Signaling link anomaly detection method and device, electronic equipment and storage medium
By acquiring monitoring data from the core network signaling link and the bearer network, and using the NetFlow protocol to determine the traffic information of the bearer network elements, the problem of anomaly location in the bearer network was solved, the stability of the core network signaling link was improved, and signaling storm incidents were reduced.
Patent Information
- Application Number
- CN202410865600.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-28
- Publication Date
- 2026-02-06
- Estimated Expiration
- 2044-06-28
AI Technical Summary
When abnormal faults such as packet loss and latency jitter occur in the bearer network, it is difficult to quickly locate the abnormal bearer network elements, leading to serious incidents such as signaling storms in the core network and affecting the stability of core network services.
By acquiring core network signaling link information and bearer network monitoring data, the path of bearer network elements is determined, and the traffic information of each bearer network element is obtained using the NetFlow protocol. Based on the traffic information, the anomaly detection results are judged, and the abnormal network elements are quickly located.
It enables accurate anomaly detection of core network signaling links, quickly locates abnormal bearer network elements, improves the stability of core network signaling links, and reduces the occurrence of signaling storm incidents.
Smart Images

Figure CN118632275B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, and particularly relates to a signaling link abnormality detection method and device, electronic equipment and storage medium. BACKGROUND
[0002] At present, with the rapid development of mobile services, combined with the introduction of new technologies and new services, the scale of the core network continues to expand, the service implementation becomes more complex, and the network structure changes continuously.
[0003] In the related art, a bearing network covering the whole country or even the whole world is usually used to connect core network elements scattered in different places to each other, and various mobile services are realized through signaling interaction between the core network elements. However, in actual application, it is found that the quality of the bearing network directly affects the stability of the core network signaling, and when abnormal faults such as packet loss and large delay jitter occur in the bearing network, it is difficult to quickly locate the bearing network element that has the abnormality, and thus serious accidents such as signaling storm of the core network are easily caused, which seriously affects the related services of the core network.
[0004] To sum up, the technical problems in the related art need to be improved. SUMMARY
[0005] The embodiments of the present application provide a signaling link abnormality detection method and device, electronic equipment and storage medium, which can accurately detect whether the core network signaling link is abnormal, and can quickly locate the bearing network element that has the abnormality according to the abnormality detection result of each bearing network element when the signaling link has an abnormal condition, thereby effectively improving the stability of the core network signaling link and reducing the possibility of accidents such as core network signaling storm.
[0006] In one aspect, the embodiments of the present application provide a signaling link abnormality detection method, which comprises the following steps:
[0007] Obtaining any core network signaling link information; the core network signaling link information comprises a starting core network element and a terminal core network element;
[0008] Obtaining bearing network monitoring data;
[0009] Determining a bearing network element path according to the core network signaling link information and the bearing network monitoring data;
[0010] Obtaining traffic information of each bearing network element in the bearing network element path;
[0011] Determining an abnormality detection result of each bearing network element according to the traffic information of each bearing network element.
[0012] Optionally, the bearer network element path is determined according to the core network signaling link information and the bearer network monitoring data, and the determining comprises:
[0013] The first five-tuple information of the core network is determined according to the core network signaling link information.
[0014] The second five-tuple information of the bearer network is determined according to the bearer network monitoring data.
[0015] All the bearer network elements and the transmission sequence participating in the signaling transmission in the bearer network are calculated according to the first five-tuple information and the second five-tuple information.
[0016] The bearer network element path is determined based on all the bearer network elements and the transmission sequence.
[0017] Optionally, the bearer network monitoring data is obtained, and the obtaining comprises:
[0018] The NetFlow data of each bearer network element in the bearer network is obtained by using the NetFlow protocol.
[0019] The signaling transmission parameters in the NetFlow data of each bearer network element are extracted as the monitoring data of each bearer network element.
[0020] The bearer network monitoring data is determined according to the monitoring data of all the bearer network elements.
[0021] Optionally, the signaling transmission parameters comprise a source address, a source port, a destination address, a destination port, a transmission protocol, a transmission direction, a data packet number and a data byte number.
[0022] Optionally, the traffic information of each bearer network element comprises a data packet number and a data byte number of the signaling traffic passing through each bearer network element.
