Alarm classification method and device, electronic equipment and storage medium

By constructing an alarm classification model based on fractal dimension and hypersphere, and using support vector machine for alarm classification, the problems of single model and high dependence on manual operation in existing technologies are solved, and efficient and accurate alarm processing is achieved.

CN116933111BActive Publication Date: 2026-01-20SHANXI CHINA MOBILE COMM CORP +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210328995.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-30
Publication Date
2026-01-20
Estimated Expiration
2042-03-30

AI Technical Summary

Technical Problem

In existing technologies, alarm classification and processing suffer from a single, linear model that easily ignores historical fluctuations, resulting in low accuracy of boundary alarms. Furthermore, it relies heavily on manually configured screening conditions, leading to a high probability of misjudgment and poor processing performance.

Method used

By constructing an alarm classification model based on the fractal dimension and hypersphere of sample alarm data, and using support vector machines for classification regression to predict the direction of alarm evolution, the alarm classification model is trained by constructing polyhedra and hyperspheres for integration and clustering.

Benefits of technology

It improved the accuracy and efficiency of alarm classification, optimized alarm handling solutions, and enhanced user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116933111B_ABST
    Figure CN116933111B_ABST
Patent Text Reader

Abstract

The application provides an alarm classification method and device, electronic equipment and storage medium, wherein the method comprises: determining alarm data to be classified; inputting the alarm data into an alarm classification model to obtain an alarm type output by the alarm classification model; the alarm classification model is obtained by training sample alarm data on the basis of an initial alarm classification model; the volume of a hypersphere constructed on the basis of a sample alarm attribute set is determined as the initial alarm classification model; the sample alarm attribute set is determined on the basis of a fractal dimension of sample alarm data; the fractal dimension reflects an alarm evolution direction of the sample alarm data; the alarm evolution direction is analyzed on the basis of full alarm data and is iteratively updated; the sample alarm attribute set is constructed under the condition that the alarm tends to be stable; and the alarm classification model is constructed on the basis of the set to classify the alarm, so that the defects of low alarm processing efficiency and poor classification accuracy in the traditional scheme are overcome, and the optimization of the alarm processing scheme and the improvement of the processing effect are realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, and in particular to an alarm classification method and device, electronic equipment and storage medium. BACKGROUND

[0002] With the rapid development of the electronic channel business market of operators, there are more and more exposed channels, and the system complexity is also higher. At this time, in order to meet the development and maintenance needs of operation and maintenance personnel, the alarm can be classified and processed to improve the processing efficiency.

[0003] At present, the classification processing of the alarm is to label the alarm and classify it according to the label. Specifically, the system filters the label, and the configuration and combination of the filtering conditions are completed by manual or system. However, in the above process, the setting of the label is derived from the long-term alarm characteristics, which undoubtedly leads to a single and linear alarm portrait model, and the fluctuation effect of a period / historical period is easily ignored, resulting in low accuracy of boundary alarm. In addition, in the above scheme, the process of manually configuring the filtering condition has strong subjectivity, which makes the subsequent label filtering process too dependent on manual experience, resulting in a large probability of misjudgment and poor alarm processing effect. SUMMARY

[0004] The present application provides an alarm classification method, device, electronic equipment and storage medium to solve the defects of poor alarm processing state, low processing efficiency and poor alarm classification accuracy in the prior art.

[0005] The present application provides an alarm classification method, comprising:

[0006] determining alarm data to be classified;

[0007] inputting the alarm data into an alarm classification model to obtain an alarm type output by the alarm classification model;

[0008] The alarm classification model is obtained by training sample alarm data based on an initial alarm classification model.

[0009] The volume of the hypersphere is determined based on a sample alarm attribute set, the sample alarm attribute set is determined based on a fractal dimension of the sample alarm data, and the fractal dimension reflects the alarm evolution direction of the sample alarm data.

[0010] According to the alarm classification method provided by the present application, the alarm classification model is determined based on the following steps:

[0011] determining a sample alarm attribute set based on a fractal dimension of the sample alarm data;

[0012] construct a polyhedron based on the sample alarm attribute set, and determine a hypersphere of the polyhedron, the hypersphere including an inscribed hypersphere and a circumscribed hypersphere;

[0013] determine an initial alarm classification model based on a volume of the polyhedron and a volume of the hypersphere;

[0014] train the initial alarm classification model based on the sample alarm data and an alarm type label of the sample alarm data to obtain an alarm classification model.

[0015] According to the alarm classification method provided by the application, the initial alarm classification model is determined based on the volume of the polyhedron and the volume of the hypersphere, and the method comprises the following steps:

[0016] integrate the polyhedron and the hypersphere respectively to obtain the volume of the polyhedron and the volume of the hypersphere;

[0017] cluster the volume of the polyhedron and the volume of the hypersphere to obtain a support vector set and an iterative relationship function of the sample alarm data;

[0018] perform regression classification on the support vector set based on the iterative relationship function to obtain the initial alarm classification model.

[0019] According to the alarm classification method provided by the application, the polyhedron is constructed based on the sample alarm attribute set, and the hypersphere of the polyhedron is determined, and the method comprises the following steps:

[0020] determine the number of attributes of the alarm type attribute in the sample alarm attribute set;

[0021] construct the polyhedron based on the number of attributes, and determine the hypersphere of the polyhedron.

[0022] According to the alarm classification method provided by the application, the number of times of integration is determined based on the number of attributes of the alarm type attribute in the sample alarm attribute set.

