A network anomaly early warning method, device, electronic device and storage medium

By obtaining the network's QOE-aware service layer and network layer indicators, and using the prediction model to predict the exception type, the problem that network exceptions can only be detected after impact is solved, and early warning is achieved, which improves user satisfaction and prediction accuracy.

CN116232851BActive Publication Date: 2025-08-19CHINA TELECOM CORP LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211697545.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-28
Publication Date
2025-08-19
Estimated Expiration
2042-12-28

AI Technical Summary

Technical Problem

In the prior art, network abnormalities can only be detected after they have already affected the user, resulting in a decrease in user satisfaction.

Method used

By obtaining the network's experience quality QOE perceives business layer indicators and network layer indicators, use prediction models to predict exception types in the future time period, and issue exception alarms are issued so that exceptions can be discovered and processed in advance.

Benefits of technology

It realizes early warning of network abnormalities, avoids the impact of abnormalities on users, improves user satisfaction, and improves the accuracy of abnormal prediction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116232851B_ABST
    Figure CN116232851B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a network anomaly early warning method, device, electronic device, and storage medium. The method includes: obtaining a target QOE-perceived service layer indicator and a target network layer indicator for the network; the target QOE-perceived service layer indicator includes multiple indicators; based on the target QOE-perceived service layer indicator and the target network layer indicator, predicting the predicted QOE-perceived service layer indicator and the predicted network layer indicator of the network within a preset time period; based on the predicted QOE-perceived service layer indicator and the predicted network layer indicator, determining the target anomaly type of the network within the preset time period; and based on the target anomaly type, issuing an anomaly alarm for the network within the preset time period. Through the embodiment of the present invention, it is possible to determine whether a network anomaly occurs based on the predicted information; thereby, issuing an early warning by discovering network anomalies in advance; and further, avoiding the impact of abnormal networks on users, thereby improving user satisfaction with the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of communications, and in particular to a network anomaly early warning method, device, electronic equipment and storage medium. Background Art

[0002] In actual applications, in order to ensure that users are provided with a stable and high-speed network, a large amount of manpower and material resources need to be invested in network testing and maintenance.

[0003] However, this method can only detect network anomalies when the network anomalies have already occurred and have already affected users, which will greatly reduce user satisfaction with network use. Summary of the Invention

[0004] In view of the above problems, a network anomaly early warning method, device, electronic device and storage medium are proposed to overcome the above problems or at least partially solve the above problems, including:

[0005] A network anomaly early warning method, the method comprising:

[0006] Obtaining a target quality of experience (QOE)-aware service layer indicator and a target network layer indicator for the network; the target QOE-aware service layer indicator includes a plurality of indicators;

[0007] Predicting a predicted QOE-aware service layer indicator and a predicted network layer indicator of the network within a preset time period based on the target QOE-aware service layer indicator and the target network layer indicator;

[0008] Determining a target anomaly type of the network within a preset time period based on the predicted QOE-aware service layer indicator and the predicted network layer indicator;

[0009] According to the target abnormality type, an abnormality alarm of the network within the preset time period is issued.

[0010] Optionally, the method further includes:

[0011] Acquire first training data, where the first training data includes QOE-aware service layer indicators at different times and network layer indicators at different times;

[0012] The first prediction model is trained by using the QOE-aware service layer indicator and the network layer indicator that are in the earlier time series in the first training data as input data and using the QOE-aware service layer indicator and the network layer indicator that are in the later time series in the first training data as output data;

[0013] The predicting, based on the target QOE-aware service layer indicator and the target network layer indicator, the predicted QOE-aware service layer indicator and the predicted network layer indicator of the network within a preset time period includes:

[0014] The target QOE-aware service layer indicator and the target network layer indicator are input into the trained first prediction model, and the predicted QOE-aware service layer indicator and the predicted network layer indicator output by the trained first prediction model are obtained.

[0015] Optionally, the method further includes:

[0016] Determining target fluctuation trends of the predicted QOE-aware service layer indicator and the predicted network layer indicator within the preset time period;

[0017] According to the target fluctuation trend, it is determined whether it is necessary to execute the step of issuing an abnormality alarm for the network within the preset time period according to the target abnormality type.

