Fault identification method, device and equipment

By extracting core words from alarms and performing semantic feature recognition, the problems of difficulty in rule files and maintenance in transmission network fault identification are solved, and efficient fault identification is achieved.

CN116644178BActive Publication Date: 2025-11-04XINYANG BRANCH HENAN CO LTD OF CHINA MOBILE COMM CORP +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210135279.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-02-14
Publication Date
2025-11-04
Estimated Expiration
2042-02-14

AI Technical Summary

Technical Problem

In existing technologies, fault identification in transmission networks relies on rule files, which increases the complexity of rule files, limits their adaptability, and makes maintenance difficult.

Method used

By identifying core words from alarms and performing semantic feature recognition based on the core words and their positions in alarm names, the fault identification result is determined by combining the semantic feature recognition results, thus avoiding the need to write rule files.

Benefits of technology

It enables accurate identification of transmission network faults without the need to write rule files, improving adaptability and reducing maintenance difficulty.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116644178B_ABST
    Figure CN116644178B_ABST
Patent Text Reader

Abstract

The application discloses a fault identification method, device and equipment, and the method comprises the following steps: determining a core word from an obtained alarm; the core word is determined according to the name of the alarm; performing semantic feature identification on the alarm according to the core word and the position of the core word in the name of the alarm; and determining a fault identification result according to the semantic feature identification result.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of transmission network, and in particular to a fault identification method, device and equipment. BACKGROUND

[0002] At present, when classifying and identifying the faults of a transmission network, a rule written in advance is usually used. Although the fault identification method based on the rule written in advance can support the correct classification of a certain number of faults, the difficulty of writing the rule file will increase for some complex fault scenarios.

[0003] In addition, the rule file has very limited ability to quickly adapt to newly added or modified fault scenarios, and a large number of repair and condition judgment need to be added to the old rule file, which also makes the maintenance of the rule file extremely difficult. SUMMARY

[0004] Embodiments of the present application provide a fault identification method, device and equipment to solve the problems of difficulty of rule file, limited adaptability and difficult maintenance caused by the rule file based on the written rule file to implement the fault identification of the transmission network in the related art.

[0005] To solve the above technical problems, the present application is implemented as follows:

[0006] In a first aspect, a fault identification method is provided, and the method comprises:

[0007] determining a core word from an obtained alarm; the core word is determined according to a name of the alarm;

[0008] performing semantic feature identification on the alarm according to the core word and a position of the core word in the name of the alarm;

[0009] determining a fault identification result according to the semantic feature identification result.

[0010] In a second aspect, a fault identification device is provided, and the device comprises:

[0011] a determination module configured to determine a core word from an obtained alarm; the core word is determined according to a name of the alarm;

[0012] a first identification module configured to perform semantic feature identification on the alarm according to the core word and a position of the core word in the name of the alarm;

[0013] a second identification module configured to determine a fault identification result according to the semantic feature identification result.

[0014] In a third aspect, a fault identification device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, which, when executed by the processor, implements the steps of the method according to the first aspect.

[0015] In a fourth aspect, a computer readable storage medium is provided, which stores a computer program, which, when executed by a processor, implements the steps of the method according to the first aspect.

[0016] The above at least one technical solution provided by the embodiments of the present application can achieve the following technical effects:

[0017] In the embodiments of the present application, the core word of the alarm can be determined according to the name of the alarm, and the semantic feature of the alarm can be identified according to the core word and the position of the core word in the name of the alarm, and the fault identification result can be determined according to the semantic feature identification result.

[0018] As can be known from the content of the embodiments of the present application, the embodiments of the present application can identify the fault according to the core word in the name of the alarm and the position of the core word. Since it is not necessary to write a rule file and identify the fault according to the rule file, the problem of difficulty in rule file, limited adaptability, and difficulty in maintenance caused by the implementation of the transmission network fault identification based on the writing of the rule file in the prior art can be effectively solved. BRIEF DESCRIPTION OF DRAWINGS

[0019] The accompanying drawings, which are included to provide a further understanding of the present application and constitute a part of this application, illustrate embodiments of the present application and together with the description serve to explain the present application. In the drawings:

[0020] Figure 1 One of the flowcharts of the fault identification method provided by an embodiment of the present application;

[0021] Figure 2 The second flowchart of the fault identification method provided by an embodiment of the present application;

[0022] Figure 3 The alarm feature template diagram shown by an embodiment of the present application;

[0023] Figure 4 The structure diagram of the sample service feature vector shown by an embodiment of the present application;

[0024] Figure 5 The module composition diagram of the fault identification device 500 provided by an embodiment of the present application;

[0025] Figure 6 A schematic diagram of a hardware structure of a fault identification device provided for an embodiment of the present application is shown in FIG. 1. DETAILED DESCRIPTION

[0026] In order to make the objectives, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be described below in detail with reference to specific embodiments of the present application and corresponding drawings. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.