[0023] According to the alarm classification method provided by the application, the sample alarm attribute set is determined based on the fractal dimension of the sample alarm data, and the method comprises the following steps:

[0024] determine the time sequence of the sample alarm data;

[0025] divide the time sequence of the sample alarm data into intervals to obtain sample alarm data of each time interval, and the sample alarm data of each time interval is subject to normal distribution;

[0026] determine a fractal dimension of the sample alarm data based on a normal distribution of a time sequence of the sample alarm data;

[0027] perform clustering regularization based on the fractal dimension to obtain a sample alarm attribute set.

[0028] According to the alarm classification method provided by the application, the fractal dimension of the sample alarm data is determined based on the normal distribution of the time sequence of the sample alarm data, and the fractal dimension of the sample alarm data is determined based on the Hurst index.

[0029] determine a covariance matrix of the time sequence of the sample alarm data based on the normal distribution of the time sequence of the sample alarm data;

[0030] determine a Hurst index of the sample alarm data based on the covariance matrix and a range of the time sequence of the sample alarm data;

[0031] determine the fractal dimension of the sample alarm data based on the Hurst index;

[0032] The range is a difference between a maximum value and a minimum value in a cumulative deviation of the time sequence of the sample alarm data.

[0033] The application further provides an alarm classification device, comprising:

[0034] a data determination unit configured to determine alarm data to be classified;

[0035] an alarm classification unit configured to input the alarm data into an alarm classification model to obtain an alarm type output by the alarm classification model, wherein the alarm classification model is obtained by training sample alarm data based on an initial alarm classification model, the initial alarm classification model is determined based on a volume of a hypersphere constructed based on a sample alarm attribute set, the sample alarm attribute set is determined based on a fractal dimension of the sample alarm data, and the fractal dimension reflects an alarm evolution direction of the sample alarm data.

[0036] The application further provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the alarm classification method according to any one of the above when executing the program.

[0037] The application further provides a non-transitory computer readable storage medium having a computer program stored thereon, wherein the computer program is executable on a processor to implement the alarm classification method according to any one of the above.

[0038] The application provides an alarm classification method and device, electronic equipment and a storage medium. BRIEF DESCRIPTION OF DRAWINGS

[0039] In order to more clearly illustrate the technical solutions in the application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.

[0040] Figure 1 FIG. 1 is a flowchart of the alarm classification method provided by the application;

[0041] Figure 2 FIG. 2 is a schematic diagram of the box dimension Lebesgue covering of different Hurst indexes;

[0042] Figure 3 FIG. 5 is a structural diagram of the alarm classification device provided by the application;

[0043] Figure 4 FIG. 6 is a structural diagram of the electronic equipment provided by the application. DETAILED DESCRIPTION

[0044] In order to make the purpose, technical solutions and advantages of the application more clear, the technical solutions in the application will be clearly and completely described below in combination with the drawings in the application. Obviously, the described embodiments are some embodiments of the application, rather than all the embodiments. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor belong to the protection scope of the application.

[0045] With the rapid development of the market of the carrier electronic channel business, the exposed channel increases and the system complexity is increasing. In this case, in order to meet the development and maintenance needs of the operation and maintenance personnel, the alarm can be classified, that is, the alarm is labeled, the alarm is classified according to the label, and specifically, the label is filtered by the system, and the filtering condition of the filtering is derived from the existing or historical label, and the configuration and combination of the filtering condition are completed by manual or system.

[0046] However, in the above scheme, the design reference of the label is the long-term alarm characteristics, which undoubtedly makes the alarm portrait model based on the label single and linear, and easily ignores the fluctuation effect of the alarm demand in a period or a historical period, thereby causing low boundary alarm accuracy; in addition, the process of manually configuring the filtering condition involves subjective factors, which easily leads to high dependence of the subsequent label filtering process on manual experience, thereby causing high misjudgment probability and further causing poor alarm processing effect.

[0047] Therefore, in order to adapt to more complex operation and development needs and alarm classification, the present application provides an alarm classification method, which aims to predict the alarm evolution direction through a hypersphere and a support vector machine, recursively deduce the alarm data, that is, perform classification regression through a support vector machine to obtain the "high probability" alarm evolution direction, optimize the alarm processing scheme, and obviously improve the alarm processing effect. Figure 1 The flowchart of the alarm classification method provided by the present application is shown in Figure 1 The method comprises the following steps.

[0048] Step 110, determining alarm data to be classified;

[0049] Specifically, before the alarm classification, the alarm data to be classified, i.e., the alarm data to be classified, needs to be determined. Each alarm is composed of corresponding alarm data, and the alarm data here is the alarm type attribute of the corresponding alarm. The alarm type attribute can be the alarm occurrence time, the alarm host, the alarm level, etc.

[0050] For example, the alarm data of a single alarm can be:

[0051] "Host: b503f02rs02_X.X.X.X:X.X.X.X; hanging point: / wx*******ku appears file system, usage ratio abnormal alarm; current index value: 96; alarm occurrence time: 2021-06-12, 11:58:28; responsible person and phone: 0123456789; alarm level: level 3".

[0052] In step 120, the alarm data is input into the alarm classification model to obtain an alarm type output by the alarm classification model; the alarm classification model is obtained by training sample alarm data on the basis of an initial alarm classification model; the initial alarm classification model is determined based on the volume of a hypersphere of a polyhedron constructed based on a sample alarm attribute set, the sample alarm attribute set is determined based on a fractal dimension of sample alarm data, and the fractal dimension reflects an alarm evolution direction of the sample alarm data.