[0018] Optionally, the method further includes:

[0019] Obtaining second training data, where the second training data includes QOE-aware service layer indicators and network layer indicators, and anomaly types corresponding to the occurring anomalies;

[0020] Training a second prediction model using the QOE-aware service layer indicator and the network layer indicator in the second training data as input data and the corresponding exception type of the exception occurring as output data;

[0021] The determining, based on the predicted QOE-aware service layer indicator and the predicted network layer indicator, a target anomaly type of the network within a preset time period includes:

[0022] The predicted QOE-aware service layer indicator and the predicted network layer indicator are input into the trained second prediction model, and the target anomaly type output by the trained second prediction model is obtained.

[0023] Optionally, the method further includes:

[0024] Analyze user needs based on the target exception type.

[0025] Optionally, the network includes network elements, optical paths, and websites; and the target abnormality type includes any one of the following:

[0026] Abnormal types for network elements, abnormal types for optical paths, and abnormal types for websites.

[0027] Optionally, the target network layer indicators include: download rate, first screen delay, packet loss rate, and number of terminal restarts.

[0028] An embodiment of the present invention further provides a network anomaly early warning device, the device comprising:

[0029] An acquisition module, configured to acquire a target quality of experience (QOE)-aware service layer indicator and a target network layer indicator for the network; the target QOE-aware service layer indicator includes a plurality of indicators;

[0030] A first prediction module is configured to predict a predicted QOE-perceived service layer indicator and a predicted network layer indicator of the network within a preset time period based on the target QOE-perceived service layer indicator and the target network layer indicator;

[0031] A second prediction module is configured to determine a target anomaly type of the network within a preset time period based on the predicted QOE-aware service layer indicator and the predicted network layer indicator;

[0032] The alarm module is used to issue an abnormality alarm for the network within the preset time period according to the target abnormality type.

[0033] Optionally, the device further comprises:

[0034] A first training module is configured to obtain first training data, the first training data including QOE-aware service layer indicators and network layer indicators at different times; use the QOE-aware service layer indicators and network layer indicators that are earlier in time sequence in the first training data as input data, and use the QOE-aware service layer indicators and network layer indicators that are later in time sequence in the first training data as output data, to train a first prediction model;

[0035] The first prediction module is used to input the target QOE-aware business layer indicator and the target network layer indicator into the trained first prediction model, and obtain the predicted QOE-aware business layer indicator and the predicted network layer indicator output by the trained first prediction model.

[0036] Optionally, the device further comprises:

[0037] A judgment module is used to determine the target fluctuation trend of the predicted QOE-aware business layer indicator and the predicted network layer indicator within the preset time period; based on the target fluctuation trend, it is judged whether it is necessary to execute the step of issuing an abnormal alarm for the network within the preset time period according to the target abnormality type.

[0038] Optionally, the device further comprises:

[0039] a second training module configured to obtain second training data, the second training data including QOE-aware service layer indicators and network layer indicators, and corresponding anomaly types of occurred anomalies; and train a second prediction model using the QOE-aware service layer indicators and network layer indicators in the second training data as input data and the corresponding anomaly types of occurred anomalies as output data;

[0040] The second prediction module is used to input the predicted QOE-aware business layer indicator and the predicted network layer indicator into the trained second prediction model, and obtain the target anomaly type output by the trained second prediction model.

[0041] Optionally, the device further comprises:

[0042] The analysis module is used to analyze user needs according to the target abnormality type.

[0043] Optionally, the network includes network elements, optical paths, and websites; and the target abnormality type includes any one of the following:

[0044] Abnormal types for network elements, abnormal types for optical paths, and abnormal types for websites.

[0045] Optionally, the target network layer indicators include: download rate, first screen delay, packet loss rate, and number of terminal restarts.

[0046] An embodiment of the present invention further provides an electronic device comprising a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program implements the above-mentioned network anomaly early warning method when executed by the processor.

[0047] An embodiment of the present invention further provides a computer-readable storage medium storing a computer program, which implements the above-mentioned network anomaly early warning method when executed by a processor.

[0048] The embodiments of the present invention have the following advantages:

[0049] In an embodiment of the present invention, a target QOE-aware business layer indicator and a target network layer indicator are obtained for the network; the target QOE-aware business layer indicator includes a plurality of indicators; based on the target QOE-aware business layer indicator and the target network layer indicator, the predicted QOE-aware business layer indicator and the predicted network layer indicator of the network within a preset time period are predicted; based on the predicted QOE-aware business layer indicator and the predicted network layer indicator, the target abnormality type of the network within the preset time period is determined; based on the target abnormality type, an abnormality alarm of the network within the preset time period is issued. Through the embodiment of the present invention, it is possible to determine whether the network is abnormal based on the predicted information; thereby, an early warning is issued by discovering the abnormality of the network in advance; and further, the impact of the abnormal network on the user is avoided, thereby improving the user's satisfaction with the network. In addition, prediction based on multi-dimensional QOE-aware business layer indicators can improve the accuracy of abnormality prediction. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] In order to more clearly illustrate the technical solution of the present invention, the following briefly introduces the drawings required for use in the description of the present invention. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0051] Figure 1 This is a flowchart of the steps of a network anomaly early warning method according to an embodiment of the present invention;

