A factor-based event similarity analysis method

By using theories such as improved Pearson similarity and information entropy, an event similarity analysis method was constructed, which solved the complexity problem of event similarity analysis during the evolution of system faults, simplified the event set, and improved the reliability of similarity analysis.

CN117290737BActive Publication Date: 2025-10-21CHENGDU MINGYUE INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311296859.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-10-09
Publication Date
2025-10-21
Estimated Expiration
2043-10-09

AI Technical Summary

Technical Problem

Existing technologies lack reliable and effective factor-based event similarity analysis methods, making it difficult to effectively distinguish and merge events during system failure evolution.

Method used

By adopting the improved Pearson similarity, information entropy and system failure evolution theory, a factor-based event similarity analysis method is constructed. Event similarity analysis and classification are achieved through the similarity of event failure probability, influencing factor similarity, probability factor similarity, event failure probability entropy similarity and event similarity.

Benefits of technology

It reduces the construction complexity of the system fault evolution process, simplifies the event set, and improves the reliability and effectiveness of event similarity analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117290737B_ABST
    Figure CN117290737B_ABST
Patent Text Reader

Abstract

The present application relates to the system failure analysis in the security field, provide a kind of event similarity analysis method based on factor, for the numerous events involved in the system failure evolution process, a kind of event similarity analysis method based on factor is presented;Method is based on influencing factor and change, event and event failure probability, involves improving pearson similarity, information entropy and system failure evolution process theory;Firstly, the feasibility of event similarity based on factor analysis is studied;Secondly, the event similarity analysis method is established, including event failure probability similarity, influencing factor similarity, probability factor similarity, event failure probability entropy similarity and event similarity;Thirdly, the event classification method is proposed for the different event similarity;For the event classification based on event similarity.The original event set is simplified by the above method, so that the system failure evolution process reduces the complexity of construction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to system failure analysis in the security field, in particular to event similarity and event classification based on factors, and provides a factor-based event similarity analysis method. Background Art

[0002] The evolution of system faults primarily describes the changing characteristics of system functionality under the influence of multiple factors. Numerous factors influence this evolutionary process, including evolving events, influencing factors, logical relationships, and evolutionary conditions. Among these factors, the impact of evolving events and influencing factors on the evolutionary process of system faults is the most direct and critical. This is because during system operation, once the evolving events are determined, the logical relationships between them and the evolutionary conditions generally remain unchanged, while the types, number, and values ​​of the influencing factors are constantly changing. These changes affect the events, altering their ability to fulfill their functions and, consequently, the ability of the system composed of these events to achieve its intended function. Therefore, the key to studying the evolutionary process of system faults is to identify the evolving events and influencing factors. As mentioned above, influencing factors directly act on events, and the system and its evolutionary process are composed of these events. Therefore, whether these events share similarities is essential for constructing the evolutionary process of system faults. Numerous events are not conducive to constructing the evolutionary process. If these events exhibit the same functional characteristics within the same variation range of the same factors, then they can be considered to be similar in terms of their intended function under the conditions of these factors. This translates to the problem of analyzing similarities between events.

[0003] The similarity and correlation of various events, systems, and states has long been a research focus in academia. These similarity analysis methods approach the problem from diverse perspectives, addressing specific similarity issues within their respective fields. The development of distinctive analysis methods provides important support for subsequent research. Each of these issues also has its own unique characteristics. First, similarity issues are discussed during the evolution of system failures. Second, event similarity is measured using factors and changes as criteria. Finally, the completion of predetermined functions by events is used as a similarity target, establishing a factor-based event similarity analysis method for the evolution of system failures. However, existing research struggles to accomplish these tasks. It is necessary to propose a factor-based event similarity analysis method that can accomplish these tasks and address the technical issue of the lack of reliable and effective factor-based event similarity analysis methods in existing technologies. Summary of the Invention

[0004] The purpose of the present invention is to provide a factor-based event similarity analysis method to solve the technical problem of the lack of a reliable and effective factor-based event similarity analysis method in the prior art.

[0005] This paper proposes a method for event similarity analysis that takes into account various factors. This method involves improvements to Pearson similarity, information entropy, and system failure evolution theory. The research aims to analyze similarities between events and further distinguish between distinct features within similarities, providing a method for event simplification and merging in constructing system failure evolution processes.

