Step S02, and / or extract one or more of the following from the performance index data: risk index type data, index anomaly threshold data, and index rule parameter data;
[0121] In this embodiment, the content of hidden danger discovery based on performance index data is as follows:
[0122] Extract one or more of the following from the performance index data: risk index type data, index anomaly threshold data, and index rule parameter data.
[0123] Specifically, 1) the collected performance index data are classified according to network element type, and a mapping relationship between network element type and performance index is established, as shown in Table 6.
[0124]
[0125] Table 6
[0126] 2) Set the threshold for anomaly detection and the rule parameters N2 and M2 for hidden danger detection for each type of indicator, as shown in Table 7.
[0127]
[0128] Table 7
[0129] From 404 network performance metrics across various disciplines (wireless network, core network, etc.), 86 metrics that can characterize network risks were selected. Mining rules were set based on dimensions such as degradation, capacity, and network topology. If a rule is triggered for M3 days out of N3 days, a corresponding vulnerability is generated. The default settings are N3=7 and M3=3. Typical mined metrics are shown in Table 8.
[0130]
[0131] Table 8
[0132] Step S03, and / or extract one or more of the following from the fault work order data: second frequency type work order data, third duration type work order data, and second quantity type work order data;
[0133] In this embodiment, the content of hazard discovery based on fault work order data is as follows:
[0134] After obtaining the fault work order data, the fault work order data is statistically analyzed according to the following three formats.
[0135] Before compiling fault work order data according to the following three formats, first run the corresponding potentially problematic equipment. After running, mark the items that meet the abnormal conditions as abnormal items according to the default parameters (work order default parameters). Determine whether the proportion of network elements included in the abnormal items is within the preset threshold P2% (e.g., within 6%) of the total number of such network elements in the entire network. If it is not within the preset threshold P2%, adjust (increase / decrease) the default parameters of each network element type and run again until the proportion of network elements included in each type of output abnormal item is within the preset threshold P2% (e.g., 6%) of the total number of such network elements in the entire network.
[0136] In this embodiment, P1 can be the same as or different from P2.
[0137] Second frequency type of work order data (high frequency work order data): The number of work orders dispatched per network element per week exceeds X4 times;
[0138] Description of the first type of format: Different number of dispatches can be set for different specialties and different network element types. The default setting is X4=50.
[0139] The second frequency type of work order data has the following granularity: network element + work order title + fault category.
[0140] Output examples are shown in Table 9:
[0141]
[0142] Table 9
[0143] The third type of work order data (extremely long work order data): Level 1 response work orders lasting more than X5 hours, Level 2 response work orders lasting more than Y2 hours, and Level 3 response work orders lasting more than Z2 hours are considered extremely long work orders. The duration is equal to the alarm clearing time minus the alarm occurrence time.
[0144] Description of the conditions for the third duration type of work order data (extremely long work order data): Different durations can be set for different professions, different network element types, and different response levels. The default settings are X5=4, Y2=48, Z2=120.
[0145] The granularity of potential hazards in the third-length type of work order data (extremely long work order data) is: network element + work order title + fault category.
[0146] Output examples are shown in Table 10:
[0147]
[0148] Table 10
[0149] Second type of work order data (excessive work order data): The number of work orders dispatched per day in a single network exceeds X6, or the number of work orders dispatched per week in a single network exceeds Y3, or the number of work orders dispatched per month in a single network exceeds Z3.
[0150] The variables for the second type of work order data (excess work order data) are as follows: For different specialties and different network element types, different X6, Y3, and Z3 values can be set. The default settings are: X6 = the average daily dispatch volume of the specialty and network element type in the past month * 3, Y3 = the average weekly dispatch volume of the specialty and network element type in the past three months * 3, and Z3 = the average monthly dispatch volume of the specialty and network element type in the past six months * 3.
[0151] In this embodiment, the granularity for hazard discovery in the second quantity type of work order data is: network element.
[0152] Output examples are shown in Table 11:
[0153]
[0154] Table 11
[0155] In this embodiment, after statistically analyzing the work order data according to the above three formats, the top 3% of network elements for each type of anomaly (anomalies in the work order data of each format) are output.
[0156] Step S04, and / or extract one or more of the third frequency type complaint data and the fourth duration type complaint data from the customer complaint data.
[0157] In this embodiment, complaint data is statistically analyzed according to the following two formats.