[0027] The technical solutions provided by the embodiments of the present application will be described in detail below with reference to the drawings.

[0028] Please refer to Figure 1 , Figure 1 A schematic diagram of a flow of a fault identification method provided for an embodiment of the present application is shown in FIG. 2, and the method includes the following steps: Figure 1

[0029] Step 102: determining a core word from the obtained alarms; the core word is determined according to the name of the alarm.

[0030] Step 104: performing semantic feature identification on the alarm according to the core word and the position of the core word in the name of the alarm.

[0031] Step 106: determining a fault identification result according to the result of the semantic feature identification.

[0032] In an embodiment of the present application, when a fault occurs, the currently generated alarms can be obtained. When the generated alarms are obtained, the compressed and aggregated alarms can be obtained.

[0033] In an embodiment of the present application, the obtained transmission network alarms can have been compressed and aggregated. The alarm compression and aggregation can aggregate the related alarms together to form alarm sets.

[0034] After the compressed and aggregated alarms are obtained, the core words of the alarms can be determined according to the names of the alarms.

[0035] When the core word is determined from the obtained alarms, the name of the alarm can be first processed by word segmentation to obtain a plurality of words, then the obtained plurality of words can be sorted based on the TF-IDF algorithm, and the words at the front of the sorting are determined as the core word. The core word can be one or multiple, and the present embodiment does not limit this.

[0036] ​In one embodiment, when extracting the core words of the alarm, some words which have little influence on the representation of the fault object and have limited influence on the fault classification can be filtered first, such as BAD, ABN, HIGH, LOW or ABN, and the like. These words have a large number of occurrences, but have small information entropy. Therefore, the TF-IDF algorithm is used to sort and filter the obtained multiple words in this embodiment. The words at the top of the ranking are the words representing the fault object, such as PWR, TEMP, FAN, NE, and the like. These words have a small number of occurrences, but have large information entropy, indicating the location and object of the fault. These words can be used as core words.

[0037] In one example, the core words are shown in Table 1.

[0038] Table 1

[0039]

[0040] As shown in Table 1, according to the names of the alarms in Table 1, the high-frequency words LOS, PWR and TEMP can be determined respectively. Then, the three high-frequency words can be used as the core words of the corresponding alarms, for example, LOS can be used as the core word of ETH_LOS and R_LOS.

[0041] After the core words of the alarms are determined, the semantic feature recognition of the alarms can be performed according to the core words and the positions of the core words in the names of the alarms.

[0042] In one embodiment of the present application, after the core words are obtained, the core words can be used to represent a type of alarms, for example, the alarms FAN_FAIL, FAN_BAD and FAIL_ABN can all be replaced by the core word FAN. However, in some cases, the position information of the core word also needs to be added, for example, TEMP_OVER and ENV_TEMP_OVER. One is that the device temperature is high, and the other is that the environment temperature is high. The represented objects are different, but if the core word TEMP is used for classification, the two alarms will be classified into one type, which will lead to inaccurate fault classification results. The position of TMEP in TMEP_OVER is at the head, and the position of TMEP in ENV_TEMP_OVER is in the middle. Therefore, the position information can be used to distinguish them. Therefore, in the final core word representation form, the core word + position is used for processing, that is, FAN-head represents all FAN_XX alarms, TEMP-head represents all device temperature related alarms, and TEMP-middle represents all environment temperature related alarms. Table 2 shows the following:

[0043] Table 2

[0044]

[0045] In an embodiment of the present application, before determining the core word from the acquired alarm, it can be determined whether the acquired alarm is a structured alarm, wherein the structure of the name of the structured alarm satisfies a preset structure condition.

[0046] In an embodiment, the preset structure condition can be: the structure is fault subject + fault type. For example, the alarm shown in Table 3 is a structured alarm.

[0047] Table 3

[0048] Alarm name Fault type FAN_FAIL Fan failure POWER_ABNORMAL Power failure TEMP_OVER High temperature failure

[0049] The name of the alarm shown in Table 3, such as FAN_FAIL, satisfies the "fault subject + fault type", and therefore the alarm described in Table 3 is a structured alarm.

[0050] For example, the alarm shown in Table 4 is not a structured alarm:

[0051] Table 4

[0052]

[0053]

[0054] The name of the alarm shown in Table 4, such as COMMUN_FAIL, has no fault subject in the name, only fault type, and therefore does not satisfy the "fault subject + fault type", and therefore the alarm described in Table 4 is not a structured alarm.