[0006] 1. Factor-based event similarity analysis

[0007] The system fault evolution process characterizes the changes in a system's functional capabilities under the influence of various factors. The system fault evolution process at any moment can be represented as the system functional state. System functional states generally consist of reliable states and failure states, which complement each other and constitute the system functional state space. Therefore, the system functional states at all moments, combined according to the evolutionary process, form the system fault evolution process.

[0008] According to current research, the system failure evolution process can be structurally decomposed into experienced events, influencing factors, logical relationships, and evolutionary conditions. Experienced events are the main components of the system failure evolution process, constituting the evolutionary process and providing its concrete manifestation. Influencing factors are the fundamental causes that affect the ability of an event to complete its function. Different numbers and values ​​of influencing factors will alter the ability of an event to complete its intended function, and thus, the ability of the system to complete its intended function. Logical relationships are the interactions between events, specifically the logical manner in which the cause event leads to the result event. Evolutionary conditions represent the conditions required for the cause event to lead to the result event.

[0009] As previously explained, during the evolution of system faults, since logical relationships and evolutionary conditions remain largely unchanged once an event is identified, experienced events and influencing factors are key to the evolution. The spatial fault network theory has been proposed to describe the evolution of system faults. This describes the evolution of system faults as a topological structure, with events as nodes, factors as attached nodes, logical relationships forming the branches and intersections of the evolution, and evolutionary conditions as directed segments between events.

[0010] The relationship between factors and events is further explained. Since the system failure evolution process is composed of the system functional state at each moment, and the system functional state is in turn determined by the event functional state at that moment, the event failure probability distribution is used to represent the event functional state in the spatial fault network. The relationship between the event failure probability and the change in a single influencing factor forms a characteristic function, and the characteristic functions of all influencing factors form the event failure probability distribution. The system functional state can be represented by the system failure probability distribution derived from the structure of the event composition system. Therefore, events are the entities in the system failure evolution process, while influencing factors influence events and the system functional state.

[0011] It can be seen that the similarity of events in constructing an evolutionary process should be determined based on influencing factors. The goal of determining event similarity is whether the same event function is achieved under the same factor changes. That is, if the ability of each event to complete its intended function is the same under similar factor changes, then these events are similar under those factors. In particular, in spatial fault network theory, when studying the evolution of system failures, both the event functional state and the system functional state are represented by failure probability distributions. Therefore, whether an event achieves its intended function is also measured by the event failure probability.

[0012] In summary, based on the influencing factors and their variation intervals, events and event failure probabilities, and with the help of improved Pearson similarity, information entropy and system failure evolution theory, an attempt is made to establish a factor-based event similarity analysis method.

[0013] The present invention provides a factor-based event similarity analysis method. In order to simplify the numerous events involved in the system fault evolution process, a factor-based event similarity analysis method is proposed. The factor-based event similarity analysis method is based on influencing factors and changes, events and event failure probabilities, and involves improved Pearson similarity, information entropy and system fault evolution process theory. First, the feasibility of factor-based event similarity analysis is studied. Secondly, an event similarity analysis method is established, including event failure probability similarity, influencing factor similarity, probability factor similarity, event failure probability entropy similarity and event similarity. Finally, an event classification method is proposed according to the different event similarities. The method is used for event classification based on event similarity.

[0014] 2 Construction of event similarity analysis method

[0015] A factor-based event similarity analysis method is established. According to research needs, the event failure probability similarity, influencing factor similarity, probability factor similarity, and event failure probability entropy similarity are defined, and the calculation method is given. Finally, the event similarity is obtained comprehensively.

[0016] 2.1 General variable settings for analysis methods

[0017] Assume that the set of events that form the system failure evolution process is E={e1,…,e M}, where the mth event is e m ∈E, m=1,…,M. The set of factors that affect the system fault evolution process is F={f1,…,f N}, where the nth factor is f n ∈F, n=1,…,N. The degree of influence of all factors on all events is expressed using the event failure probability under the corresponding circumstances. This forms the matrix R of the degree of influence of factors on events, as shown in Table 1.

[0018] Table 1 Matrix of factors affecting event degree

[0019]

[0020] q in Table 1 mn It is event e m Affected by factor f n The failure probability of an event after the impact. It should be noted that the system failure evolution process and the failure probability of each event are strictly the result of all factors F at a certain moment. However, according to the actual situation, the failure probability of an event can be determined by estimation, analysis or average within the determined interval of factor changes. This paper does not distinguish between these two situations and only considers the failure probability of an event q under the condition of certain factors. mn As the basic parameters for analysis.