[0052] Figure 2 This is a flowchart of another method for early warning of network anomalies according to an embodiment of the present invention;

[0053] Figure 3 is a schematic diagram of the structure of a network according to an embodiment of the present invention;

[0054] Figure 4 The present invention is a schematic structural diagram of a method for early warning of network anomalies according to an embodiment of the present invention. DETAILED DESCRIPTION

[0055] To make the above-mentioned objects, features, and advantages of the present invention more clearly understood, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments described are only a portion of the embodiments of the present invention, not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without inventive effort are also within the scope of protection of the present invention.

[0056] In practical applications, if network maintenance is performed only after an anomaly has occurred, user satisfaction with the network may be significantly reduced. To ensure a stable and high-speed network for users, an embodiment of the present invention provides a network anomaly early warning method. The method predicts future network QOE-aware service layer and network layer indicators based on prior QOE-aware service layer and network layer indicators, and determines whether a network anomaly has occurred based on the predicted information. Thus, an early warning is issued by pre-detecting network anomalies, thereby avoiding the impact of abnormal networks on users and improving user satisfaction with the network.

[0057] In addition, predictions based on multi-dimensional QOE-aware business-layer indicators can improve the accuracy of anomaly predictions.

[0058] Reference Figure 1 , which shows a flowchart of a method for early warning of network anomalies according to an embodiment of the present invention, which may include the following steps:

[0059] Step 101: Obtain target quality of experience (QOE)-aware service layer indicators and target network layer indicators for the network; the target QOE-aware service layer indicators include multiple indicators.

[0060] As an example, target network layer indicators include any one or more of the following: download rate, first screen delay, packet loss rate, and number of terminal restarts. Target QOE-aware service layer indicators may include any one or more of the following: user satisfaction, user fault reporting, etc., although this is not limited in this embodiment of the present invention.

[0061] The target network layer indicators may refer to the evaluation of network quality from the perspective of the network layer; the target perceived service layer indicators may refer to the evaluation of network quality from the perspective of users and services.

[0062] The target network layer indicator and the target perception service layer indicator may be data at the current moment or data at a previous historical moment, and the embodiment of the present invention does not impose any limitation on this.

[0063] In practical applications, when it is necessary to predict network anomalies, multiple target QOE-aware business layer indicators and one or more target network layer indicators for the network can be obtained first.

[0064] Step 102: Predict the predicted QOE-aware service layer indicator and the predicted network layer indicator of the network within a preset time period based on the target QOE-aware service layer indicator and the target network layer indicator.

[0065] After obtaining multiple target QOE-perceived service layer indicators and target network layer indicators, the predicted QOE-perceived service layer indicators and predicted network layer indicators that may appear in the network within a preset time period can be predicted based on the multiple target QOE-perceived service layer indicators and target network layer indicators; wherein the preset time period can be a future time period set according to actual conditions, and the embodiments of the present invention do not limit this.

[0066] Step 103: Determine a target anomaly type of the network within a preset time period based on the predicted QOE-aware service layer indicator and the predicted network layer indicator.

[0067] After obtaining the predicted QOE-aware business layer indicators and the predicted network layer indicators, the target anomaly type of the network that may occur within a preset time period can be determined based on the obtained predicted QOE-aware business layer indicators and the predicted network layer indicators; for example: where the anomaly may occur, what type of anomaly may occur, etc., and the embodiments of the present invention do not limit this.

[0068] Step 104: Based on the target abnormality type, issue a network abnormality alarm within a preset time period.

[0069] After determining the target anomaly type of the network that may occur within a preset time period, an anomaly alarm can be issued for the network anomaly within the preset time period based on the target anomaly type. For example, an anomaly alarm prompt is generated for the preset time period so that relevant staff can inspect the network in advance, thereby avoiding inspecting the network only when an anomaly occurs and affecting the user experience.