[0158] Before compiling complaint data according to the following two formats, first run the corresponding potential equipment. After running, mark the items that meet the abnormal conditions as abnormal items according to the default parameters (complaint default parameters). Determine whether the proportion of network elements included in the abnormal items is within the preset threshold P3% (e.g., within 7%) of the total number of such network elements in the entire network. If it is not within the preset threshold P3%, adjust (increase / decrease) the default parameters of each network element type and run again until the proportion of network elements included in each type of output abnormal item is within the preset threshold P3% (e.g., 7%) of the total number of such network elements in the entire network.
[0159] In this embodiment, the specific content of the complaint data is statistically analyzed according to the following two formats:
[0160] Extract one or more of the third frequency type complaint data and the fourth duration type complaint data from the customer complaint data.
[0161] First type of format: Third frequency type of complaint data (high frequency complaint data): A customer has more than M4 complaints in a month.
[0162] Variable description: Different M4 values can be set for different types of complaints. The default setting is M4=3.
[0163] Output examples are shown in Table 12:
[0164]
[0165] Table 12
[0166] In this embodiment, complaint data is statistically analyzed according to the second type of format described above, and the top P4% of network element lists for each type of anomaly (anomalies in each type of complaint data) are output.
[0167] Alternatively, complaint data can be statistically analyzed according to the two formats mentioned above, with monthly granularity. The top 4% customer list can be determined monthly, and the incremental list of each month compared to the previous month can be output.
[0168] The second type of format, the fourth duration type of complaint data (overdue complaint data): The duration of the complaint exceeds M5 hours, where the duration = complaint processing completion time - complaint initiation time.
[0169] Variable description: Different M5 values can be set for different types of complaints. The default setting is M5=4.
[0170] Output examples are shown in Table 13:
[0171]
[0172] In this embodiment, after statistically analyzing the complaint data according to the second type of format described above, the top P5% of network element lists for each type of anomaly (anomalies in the complaint data of each type of format) are determined and output.
[0173] Alternatively, the complaint data can be statistically analyzed according to the second type of format mentioned above, with the statistics of the complaint data performed on a daily basis, and the top 5% customer list determined on a daily basis, with the incremental list output for each month compared to the previous month.
[0174] In this embodiment, vulnerability discovery is performed based on both software and hardware network resources. Specifically, it is based on data such as primary and backup servers sharing the same local address, physical co-routing, and single-chain lack of protection to discover network resource vulnerabilities, as detailed below:
[0175] 1) Primary and backup network elements are located in the same office: Obtain resource information such as the computer room where the network element is located and the primary / backup / group POOL status of the network element to determine whether the primary and backup network elements are in the same computer room and whether the network elements in the same POOL are evenly distributed in various computer rooms. If they are not in the same computer room or are unevenly distributed, there are potential risks.
[0176] 2) Physical co-routing: Based on optical path resource data, obtain the serial association relationship between network element-circuit-topology-transmission system-optical path-optical path string-fiber core-optical cable-pipe / pole path, realize the judgment of physical routing information of electrical / optical path association on transmission network element, and determine whether there is a co-routing segment. If a co-routing segment exists, there is a potential risk.
[0177] 3) Unprotected single-chain link: Compare the core network uplink resources to determine if there is an unprotected single-chain link (if there is an unprotected single-chain link, there is a hidden danger); compare the transmission network element optical path resources to determine if there is a single-chain network element (if there is a single-chain network element, there is a hidden danger).
[0178] In this embodiment, since the vulnerability discovery is based on software vulnerability data and hardware vulnerability data, the vulnerability discovery is carried out from both hardware and software perspectives, thereby improving the efficiency of vulnerability investigation.
[0179] In this embodiment, the step of performing data fusion processing on the maintenance vulnerability data to obtain feature matrices of different granularity slices includes:
[0180] Step S21: According to the network element granularity and the alarm title granularity, extract the first active alarm quantity and the other second active alarm quantity in the other second slice time from the device alarm data, respectively. The other second slice time can be multiple times.
[0181] In this embodiment, the first slice time can be 1 day, and the other second slice times can be 5 minutes, 15 minutes, 1 hour, etc., respectively, without any specific limitation.
[0182] In this embodiment, the active alarm volume of slices with granularity of 5 minutes, 15 minutes, 1 hour, and 1 day is extracted according to the network element name and alarm title granularity (including all alarms that occurred within the slice granularity + all alarms that have not been cleared).