[0021] 2.2 Construction of event failure probability similarity

[0022] Determining the similarity of event failure probabilities of different events under the influence of different factors is the basis for studying the problem of event similarity. As far as Table 1 is concerned, the event failure probabilities under all influencing factors are provided. Then for any event, these failure probabilities are considered to be characteristic values ​​in different factor dimensions. Since the range of event failure probabilities under the influence of various factors is the same as [0,1], the failure probability is the unit change degree of the event failure characteristics in each factor dimension. This constitutes the failure probability feature vector of each event. Then the Pearson similarity is used to compare the similarity of different events. The event failure probability similarity s(e u ,e v ) as shown in formula (1).

[0023]

[0024] Where: F uv It is event e u and e v The set of factors that are affected; f n It's F uv Events in the collection;q un and q vn They are events e u and e v Affected by factor f n Probability of failure of the event after the impact; and They are events e u and e v The average probability of failure of an event after all factors have been affected.

[0025] Formula (1) is established based on the factor-influencing event degree matrix in Table 1. The e of any two events can be directly calculated by the data in Table 1. u and ev The similarity of event failure probability under all factors. Construct the event failure probability similarity matrix S, which is an M×M symmetric matrix. The horizontal and vertical headers are all events, and the corresponding unit value is s(e u ,e v ), determined by formula (1).

[0026] 2.3 Construction of Similarity of Influencing Factors

[0027] The advantage of the improved Jaccard similarity method is that it can consider the proportion of common influencing factors between events in all influencing factors. It measures the degree of similarity and similarity of different events in the dimension of factor effects. Therefore, the influencing factor similarity F(e u ,e v ), as shown in formula (2).

[0028]

[0029] Where: F u and F v They are events e u and e v The set of factors affected, || represents the number of elements in the collection.

[0030] The similarity of influencing factors F(e u ,e v ) Construct the similarity matrix F of influencing factors. F is a symmetric square matrix of M×M. The horizontal and vertical headers are all events, and the corresponding unit value is F(e u ,e v ), determined by formula (2).

[0031] 2.4 Probabilistic Factor Similarity Construction

[0032] The probability factor similarity is a measure of the comprehensive similarity of the failure probability and the combined effects of factors between events. The event failure probability similarity S(e) obtained by formula (1) and formula (2) is u ,e v ) and the similarity of influencing factors F(e u ,e v ), thereby calculating the probability factor similarity SF(e u ,e v ), as shown in formula (3).

[0033]

[0034] Construct the probability factor similarity matrix SF, which is a symmetric square matrix of M×M. The horizontal and vertical headers are all events, and the corresponding unit position is SF(eu ,e v ), determined by formula (3). u ,e v ) and matrix SF are determined values ​​obtained based on the data in Table 1 and do not include the uncertainty of the data.

[0035] 2.5 Construction of event failure probability entropy similarity

[0036] First, the information entropy of the event failure probability is established. According to Table 1, among events, factors and failure probabilities, the uncertainty of events and factors is weaker, while the uncertainty of event failure probability is more prominent. Because the event failure probability is obtained under the condition of a certain numerical value of the factor at a certain moment, or determined by estimation, analysis or average value within a certain interval of factor change. Therefore, there is a more obvious uncertainty, and information entropy is used to represent the uncertainty of the event failure probability. In addition, for the comparison of similarity, whether the failure probability of two events under the influence of different factors is valid remains to be discussed. Because the change of factor value leads to the change of failure probability, the similarity of the two events needs to be measured by the difference in failure probability under the same factor but different factor values. Therefore, the information entropy used to represent the similarity of the failure probability of two events should use the difference Δq of the event failure probability under all factor conditions. n =q un -q vn Calculate the event failure probability information entropy H(e u ,e v ) as shown in formula (4).

[0037]

[0038] Construct the event failure probability information entropy matrix H, which is an M×M symmetric matrix. The horizontal and vertical headers are all events, and the corresponding unit value is H(e u ,e v ), determined by formula (4). u ,e v ) and matrix H can reflect the uncertainty in the process of determining the failure probability of an event. This uncertainty is based on the difference between the failure probabilities of two events.

[0039] Secondly, based on the event failure probability information entropy H(e u ,e v ) Construct the event failure probability entropy similarity. Construct the event failure probability entropy similarity SH(e u ,e v ), as shown in formula (5).

[0040]

[0041] Formula (5) mainly measures the similarity of the uncertainty of the event failure probability, and then corrects the uncertainty of the event failure probability contained in the similarity of the probability factors. Construct the event failure probability entropy similarity matrix SH, which is an M×M symmetric matrix. The horizontal and vertical headers are all events, and the corresponding unit value is SH(e u ,e v ), determined by formula (5).