[0023] Optionally, the abnormality detection result of each bearer network element is determined according to the traffic information of each bearer network element, and the determining comprises:
[0024] The data packet number and the data byte number of any bearer network element are determined.
[0025] When the data packet number is equal to a first threshold value and the data byte number is equal to a second threshold value, the abnormality detection result of any bearer network element is determined as no abnormality.
[0026] When the data packet number is not equal to the first threshold value or the data byte number is not equal to the second threshold value, the abnormality detection result of any bearer network element is determined as abnormality.
[0027] The step of determining the data packet number and the data byte number of any bearer network element is returned until the abnormality detection results of all the bearer network elements are determined.
[0028] Optionally, the first threshold value and the second threshold value are calculated by a weekly average trend method.
[0029] Optionally, the method further comprises:
[0030] updating the first threshold value and the second threshold value in response to the triggered update instruction.
[0031] Optionally, the update instruction comprises a text input update instruction; and updating the first threshold value and the second threshold value in response to the triggered update instruction comprises:
[0032] in response to the triggered text input update instruction, acquiring text input data, performing text recognition on the text input data, and updating the first threshold value and the second threshold value according to a result of the text recognition.
[0033] Optionally, the update instruction comprises a button click update instruction; and updating the first threshold value and the second threshold value in response to the triggered update instruction comprises:
[0034] in response to the triggered button click update instruction, acquiring button click data, performing recognition on the button click data, and updating the first threshold value and the second threshold value according to a result of the recognition.
[0035] Optionally, after determining the abnormal detection result of all the bearer network elements, the method further comprises:
[0036] determining that all the abnormal detection results are the bearer network elements with the exception, and adding the bearer network elements with the exception into an exception element set;
[0037] turning off each bearer network element in the exception element set.
[0038] Optionally, the core network signaling link information is any one of voice service core network signaling link information, 4G core network signaling link information, or 5G core network signaling link information.
[0039] In another aspect, an embodiment of the present application provides a signaling link exception detection device, the device comprising:
[0040] a link information acquisition module configured to acquire any core network signaling link information; the core network signaling link information comprises a starting core network element and a terminal core network element;
[0041] a monitoring data acquisition module configured to acquire bearer network monitoring data;
[0042] an element path determination module configured to determine a bearer network element path according to the core network signaling link information and the bearer network monitoring data;
[0043] a flow information acquisition module configured to acquire flow information of each bearer network element in the bearer network element path;
[0044] An abnormality detection result module is configured to determine an abnormality detection result of each bearer network element according to the traffic information of each bearer network element.
[0045] In another aspect, the embodiments of the present application provide an electronic device, which comprises a memory and a processor. The memory stores a computer program, and the processor implements the signaling link abnormality detection method when executing the computer program.
[0046] In another aspect, the embodiments of the present application provide a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to implement the signaling link abnormality detection method.
[0047] The embodiments of the present application determine the traffic information of each bearer network element on the path of the bearer network element related to the core network signaling link, thereby accurately detecting whether the core network signaling link is abnormal. In addition, when the signaling link is abnormal, the embodiments of the present application can quickly locate the abnormal bearer network element according to the abnormality detection result of each bearer network element, thereby effectively improving the stability of the core network signaling link and reducing the possibility of core network signaling storm and other accidents. BRIEF DESCRIPTION OF DRAWINGS
[0048] Figure 1 FIG. 1 is a schematic diagram of an implementation environment of a signaling link abnormality detection method provided by the embodiments of the present application;
[0049] Figure 2 FIG. 2 is a flowchart of a signaling link abnormality detection method provided by the embodiments of the present application;
[0050] Figure 3 FIG. 3 is a flowchart of determining bearer network monitoring data provided by the embodiments of the present application;
[0051] Figure 4 FIG. 4 is a flowchart of determining a bearer network element path provided by the embodiments of the present application;
[0052] Figure 5 FIG. 5 is a flowchart of determining an abnormality detection result of a bearer network element provided by the embodiments of the present application;
[0053] Figure 6 FIG. 6 is a flowchart of closing an abnormal bearer network element provided by the embodiments of the present application;
[0054] Figure 7 FIG. 7 is a flowchart of voice service core network signaling link abnormality detection provided by the embodiments of the present application;
[0055] Figure 8 FIG. 8 is a flowchart of 4G core network and 5G core network signaling link abnormality detection provided by the embodiments of the present application;
[0056] Figure 9 is a structural schematic diagram of a signaling link exception detection device provided by an embodiment of the present application;
[0057] Figure 10 is a hardware structural schematic diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0058] In order to make the objects, technical solutions and advantages of the present application clearer, the present application is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application. When the following description refers to the accompanying drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementation described in the following exemplary embodiments does not represent all the implementations consistent with the embodiments of the present application, but is only an example of devices and methods consistent with some aspects of the embodiments of the present application as described in the appended claims.