[0055] In an embodiment of the present application, when the alarm is not a structured alarm, the name of the alarm can be structurally modified so that the modified name satisfies the preset structure condition. The structural modification can include at least one of the following: supplementing the alarm subject, completing the abbreviation.

[0056] In an embodiment of the present application, for unstructured alarm names, since the semantic information contained in the original alarm name is not clear, for example, BUS_ERR alarm, BUS and ERR after word segmentation cannot correspond to the fault subject, and for example, COMMUN_FAIL, COMMU and FAIL after word segmentation also cannot indicate which module communication fails, therefore, the unstructured alarm name can be first structured and modified, the alarm subject is supplemented, the meaning of the subject is clarified, and the abbreviation is perfected, for example, as shown in Table 5:

[0057] Table 5

[0058] Alarm name Alarm after supplementing the main body COMMUN_FAIL BOARD_COMMUN_FAIL BUS_ERR BOARD_BUS_ERR

[0059] The alarm names shown in Table 5, such as COMMUN_FAIL, originally only contained the fault type, not the fault subject. After adding the fault subject BOARD, the alarm name became BOARD_COMMUN_FAIL, satisfying the condition of "fault subject + fault type". Therefore, the alarms shown in Table 5, after structural modification, meet the preset structural conditions and can be identified as structured alarms.

[0060] After restructuring the names of unstructured alarms, structured alarms can be obtained. Then, the core keywords of the alarms and their positions within the alarm names can be determined, as shown in Table 6:

[0061] Table 6

[0062]

[0063] In one embodiment of the present invention, semantic feature recognition can be performed based on the core words and their positions in the alarm name, and the fault recognition result can be determined based on the semantic feature recognition result.

[0064] In this embodiment of the invention, semantic recognition results can be obtained based on core words and their positions in the alarm names. For example, TEMP-head represents all alarms related to device temperature, and TEMP-middle represents all alarms related to ambient temperature. After obtaining the semantic recognition results, the fault identification results can be determined based on these results. For instance, if the semantic recognition result is an alarm related to device temperature, the fault identification result can be determined to be a fault related to device temperature.

[0065] Please see Figure 2 This is a second schematic flowchart of a fault identification method provided in an embodiment of the present invention, as shown below. Figure 2 As shown, after acquiring the original alarm, it can be first determined whether the alarm is a structured alarm. If it is a structured alarm, the multiple words obtained after word segmentation can be sorted using the TF-IDF algorithm, and the core words can be determined based on the sorting results. If it is not a structured alarm, the alarm name can be structurally modified by adding fault information to convert it into a structured alarm. When converting to a structured alarm, the conversion can be performed using the format of core words + position. After conversion to a structured alarm, the multiple words obtained after word segmentation can be sorted using the TF-IDF algorithm, and the core words can be determined based on the sorting results.

[0066] After identifying the core words, we can further determine the position of the core words in the alarm name, and determine the semantic feature recognition result based on the core words + position, and then determine the fault recognition result based on the semantic feature recognition.

[0067] Since the detailed implementation process of the embodiment of the application has been described in the previous embodiment, the embodiment of the application will not be described here again.

[0068] In an embodiment of the application, after determining the semantic feature recognition result according to the core word and the position where the core word is located, if the semantic feature recognition result indicates one fault category, the fault category indicated by the semantic feature recognition result can be determined as the fault recognition result; if the semantic feature recognition result indicates multiple fault categories or cannot indicate the fault category, i.e., the fault category cannot be determined according to the semantic feature recognition result, the service feature of the alarm can be extracted, and the fault recognition of the alarm can be performed based on the extracted service feature to obtain the fault recognition result.

[0069] In an embodiment of the application, a single alarm semantic can correspond to multiple fault categories, for example, the ETH_LOS alarm can be a port one-way no light, a port two-way mutual no light or a network element off service fault category, and only relying on the semantic information cannot correctly classify. In addition, when the alarm contains multiple fault subjects, only relying on the semantic information cannot correctly classify, for example, when containing the ETH_LOS and BD_STATUS alarms, according to the alarm semantic analysis, it can be a single board fault, or it can be a line fault, and cannot be accurately classified.

[0070] When the fault category cannot be determined according to the semantic feature recognition result, the service feature of the alarm can be extracted.

[0071] In an embodiment of the application, the service feature of the alarm can be extracted through the alarm feature template to obtain a service feature matrix. The alarm feature template can include multiple service feature attribute judgment conditions, the service feature matrix can include the values of the alarm under the multiple service feature attribute judgment conditions, and the multiple service feature attributes in the alarm feature template are independent of each other.

[0072] Please refer to Figure 3 , which is an alarm feature template diagram shown in an embodiment of the application.