[0042] 2.6 Event Similarity Construction

[0043] Based on the probability factor similarity SF(e u ,e v ), and use the event failure probability entropy similarity SH(e u ,e v ) is corrected to obtain the event similarity SE(e u ,e v ), as shown in formula (6).

[0044]

[0045] Construct the event similarity matrix SE, which is a symmetric square matrix of M×M. The horizontal and vertical headers are all events, and the corresponding unit value is SE(e u ,e v ), determined by formula (6). Formula (6) is the final event similarity, but it is still difficult to determine the similarity between events. Because there are M(M-1) / 2 events e in the SE matrix u ,e v The similarity relationships of the two pairs have different similarities and different changing trends. We need to continue to calculate the similarity SE(e u ,e v ) to distinguish.

[0046] 3 Event Classification Method Based on Event Similarity

[0047] The result of the event similarity matrix SE is separated by diagonal elements. Since SE is a symmetric matrix, the event similarity array is composed of the elements below the diagonal. SE is used to represent it without ambiguity. Then the event similarity array is SE = {SE 1 (e i ,e j ),…,SE K (e i ,e j )}, the number of elements is K=M(M-1) / 2, k=1,…,K, i≠j, i,j=1,…,M. It should be noted that SE 1 (e i ,e j ),…,SE K (ei ,e j ) where i and j are different for different k. Event similarity is the similarity relationship between two events, i.e., event e i and event e j A similar event pair is formed, and the similarity of the event pair is SE k (e i ,e j ). Therefore, for any SE k (e i ,e j ) and SE k '(e i ,e j ) where i and j are different. Use event e i and event e j The subscripts i and j are used to distinguish the order of two events in a similar event pair. i is the previous event, e j For subsequent events. According to the needs of subsequent research, e i and e j The events represented are interchangeable within similar event pairs; however, the order of events cannot be changed after similar event pairs are included in the analysis.

[0048] For the convenience of discussion, SE={SE 1 (e i ,e j ),…,SE K (e i ,e j )} is abbreviated as according to The value of is different, and we divide it into three cases for discussion. When i and event e j Similar to e i and e j The failure probability values ​​and changing trends are similar; when When i and event e j Not similar; but When the event e i and event e j Negative similarity, indicating e i and e j The failure probability values ​​of are similar, but the changing trends are opposite. Expressed as a pair of similar events, denoted as The above three situations are analyzed separately.

[0049] If the event and or but Form a fully closed similarity group Continue to subdivide, when is a positive fully closed similarity group; when is a negative fully closed similarity group. At this time, the above events can form a closed loop connected end to end.

[0050] when When , the similarity of the events at the beginning of the analysis is From the event Start; when When , the similarity of the events at the beginning of the analysis is From the event start.

[0051] If the event but or but Form a non-closed similarity group ψ, ψ={ψ1,…,ψ μ}.when ψ >0 is a positive non-closed similarity group; ψ <0 is a negative non-closed similarity group. In this case, the above events cannot form a closed loop, but form a chain structure.

[0052] if Then the analysis ends. Or ψ={ψ1,…,ψ μ When there are repeated events in each similarity group in}, the repeated events should be split and treated as separate non-closed similarity groups, and these events should be removed from the original fully closed similarity groups and non-closed similarity groups to form new fully closed similarity groups and non-closed similarity groups.

[0053] Continue to and ψ are refined. If Then all form a non-closed similar group; similarly, if Then all Form a non-closed similar group; or ψ >0 ∩ψ <0 ≠φ, and or So Form non-closed dissimilar groups.

[0054] Establish event similarity array SE and distinguish three cases; Represent the event in the form of similar event pairs and determine fully closed similar groups and non-closed similar groups; extract the repeated events of the fully closed similar groups and non-closed similar groups to form non-closed similar groups; finally, determine whether there are non-closed dissimilar groups. In addition, the events within the positive fully closed similar groups and non-closed similar groups have strong similarities, including the event failure probability and the failure probability change trend, and can be merged into one event. The events within the negative fully closed similar groups have strong similarities, the event failure probabilities are similar, but the failure probability change trends are opposite, and the events cannot be merged. The non-closed dissimilar group is not associated with the positive and negative similar groups, and the events within the group are also not similar, so the events cannot be merged. The above method simplifies the original event set, reducing the construction complexity of the system failure evolution process.