[0059] It can be understood that the terms "first", "second", and the like used in the present application can be used herein to describe various concepts, but unless specifically stated, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiments of the present application, the first information can also be referred to as the second information, and similarly, the second information can also be referred to as the first information. Depending on the context, the word "if" as used herein can be interpreted as "when" or "when" or "in response to determining".
[0060] The terms "at least one", "multiple", "each", "any" and the like used in the present application include one, two or more than two, multiple includes two or more than two, each refers to each of the corresponding multiple, and any refers to any one of the multiple.
[0061] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as understood by those skilled in the art to which the present application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.
[0062] Currently, with the rapid development of mobile services, combined with the introduction of new technologies and new services, the core network network scale continues to expand, the service implementation is more and more complex, the network structure is constantly changing, and the continuous introduction of IP and virtualization technology makes the internal and external structure of the core network change repeatedly, and the core network is no longer concentrated in one place.
[0063] In the related art, core network network elements scattered in different locations are usually connected by a nationwide or even global bearer network, and various mobile services are realized by means of signaling interaction between the core network network elements. However, in actual application, it is found that the quality of the bearer network directly affects the stability of the core network signaling, and when the bearer network has faults such as packet loss and large delay jitter, it is difficult to quickly locate the abnormal bearer network element, thereby easily leading to serious accidents such as signaling storm of the core network, and seriously affecting the related services of the core network.
[0064] Therefore, in the embodiments of the present application, a signaling link abnormality detection method, device, electronic equipment and storage medium are provided, by determining the traffic information of each bearer network element on the path of the bearer network element related to the core network signaling link, the accurate detection of whether the core network signaling link is abnormal is realized, and when the signaling link is abnormal, the abnormal bearer network element can be quickly located according to the abnormality detection result of each bearer network element, thereby effectively improving the stability of the core network signaling link and reducing the possibility of accidents such as core network signaling storm.
[0065] The specific implementation of the embodiments of the present application will be described in detail below with reference to the accompanying drawings. First, a signaling link abnormality detection method provided in the embodiments of the present application is described with reference to the accompanying drawings.
[0066] Please refer to Figure 1 , Figure 1 An implementation environment schematic diagram of a signaling link abnormality detection method provided in the embodiments of the present application is shown. In the implementation environment, the main subjects involved include a signaling link abnormality detection device 110 and a server 120.
[0067] Specifically, the signaling link abnormality detection device 110 can be installed with a processor, and the processor is in communication connection with the server 120.
[0068] The server 120 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and basic cloud computing services such as big data and artificial intelligence platforms.
[0069] The processor and the server 120 can establish a communication connection through a wireless network. The wireless network uses standard communication technology and / or protocols, and the network can be set as the Internet, or any other network, such as but not limited to a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile or wireless network, a private network, or any combination of virtual private networks. In addition, the same communication connection method or different communication connection methods can be used between the above-mentioned software and hardware, and the application does not make specific limitations.
[0070] Of course, it can be understood that Figure 1 The implementation environment in the above embodiment is only some optional application scenarios of the signaling link abnormality detection method provided in the embodiment of the application, and the actual application is not fixed to the environment shown in Figure 1 The application does not make specific limitations.
[0071] As Figure 2 shown, Figure 2 is a flowchart of a signaling link abnormality detection method provided in an embodiment of the application, and the method comprises the following steps:
[0072] S100, acquiring any core network signaling link information; the core network signaling link information comprises a starting core network element and a terminal core network element.