[0183] In this embodiment, the active alarm volume of a 1-day granular slice extracted by network element name and alarm title granularity is the first active alarm volume, and the active alarm volume of 5-minute, 15-minute, and 1-hour granular slices extracted by network element name and alarm title granularity is the second active alarm volume.
[0184] Step S22: Generate a first alarm quantity matrix based on the first active alarm quantity, and generate a second alarm quantity matrix based on the second active alarm quantity;
[0185] In this embodiment, the first active alarm quantity and the second active alarm quantity are grouped and summarized by network element name to generate alarm quantity matrices (first alarm quantity matrix and second alarm quantity matrix) that are subdivided by time granularity.
[0186] Step S23: Continue to group the first alarm quantity matrix and the second alarm quantity matrix according to network element type to obtain the data of each group. Based on the group data under each network element type group and the performance index data, generate the first performance index matrix and the second performance index matrix.
[0187] In this embodiment, the first alarm quantity matrix and the second alarm quantity matrix are further grouped by network element type to obtain data for each group. Furthermore, according to the "network element type-performance index mapping", performance index data is extracted from all network element names under each network element type group to generate a progressively subdivided performance index matrix.
[0188] Step S24: Concatenate the first alarm quantity matrix and the first performance index matrix to obtain the first slice feature matrix;
[0189] Step S25: Concatenate the second alarm quantity matrix and the second performance index matrix to obtain the second slice feature matrix.
[0190] In this embodiment, alarm quantity matrices with granularity of 5 minutes, 15 minutes, 1 hour, and 1 day are concatenated with corresponding performance index matrices according to network element names to obtain feature matrices of different granularity slices.
[0191] Step S30: Perform anomaly detection on the feature matrices of the slices at different granularities to obtain the network elements with hidden dangers pointed to by the operation and maintenance hidden danger data.
[0192] In this embodiment, after obtaining the feature matrices of slices at different granularities, anomaly detection is performed on the feature matrices of slices at different granularities to obtain the network elements with hidden dangers pointed to by the operation and maintenance hidden danger data.
[0193] The specific process of anomaly detection can be as follows: based on the trained anomaly detection model, anomaly detection is performed on the feature matrix of slices at different granularities to obtain the hidden network element pointed to by the operation and maintenance hidden danger data.
[0194] This application provides a method, apparatus, device, and storage medium for identifying potential network vulnerabilities. Compared to existing methods that rely on manual sorting, resulting in a small and limited number of vulnerabilities discovered, significant delays, and substantial resource waste, leading to low efficiency in network vulnerability investigation or discovery, this application acquires multi-dimensional operational vulnerability data. This multi-dimensional operational vulnerability data includes at least several items from equipment alarm data, performance indicator data, fault work order data, and customer complaint data. The operational vulnerability data is then fused to obtain feature matrices of different granularities. Anomaly detection is performed on the feature matrices of the different granularities to obtain the network elements with vulnerabilities identified by the operational vulnerability data. This application comprehensively utilizes and automatically acquires multi-dimensional operational and maintenance (O&M) vulnerability data, including multiple data sources such as equipment alarm data, performance indicator data, fault work order data, and customer complaint data. It then automatically performs data fusion processing on this O&M vulnerability data to obtain feature matrices of different granularities, enabling comprehensive and automatic anomaly detection and identifying the vulnerable network elements pointed to by the O&M vulnerability data. It can be understood that this application prioritizes comprehensive investigation of network vulnerabilities before major / important faults, avoiding situations where the number of vulnerabilities discovered is small and singular. Furthermore, this application employs automatic investigation rather than manual investigation, thus avoiding investigation delays and resource waste, and improving the efficiency of network vulnerability investigation or discovery.
[0195] Furthermore, based on the first embodiment of this application, another embodiment of this application is provided. In this embodiment, the step of concatenating the first alarm quantity matrix and the first performance index matrix to obtain the first time feature matrix includes:
[0196] Step A1: Extract alarm data of the first quantity type, alarm data of the first duration type, alarm data of the second duration type, and alarm data of the first frequency type from the device alarm data;
[0197] Step A2: Determine the percentages of the first quantity type alarm data, the first duration type alarm data, the second duration type alarm data, and the first frequency type alarm data relative to the corresponding anomaly indicators of all network elements of the same network element type.
[0198] Step A3: Determine the first reference feature matrix based on the percentage;
[0199] In this embodiment, for the first alarm quantity matrix, i.e. the 1-day granularity (time granularity) matrix, the feature matrices H1-H4 obtained by the following method are further associated. The feature matrices H1-H4 are then concatenated with the first alarm quantity matrix to obtain a new feature matrix of the 1-day granularity slice.