[0070] In an embodiment of the present invention, a target QOE-aware business layer indicator and a target network layer indicator are obtained for the network; the target QOE-aware business layer indicator includes a plurality of indicators; based on the target QOE-aware business layer indicator and the target network layer indicator, the predicted QOE-aware business layer indicator and the predicted network layer indicator of the network within a preset time period are predicted; based on the predicted QOE-aware business layer indicator and the predicted network layer indicator, the target abnormality type of the network within the preset time period is determined; based on the target abnormality type, an abnormality alarm of the network within the preset time period is issued. Through the embodiment of the present invention, it is possible to determine whether the network is abnormal based on the predicted information; thereby, an early warning is issued by discovering the abnormality of the network in advance; and further, the impact of the abnormal network on the user is avoided, thereby improving the user's satisfaction with the network. In addition, prediction based on multi-dimensional QOE-aware business layer indicators can improve the accuracy of abnormality prediction.

[0071] Reference Figure 2 , shows a flowchart of another network anomaly early warning method according to an embodiment of the present invention, which may include the following steps:

[0072] Step 201: Obtain target QOE-aware service layer indicators and target network layer indicators for the network.

[0073] In practical applications, when it is necessary to predict network anomalies, multiple target QOE-aware business layer indicators and one or more target network layer indicators for the network can be obtained first.

[0074] Step 202: Input the target QOE-aware service layer indicator and the target network layer indicator into the trained first prediction model, and obtain the predicted QOE-aware service layer indicator and the predicted network layer indicator output by the trained first prediction model.

[0075] After obtaining multiple target QOE-aware business layer indicators and target network layer indicators, the predicted QOE-aware business layer indicators and predicted network layer indicators that may appear in the network within a preset time period can be predicted based on the multiple target QOE-aware business layer indicators and target network layer indicators.

[0076] Specifically, the target QOE-perceived service layer indicator and the target network layer indicator can be input into a trained first prediction model; the trained first prediction model can predict the predicted QOE-perceived service layer indicator and the predicted network layer indicator that may appear in the network within a preset time period based on the input target QOE-perceived service layer indicator and the target network layer indicator.

[0077] The trained first prediction model can output the predicted QOE-aware service layer indicators and predicted network layer indicators after predicting the possible QOE-aware service layer indicators and predicted network layer indicators that may appear in the network within a preset time period.

[0078] In one embodiment of the present invention, the first prediction model can be trained in the following manner:

[0079] Obtain first training data, where the first training data includes QOE-aware business layer indicators at different times and network layer indicators at different times; use the QOE-aware business layer indicators and network layer indicators that are earlier in time sequence in the first training data as input data, and use the QOE-aware business layer indicators and network layer indicators that are later in time sequence in the first training data as output data, to train a first prediction model.

[0080] First, QOE-aware service layer indicators at different times and network layer indicators at different times may be obtained, and the QOE-aware service layer indicators at different times and the network layer indicators at different times may form first training data.

[0081] Then, the first prediction model can be trained by using the QOE-aware business layer indicators and network layer indicators in the earlier time series as input data and the QOE-aware business layer indicators and network layer indicators in the later time series as output data; for example: the first prediction model can be trained by using the QOE-aware business layer indicators and network layer indicators from December 1, 2022 to December 7, 2022 as input data and the QOE-aware business layer indicators and network layer indicators from December 8, 2022 to December 10, 2022 as output data.

[0082] Step 203: Input the predicted QOE-aware service layer indicator and the predicted network layer indicator into the trained second prediction model, and obtain the target anomaly type output by the trained second prediction model.

[0083] After obtaining the predicted QOE-aware service layer indicator and the predicted network layer indicator, the target anomaly type of the network anomaly that may occur within a preset time period can be determined based on the obtained predicted QOE-aware service layer indicator and the predicted network layer indicator.

[0084] Specifically, the predicted QOE-aware business layer indicators and the predicted network layer indicators can be output to a second prediction model obtained after pre-training; the trained second prediction model can predict the target anomaly type that may occur in the network within a preset time period based on the predicted QOE-aware business layer indicators and the predicted network layer indicators.

[0085] After the trained second prediction model predicts a target abnormality type of an abnormality that may occur in the network within a preset time period, it can output the target abnormality type.

[0086] As an example, a network may include network elements, optical paths, and network stations; and target anomaly types may include any of the following:

[0087] Abnormal types for network elements, abnormal types for optical paths, and abnormal types for websites.

[0088] As another example, in order to further subdivide the anomalies of network elements, optical paths and websites, there may be multiple types of anomalies for network elements, multiple types of anomalies for optical paths, and multiple types of anomalies for websites. The embodiments of the present invention do not limit this.