[0053] Specifically, in step 110, based on the determination of the alarm data to be classified, the alarm classification of the alarm data to be classified is performed, that is, step 120 is executed, the alarm classification of the alarm data to be classified is performed by the alarm classification model, so as to obtain the alarm type of the alarm data. Specifically, the alarm data to be classified is input into the alarm classification model, the alarm classification model classifies the alarm according to the information contained in the input alarm data, and finally obtains the alarm type of the alarm data to be classified output by the alarm classification model.

[0054] It should be noted that the alarm classification model herein is obtained by training sample alarm data on the basis of an initial alarm classification model, and the initial alarm classification model is determined based on a sample alarm attribute set, that is, a polyhedron constructed based on the sample alarm attribute set and a hypersphere of the polyhedron. The volume of the two is determined, and the sample alarm attribute set is determined based on the fractal dimension of the sample alarm data. The sample alarm data herein can be full alarm data derived from the system, that is, historical alarm data. The historical alarm data can be historical alarm level, historical alarm module, historical alarm database, etc. Since the fractal dimension can reflect the alarm evolution direction of the sample alarm data, when the value is positive, it indicates that the alarm uncertain behavior occurs; otherwise, when the value is negative, it indicates that the alarm tends to be stable. Therefore, when the fractal dimension of the sample alarm data reflects that the alarm tends to be stable, the sample alarm attribute set is determined based on the fractal dimension.

[0055] After determining the initial alarm classification model based on the sample alarm attribute set, the initial alarm classification model needs to be trained to obtain the alarm classification model, that is, the alarm classification model is obtained by training the sample alarm data and the alarm type label of the sample alarm data on the basis of the initial alarm classification model. This process specifically includes the following steps: first, obtain the sample alarm data and label the alarm type of the sample alarm data to obtain the alarm type label of the sample alarm data; then, train the initial alarm classification model by using the sample alarm data and the alarm type label of the sample alarm data to obtain the trained alarm classification model. It should be noted that the alarm classification model herein can be a support vector machine alarm classification model.

[0056] The alarm classification method provided by the application inputs alarm data into an alarm classification model to obtain an alarm type output by the alarm classification model, wherein the alarm classification model is obtained by training sample alarm data based on an initial alarm classification model; the volume of a hypersphere of the initial alarm classification model is determined based on a sample alarm attribute set, and the sample alarm attribute set is determined based on a fractal dimension of sample alarm data, wherein the fractal dimension reflects an alarm evolution direction of the sample alarm data; based on full alarm data, the alarm evolution direction is analyzed and iteratively updated, and the sample alarm attribute set is constructed when the alarm tends to be stable; and the alarm classification model is constructed based on the set to classify alarms, thereby overcoming the defects of poor alarm processing state, low processing efficiency, and poor alarm classification accuracy in the traditional scheme, and realizing optimization of the alarm processing scheme and double improvement of alarm processing effect and user perception.

[0057] Based on the above embodiments, the alarm classification model is determined based on the following steps:

[0058] Based on the fractal dimension of the sample alarm data, a sample alarm attribute set is determined.

[0059] Based on the sample alarm attribute set, a polyhedron is constructed, and a hypersphere of the polyhedron is determined, wherein the hypersphere includes an inscribed hypersphere and a circumscribed hypersphere.

[0060] Based on the volume of the polyhedron and the volume of the hypersphere, an initial alarm classification model is determined.

[0061] Based on the sample alarm data and the alarm type label of the sample alarm data, the initial alarm classification model is trained to obtain the alarm classification model.

[0062] Specifically, in step 120, the determination process of the alarm classification model for classifying the alarm data includes the following steps:

[0063] First, based on the fractal dimension of the sample data, a sample alarm attribute set is determined, wherein the fractal dimension of the sample alarm data can be determined by Hurst index, Lyapunov index, box dimension (upper box dimension and lower box dimension), etc., that is, at least one of the Hurst index, Lyapunov index, and box dimension of the obtained sample alarm data is determined, and then the fractal dimension of the sample alarm data is determined based on this; and thereafter, the fractal dimension can be applied to cluster and regularize the user corresponding to the sample alarm data, thereby obtaining the sample alarm attribute set.

[0064] Then, a polyhedron can be constructed according to the sample alarm attribute set, specifically, the dimension of the polyhedron can be determined according to the attribute number of the alarm type attribute in the sample alarm attribute set, that is, the attribute number of the alarm type attribute is taken as the dimension of the polyhedron, then the polyhedron is constructed, and the hypersphere of the polyhedron is determined, where the hypersphere includes an inscribed hypersphere and a circumscribed hypersphere;

[0065] Subsequently, the volume of the polyhedron, the volume of the inscribed hypersphere and the volume of the circumscribed hypersphere are calculated, and based on the volumes of the three, a clustering algorithm is used for clustering, and the results obtained by clustering are classified and regressed to determine an initial alarm classification model;

[0066] Thereafter, the sample alarm data and the alarm type label of the sample alarm data can be used to train the initial alarm classification model, specifically, first, the sample alarm data is obtained, and the sample alarm data is labeled for the alarm type, so as to obtain the alarm type label of the sample alarm data; then, based on the sample alarm data and the alarm type label, the parameters of the initial alarm classification model are updated, so as to obtain the alarm classification model.