[0200] The specific H) method is as follows:
[0201] By associating alarm data of the first quantity type (excessive alarms, alarm data of the first duration type (excessively long alarms), alarm data of the second duration type (excessively short alarms), and alarm data of the first frequency type (high-frequency alarms) with the network element name and date, the percentage of the four types of hidden danger indicators in the above abnormal network elements relative to the corresponding abnormal indicators of all network elements of the same type is calculated, and the reference feature matrix H1-H4 is obtained.
[0202] Step A4: Concatenate the first reference feature matrix, the first alarm quantity matrix, and the first performance index matrix to obtain the first slice feature matrix.
[0203] After obtaining the first reference feature matrix, each first reference feature matrix is concatenated with the first alarm quantity matrix and the first performance index matrix to obtain the first slice feature matrix.
[0204] The step of concatenating the first reference feature matrix, the first alarm quantity matrix, and the first performance index matrix to obtain the first slice feature matrix includes:
[0205] Step B1: Extract second frequency type work order data, third duration type work order data, and second quantity type work order data from the fault work order data;
[0206] Step B2: Based on the second frequency type work order data, the third duration type work order data, and the second quantity type work order data, determine the second reference feature matrix within a preset time period before the first slice time;
[0207] In this embodiment, the second reference feature matrix is determined by associating the second frequency type work order data, the third duration type work order data, and the second quantity type work order data with the network element name and date. Specifically, the reference feature matrix I1 and I2 are obtained by summarizing and calculating the number of work orders in the 30 days before the abnormal time (before the first slice time).
[0208] Step A3: Concatenate the first reference feature matrix, the second reference feature matrix, the first alarm quantity matrix, and the first performance index matrix to obtain the first slice feature matrix.
[0209] By concatenating the first reference feature matrix, the second reference feature matrix, the first alarm quantity matrix, and the first performance index matrix, a first slice feature matrix is obtained. In this embodiment, if the first reference feature matrix, the second reference feature matrix, the first alarm quantity matrix, and the first performance index matrix are (W1), (W2), (W3), and (W4) respectively, then the first slice feature matrix is (W1, W2, W3, W4).
[0210] The step of performing anomaly detection on the feature matrices of the different granularity slices to obtain the hidden network elements pointed to by the operation and maintenance hidden danger data includes:
[0211] Step C1: Using multiple integrated preset machine learning anomaly detection algorithms, anomaly detection is performed on the feature matrices of the slices at different granularities, and the abnormal network elements and their time locations are output according to the voting mechanism.
[0212] In this embodiment, multiple integrated machine learning anomaly detection algorithms are used to perform anomaly detection on feature vectors at granular levels of 5 minutes / 15 minutes / 1 hour / 1 day (anomaly detection is performed on the first alarm quantity matrix and the second alarm quantity matrix). The abnormal network elements and time location information are output according to the voting mechanism, and the network elements with a high probability of having hidden dangers and their corresponding time ranges are indicated by sorting the anomaly confidence levels of different slice granularities.
[0213] Step C2, and / or determine the first mining network element corresponding to the device alarm data;
[0214] Step C3, and / or determine the second mining network element corresponding to the performance index data;
[0215] Step C4, and / or determine the third mining network element corresponding to the fault work order data;
[0216] Step C5, and / or determine the fourth mining network element corresponding to each of the customer complaint data;
[0217] Step C6: Based on the abnormal network element under the same date, the time location, and the abnormal confidence interval of different slice granularities, and / or the first mining network element, and / or the second mining network element, and / or the third mining network element, and / or the fourth mining network element, determine the hidden network element pointed to by the operation and maintenance hidden danger data.
[0218] After obtaining the network elements with a high probability of potential hazards and their corresponding time ranges, in this embodiment, the following steps are taken: First mining network element corresponding to the equipment alarm data; second mining network element corresponding to the performance indicator data; third mining network element corresponding to the fault work order data; and fourth mining network element corresponding to the customer complaint data. Based on the abnormal network elements on the same date, the time location, and the abnormal confidence intervals of different slice granularities, the first mining network element, the second mining network element, the third mining network element, and the fourth mining network element are used to determine the network element with potential hazards pointed to by the maintenance hazard data.