[0089] like Figure 3 , you can find abnormalities in the optical modem, OLT (Optical Line Terminal), or MSE (Multi Service Edge) in the network; or test network abnormalities, etc.

[0090] In one embodiment of the present invention, the second prediction model can be trained in the following manner:

[0091] Obtain second training data, where the second training data includes QOE-aware business layer indicators and network layer indicators, as well as the corresponding anomaly types of the anomalies that occur; use the QOE-aware business layer indicators and network layer indicators in the second training data as input data, and use the corresponding anomaly types of the anomalies that occur as output data to train the second prediction model.

[0092] First, QOE-aware business layer indicators and network layer indicators, as well as the types of the corresponding exceptions, can be obtained, and the second training data is composed of the QOE-aware business layer indicators and network layer indicators, as well as the types of the corresponding exceptions.

[0093] Then, the second prediction model may be trained by using the QOE-aware business layer indicators and network layer indicators in the second training data as input data and the exception types corresponding to the exceptions that occurred in the second training data as output data.

[0094] Step 204: Based on the target abnormality type, issue a network abnormality alarm within a preset time period.

[0095] After determining the target anomaly type of the network that may occur within a preset time period, an anomaly alarm can be issued for the network anomaly within the preset time period based on the target anomaly type. For example, an anomaly alarm prompt is generated for the preset time period so that relevant staff can inspect the network in advance, thereby avoiding inspecting the network only when an anomaly occurs and affecting the user experience.

[0096] In one embodiment of the present invention, the following steps may also be included:

[0097] Determine the target fluctuation trend of the predicted QOE perception business layer indicators and the predicted network layer indicators within a preset time period; based on the target fluctuation trend, determine whether it is necessary to execute the step of issuing an abnormal alarm for the network within a preset time period based on the target abnormality type.

[0098] In practical applications, before executing the step of issuing a network abnormality alarm within a preset time period according to the target abnormality type, the target fluctuation trend of the predicted QOE perception service layer indicators and the predicted network layer indicators within the preset time period can be determined first.

[0099] Specifically, the predicted QOE-aware service layer indicators may include multiple indicators, and the predicted network layer indicators may also include multiple indicators. The multiple predicted QOE-aware service layer indicators / predicted network layer indicators may be indicators corresponding to different time periods.

[0100] Based on multiple predicted QOE-aware service layer indicators and multiple predicted network layer indicators, the target fluctuation trend can be determined.

[0101] Then, based on the target fluctuation trend, it can be determined whether it is necessary to execute the step of issuing an abnormality alarm for the network within a preset time period based on the target abnormality type.

[0102] Specifically, if the target fluctuation trend indicates that the QOE-perceived business layer indicators and network layer indicators are gradually deteriorating, it may mean that the quality of the network is declining. At this time, the step of issuing an abnormal alarm for the network within a preset time period can be executed according to the target abnormality type.

[0103] If the target fluctuation trend indicates that the QOE-aware service layer indicators and network layer indicators are gradually improving, it may mean that the quality of the network is on the rise. At this time, the step of issuing an abnormality alarm for the network within a preset time period based on the target abnormality type may not be performed, and the embodiment of the present invention does not impose any restrictions on this.

[0104] In another embodiment of the present invention, the following steps may also be included:

[0105] Analyze user needs based on the target exception type.

[0106] In actual applications, when different target anomaly types occur in the network, it may be caused by certain user needs. For example, if a user goes offline, we can analyze and determine whether the user needs to go offline.

[0107] In an embodiment of the present invention, a target QOE-aware business layer indicator and a target network layer indicator for the network are obtained; the target QOE-aware business layer indicator and the target network layer indicator are input into a trained first prediction model, and the predicted QOE-aware business layer indicator and the predicted network layer indicator output by the trained first prediction model are obtained; the predicted QOE-aware business layer indicator and the predicted network layer indicator are input into a trained second prediction model, and the target anomaly type output by the trained second prediction model is obtained; and an anomaly alarm for the network within a preset time period is issued based on the target anomaly type. Through the embodiment of the present invention, it is possible to determine whether an anomaly has occurred in the network based on the predicted information; thereby, an early warning is issued by discovering anomalies in the network in advance; and further, the impact of an abnormal network on users is avoided, thereby improving user satisfaction with the network. In addition, prediction based on multi-dimensional QOE-aware business layer indicators can improve the accuracy of anomaly prediction.