[0073] In an embodiment of the application, the alarm feature template can be obtained based on the fault classification purpose, combined with historical expert experience for summary, so that Figure 3 Taking the ETH_LOS alarm as an example, the alarm obtained contains the ETH_LOS alarm, when the port corresponding to the ETH_LOS alarm is the user side, it can be identified as a user side line fault; when the alarm contains multiple ETH_LOS alarms, and the two ports reporting the ETH_LOS alarm are opposite to each other, it can be identified as a port two-way mutual no light; the alarm feature template corresponding to the ETH_LOS alarm can be generated based on the above description, and can be summarized and improved based on the historical fault classification data and expert experience.

[0074] The feature template use process is a constantly revised and improved process. When it is found that the business feature attribute judgment condition is insufficient to support fault classification, such as the fault classification result and the expectation are inconsistent, a new influencing factor appears in the fault scenario, the business feature attribute judgment condition needs to be revised based on the newly appeared scenario, and the model used for identifying the fault category is retrained to ensure that the new model can accurately classify.

[0075] When extracting the feature attributes of the alarm, each business feature attribute judgment condition used for extracting the feature attributes is independent of each other and does not affect each other. The business feature attribute belongs to the "atomic" granularity. For example, for the feature attribute 2 and the feature attribute 3 of the ETH_LOS, they are at the "atomic" granularity, and the feature cannot be further subdivided. On the contrary, a poor feature attribute is, for example, a newly generated feature attribute of the ETH_LOS, which is used to detect whether there is a fiber between the ports connected by multiple LOS alarms. This feature includes two features, i.e., the number of LOS alarms and whether there is a fiber between the LOS alarm ports. The feature is not in the "atomic" state, and the feature needs to be processed based on the principle of "atomic" state in the feature attribute selection process. The feature cannot be further divided, which is good. When constructing the feature, the feature cannot be further decomposed.

[0076] In an embodiment of the present application, after the business features are extracted, the alarm can be identified according to the business feature matrix and the classification neural network model, wherein the classification neural network model adopts a neural network back propagation model.

[0077] In an embodiment of the present application, the alarm feature matrix obtained by the alarm feature template can be as shown in Table 7 and Table 8:

[0078] Table 7

[0079]

[0080]

[0081] Table 8

[0082]

[0083] By collecting and analyzing the alarm historical data, the fault identification result of part of the historical alarm can be determined, that is, the fault label value of the training sample can be determined. In this way, the classification neural network model corresponding to the alarm can be trained based on the neural network model. The neural network is a supervised learning algorithm, which can be divided into two lines of offline training and online prediction. The feature extraction has a corresponding feature template, which mainly corresponds to the alarm one by one. In an embodiment, the classification neural network model can adopt a neural network back propagation model.

[0084] In the embodiment of the present application, before the fault identification of the alarm according to the service feature matrix and the classification neural network model, a sample service feature matrix can also be obtained first, and the sample service feature matrix is subjected to vectorization processing to obtain a sample service feature vector. The sample feature vector includes the number of a sample alarm corresponding to the sample service feature matrix, the value of the sample service feature matrix, and a fault scene label value corresponding to the sample alarm. The number of the sample alarm can be used to identify the alarm event type corresponding to the sample alarm, and then the classification neural network model can be trained according to the sample service feature vector.

[0085] In the embodiment of the present application, the training process of the classification neural network model can be a standard supervised learning process, and the training process is described in detail below. The training samples are derived from a historical fault list, and the alarm and fault categories are known. At this time, the fault can be converted into a feature matrix according to the alarm feature template. Taking Table 7 and Table 8 as examples, Table 7 corresponds to a fault, which only includes an ETH_LOS alarm. The service feature matrix is obtained by performing service feature extraction on the ETH_LOS alarm according to the alarm feature template of ETH_LOS, and the obtained service feature matrix is subjected to vectorization processing. Table 8 also corresponds to a fault, which includes ETH_LOS and BD_STATUS alarms. Therefore, the service feature matrix is obtained by performing service feature extraction on the ETH_LOS and BD_STATUS alarms according to the alarm feature templates of ETH_LOS and BD_STATUS respectively, and the obtained service feature matrix is subjected to vectorization processing. Here, the alarms are sorted, for example, the ETH_LOS alarm is in the first row of the feature matrix, and the single board alarm represented by BD_STATUS is in the fourth row of the feature matrix. In this way, the unified position facilitates subsequent sample calculation and classification model training.

[0086] In one embodiment of the present application, semantic information can also be integrated into the service feature matrix, for example, the PWR-middle semantic information in the second row of Table 7 and Table 8. When a fault includes alarms such as IN_PWR_ABN, OUT_PWR_ABN, OUT_PWR_HIGH_ABN or IN_PWR_HIGH_ABN, the PWR-middle can be used for unified processing to avoid feature extraction for each alarm, thereby improving the overall efficiency.