[0219] The first, second, third, and fourth mining network elements are all network elements (lists) with a time slice granularity of 1 day. Specifically, the first, second, third, and fourth mining network elements are the network element lists corresponding to P1%, P2%, P3%, and P4% respectively in the first embodiment mentioned above. They are associated with the same date, and the names of the matched network elements are further extracted as the list of network elements with key hidden dangers to be dealt with on that day, which is the hidden danger network element.
[0220] In this embodiment, alarm data of a first quantity type, alarm data of a first duration type, alarm data of a second duration type, and alarm data of a first frequency type are extracted from the device alarm data. The percentages of the first quantity type alarm data, the first duration type alarm data, the second duration type alarm data, and the first frequency type alarm data relative to the corresponding anomaly indicators of all network elements of the same type are determined. Based on these percentages, a first reference feature matrix is determined. The first reference feature matrix, the first alarm quantity matrix, and the first performance indicator matrix are concatenated to obtain a first slice feature matrix. In this embodiment, since the first slice feature matrix is obtained from a multi-dimensional data source through hazard investigation, the accuracy of identifying hazard-prone network elements can be improved.
[0221] Furthermore, based on the first and second embodiments of this application, another embodiment of this application is provided. In this embodiment, after the step of performing anomaly detection on the feature matrices of the different granularity slices to obtain the hidden network elements pointed to by the operation and maintenance hidden danger data, the method includes:
[0222] Step D1: Based on the hidden danger network element and the device alarm data, determine the alarm titles whose anomaly ranking is within a preset range;
[0223] Step D2: Determine the first title alarm quantity of the alarm title in the first slice time and other second slice time, and determine the second title alarm quantity corresponding to the alarm title in the device alarm data;
[0224] Step D3: Determine the associated alarm information based on the first title alarm quantity and the second title alarm quantity.
[0225] In this embodiment, for each key hidden danger network element (hidden danger network element), alarm titles (3 alarm titles) ranked within a preset range based on the degree of anomaly (determined according to a preset anomaly determination method) are also determined. For each alarm title, the first title alarm quantity of the alarm title in the first slice time and other second slice time is determined, and the second title alarm quantity corresponding to the alarm title in the device alarm data is determined, that is, the alarm quantity of statistical 5-minute, 15-minute, 1-hour granularity, etc. is determined.
[0226] Based on the alarm counts of the first title and the second title, related alarm information is determined. Specifically, alarm counts at 5-minute, 15-minute, and 1-hour granularities are sorted from highest to lowest. All alarm titles with alarm counts equal to or higher than these three alarm titles are considered as all related alarm information. The alarm title with the highest number of alarms across all 5-minute slices for the day is designated as the primary alarm. Based on this primary alarm information, a potential hazard event is generated and a work order is dispatched to process the alarm information.
[0227] In this embodiment, based on the problematic network element and the device alarm data, alarm titles with anomaly ranking within a preset range are determined; the number of alarms for each alarm title within a first slice time and other second slice time periods is determined, and the number of alarms for each alarm title corresponding to a second alarm title in the device alarm data is determined; based on the number of alarms for the first and second alarm titles, associated alarm information is determined. In this embodiment, capacity-related network perception factors are accurately adjusted according to different types of cells, laying the foundation for improving the identification rate of complaint cells and thus enhancing the quality of mobile network services.
[0228] Reference Figure 3 , Figure 3This is a schematic diagram of the device structure of the hardware operating environment involved in the embodiments of this application.
[0229] like Figure 3 As shown, the hazard detection device may include: a processor 1001, such as a CPU, a memory 1005, and a communication bus 1002. The communication bus 1002 is used to establish communication between the processor 1001 and the memory 1005. The memory 1005 may be a high-speed RAM or a stable, non-volatile memory, such as a disk drive. Optionally, the memory 1005 may also be a storage device independent of the aforementioned processor 1001.
[0230] Optionally, the hazard detection equipment may also include a rectangular user interface, a network interface, a camera, RF (Radio Frequency) circuitry, sensors, audio circuitry, a WiFi module, etc. The rectangular user interface may include a display screen and an input submodule such as a keyboard. Optionally, the rectangular user interface may also include a standard wired interface or a wireless interface. The network interface may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface).
[0231] Those skilled in the art will understand that Figure 3 The structure of the hazard excavation equipment shown does not constitute a limitation on the hazard excavation equipment. It may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0232] like Figure 3 As shown, the memory 1005, serving as a storage medium, may include an operating system, a network communication module, and a hazard detection program. The operating system is a program that manages and controls the hardware and software resources of the hazard detection equipment, supporting the operation of the hazard detection program and other software and / or programs. The network communication module is used to enable communication between the various components within the memory 1005, as well as communication with other hardware and software in the hazard detection system.