[0108] And by analyzing user needs based on the prediction results, user needs can be predicted in advance, so that user needs can be met in advance, further improving the user experience.

[0109] To further illustrate the above-mentioned network anomaly warning method, the following examples are given:

[0110] Establish a broadband awareness and hidden danger detection system. This system promptly identifies potential hidden dangers in network elements and optical paths from the MSE to the optical network unit (ONU). This system enables predictive maintenance, drives network optimization, and improves predictive maintenance capabilities, preventing problems before they occur. This effectively reduces the three rates (complaint rate, failure rate, and notification rate) and serves as an effective way to improve user satisfaction.

[0111] 1. Poor quality network element mining algorithm outputs poor quality MSE\OLT\ONU: automatic binning identification + SVM (Support Vector Machine, Support Vector Machine) + time series algorithm:

[0112] (1) The automatic binning algorithm can solve the problem of low modeling efficiency, strong subjectivity and reliance on experience in manual modeling methods.

[0113] A continuous variable linear analysis model is established for the QOE perception business layer indicators and the core network layer indicators such as download rate, first screen delay, packet loss rate, TRACE first hop delay, and the number of terminal disconnection and restart times. Based on the k-means clustering analysis algorithm, each indicator is divided into 10 intervals from 0 to 10 points, and evaluation indicators for each indicator are formed based on this.

[0114] (2) Based on the evaluation indicators established by automatic binning and the volatility indicators (rising or falling rates) established on the original basic indicators, a multi-dimensional vector SVM model of the fault dimension is formed to assist the fault work order. The steps are as follows: the automatic binning scoring intervals of the download rate, first screen delay, packet loss rate, TRACE first hop delay, and terminal disconnection and restart times indicators are used to establish a five-dimensional vector space model, and correspond to the fault work order data classification (such as: terminal quality problems, terminal optical path problems, uplink congestion, PON port failure, etc.).

[0115] The training data was based on five dimensions of terminal data, including the time each type of fault work order occurred and the three days before and after it was processed. After training with 10,000 user data samples for each type of fault work order, a data training model for each type of work order was developed, along with the correlation weights and thresholds for the basic indicators and evaluation indicators to potential fault hazards.

[0116] (3) Time Series Establishment and Prediction: Each terminal sensor probe performs six sampling tests per day for five indicators (download rate, first screen delay, packet loss rate, TRACE first hop delay, and terminal restart count), generating indicator data in a 4-hour time series. Terminal data over a 7-day period is input into a long short-term memory (LSTM) time series model. Further calculations are performed to obtain indicator predictions within 12 hours. The predicted indicator values are then input into a multidimensional vector support vector machine (SVM) model to determine the type of potential fault.

[0117] (4) The broadband perception hidden danger network element quality difference model is finally formed through the combination of automatic bin identification + SVM + time series algorithm.

[0118] 2. Optical path hidden danger discovery algorithm: automatic binning and identification + spatial dimension clustering

[0119] (1) For user units, QOE perception service layer indicators and network layer core indicators such as download rate, first screen delay, packet loss rate and number of terminal restarts are established. Continuous variables are established to establish a linear analysis model. Based on the k-means clustering analysis algorithm, each indicator is divided into 10 intervals of 0-10 points, and based on this, the evaluation index of each indicator is formed.

[0120] (2) Evaluation indicators are established based on automatic binning, and volatility indicators (rise or fall rate) are established at adjacent time unit granularity. The above indicators are indicators of user units. Through spatial clustering, the indicators of the optical path unit are calculated according to the average weight of all user units under the same optical path unit to form an evaluation indicator of 0-10 points for the optical path unit. If the evaluation indicator of the optical path unit is set to less than 7, it indicates a hidden optical path problem, and if the volatility indicator drops by 20% in the time unit, it indicates a hidden optical path problem.

[0121] The above method can be used to integrate and analyze big data sources such as QOE perception indicators, faults, and historical user satisfaction (for example, health records such as optical attenuation, user fault reports, download speed, trace first hop delay, first screen delay, ping packet loss rate, number of optical modem dropouts, user dropout rate at the board card, user dropout rate at the PON (Passive Optical Network) port, user dropout rate at the OLT, and user dropout rate at the MSE) to realize a perception quality difference output model. This can solve the problem of high investment and low return in traditional single-indicator alarm processing.

[0122] It can also detect potential hidden dangers and implement predictive maintenance, effectively improving user perception, which is an effective way to improve user satisfaction.