[0087] When the service feature matrix is subjected to vectorization processing, in order to save space, for example, a fault can only include an ETH_LOS alarm, and the feature matrix must include all alarms, which will obviously cause great waste of storage space. Based on this, the embodiment of the present application further converts the service feature matrix once again, as shown in Table 9. Figure 4 ​

[0088] As Figure 4 shown in the sample data, the first half corresponds to the training input of the model; the latter half corresponds to the label data of the model, where (0, 0, 0, 1) represents fault scenario 4. The first half contains all the alarm feature attribute vectors of the fault sample, as shown in Table 8, the fault sample data contains two alarms, so it has two alarm feature attribute vectors. As to the alarm feature attribute vector, the first bit is the alarm number, which is introduced as an alarm marker bit to clearly indicate the alarm event type corresponding to this part of the feature vector. Different alarms may have the same alarm features. The scheme first determines the alarm event type, and then the alarm feature attribute vector, thereby increasing the accuracy of the model. Followed by the feature attribute vector obtained by this alarm according to the feature extraction template, combined with Figure 3 the corresponding relationship between the alarm and its alarm position number in Figure 4 , it can be seen that Figure 3 represents the ETH_LOS alarm feature attribute vector (1, 0, 0, 0, 0, 1) and the BD_STATUS alarm feature attribute vector (1, 0, 0, 0, 0, 0), which are combined to form a feature matrix, representing fault scenario 4. Table 9 lists the corresponding fault scenario label data:

[0089] Table 9

[0090] Fault scene number Label data mode Fault scene classification result 1 (1,0,0,0) One-way no-reception light caused by fiber problem 2 (0,1,0,0) One-way no-reception light caused by network element withdrawal 3 (0,0,1,0) Two-way no-reception light caused by fiber problem 4 (0,0,0,1) No-reception light at the opposite end caused by local board failure

[0091] Since the alarm feature attribute mines the possible root cause of the fault, the result of the algorithm classification is no longer limited to the fault phenomenon, but adopts a more fine-grained classification method of fault root cause + fault phenomenon.

[0092] After confirming the input and label data of the model, the model can be trained based on the collected sample data. Through testing, it is found that the model trained by the BP back-propagation neural network can accurately classify faults, where the number of intermediate layer nodes can be 16, the learning coefficient can be 0.15, and the number of iteration training times can be 5000.

[0093] After the training of the classification neural network model is completed, the model can be used to identify and predict faults. For example, the alarm FAN_FAIL, the device temperature alarm TEMP_OVER, the single board alarm HARD_BAD, and two ETH_LOS alarms are aggregated in the alarm. Through the word segmentation processing, the core word + position "FAN-head" and "TEMP-head" can be extracted from the structured alarms FAN_FAIL and TEMP_OVER. However, the fault subject indicated by "TEMP-head" is not clear, and the specific fault category cannot be indicated, so the fault identification result cannot be directly determined according to the semantic feature recognition result.

[0094] The remaining two alarms, the HARD_BAD alarm, need to be clear about the fault subject, which is (BOARD_)HARD_BAD, that is, the subject of the HARD_BAD alarm is the single board. However, since the specific hardware fault is not indicated, the fault identification result cannot be determined according to the semantic feature recognition result. The ETH_LOS alarm can indicate multiple fault categories, so the fault identification result cannot be directly determined according to the semantic feature recognition result.

[0095] After the semantic analysis is completed, the business feature matrix needs to be extracted according to the alarm feature template mainly for the TEMP_OVER, HARD_BAD, and ETH_LOS alarms. The extraction result can be as shown in Table 10:

[0096] Table 10

[0097]

[0098] As shown in Table 10, the business feature matrix corresponding to the fault can be:

[0099] 1, 0, 0, 1

[0100] 1, 0, 0, 0

[0101] 1, 1, 1, 0

[0102] 1, / , / , /

[0103] The matrix is input into the trained classification neural network model, and the final fault identification result is obtained: the fan is damaged, causing the network element to retire.

[0104] In the embodiments of the present application, the core word of the alarm can be determined according to the name of the alarm, and the semantic feature of the alarm can be recognized according to the core word and the position of the core word in the name of the alarm, and the fault identification result can be determined according to the semantic feature recognition result.

[0105] From the content of the embodiment of the present application, it can be known that the embodiment of the present application can identify the fault according to the core word in the alarm name and the position where the core word is located. Since it is not necessary to write a rule file and it is not necessary to identify the fault according to the rule file, the problem that the rule file is difficult to write, the adaptive capacity is limited and the maintenance is difficult due to the implementation of the transmission network fault identification based on the rule file in the prior art can be effectively solved.