[0233] exist Figure 3 In the hazard discovery device shown, the processor 1001 is used to execute the hazard discovery program stored in the memory 1005 to implement the steps of the hazard discovery method described above.
[0234] The specific implementation method of the hidden danger excavation equipment in this application is basically the same as the embodiments of the above-mentioned hidden danger excavation methods, and will not be repeated here.
[0235] This application also provides a hazard excavation device, the hazard excavation device comprising:
[0236] The acquisition module is used to acquire multi-dimensional operation and maintenance potential data, wherein the multi-dimensional operation and maintenance potential data includes at least several items from equipment alarm data, performance index data, fault work order data, and customer complaint data.
[0237] The fusion module is used to perform data fusion processing on the operation and maintenance hidden danger data to obtain feature matrices of slices with different granularities;
[0238] The detection module is used to perform anomaly detection on the feature matrix of the slices at different granularities to obtain the network elements with hidden dangers pointed to by the operation and maintenance hidden danger data.
[0239] Optionally, the hazard excavation device further includes:
[0240] The first extraction unit is used to extract one or more of the following from the device alarm data: alarm data of the first quantity type, alarm data of the first duration type, alarm data of the second duration type, and alarm data of the first frequency type.
[0241] The second extraction unit is used to extract one or more of the following from the performance indicator data: risk indicator type data, indicator anomaly threshold data, and indicator rule parameter data:
[0242] The third extraction unit is used to extract one or more of the following from the fault work order data: second frequency type work order data, third duration type work order data, and second quantity type work order data:
[0243] The fourth extraction unit is used to extract one or more of the third frequency type complaint data and the fourth duration type complaint data from the customer complaint data.
[0244] Optionally, the maintenance vulnerability data includes equipment alarm data and performance indicator data, wherein the equipment alarm data is used for vulnerability mining at the network element granularity and / or alarm title granularity.
[0245] The fusion module includes:
[0246] The fifth extraction unit is used to extract the first active alarm quantity and the other second active alarm quantity in other second slice times from the device alarm data according to the network element granularity and the alarm title granularity, respectively. The other second slice times can be multiple times.
[0247] The first generation unit is used to generate a first alarm quantity matrix based on the first active alarm quantity and to generate a second alarm quantity matrix based on the second active alarm quantity.
[0248] The second generation unit is used to further group the first alarm quantity matrix and the second alarm quantity matrix according to network element type to obtain the group data, and generate the first performance index matrix and the second performance index matrix based on the group data under each network element type group and the performance index data.
[0249] The first splicing unit is used to splice the first alarm quantity matrix and the first performance index matrix to obtain the first slice feature matrix;
[0250] The second splicing unit is used to splice the second alarm quantity matrix and the second performance index matrix to obtain the second slice feature matrix.
[0251] Optionally, the first splicing unit includes:
[0252] An extraction subunit is used to extract alarm data of a first quantity type, alarm data of a first duration type, alarm data of a second duration type, and alarm data of a first frequency type from the device alarm data;
[0253] The first determining subunit is used to determine the percentages of the first quantity type alarm data, the first duration type alarm data, the second duration type alarm data, and the first frequency type alarm data relative to the corresponding anomaly indicators of all network elements of the same network element type.
[0254] The second determining subunit is used to determine the first reference feature matrix based on the percentage;
[0255] The splicing sub-unit is used to splice the first reference feature matrix, the first alarm quantity matrix and the first performance index matrix to obtain the first slice feature matrix.
[0256] Optionally, the splicing subunit is used to implement:
[0257] Extract second frequency type work order data, third duration type work order data, and second quantity type work order data from the fault work order data;
[0258] Based on the second frequency type work order data, the third duration type work order data, and the second quantity type work order data, determine the second reference feature matrix within a preset time period before the first slice time.
[0259] The first reference feature matrix, the second reference feature matrix, the first alarm quantity matrix, and the first performance index matrix are concatenated to obtain the first slice feature matrix.
[0260] Optionally, the detection module includes:
[0261] An anomaly detection unit is used to perform anomaly detection on the feature matrix of the slices at different granularities using multiple integrated preset machine learning anomaly detection algorithms, and output the abnormal network element and time location according to the voting mechanism.