[0055] The beneficial technical effects of the present invention include at least: utilizing the factor-based event similarity analysis method provided by the present invention, the original event set can be simplified, the construction complexity of the system fault evolution process can be reduced, and the technical problem of the lack of a reliable and effective factor-based event similarity analysis method in the prior art is solved. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] Figure 1 A schematic diagram showing the relationship between similar event pairs with event similarity greater than 0;

[0057] Figure 2 A schematic diagram showing the relationship between similar event pairs with event similarity less than 0. DETAILED DESCRIPTION

[0058] Using the above method to analyze an example, let's assume that the set of events that make up the system fault evolution process is E = {e1, e2, e3, e4, e5}, M = 5; and the set of factors that influence the system fault evolution is F = {f1, f2, f3, f4, f5, f6, f7}, N = 7. The matrix R of the degree of influence of factors on events is obtained, as shown in Table 2. This data is the original data.

[0059] Table 2 Matrix of factors affecting event degree

[0060] R <![CDATA[f1]]> <![CDATA[f2]]> <![CDATA[f3]]> <![CDATA[f4]]> <![CDATA[f5]]> <![CDATA[f6]]> <![CDATA[f7]]> <![CDATA[e1]]> 0.1 0.3 0.2 0.1 0.4 0.1 0.2 <![CDATA[e2]]> 0.2 0.2 0.3 0.6 0.5 0.3 0.1 <![CDATA[e3]]> 0.1 0.2 0.2 0.3 0.2 0.1 0.1 <![CDATA[e4]]> 0.6 0.5 0.3 0.2 0.2 0.3 0.4 <![CDATA[e5]]> 0.3 0.4 0.3 0.3 0.3 0.2 0.2

[0061] Table 2 shows the failure probability of each event under the conditions of various influencing factors. According to formula (1) and Table 2, the similarity of event failure probability s(e u ,e v ), forming the event failure probability similarity matrix S, as shown in Table 3.

[0062] Table 3. Event failure probability similarity matrix

[0063] S <![CDATA[e1]]> <![CDATA[e2]]> <![CDATA[e3]]> <![CDATA[e4]]> <![CDATA[e5]]> <![CDATA[e1]]> 1.0000 0.0814 0.1909 0.1909 0.4183 <![CDATA[e2]]> 0.0814 1.0000 0.7817 0.7817 0.1557 <![CDATA[e3]]> 0.1909 0.7817 1.0000 0.5625 0.5477 <![CDATA[e4]]> 0.1909 0.7817 0.5625 1.0000 0.2510 <![CDATA[e5]]> 0.4183 0.1557 0.5477 0.2510 1.0000

[0064] According to the definition of formula (1), the event failure probability similarity S(e u ,e v ) has the following properties. 0≤|S(e u ,e v )|≤1; when |S(e u ,e v )|→0, event e u and event e v The weaker the similarity of the failure probability is; when |S(e u ,e v )|→1, event e u and event e v The stronger the similarity of the failure probability is, the greater the similarity of the failure probability is. According to Table 1 and formula (2), the similarity of the influencing factors F(e u ,e v ), and form the influencing factor similarity matrix F, as shown in Table 4.

[0065] Table 4 Similarity matrix of influencing factors

[0066]

[0067]

[0068] According to formula (2), referring to Table 1, all events affected by factors are |F u |=|F v |=|F u ∩F v |=5, so the similarity of the influencing factors of all events is According to formula (1) and formula (2), the probability factor similarity SF(e u ,e v ), and form the probability factor similarity matrix SF, as shown in Table 5.

[0069] Table 5. Probability factor similarity matrix

[0070] SF <![CDATA[e1]]> <![CDATA[e2]]> <![CDATA[e3]]> <![CDATA[e4]]> <![CDATA[e5]]> <![CDATA[e1]]> 0.5000 0.0407 0.0955 0.0955 0.2092 <![CDATA[e2]]> 0.0407 0.5000 0.3909 0.3909 0.0778 <![CDATA[e3]]> 0.0955 0.3909 0.5000 0.2812 0.2739 <![CDATA[e4]]> 0.0955 0.3909 0.2812 0.5000 0.1255 <![CDATA[e5]]> 0.2092 0.0778 0.2739 0.1255 0.5000

[0071] According to Table 1 and formula (4), the information entropy of event failure probability H(e u ,e v ), forming the event failure probability information entropy matrix H, as shown in Table 6.