[0106] Corresponding to the above fault identification method, the embodiment of the present application further provides a fault identification device, Figure 5 The module composition schematic diagram of the fault identification device 500 provided by the embodiment of the present application is shown in Figure 5 As shown in the figure, the fault identification device 500 comprises:

[0107] A determination module 501 is configured to determine a core word from the obtained alarm; the core word is determined according to the name of the alarm;

[0108] A first identification module 502 is configured to perform semantic feature identification on the alarm according to the core word and the position where the core word is located in the name of the alarm;

[0109] A second identification module 503 is configured to determine a fault identification result according to the semantic feature identification result.

[0110] Optionally, the determination module 501 is configured to:

[0111] perform word segmentation processing on the name of the alarm to obtain a plurality of words;

[0112] sort the obtained plurality of words based on a TF-IDF algorithm;

[0113] determine the words at the front of the sorting as the core word.

[0114] Optionally, the device further comprises Figure 5 which is not shown in the figure)

[0115] A judgment module 504 is configured to determine whether the obtained alarm is a structured alarm before determining the core word from the obtained alarm; wherein the structure of the name of the structured alarm satisfies a preset structure condition;

[0116] A modification module 505 is configured to perform structure modification on the name of the alarm when the alarm is not a structured alarm, so that the name after the structure modification satisfies the preset structure condition; wherein the structure modification at least comprises one of the following: supplementing a fault subject, supplementing an abbreviation;

[0117] The determination module 501 is configured to:

[0118] Determine a core word from a structured alarm.

[0119] Optionally, the second identification module 503 is configured to:

[0120] When the semantic feature identification result indicates one fault category, determine the fault category indicated by the semantic feature identification result as the fault identification result;

[0121] When the semantic feature identification result indicates multiple fault categories or cannot indicate a fault category, perform service feature extraction on the alarm, and perform fault identification on the alarm based on the extracted service features to obtain a fault identification result.

[0122] Optionally, the second identification module 503 is further configured to:

[0123] extract service features of the alarm through an alarm feature template to obtain a service feature matrix; the alarm feature template includes multiple service feature attribute judgment conditions; the service feature matrix includes values of the alarm under the multiple service feature attribute judgment conditions; and the multiple service feature attributes in the alarm feature template are independent of each other.

[0124] Optionally, the second identification module 503 is further configured to:

[0125] perform fault identification on the alarm according to the service feature matrix and a classification neural network model; the classification neural network model adopts a neural network back propagation model.

[0126] Optionally, the apparatus further includes (not shown in the figure): Figure 5

[0127] The first acquisition module 306 is configured to acquire a sample service feature matrix.

[0128] The second acquisition module 307 is configured to perform vectorization processing on the sample service feature matrix to obtain a sample service feature vector; the sample feature vector includes a number of a sample alarm corresponding to the sample service feature matrix, a value of the sample service feature matrix, and a fault scene label value corresponding to the sample alarm; and the number of the sample alarm is used to identify an alarm event type corresponding to the sample alarm.

[0129] The training module 308 is configured to train a classification neural network model according to the sample service feature vector.

[0130] The second identification module 503 is further configured to:

[0131] perform fault identification on the alarm according to the service feature vector and the trained classification neural network model. ​

[0132] In the embodiments of the present application, the core word of the alarm can be determined according to the name of the alarm, and the semantic feature of the alarm can be recognized according to the core word and the position of the core word in the name of the alarm, and the fault recognition result can be determined according to the semantic feature recognition result.

[0133] As can be seen from the content of the embodiments of the present application, the embodiments of the present application can recognize the fault according to the core word in the name of the alarm and the position of the core word. Since it is not necessary to write a rule file and it is not necessary to recognize the fault according to the rule file, the problem that the rule file is difficult to write, the adaptability is limited, and the maintenance is difficult due to the implementation of the transmission network fault recognition based on the rule file in the prior art can be effectively solved.

[0134] Corresponding to the above fault recognition method, the embodiments of the present application also provide a fault recognition device, Figure 6 The hardware structure schematic diagram of the fault recognition device provided by one embodiment of the present application is shown.

[0135] The fault recognition device can be a terminal device or a server provided by the above-mentioned embodiments for identifying faults.

[0136] The fault recognition device can have great differences due to different configurations or performances, and can include one or more processors 601 and memories 602, and one or more storage applications or data can be stored in the memories 602. The memory 602 can be temporary storage or persistent storage. The application stored in the memory 602 can include one or more modules (not shown in the figure), and each module can include a series of computer executable instructions in the fault recognition device. Further, the processor 601 can be configured to communicate with the memory 602 and execute a series of computer executable instructions in the memory 602 on the fault recognition device. The fault recognition device can also include one or more power supplies 603, one or more wired or wireless network interfaces 604, one or more input / output interfaces 605, and one or more keyboards 606.