[0262] The first determining unit is used to determine, and / or determine, the first mining network element corresponding to the device alarm data;
[0263] The second determining unit is used to determine the second mining network element corresponding to the performance index data;
[0264] The third determining unit is used to determine the third mining network element corresponding to the fault work order data;
[0265] The fourth determining unit is used to determine and / or determine the fourth mining network element corresponding to the customer complaint data respectively;
[0266] The fifth determining unit is used to determine the hidden danger network element pointed to by the operation and maintenance hidden danger data based on the abnormal network element under the same date, the time location, and the abnormal confidence interval of different slice granularity, and / or the first mining network element, and / or the second mining network element, and / or the third mining network element, and / or the fourth mining network element.
[0267] Optionally, the hazard excavation device further includes:
[0268] The first determining module is used to determine alarm titles whose anomaly ranking is within a preset range based on the hidden danger network element and the device alarm data;
[0269] The second determining module is used to determine the first title alarm quantity of the alarm title in the first slice time and other second slice time, and to determine the second title alarm quantity corresponding to the alarm title in the device alarm data;
[0270] The third determining module is used to determine the associated alarm information based on the first title alarm quantity and the second title alarm quantity.
[0271] The specific implementation of the hidden danger excavation device in this application is basically the same as the embodiments of the hidden danger excavation method described above, and will not be repeated here.
[0272] This application provides a storage medium that stores one or more programs, which can be executed by one or more processors to implement the steps of the hazard discovery method described above.
[0273] The specific implementation of the storage medium in this application is basically the same as the embodiments of the hidden danger discovery method described above, and will not be repeated here.
[0274] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the aforementioned hidden danger discovery method.
[0275] The specific implementation of the computer program product in this application is basically the same as the embodiments of the hidden danger discovery method described above, and will not be repeated here.
[0276] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0277] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0278] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0279] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.
Claims
1. A method for identifying potential hazards, characterized in that, The method for identifying potential hazards includes: Obtain multi-dimensional operational and maintenance potential data, wherein the multi-dimensional operational and maintenance potential data includes at least several items from equipment alarm data, performance indicator data, fault work order data, and customer complaint data; The operation and maintenance risk data are fused to obtain feature matrices of slices with different granularities; Anomaly detection is performed on the feature matrices of the slices at different granularities to obtain the network elements with hidden dangers pointed to by the operation and maintenance hidden danger data; The maintenance vulnerability data includes device alarm data and performance indicator data. The device alarm data is used for vulnerability mining at the network element granularity and / or alarm title granularity. The step of performing data fusion processing on the maintenance vulnerability data to obtain feature matrices of different granularity slices includes: According to the network element granularity and the alarm title granularity, the first active alarm quantity and the other second active alarm quantity in other second slice times are extracted from the device alarm data, respectively. The other second slice times can be multiple times. A first alarm quantity matrix is generated based on the first active alarm quantity, and a second alarm quantity matrix is generated based on the second active alarm quantity. The first alarm quantity matrix and the second alarm quantity matrix are further grouped by network element type to obtain the data of each group. Based on the group data under each network element type group and the performance index data, a first performance index matrix and a second performance index matrix are generated. By concatenating the first alarm quantity matrix and the first performance index matrix, the first slice feature matrix is obtained; By concatenating the second alarm quantity matrix and the second performance index matrix, a second slice feature matrix is obtained.
2. The method for identifying potential hazards according to claim 1, characterized in that, Before the step of performing data fusion processing on the maintenance vulnerability data to obtain feature matrices of different granularity slices, the method includes: Extract one or more of the following from the device alarm data: alarm data of the first quantity type, alarm data of the first duration type, alarm data of the second duration type, and alarm data of the first frequency type; And / or extract one or more of the following from the performance index data: risk index type data, index anomaly threshold data, and index rule parameter data; And / or extract one or more of the following from the fault work order data: second frequency type work order data, third duration type work order data, and second quantity type work order data; And / or extract one or more of the third frequency type complaint data and the fourth duration type complaint data from the customer complaint data.
3. The method for identifying potential hazards as described in claim 1, characterized in that, The step of concatenating the first alarm quantity matrix and the first performance index matrix to obtain the first slice feature matrix includes: Extract alarm data of the first quantity type, alarm data of the first duration type, alarm data of the second duration type, and alarm data of the first frequency type from the device alarm data; Determine the percentages of the first quantity type alarm data, the first duration type alarm data, the second duration type alarm data, and the first frequency type alarm data relative to the corresponding anomaly indicators of all network elements of the same network element type; Based on the percentage, a first reference feature matrix is determined; The first reference feature matrix, the first alarm quantity matrix, and the first performance index matrix are concatenated to obtain the first slice feature matrix.