[0067] The method provided by the embodiment of the application determines the sample alarm attribute set through recursive deduction of large alarm data, and constructs an initial alarm classification model based on the derived polyhedron and hypersphere, and then obtains an alarm classification model through training, thereby providing strong data support for the subsequent alarm classification process based on the alarm classification model, and greatly saving the business support cost.

[0068] Based on the above embodiment, the initial alarm classification model is determined based on the volume of the polyhedron and the volume of the hypersphere, including:

[0069] The polyhedron and the hypersphere are integrated respectively to obtain the volume of the polyhedron and the volume of the hypersphere;

[0070] The volume of the polyhedron and the volume of the hypersphere are clustered to obtain a support vector set of the sample alarm data and an iterative relationship function;

[0071] Based on the iterative relationship function, the support vector set is classified and regressed to obtain the initial alarm classification model.

[0072] Specifically, in the above process, the initial alarm classification model is determined according to the volume of the polyhedron and the volume of the inscribed hypersphere and the circumscribed hypersphere, which can be divided into the following steps:

[0073] Firstly, according to the attribute number of the alarm type attribute in the sample alarm attribute set, the integral multiple is determined, then the polyhedron, the inscribed hypersphere and the circumscribed hypersphere are integrated respectively according to the integral multiple, and the volume of the polyhedron, the volume of the inscribed hypersphere and the volume of the circumscribed hypersphere are obtained;

[0074] Subsequently, the volume of the polyhedron, the volume of the inscribed hypersphere and the volume of the circumscribed hypersphere can be combined into a volume vector, then the clustering algorithm is used to cluster the volume vector, and the support vector set of the sample alarm data and the iterative relationship function can be obtained;

[0075] After that, the initial alarm classification model can be determined according to the support vector set and the iterative relationship function, specifically, the iterative relationship function is used as a kernel function to perform regression classification on the support vector set according to the one-to-one principle, so as to obtain the classifier, that is, the initial alarm classification model.

[0076] The method provided by the embodiment of the application provides strong help for the implementation of the specific classification reminder of the alarm classification model trained based on the initial alarm classification model and the improvement of user perception by means of iterative calculation to construct the initial alarm classification model.

[0077] Based on the above embodiment, the volume of the polyhedron, the volume of the inscribed hypersphere and the volume of the circumscribed hypersphere can be calculated by the following formulas respectively:

[0078] a = ∫··∫A; b = ∫··∫B; c = ∫··∫C

[0079] Wherein, A represents the polyhedron, and a represents the volume of the polyhedron; B represents the inscribed hypersphere, and b represents the volume of the inscribed hypersphere; C represents the circumscribed hypersphere, and c represents the volume of the circumscribed hypersphere.

[0080] The volume vector composed of the volume of the polyhedron, the volume of the inscribed hypersphere and the volume of the circumscribed hypersphere can be represented by the following formula:

[0081] φ(i) = (a, b, c)

[0082] Wherein, φ(i) represents the volume vector.

[0083] The iterative relationship function can be represented by the following formula:

[0084] Θ = f(φ(i))

[0085] Wherein, Θ represents the iterative relationship function.

[0086] Based on the above embodiment, the polyhedron is constructed based on the sample alarm attribute set, and the hypersphere of the polyhedron is determined, including:

[0087] Determine the number of alarm type attributes in the sample alarm attribute set;

[0088] Based on the number of attributes, construct a polyhedron and determine the hypersphere of the polyhedron.

[0089] Specifically, the process of constructing a polyhedron based on the sample alarm attribute set essentially uses the number of alarm type attributes in the sample alarm attribute set. The specific process can be as follows: First, determine the alarm type attributes in the sample alarm attribute set and count the number of alarm type attributes; then, determine the dimensions of the polyhedron based on this number of attributes; subsequently, construct the polyhedron with the corresponding dimensions and determine the inscribed hypersphere and circumscribed hypersphere of the polyhedron.

[0090] Based on the above embodiments, the multiplicity of the integral is determined based on the number of attributes of the alarm type attribute in the sample alarm attribute set.

[0091] Specifically, in the process of determining the volume of the polyhedron and the hypersphere by integrating the components respectively, the multiplicity of the integral is determined by the construction datum of the polyhedron and the sample alarm attribute set, specifically by the number of alarm type attributes in the sample alarm attribute set.

[0092] For example, when the set of sample alarm attributes is represented as X'={x'1,x'2,x'3,…,x' m When x' m Let m represent the m-th alarm type attribute. The number of alarm type attributes in the sample alarm attribute set is m. At this time, we can determine that the dimension of the polyhedron is m-dimensional, and the integral multiplicity of the integrals performed on the polyhedron and its hypersphere is m-fold.

[0093] Based on the above embodiments, the set of sample alarm attributes is determined based on the fractal dimension of the sample alarm data, including:

[0094] Determine the time series of sample alarm data;

[0095] The time series of sample alarm data is divided into intervals to obtain sample alarm data for each time interval. The sample alarm data for each time interval follows a normal distribution.

[0096] Based on the normal distribution of the time series of sample alarm data, determine the fractal dimension of the sample alarm data;

[0097] Clustering regularization based on fractal dimension yields a set of alarm attributes for the samples.