[0072] Table 6 Event failure probability information entropy matrix

[0073] H <![CDATA[e1]]> <![CDATA[e2]]> <![CDATA[e3]]> <![CDATA[e4]]> <![CDATA[e5]]> <![CDATA[e1]]> 0 1.8198 1.1043 2.0946 1.5648 <![CDATA[e2]]> 1.8198 0 1.5048 1.8166 1.6957 <![CDATA[e3]]> 1.1043 1.5048 0 1.8514 1.5648 <![CDATA[e4]]> 2.0946 1.8166 1.8514 0 1.6041 <![CDATA[e5]]> 1.5648 1.6957 1.5648 1.6041 0

[0074] When Δq n →0, then According to formula (5) and Table 6, the event failure probability entropy similarity SH (e u ,e v ), and establish the event failure probability entropy similarity matrix SH, as shown in Table 7.

[0075] Table 7 Event failure probability entropy similarity matrix

[0076] SH <![CDATA[e1]]> <![CDATA[e2]]> <![CDATA[e3]]> <![CDATA[e4]]> <![CDATA[e5]]> <![CDATA[e1]]> 1.0000 -0.1307 0.3139 -0.3015 0.0277 <![CDATA[e2]]> -0.1307 1.0000 0.0650 -0.1287 -0.0536 <![CDATA[e3]]> 0.3139 0.0650 1.0000 -0.1503 0.0277 <![CDATA[e4]]> -0.3015 -0.1287 -0.1503 1.0000 0.0033 <![CDATA[e5]]> 0.0277 -0.0536 0.0277 0.0033 1.0000

[0077] According to formula (6), combined with Table 5 and Table 7, the event failure probability entropy similarity SH (e u ,e v ) Modified probability factor similarity SF(e u ,e v ), and obtain the event similarity SE(e u ,e v ), and form the event similarity matrix SE, as shown in Table 8.

[0078] Table 8 Event similarity matrix

[0079] SE <![CDATA[e1]]> <![CDATA[e2]]> <![CDATA[e3]]> <![CDATA[e4]]> <![CDATA[e5]]> <![CDATA[e1]]> 0.5000 -0.0053 0.0300 -0.0288 0.0058 <![CDATA[e2]]> -0.0053 0.5000 0.0254 -0.0503 -0.0042 <![CDATA[e3]]> 0.0300 0.0254 0.5000 -0.0423 0.0076 <![CDATA[e4]]> -0.0288 -0.0503 -0.0423 0.5000 0.0004 <![CDATA[e5]]> 0.0058 -0.0042 0.0076 0.0004 0.5000

[0080] Arrange Table 8 to form the event similarity array SE = {SE 12 =-0.0053, SE 13 =0.03, SE 14 =-0.0288, SE 15 =0.0058, SE 23 =0.0254, E 24 =-0.0503, SE 25 =-0.0042, SE 34 =-0.0423, SE 35 =0.0076, SE 45 =0.0004}.

[0081] Sorting by numerical value:

[0082]

[0083] when When , the similarity of the events at the beginning of the analysis is Right now Converted into similar event pairs Right now Continue to are transformed into similar event pairs and plotted The relationship between similar event pairs corresponding to the similarity of all events at time , such as Figure 1 shown.

[0084] Depend on Figure 1 Positive fully closed similarity group when When , the similarity of the events at the beginning of the analysis is Right now Converted into similar event pairs Continue to are transformed into similar event pairs and plotted The relationship between similar event pairs corresponding to the similarity of all events at time , such as Figure 2 shown.

[0085] Depend on Figure 2 Negative fully closed similarity group because and Non-closed dissimilar groups And the original collection and Therefore, for this example, the original event set E = {e1, e2, e3, e4, e5} is divided into three event sets of three similar groups. The division result is a positive fully closed similarity group Negative fully closed similarity group Non-closed dissimilar groups This shows that events e3 and e5 have strong similarities, including event failure probability and failure probability change trend, and can be merged into one event. Events e2 and e4 have strong similarities, with similar event failure probabilities, but opposite failure probability change trends, and cannot be merged. Event e1 is not related to either of the above two categories and has no similarity with all other events, so it cannot be merged. Therefore, the original event set E = {e1, e2, e3, e4, e5} is simplified to E = {e1, e2, e3, e4, e5} according to the above similarity determination method. 35 ,e4}.