[0123] By exploring hidden dangers, we can also discover some potential needs of users, which can be used as a reference for front-line precision marketing.

[0124] Furthermore, the perception index thresholds obtained through automatic binning, SVM, and time series algorithms can be applied to multiple fields. The resulting perception quality model can identify network elements with potential problems. Furthermore, a combination of automatic binning and spatial dimension clustering can identify potential optical path problems.

[0125] It should be noted that for the sake of simplicity, the method embodiments are described as a series of actions. However, those skilled in the art should be aware that the embodiments of the present invention are not limited by the order of the actions described, because according to the embodiments of the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present invention.

[0126] Reference Figure 4 , which shows a schematic structural diagram of a network anomaly early warning device according to an embodiment of the present invention, and may include the following modules:

[0127] An acquisition module 401 is configured to acquire a target quality of experience (QOE)-aware service layer indicator and a target network layer indicator for the network; the target QOE-aware service layer indicator may include multiple indicators;

[0128] A first prediction module 402 is configured to predict a predicted QOE-perceived service layer indicator and a predicted network layer indicator of a network within a preset time period based on a target QOE-perceived service layer indicator and a target network layer indicator;

[0129] The second prediction module 403 is used to determine the target abnormality type of the network within a preset time period based on the predicted QOE perception service layer indicator and the predicted network layer indicator;

[0130] The alarm module 404 is used to generate an abnormality alarm for the network within a preset time period according to the target abnormality type.

[0131] In an optional embodiment of the present invention, the device further comprises:

[0132] A first training module is configured to obtain first training data, the first training data including QOE-aware service layer indicators and network layer indicators at different times; use the QOE-aware service layer indicators and network layer indicators that are earlier in time sequence in the first training data as input data, and use the QOE-aware service layer indicators and network layer indicators that are later in time sequence in the first training data as output data, to train a first prediction model;

[0133] The first prediction module 402 is used to input the target QOE-aware service layer indicator and the target network layer indicator into the trained first prediction model, and obtain the predicted QOE-aware service layer indicator and the predicted network layer indicator output by the trained first prediction model.

[0134] In an optional embodiment of the present invention, the device further comprises:

[0135] The judgment module is used to determine the target fluctuation trend of the predicted QOE perception business layer indicators and the predicted network layer indicators within a preset time period; based on the target fluctuation trend, it is determined whether it is necessary to execute the step of issuing an abnormal alarm for the network within a preset time period based on the target abnormality type.

[0136] In an optional embodiment of the present invention, the device further comprises:

[0137] a second training module configured to obtain second training data, the second training data including QOE-aware service layer indicators and network layer indicators, and corresponding anomaly types of the anomalies that occurred; and train a second prediction model using the QOE-aware service layer indicators and network layer indicators in the second training data as input data and the corresponding anomaly types of the anomalies that occurred as output data;

[0138] The second prediction module 403 is configured to input the predicted QOE-aware service layer indicator and the predicted network layer indicator into the trained second prediction model, and obtain the target anomaly type output by the trained second prediction model.

[0139] In an optional embodiment of the present invention, the device further comprises:

[0140] The analysis module is used to analyze user needs based on the target exception type.

[0141] In an optional embodiment of the present invention, the network includes network elements, optical paths, and network stations; and the target abnormality type includes any one of the following:

[0142] Abnormal types for network elements, abnormal types for optical paths, and abnormal types for websites.

[0143] In an optional embodiment of the present invention, the target network layer indicators include: download rate, first screen delay, packet loss rate, and number of terminal restarts

[0144] In an embodiment of the present invention, a target QOE-aware business layer indicator and a target network layer indicator are obtained for the network; the target QOE-aware business layer indicator includes a plurality of indicators; based on the target QOE-aware business layer indicator and the target network layer indicator, the predicted QOE-aware business layer indicator and the predicted network layer indicator of the network within a preset time period are predicted; based on the predicted QOE-aware business layer indicator and the predicted network layer indicator, the target abnormality type of the network within the preset time period is determined; based on the target abnormality type, an abnormality alarm of the network within the preset time period is issued. Through the embodiment of the present invention, it is possible to determine whether the network is abnormal based on the predicted information; thereby, an early warning is issued by discovering the abnormality of the network in advance; and further, the impact of the abnormal network on the user is avoided, thereby improving the user's satisfaction with the network. In addition, prediction based on multi-dimensional QOE-aware business layer indicators can improve the accuracy of abnormality prediction.