[0098] Specifically, the process of determining the set of sample alarm attributes based on the fractal dimension of the sample alarm data in the above process includes the following steps:

[0099] Firstly, a time sequence of sample alarm data of the user at a system alarm is collected; here, the time sequence of sample alarm data satisfies a probability density function, a distribution function and a multivariate normal distribution function;

[0100] Subsequently, the time sequence of sample alarm data is divided into intervals, which is divided into a plurality of time intervals, for example, it can be divided into a plurality of time intervals (interval blocks) of a preset length, so as to obtain sample alarm data of each time interval; it should be noted that the sample alarm data of each time interval is subject to normal distribution;

[0101] After that, the mean and the covariance matrix of the time sequence of sample alarm data can be determined according to the normal distribution of the time sequence of sample alarm data, and then the fractal dimension of the sample alarm data is calculated according to the covariance matrix;

[0102] And after obtaining the fractal dimension, the user can be clustered and regularized according to the fractal dimension to determine the sample alarm attribute set; it should be noted that the regularization here is to prevent overfitting, and the conventional regularization has L1 regularization and L2 regularization, wherein the L1 regularization is to take the sum of the absolute values of each vector in each sample as a norm, and then divide each vector by the norm; the L2 regularization is to square each vector in each sample first, then sum the squares, and then take the square root as the norm, and then divide each vector by the norm.

[0103] Based on the above embodiment, the calculation formula of the probability density function, the distribution function and the multivariate normal distribution function is as follows:

[0104] Wherein, the probability density function can be expressed as:

[0105]

[0106] Wherein, r(x1,x2,x3,…,x p ) represents the probability density function, p represents the data dimension of the sample alarm data, ∑ represents the covariance matrix of the time sequence of the sample alarm data, μ represents the mean of the time sequence of the sample alarm data, and X represents the sample alarm data.

[0107] The calculation formula of the distribution function corresponding to the alarm evolution direction of the sample alarm data is as follows:

[0108]

[0109] Wherein, R(x1,x2,…,x p ) represents the distribution function.

[0110] The alarm evolution direction is subject to a multivariate normal distribution, and the multivariate normal distribution function can be expressed as:

[0111] R~N p (mu, Sigma)

[0112] Wherein, R represents the alarm evolution direction.

[0113] Based on the above embodiment, based on the normal distribution of the time sequence of the sample alarm data, the fractal dimension of the sample alarm data is determined, comprising:

[0114] Based on the normal distribution of the time sequence of the sample alarm data, the covariance matrix of the time sequence of the sample alarm data is determined;

[0115] Based on the covariance matrix, and the range of the time sequence of the sample alarm data, the Hurst index of the sample alarm data is determined; the range is the difference between the maximum and minimum of the cumulative deviation of the time sequence of the sample alarm data;

[0116] Based on the Hurst index, the fractal dimension of the sample alarm data is determined.

[0117] Specifically, in the above process, according to the normal distribution of the time sequence of the sample alarm data, the process of determining the fractal dimension of the sample alarm data can be divided into the following steps:

[0118] Firstly, since the normal distribution function contains two parameters, which are mean and variance (covariance matrix), therefore, after determining that the time sequence of the sample alarm data obeys the normal distribution, the covariance matrix of the time sequence of the sample alarm data can be determined according to the normal distribution of the time sequence of the sample alarm data;

[0119] Then, on the basis of this covariance matrix, combined with the range of the time sequence of the sample alarm data, the Hurst index of the sample alarm data is calculated, and the range here is the difference between the maximum and minimum of the cumulative deviation of the time sequence of the sample alarm data, and the cumulative deviation of the time sequence of the sample alarm data can be determined according to the average value of the sample alarm data corresponding to the time interval;

[0120] After that, the fractal dimension of the sample alarm data can be determined according to the Hurst index, and this fractal dimension can reflect the alarm evolution direction of the sample alarm data, and when the value is positive, it indicates that the alarm uncertain behavior occurs; otherwise, when the value is negative, it indicates that the alarm tends to be stable.

[0121] The method provided by the embodiment of the application recursively deduces the historical alarm data, so as to determine the principal component of the alarm data to be classified through the historical alarm data, thereby realizing the prediction of the alarm evolution direction; and the fractal dimension reflecting the alarm change trend is calculated through the historical alarm data, thereby providing key assistance for the subsequent alarm classification process.

[0122] Based on the above embodiment, the calculation formula of the Hurst index is as follows:

[0123]

[0124] wherein p represents the range of the time series of the sample alarm data, H represents the Hurst index, H ∈ [0, 1], c is a constant, and N represents the total number of time intervals.

[0125] The calculation formula of the cumulative deviation can be expressed as:

[0126]

[0127] wherein R(a, t) represents the cumulative deviation of the sample alarm data of the ath time interval, R N(a-1)+i represents the ith observation value of the ath time interval, represents the average value of the sample alarm data of the ath time interval.

[0128] The calculation formula of the range of the time series of the sample alarm data is:

[0129] p = sup [MaxR(a, t) - MinR(a, t)]

[0130] wherein MaxR(a, t) represents the maximum value in R(a, t), and MinR(a, t) represents the minimum value in R(a, t).

[0131] Based on the above embodiment, the Hurst index of the sample alarm data can also be determined based on the box dimension of the sample alarm data.

[0132] Specifically, the calculation formula of the upper box dimension of the sample alarm data is:

[0133]

[0134] The calculation formula of the lower box dimension of the sample alarm data is:

[0135]

[0136] wherein represents the upper box dimension, dim B F represents the lower box dimension, δ is the length of the time interval, and N δ (F) represents the counting measure of the metric space.