[0137] Specifically, in the present embodiment, the fault recognition device includes a memory and one or more programs, wherein one or more programs are stored in the memory, and one or more programs can include one or more modules, and each module can include a series of computer executable instructions in the fault recognition device, and configured to be executed by one or more processors to implement the above-mentioned embodiments.

[0138] In the embodiment of the present application, the core word of the alarm can be determined according to the name of the alarm, the semantic feature of the alarm can be recognized according to the core word and the position of the core word in the name of the alarm, and the fault recognition result can be determined according to the semantic feature recognition result.

[0139] As can be seen from the content of the embodiment of the present application, the embodiment of the present application can recognize the fault according to the core word in the alarm name and the position of the core word. Since it is not necessary to write a rule file and recognize the fault according to the rule file, the problem that the rule file is difficult to write, the adaptability is limited, and the maintenance is difficult due to the realization of the transmission network fault recognition based on the writing of the rule file in the prior art can be effectively solved.

[0140] In the 1990s, it was relatively easy to distinguish whether an improvement in a technology was a hardware improvement (e.g., an improvement in the circuit structure of a diode, transistor, switch, etc.) or a software improvement (an improvement in a method flow). However, as technology has evolved, many improvements in method flows today can be considered as direct improvements in hardware circuit structures. Designers almost always obtain the corresponding hardware circuit structures by programming the improved method flows into hardware circuits. Therefore, it cannot be said that an improvement in a method flow cannot be implemented using hardware entity modules. For example, a programmable logic device (PLD) (e.g., a field programmable gate array (FPGA)) is an integrated circuit whose logic function is determined by user programming of the device. A digital system is "integrated" on a PLD by the designer programming the PLD, rather than by ordering a chip manufacturer to design and fabricate a custom integrated circuit chip. Moreover, instead of manually fabricating integrated circuit chips, this programming is now mostly implemented using "logic compiler" software, which is similar to software compilers used in program development, and the original code to be compiled is written in a specific programming language, which is called a hardware description language (HDL), and there are many such languages, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc., and the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should be aware that, as long as the method flow is logically programmed in the above-mentioned hardware description languages and programmed into an integrated circuit, a hardware circuit implementing the logical method flow can be easily obtained.

[0141] The controller can be implemented in any suitable way, for example, the controller can take the form of a microprocessor or processor and a computer readable medium storing computer readable program code, such as software or firmware, executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller and an embedded microcontroller, examples of which include but are not limited to the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20 and Silicone Labs C8051F320, the memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also know that, in addition to being implemented in pure computer readable program code, the controller can equally well be implemented to perform the same functions using logic gates, switches, an application specific integrated circuit, a programmable logic controller and an embedded microcontroller, etc. by means of a logical programming of the method steps. The controller can thus be considered as a hardware component, and the means comprised therein for performing the various functions can be considered as structures within the hardware component. Alternatively, the means for performing the various functions can even be considered as both a software module implementing the method and a structure within the hardware component.

[0142] The systems, apparatuses, modules or units illustrated by the above embodiments can be implemented by computer chips or entities, or products with certain functions. A typical implementation device is a computer. Specifically, the computer can be a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0143] For the sake of description, the above apparatuses are described in various units with functions respectively. Of course, the functions of the units can be implemented in one or more software and / or hardware in the implementation of the present application.

[0144] Those skilled in the art will understand that the embodiments of the present application can be provided as a method, a system or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer usable program code.

[0145] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flowcharts and / or blocks in the flowcharts and / or combination thereof. Figure 1 one or more flowcharts and / or blocks in the flowcharts and / or combination thereof.

[0146] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flowcharts and / or blocks in the flowcharts and / or combination thereof. Figure 1 one or more flowcharts and / or blocks in the flowcharts and / or combination thereof.

[0147] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flowcharts and / or blocks in the flowcharts and / or combination thereof. Figure 1 one or more flowcharts and / or blocks in the flowcharts and / or combination thereof.

[0148] In one typical configuration, the computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0149] The memory can include non-persistent memory and / or volatile memory, such as random access memory (RAM) and / or cache memory, non-volatile memory, such as read-only memory (ROM), EPROM, and / or flash memory. The memory is an example of computer-readable media.

[0150] Computer-readable media includes permanent and non-permanent, movable and non-movable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.

[0151] It should also be noted that the terms "comprising", "comprising" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or apparatus that includes a list of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or apparatus. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or apparatus that includes the element.

[0152] Those skilled in the art will appreciate that embodiments of the present application can be provided as a method, system or computer program product. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0153] The present application can be described in the general context of computer-executable instructions, such as program modules, being executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform particular tasks or implement particular abstract data types. The present application can also be practiced in a distributed computing environment where tasks are performed by remote processing devices that are connected through a communication network. In a distributed computing environment, program modules can be located in both local and remote computer storage media including storage devices.