Claims

1. A factor-based event similarity analysis method, characterized in that: In order to simplify the numerous events involved in the evolution of system failures, a factor-based event similarity analysis method is proposed. The factor-based event similarity analysis method is based on influencing factors and changes, events, and event failure probabilities, and involves improved Pearson similarity, information entropy, and system failure evolution process theory. First, the feasibility of factor-based event similarity analysis is studied. Second, an event similarity analysis method is established, including event failure probability similarity, influencing factor similarity, probability factor similarity, event failure probability entropy similarity, and event similarity. Finally, an event classification method is proposed based on different event similarities, which is used for event classification based on event similarity. Construction of event similarity analysis method; suppose the event set that forms the system failure evolution process is , where the mth event is , ; The set of factors that affect the system failure evolution process is , where the nth factor is , The degree of influence of all factors on all events is expressed using the probability of event failure under the corresponding circumstances; Forming factor impact event degree matrix R , is the matrix of factors affecting event degree; ; Constructing the similarity of event failure probability; since the range of event failure probability under the influence of various factors is the same as [0,1], the failure probability is the unit change degree of the event failure characteristics in each factor dimension; The similarity between different events is compared using Pearson similarity and the similarity of event failure probability As shown in formula (1); (1) Where: It's an event and A collection of factors that are all affected; yes events in a collection; and The events and Affected factors Probability of failure of the event after the impact; and The events and The average probability of failure of an event after all factors have been affected; Formula (1) is established based on the matrix of factors affecting the degree of events, and the relationship between any two events is calculated. and Similarity of event failure probability under the influence of all factors; Constructing event failure probability similarity matrix S , S yes A symmetrical matrix with horizontal and vertical headers representing all events and corresponding cell values , determined by formula (1); Construction of influencing factor similarity; Establishment of influencing factor similarity based on improved Jaccard similarity method , as shown in formula (2); (2) Where: and The events and The set of factors affected, , ; Indicates the number of elements in the collection; Constructing the similarity matrix of influencing factors F , F yes A symmetrical matrix with horizontal and vertical headers representing all events and corresponding cell values , determined by formula (2); Probabilistic factor similarity construction; The probability factor similarity is a measure of the comprehensive similarity of the failure probability and the combined effect of factors between events; the event failure probability similarity obtained according to formula (1) and formula (2) is Similarity with influencing factors , thereby calculating the probability factor similarity , as shown in formula (3); (3) Constructing probability factor similarity matrix SF , SF yes A symmetrical matrix with horizontal and vertical headers representing all events, and the corresponding unit positions are , determined by formula (3); and matrix SF It is a definite value obtained based on the matrix data of the degree of influence of factors on events, and does not include the uncertainty of the data; Construction of event failure probability entropy similarity; First, establish the event failure probability information entropy; the information entropy representing the similarity of two event failure probabilities should use the difference in event failure probabilities under all factors. Calculate the information entropy of the event failure probability As shown in formula (4); (4) Construct event failure probability information entropy matrix H , H yes A symmetrical matrix with horizontal and vertical headers representing all events and corresponding cell values , determined by formula (4); and matrix H It can reflect the uncertainty involved in determining the probability of failure of an event; this uncertainty is based on the difference between the failure probabilities of two events; Information entropy based on event failure probability Construct event failure probability entropy similarity; Construct event failure probability entropy similarity , as shown in formula (5); (5) Construct event failure probability entropy similarity matrix SH , SH yes A symmetrical matrix with horizontal and vertical headers representing all events and corresponding cell values , determined by formula (5); Event similarity construction; Similarity based on probability factors , using event failure probability entropy similarity Make corrections to obtain event similarity , as shown in formula (6); (6) Constructing event similarity matrix SE , SE yes A symmetrical matrix with horizontal and vertical headers representing all events and corresponding cell values , determined by formula (6); Event classification method based on event similarity; The event similarity array is , the number of elements is , , , ;Will Abbreviated as ;according to The value of is different, when When, it is an event and events Similar, indicating and The failure probability values ​​and changing trends are similar; when When, it is an event and events Not similar; but When, it is an event and events Negative similarity, indicating and The failure probability values ​​of are similar, but the changing trends are opposite; Expressed as a pair of similar events, denoted as , analyze the above three situations respectively; If the event , ,and , or ,but Form a fully closed similarity group , ; Continue to subdivide, when , is a positive fully closed similarity group; when , It is a negative fully closed similarity group; in this case, the above events can form a closed loop connected end to end; when When , the similarity of the events at the beginning of the analysis is , that is, from the event Start; when When , the similarity of the events at the beginning of the analysis is , that is, from the event start; If the event , ,but , or ,but Forming non-closed similarity groups , ;when , is a positive non-closed similarity group; , It is a negative non-closed similarity group; in this case, the above events cannot form a closed loop, but form a chain structure; if The analysis ends; further, when or When there are repeated events in each similarity group, the repeated events should be split and treated as separate non-closed similarity groups. These events should be removed from the original fully closed similarity groups and non-closed similarity groups to form new fully closed similarity groups and non-closed similarity groups. if , then all form a non-closed similar group; similarly, if , then all Form a non-closed similar group; or ,and or ,So Form non-closed dissimilar groups.