[0137] The calculation formula of the counting measure of the metric space can be expressed as:

[0138] N δ (i) = {‖Π i -H‖ < δ}

[0139] Where δ is the preset exponential threshold (in the sense of Lebesgue measure coverage), Π i This represents the reference coefficient corresponding to the i-th cluster. This formula is actually a clustering formula based on the fractal dimension to cluster users. It means that when the Euclidean distance between the Hearst exponent of the sample alarm data and the reference coefficient corresponding to the i-th cluster is less than the preset exponent threshold, the sample alarm data belongs to this alarm type.

[0140] Figure 2 This is a schematic diagram of the Lebesgue coverage of different Hearst indices in the box dimension provided by the present invention, as shown below. Figure 2 As shown, if there are 4 alarm types, their corresponding parameter coefficients (baseline Hurst exponents) are 0.52, 0.61, 0.73 and 0.81, respectively. The sample alarm data can be classified into the corresponding alarm type according to the Hurst exponent of the sample alarm data.

[0141] Based on the above embodiments, the fractal dimension of the sample alarm data can also be determined based on the Lyapunov exponent of the sample alarm data.

[0142] Specifically, the formula for calculating the Lyapunov index can be expressed as:

[0143]

[0144] Where, λ R (t) represents the Lyapunov exponent of the sample alarm data at time t. This represents the calculation of the covariant differential along different directions of different eigenvectors in the same space for the i-th iteration of the time series of sample alarm data, where n represents the number of iterations.

[0145] The Lyapunov index reflects the direction of alarm evolution. A positive value indicates the occurrence of uncertain alarm behavior, while a negative value indicates that the alarm is stabilizing.

[0146] Based on the above embodiments, the algorithm flow of the alarm classification method includes the following steps:

[0147] First, determine the sample alarm data X, X = {x1, x2, x3, ..., x n}, 1≤i≤n, where i is an integer, x i This indicates the alarm type attribute, where n represents the number of alarm type attributes.

[0148] Subsequently, a time-series chaotic iterator based on fractal geometry is used to analyze the sample alarm data X to obtain the fractal dimension of the sample alarm data. Then, based on the fractal dimension of the sample alarm data, clustering regularization is performed on the users to obtain the sample alarm attribute set X', where X'={x'1,x'2,x'3,…,x' m};

[0149] Subsequently, according to the attribute number of the alarm type attribute in the sample alarm attribute set, an m-dimensional polyhedron A is constructed, and an inscribed hypersphere B and a circumscribed hypersphere C of the polyhedron A are determined;

[0150] Thereafter, m-fold integrals are respectively performed on the polyhedron A, the inscribed hypersphere B and the circumscribed hypersphere C to obtain the volume of the polyhedron A, the volume of the inscribed hypersphere B and the volume of the circumscribed hypersphere C, denoted as φ(i)=(a, b, c);

[0151] Finally, using a clustering algorithm, φ(i)=(a, b, c) is clustered to obtain a support vector set and an iterative relationship function Θ, Θ=f(φ(i)); then, according to a one-to-one principle, Θ=f(φ(i)) is taken as a kernel function to perform regression classification on the support vector set to obtain an initial alarm classification model; sample alarm data and alarm type labels of the sample alarm data are applied to train the initial alarm classification model to obtain an alarm classification model; based on the alarm classification model, alarm classification is performed on alarm data to be classified.

[0152] For example, when the system receives alarm data to be classified, the values output by the fractal geometry-based time series chaotic iterator and the clustering analyzer are (SX-055****-551, 0.76, N4(μ,Σ)), in which "SX-055****-551" is an alarm identifier, "0.76" is the Hurst exponent output by the clustering analyzer, and N4(μ,Σ) is a four-dimensional normal distribution including a mean value and a covariance matrix.

[0153] If there are three types of alarms to be distributed, namely, ordinary alarms (such as on-off interface downtime and system timing processing), upgrade alarms (such as process slow increase alarms) and important alarms (which affect business and need to be processed immediately), the corresponding fractal dimensions are 0.22, 0.29 and 0.77, respectively. According to the analysis result, it can be determined that the alarm data to be classified belongs to an important alarm, should be labeled as an important alarm, and the responsible person should be notified by phone. In addition, since the attractor has obvious persistence, the alarm has certain regularity and can be predicted.

[0154] The method provided by the embodiment of the application inputs alarm data into an alarm classification model to obtain an alarm type output by the alarm classification model, the alarm classification model is obtained by training sample alarm data on the basis of an initial alarm classification model, the volume of a hypersphere constructed on the basis of a sample alarm attribute set is determined according to the initial alarm classification model, the sample alarm attribute set is determined according to a fractal dimension of sample alarm data, the fractal dimension reflects an alarm evolution direction of the sample alarm data, the alarm evolution direction is analyzed on the basis of full alarm data and is iteratively updated, the sample alarm attribute set is constructed when the alarm tends to be stable, and the alarm classification model is constructed according to the set to classify alarms, thereby overcoming the defects of poor alarm processing state, low processing efficiency and poor alarm classification accuracy in the traditional scheme, and realizing optimization of the alarm processing scheme and double improvement of alarm processing effect and user perception.

[0155] The alarm classification device provided by the application is described below, and the alarm classification device described below can be referred to in correspondence with the alarm classification method described above.

[0156] Figure 3 FIG. 1 is a structural schematic diagram of the alarm classification device provided by the application, as shown in the figure, the device comprises: Figure 3

[0157] The data determination unit 310 is configured to determine alarm data to be classified.