4. The method for identifying potential hazards as described in claim 3, characterized in that, The step of concatenating the first reference feature matrix, the first alarm quantity matrix, and the first performance index matrix to obtain the first slice feature matrix includes: Extract second frequency type work order data, third duration type work order data, and second quantity type work order data from the fault work order data; Based on the second frequency type work order data, the third duration type work order data, and the second quantity type work order data, determine the second reference feature matrix within a preset time period before the first slice time. The first reference feature matrix, the second reference feature matrix, the first alarm quantity matrix, and the first performance index matrix are concatenated to obtain the first slice feature matrix.
5. The method for identifying potential hazards as described in claim 4, characterized in that, The step of performing anomaly detection on the feature matrices of the different granularity slices to obtain the hidden network elements pointed to by the operation and maintenance hidden danger data includes: By utilizing multiple integrated preset machine learning anomaly detection algorithms, anomaly detection is performed on the feature matrices of the slices at different granularities, and the abnormal network elements and their time locations are output according to a voting mechanism. And / or determine the first mining network element corresponding to the device alarm data; And / or determine the second mining network element corresponding to the performance index data; And / or determine the third mining network element corresponding to the fault work order data; And / or determine the fourth mining network element corresponding to each of the customer complaint data; Based on the abnormal network element under the same date, the time location, and the abnormal confidence interval of different slice granularities, and / or the first mining network element, and / or the second mining network element, and / or the third mining network element, and / or the fourth mining network element, the hidden network element pointed to by the operation and maintenance hidden danger data is determined.
6. The method for identifying potential hazards as described in claim 5, characterized in that, After the step of performing anomaly detection on the feature matrices of the different granularity slices to obtain the hidden network elements pointed to by the operation and maintenance hidden danger data, the method includes: Based on the hidden danger network element and the device alarm data, determine the alarm title whose anomaly ranking is within a preset range; Determine the number of first title alarms in the first slice time and other second slice time periods, and determine the number of second title alarms corresponding to the alarm title in the device alarm data; Based on the alarm volume of the first title and the alarm volume of the second title, determine the associated alarm information.
7. A hidden danger excavation device, characterized in that, The hazard detection device includes: The acquisition module is used to acquire multi-dimensional operation and maintenance potential data, wherein the multi-dimensional operation and maintenance potential data includes at least several items from equipment alarm data, performance index data, fault work order data, and customer complaint data. The fusion module is used to perform data fusion processing on the operation and maintenance hidden danger data to obtain feature matrices of slices with different granularities; The detection module is used to perform anomaly detection on the feature matrix of the slices at different granularities to obtain the hidden network elements pointed to by the operation and maintenance hidden danger data; The maintenance vulnerability data includes device alarm data and performance indicator data. The device alarm data is used for vulnerability mining at the network element granularity and / or alarm title granularity. The hazard detection device is used to achieve: According to the network element granularity and the alarm title granularity, the first active alarm quantity and the other second active alarm quantity in other second slice times are extracted from the device alarm data, respectively. The other second slice times can be multiple times. A first alarm quantity matrix is generated based on the first active alarm quantity, and a second alarm quantity matrix is generated based on the second active alarm quantity. The first alarm quantity matrix and the second alarm quantity matrix are further grouped by network element type to obtain the data of each group. Based on the group data under each network element type group and the performance index data, a first performance index matrix and a second performance index matrix are generated. By concatenating the first alarm quantity matrix and the first performance index matrix, the first slice feature matrix is obtained; By concatenating the second alarm quantity matrix and the second performance index matrix, a second slice feature matrix is obtained.
8. A hidden danger excavation device, characterized in that, The hazard discovery device includes: a memory, a processor, and a program stored in the memory for implementing the hazard discovery method. The memory is used to store the program for implementing the hazard discovery method; The processor is used to execute a program that implements the hazard discovery method, so as to implement the steps of the hazard discovery method as described in any one of claims 1 to 6.
9. A storage medium, characterized in that, The storage medium stores a program for implementing the hazard discovery method, which is executed by a processor to implement the steps of the hazard discovery method as described in any one of claims 1 to 6.