[0145] An embodiment of the present invention further provides an electronic device, including a processor, a memory, and a computer program stored in the memory and capable of running on the processor. When the computer program is executed by the processor, the above-mentioned network anomaly early warning method is implemented.

[0146] An embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the above-mentioned network anomaly early warning method is implemented.

[0147] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0148] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0149] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, apparatus, or computer program products. Thus, embodiments of the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, embodiments of the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0150] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the process in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0151] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0152] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable terminal device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0153] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they become aware of the basic creative concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.

[0154] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or terminal device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or terminal device that includes the element.

[0155] The above is a detailed introduction to the provided network anomaly warning method, device, electronic device and storage medium. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. At the same time, for those skilled in the art, according to the ideas of the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting the present invention.

Claims

1. A network anomaly early warning method, characterized in that: The method comprises: Obtaining a target quality of experience (QOE)-aware service layer indicator and a target network layer indicator for the network; the target QOE-aware service layer indicator includes a plurality of indicators; Predicting a predicted QOE-aware service layer indicator and a predicted network layer indicator of the network within a preset time period based on the target QOE-aware service layer indicator and the target network layer indicator; Determining a target anomaly type of the network within a preset time period based on the predicted QOE-aware service layer indicator and the predicted network layer indicator; Determining target fluctuation trends of the predicted QOE-aware service layer indicator and the predicted network layer indicator within the preset time period; According to the target fluctuation trend, it is determined whether it is necessary to execute an abnormality alarm of the network within the preset time period according to the target abnormality type.

2. The method according to claim 1, characterized in that The method further comprises: Acquire first training data, where the first training data includes QOE-aware service layer indicators at different times and network layer indicators at different times; The first prediction model is trained by using the QOE-aware service layer indicator and the network layer indicator that are in the earlier time series in the first training data as input data and using the QOE-aware service layer indicator and the network layer indicator that are in the later time series in the first training data as output data; The predicting, based on the target QOE-aware service layer indicator and the target network layer indicator, the predicted QOE-aware service layer indicator and the predicted network layer indicator of the network within a preset time period includes: The target QOE-aware service layer indicator and the target network layer indicator are input into the trained first prediction model, and the predicted QOE-aware service layer indicator and the predicted network layer indicator output by the trained first prediction model are obtained.

3. The method according to claim 1, characterized in that The method further comprises: Obtaining second training data, where the second training data includes QOE-aware service layer indicators and network layer indicators, and anomaly types corresponding to the occurring anomalies; Training a second prediction model using the QOE-aware service layer indicator and the network layer indicator in the second training data as input data and the corresponding exception type of the exception as output data; The determining, based on the predicted QOE-aware service layer indicator and the predicted network layer indicator, a target anomaly type of the network within a preset time period includes: The predicted QOE-aware service layer indicator and the predicted network layer indicator are input into the trained second prediction model, and the target anomaly type output by the trained second prediction model is obtained.

4. The method according to claim 1, wherein The method further comprises: Analyze user needs based on the target exception type.

5. The method according to claim 1, wherein The network includes network elements, optical paths, and websites; the target anomaly type includes any of the following: Abnormal types for network elements, abnormal types for optical paths, and abnormal types for websites.

6. The method according to claim 1, characterized in that The target network layer indicators include: download rate, first screen delay, packet loss rate, and number of terminal restarts.

7. A network anomaly warning device, characterized in that: The device comprises: An acquisition module, configured to acquire a target quality of experience (QOE)-aware service layer indicator and a target network layer indicator for the network; the target QOE-aware service layer indicator includes a plurality of indicators; A first prediction module is configured to predict a predicted QOE-perceived service layer indicator and a predicted network layer indicator of the network within a preset time period based on the target QOE-perceived service layer indicator and the target network layer indicator; A second prediction module is configured to determine a target anomaly type of the network within a preset time period based on the predicted QOE-aware service layer indicator and the predicted network layer indicator; An alarm module is configured to generate an abnormality alarm for the network within the preset time period according to the target abnormality type; The judgment module is used to determine the target fluctuation trend of the predicted QOE perception business layer indicators and the predicted network layer indicators within a preset time period; based on the target fluctuation trend, it is determined whether it is necessary to execute the step of issuing an abnormal alarm for the network within a preset time period based on the target abnormality type.

8. An electronic device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein when the computer program is executed by the processor, the method for early warning of network anomalies according to any one of claims 1 to 6 is implemented.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the network anomaly early warning method according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Fault diagnosis method and device for power grid dispatching support system

    CN115441456A