[0158] The alarm classification unit 320 is configured to input the alarm data into an alarm classification model to obtain an alarm type output by the alarm classification model, the alarm classification model is obtained by training sample alarm data on the basis of an initial alarm classification model, the volume of a hypersphere constructed on the basis of a sample alarm attribute set is determined according to the initial alarm classification model, the sample alarm attribute set is determined according to a fractal dimension of sample alarm data, and the fractal dimension reflects an alarm evolution direction of the sample alarm data.

[0159] ​The alarm classification method provided by the application comprises the following steps: inputting alarm data into an alarm classification model to obtain an alarm type output by the alarm classification model, wherein the alarm classification model is obtained by training sample alarm data on the basis of an initial alarm classification model; the volume of a hypersphere of the initial alarm classification model is determined based on a sample alarm attribute set; the sample alarm attribute set is determined based on a fractal dimension of sample alarm data; the fractal dimension reflects an alarm evolution direction of the sample alarm data; the alarm evolution direction is analyzed based on full alarm data, and is iteratively updated; the sample alarm attribute set is constructed when the alarm tends to be stable; and the alarm classification model is constructed based on the set to classify alarms, so that the defects of poor alarm processing state, low processing efficiency and poor alarm classification accuracy in the traditional scheme are overcome, the alarm processing scheme is optimized, and the alarm processing effect and user perception are improved.

[0160] Based on the above embodiment, the device further comprises a model determination unit configured to:

[0161] Determine a sample alarm attribute set based on a fractal dimension of the sample alarm data.

[0162] Construct a polyhedron based on the sample alarm attribute set, and determine a hypersphere of the polyhedron, wherein the hypersphere comprises an inscribed hypersphere and a circumscribed hypersphere.

[0163] Determine an initial alarm classification model based on the volume of the polyhedron and the volume of the hypersphere.

[0164] Train the initial alarm classification model based on the sample alarm data and alarm type labels of the sample alarm data to obtain an alarm classification model.

[0165] Based on the above embodiment, the model determination unit is configured to:

[0166] Integrate the polyhedron and the hypersphere respectively to obtain the volume of the polyhedron and the volume of the hypersphere.

[0167] Cluster the volume of the polyhedron and the volume of the hypersphere to obtain a support vector set of the sample alarm data and an iterative relationship function.

[0168] Classify the support vector set based on the iterative relationship function to obtain the initial alarm classification model.

[0169] Based on the above embodiment, the model determination unit is configured to:

[0170] Determine the number of alarm type attributes in the sample alarm attribute set.

[0171] Based on the attribute number, a polyhedron is constructed, and a hypersphere of the polyhedron is determined.

[0172] Based on the above embodiment, the integral number is determined based on the attribute number of the alarm type attribute in the sample alarm attribute set.

[0173] Based on the above embodiment, the model determination unit is configured to:

[0174] determine the time series of the sample alarm data;

[0175] interval division is performed on the time series of the sample alarm data to obtain sample alarm data of each time interval, and the sample alarm data of each time interval is subject to normal distribution;

[0176] Based on the normal distribution of the time series of the sample alarm data, a fractal dimension of the sample alarm data is determined;

[0177] Based on the fractal dimension, clustering regularization is performed to obtain a sample alarm attribute set.

[0178] Based on the above embodiment, the model determination unit is configured to:

[0179] Based on the normal distribution of the time series of the sample alarm data, a covariance matrix of the time series of the sample alarm data is determined;

[0180] Based on the covariance matrix and the range of the time series of the sample alarm data, a Hurst index of the sample alarm data is determined;

[0181] Based on the Hurst index, a fractal dimension of the sample alarm data is determined;

[0182] The range is the difference between the maximum value and the minimum value in the cumulative deviation of the time series of the sample alarm data.

[0183] Figure 4 An example of an entity structure diagram of an electronic device is shown as Figure 4As shown, the electronic device can include a processor 410, a communications interface 420, a memory 430, and a communications bus 440, wherein the processor 410, the communications interface 420, and the memory 430 complete mutual communication through the communications bus 440. The processor 410 can invoke a logical instruction in the memory 430 to execute an alarm classification method, which includes determining alarm data to be classified; inputting the alarm data into an alarm classification model to obtain an alarm type output by the alarm classification model; the alarm classification model is obtained by training sample alarm data on the basis of an initial alarm classification model; the alarm classification model is obtained by training sample alarm data on the basis of an initial alarm classification model; the volume of the hypersphere based on the sample alarm attribute set is determined based on the initial alarm classification model, the sample alarm attribute set is determined based on the fractal dimension of the sample alarm data, and the fractal dimension reflects the alarm evolution direction of the sample alarm data.

[0184] In addition, the logical instruction in the memory 430 described above can be implemented in the form of a software functional unit and sold or used as an independent product, and can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or part of the technical solutions can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the methods described in the embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various program code storage media.

[0185] In another aspect, the present application also provides a computer program product, which comprises a computer program stored on a non-transitory computer readable storage medium, the computer program comprising program instructions which, when executed by a computer, enable the computer to perform the alarm classification method provided by any of the above methods, the method comprising: determining alarm data to be classified; inputting the alarm data into an alarm classification model to obtain an alarm type output by the alarm classification model; the alarm classification model being trained based on sample alarm data on the basis of an initial alarm classification model; the alarm classification model being trained based on sample alarm data on the basis of an initial alarm classification model; the initial alarm classification model being determined based on a volume of a hypersphere constructed based on a sample alarm attribute set, the sample alarm attribute set being determined based on a fractal dimension of the sample alarm data, the fractal dimension reflecting an alarm evolution direction of the sample alarm data.