2. The method for analyzing event similarity based on factors according to claim 1, characterized in that: Create an event similarity array SE And distinguish three situations; Express them in the form of similar event pairs and determine fully closed similar groups and non-closed similar groups; extract the repeated events of fully closed similar groups and non-closed similar groups to form non-closed similar groups; finally, determine whether there is a non-closed dissimilar group; In addition, the events in the fully closed similarity group and the non-closed similarity group have strong similarities, including the event failure probability and the failure probability change trend, and can be merged into one event; The events in the negative fully closed similarity group have strong similarity and similar failure probabilities, but the failure probability change trends are opposite, so the events cannot be merged; The non-closed dissimilar groups are not associated with the positive and negative similar groups, and the events within the groups are not similar, so the events cannot be merged.

3. The event similarity analysis method based on factors according to claim 1 is characterized in that The set of events that constitute the system failure evolution process is ; The set of factors affecting the evolution of system failure is: ; Get the matrix of factors affecting event degree R , is the matrix of factors affecting event degree; The factor influence event degree matrix is ​​the failure probability of each event under the conditions of each influencing factor; the event failure probability similarity is calculated based on formula (1) and the factor influence event degree matrix , forming the event failure probability similarity matrix , is the event failure probability similarity matrix; ; According to the definition of formula (1), the event failure probability similarity It has the following properties; ;when Time, event and events The weaker the similarity of the failure probability is; when Time, event and events The stronger the similarity of the failure probability is; the similarity of the influencing factors is calculated according to the factor influence event degree matrix and formula (2): , and form the influencing factor similarity matrix F , is the similarity matrix of influencing factors; According to formula (2), the reference factor influence event degree matrix, all events affected by factors are , so the similarity of the influencing factors of all events is ; Calculate the probability factor similarity according to formula (1) and formula (2) , and form a probability factor similarity matrix , is the probability factor similarity matrix; ; The information entropy of event failure probability is calculated based on the factor influence event degree matrix and formula (4): , forming the event failure probability information entropy matrix H , is the event failure probability information entropy matrix; When there is When ; According to formula (5) and the event failure probability information entropy matrix, the event failure probability entropy similarity is calculated , and establish the event failure probability entropy similarity matrix , is the event failure probability entropy similarity matrix; ; According to formula (6), the event failure probability entropy similarity matrix is ​​combined with the probability factor similarity matrix and the event failure probability entropy similarity matrix to use the event failure probability entropy similarity matrix. Corrected probability factor similarity , get the event similarity , and form an event similarity matrix , is the event similarity matrix; Arrange the event similarity matrix to form an event similarity array ; Sorting by numerical value: ; when When , the similarity of the events at the beginning of the analysis is ,Right now , converted into similar event pairs ,Right now ; Continue to are transformed into similar event pairs and plotted The relationship between similar event pairs corresponding to the similarity of all events at time ; The result is a positive fully closed similarity group ;when When , the similarity of the events at the beginning of the analysis is ,Right now , converted into similar event pairs ; Continue to are transformed into similar event pairs and plotted The relationship between similar event pairs corresponding to the similarity of all events at time ; The result is a negative fully closed similarity group ;because and , forming a non-closed dissimilar group ; and the original collection and in Remove; Therefore, for the many events involved in the evolution of the system failure, the original event set Three sets of events divided into three similar groups; the division result is a positive fully closed similar group , negative fully closed similarity group , non-closed dissimilar groups ; This indicates that the event The events with strong similarity, including the event failure probability and the failure probability change trend, are merged into one event; There is a strong similarity, the failure probabilities of the events are similar, but the failure probability change trends are opposite, and the events cannot be merged; event It is not related to the above two categories and has no similarity with all other events, so it cannot be merged; so the original event set According to the above similarity determination method, it can be simplified to .

Citation Information

Patent Citations

  • Event significance analytical method in compressor fault process

    CN111456932A

  • System, method and computer readable storage medium for troubleshooting

    US20110016355A1