[0154] The various embodiments described in this specification are intended to be exemplary only. The same elements having the same reference numerals designate the same elements throughout the various embodiments. Each embodiment described in this specification is intended to be exemplary only. The same elements having the same reference numerals designate the same elements throughout the various embodiments. Each embodiment described in this specification is intended to be exemplary only, and each embodiment highlights the differences from other embodiments. In particular, the system embodiments are described more simply, as they are substantially similar to the method embodiments, and reference is made to the relevant parts of the method embodiments.

[0155] The above description is merely illustrative of the embodiments of the present application and is not intended to limit the present application. The present application can be modified and changed in various ways by those skilled in the art. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the scope of the claims of the present application.

Claims

1. A fault identification method, characterized in that, The method includes: The core keywords are determined from the acquired alarms; the core keywords are determined based on the name of the alarm. Based on the core words and their position in the name of the alarm, the alarm is semantically identified. The fault identification result is determined based on the semantic feature recognition result; Before determining the core keywords from the acquired alarms, the method further includes: Determine whether the acquired alarm is a structured alarm; wherein, the structure of the name of the structured alarm satisfies a preset structure condition; the preset structure is fault subject + fault type; When the alarm is not a structured alarm, the name of the alarm is structurally modified so that the modified name meets the preset structural conditions; wherein, the structural modification includes at least one of the following: supplementing the fault subject, or completing the abbreviation; The process of identifying core keywords from the acquired alarms includes: Identify core keywords from structured alerts.

2. The method according to claim 1, characterized in that, The process of identifying core keywords from the acquired alarms includes: The alarm name is segmented into multiple words. The resulting multiple words are sorted based on the TF-IDF algorithm; The words that appear at the top of the list are identified as core words.

3. The method according to claim 1, characterized in that, The step of determining the fault identification result based on the semantic feature recognition result includes: When the semantic feature recognition result indicates a fault category, the fault category indicated by the semantic feature recognition result is determined as the fault recognition result; When the semantic feature recognition result indicates multiple fault categories or cannot indicate a fault category, the alarm is subjected to business feature extraction, and the alarm is subjected to fault recognition based on the extracted business features to obtain the fault recognition result.

4. The method according to claim 3, characterized in that, The process of extracting business features from the alarm includes: The alarm features are extracted using an alarm feature template to obtain a service feature matrix. The alarm feature template includes multiple service feature attribute judgment conditions. The service feature matrix includes the values ​​of the alarm under the multiple service feature attribute judgment conditions. The multiple service feature attributes in the alarm feature template are independent of each other.

5. The method according to claim 4, characterized in that, The fault identification of the alarm based on the extracted business features includes: The alarm is identified based on the business feature matrix and the classification neural network model; the classification neural network model adopts the neural network backpropagation model.

6. The method according to claim 5, characterized in that, Before performing fault identification on the alarm based on the business feature matrix and the classification neural network model, the method further includes: Obtain the sample business feature matrix; The sample service feature matrix is ​​vectorized to obtain a sample service feature vector; wherein, the sample service feature vector includes the number of the sample alarm corresponding to the sample service feature matrix, the value of the sample service feature matrix, and the fault scenario label value corresponding to the sample alarm; the number of the sample alarm is used to identify the alarm event type corresponding to the sample alarm; The classification neural network model is trained based on the sample business feature vectors; The step of identifying faults in the alarms based on the business feature matrix and the classification neural network model includes: The business feature matrix is ​​vectorized to obtain the business feature vector; The alarm is identified based on the business feature vector and the trained classification neural network model.

7. A fault identification device, characterized in that, The device includes: A determination module is used to determine core keywords from the acquired alarms; the core keywords are determined based on the name of the alarm. The first identification module is used to perform semantic feature identification on the alarm based on the core word and the position of the core word in the name of the alarm; The second identification module is used to determine the fault identification result based on the semantic feature identification result; The device is also used for: Before determining the core keywords from the acquired alarms, it is determined whether the acquired alarms are structured alarms; wherein, the structure of the name of the structured alarm satisfies a preset structure condition; the preset structure is fault subject + fault type; When the alarm is not a structured alarm, the name of the alarm is structurally modified so that the modified name meets the preset structural conditions; wherein, the structural modification includes at least one of the following: supplementing the fault subject, or completing the abbreviation; The process of identifying core keywords from the acquired alarms includes: Identify core keywords from structured alerts.

8. A fault identification device, characterized in that, include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the steps of the method as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Fault classification method, storage medium and computer device

    CN108388601A

  • Event-based autonomous identification method for power grid monitoring alarm information

    CN110263172A