[0186] In another aspect, the present application also provides a non-transitory computer readable storage medium, which stores a computer program, the computer program being executed by a processor to implement the alarm classification method provided by any of the above methods, the method comprising: determining alarm data to be classified; inputting the alarm data into an alarm classification model to obtain an alarm type output by the alarm classification model; the alarm classification model being trained based on sample alarm data on the basis of an initial alarm classification model; the alarm classification model being trained based on sample alarm data on the basis of an initial alarm classification model; the initial alarm classification model being determined based on a volume of a hypersphere constructed based on a sample alarm attribute set, the sample alarm attribute set being determined based on a fractal dimension of the sample alarm data, the fractal dimension reflecting an alarm evolution direction of the sample alarm data.

[0187] The device embodiments described above are merely illustrative, wherein the units described as separate components can or can not be physically separated, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the present embodiment scheme according to actual needs. Those skilled in the art can understand and implement without creative labor.

[0188] Those skilled in the art can clearly understand the technical solutions of the various embodiments from the above description of the embodiments, and the various embodiments can be implemented by means of software with the necessary general hardware platforms, and of course, can also be implemented by hardware. Based on such understanding, the above technical solutions, essentially or in other words, the part of the prior art that makes a contribution, can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, and the like, and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0189] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, rather than limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for some technical features therein; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. An alarm classification method, characterized in that, include: Identify the alarm data to be categorized; The alarm data is input into the alarm classification model to obtain the alarm type output by the alarm classification model; The alarm classification model is trained using sample alarm data based on the initial alarm classification model. The initial alarm classification model is determined based on the volume of a hypersphere constructed from the sample alarm attribute set. The sample alarm attribute set is determined based on the fractal dimension of the sample alarm data. The fractal dimension reflects the alarm evolution direction of the sample alarm data. The set of sample alarm attributes is determined based on the following steps: Determine the time series of the sample alarm data; The time series of the sample alarm data is divided into intervals to obtain sample alarm data for each time interval, and the sample alarm data for each time interval follows a normal distribution. Based on the normal distribution of the time series of the sample alarm data, determine the fractal dimension of the sample alarm data; Clustering regularization is performed based on the fractal dimension to obtain the sample alarm attribute set.

2. The alarm classification method according to claim 1, characterized in that, The alarm classification model is determined based on the following steps: Based on the fractal dimension of the sample alarm data, determine the set of sample alarm attributes; A polyhedron is constructed based on the sample alarm attribute set, and the hypersphere of the polyhedron is determined. The hypersphere includes an inscribed hypersphere and a circumscribed hypersphere. Based on the volume of the polyhedron and the volume of the hypersphere, an initial alarm classification model is determined; Based on the sample alarm data and the alarm type labels of the sample alarm data, the initial alarm classification model is trained to obtain the alarm classification model.

3. The alarm classification method according to claim 2, characterized in that, The determination of the initial alarm classification model based on the volume of the polyhedron and the volume of the hypersphere includes: Integrating the polyhedron and the hypersphere respectively yields the volume of the polyhedron and the volume of the hypersphere; Clustering the volumes of the polyhedron and the hypersphere yields the support vector set and iterative relation function of the sample alarm data; Based on the iterative relationship function, regression classification is performed on the support vector set to obtain the initial alarm classification model.

4. The alarm classification method according to claim 2, characterized in that, The process of constructing a polyhedron based on the set of sample alarm attributes and determining the hypersphere of the polyhedron includes: Determine the number of alarm type attributes in the sample alarm attribute set; Based on the number of attributes, a polyhedron is constructed, and the hypersphere of the polyhedron is determined.

5. The alarm classification method according to claim 3, characterized in that, The multiplicity of the integral is determined based on the number of attributes of the alarm type attribute in the sample alarm attribute set.

6. The alarm classification method according to claim 1, characterized in that, Determining the fractal dimension of the sample alarm data based on the normal distribution of the time series of the sample alarm data includes: Based on the normal distribution of the time series of the sample alarm data, determine the covariance matrix of the time series of the sample alarm data; Based on the covariance matrix and the range of the time series of the sample alarm data, the Hearst exponent of the sample alarm data is determined. Based on the Hearst exponent, the fractal dimension of the sample alarm data is determined; The range is the difference between the maximum and minimum values ​​of the cumulative deviation of the time series of the sample alarm data.

7. An alarm classification device, characterized in that, include: The data determination unit is used to determine the alarm data to be classified. An alarm classification unit is used to input the alarm data into an alarm classification model to obtain the alarm type output by the alarm classification model. The alarm classification model is trained using sample alarm data based on an initial alarm classification model. The volume of the initial alarm classification model is determined based on a hypersphere constructed from a set of sample alarm attributes. The set of sample alarm attributes is determined based on the fractal dimension of the sample alarm data, and the fractal dimension reflects the alarm evolution direction of the sample alarm data. The set of sample alarm attributes is determined based on the following steps: Determine the time series of the sample alarm data; The time series of the sample alarm data is divided into intervals to obtain sample alarm data for each time interval, and the sample alarm data for each time interval follows a normal distribution. Based on the normal distribution of the time series of the sample alarm data, determine the fractal dimension of the sample alarm data; Clustering regularization is performed based on the fractal dimension to obtain the sample alarm attribute set.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the alarm classification method as described in any one of claims 1 to 6.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the alarm classification method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Alarm data processing method and device, storage medium and equipment

    CN114239750A