[0073] In the embodiment of the application, the specific implementation method of acquiring any core network signaling link information can be various. Exemplarily, in some embodiments, the Wireshark network analysis tool can be used to capture the signaling link information between different core network elements, and the specific information of the starting core network element and the terminal core network element carried in the signaling link information can be acquired. Exemplarily, in some embodiments, the core network signaling link information can be acquired by reading the signaling log stored on the P-CSCF (Proxy-Call Session Control Function) server.
[0074] It can be understood that the core network signaling link information can further comprise source address, source port, destination address, destination port, transmission protocol and other core network signaling link parameter data.
[0075] Of course, it should be noted that the introduction of the core network signaling link information provided in the above embodiment is only for exemplary description, and does not mean to limit the actual core network signaling link information determination method.
[0076] Step S200, acquiring the bearer network monitoring data.
[0077] In the embodiment of the present application, when any core network signaling link information is acquired, the bearer network monitoring data can be further acquired. Specifically, the transmission data and configuration data of each network element in the bearer network are acquired and integrated as the bearer network monitoring data.
[0078] Specifically, in a possible implementation, referring to Figure 3 , Figure 3 is a flow diagram provided by the embodiment of the present application for determining the bearer network monitoring data. The above-mentioned acquiring the bearer network monitoring data includes the following steps:
[0079] S210, acquiring the NetFlow data of each bearer network network element in the bearer network by using the NetFlow protocol.
[0080] S220, traversing and extracting the signaling transmission parameters in the NetFlow data of each bearer network network element as the monitoring data of each bearer network network element.
[0081] S230, determining the bearer network monitoring data according to the monitoring data of all bearer network network elements.
[0082] In the embodiment of the present application, the NetFlow data of each bearer network network element can be acquired by using the NetFlow protocol. The NetFlow protocol is a protocol that can be used to collect and monitor network traffic data. By monitoring and recording all IP traffic through different types of network elements such as router or switch interfaces, detailed NetFlow data can be provided.
[0083] Further, the signaling transmission parameters in the NetFlow data of each bearer network network element in the bearer network are traversed and extracted as the monitoring data of each bearer network network element.
[0084] Specifically, in a possible implementation, the signaling transmission parameters can include source address, source port, destination address, destination port, transmission protocol, transmission direction, data packet number and data byte number.
[0085] The source address refers to the IP address of the device initiating communication, the source port refers to the port number of the device initiating communication, the destination address refers to the IP address of the device receiving communication, the destination port refers to the port number of the device receiving communication, the transmission protocol refers to the protocol type (such as TCP, SCTP, etc.) used for communication, the transmission direction refers to the direction of communication, i.e., indicating whether the data packet enters or leaves a certain specific network interface, the data packet number refers to the number of data packets transmitted in a communication session, and the data byte number refers to the total number of data bytes transmitted in a communication session.
[0086] Finally, when the monitoring data of all the bearer network elements in the bearer network are extracted, the extracted monitoring data of all the bearer network elements can be integrated and unified as the bearer network monitoring data.
[0087] Step S300, determining a bearer network element path according to the core network signaling link information and the bearer network monitoring data.
[0088] In the embodiments of the present application, when any core network signaling link information and bearer network monitoring data are acquired, all the bearer network elements on the signaling link from the starting core network element to the terminal core network element can be matched out by association.
[0089] Specifically, in a possible implementation, please refer to Figure 4 , Figure 4 is a flowchart of determining a bearer network element path provided by the embodiments of the present application, and the above determining a bearer network element path according to core network signaling link information and bearer network monitoring data comprises the following steps:
[0090] S310, determining first five-tuple information of a core network according to the core network signaling link information;
[0091] S320, determining second five-tuple information of a bearer network according to the bearer network monitoring data;
[0092] S330, associating and calculating all the bearer network elements participating in signaling transmission in the bearer network and a transmission order according to the first five-tuple information and the second five-tuple information;
[0093] S340, determining the bearer network element path based on the all the bearer network elements and the transmission order.
[0094] Specifically, when the core network signaling link information is acquired, the five-tuple information of the core network, i.e. source address, source port, destination address, destination port and transmission protocol, can be determined as the first five-tuple information; when the bearer network monitoring data is acquired, the five-tuple information of the bearer network can be determined as the second five-tuple information; according to the source address, source port, destination address, destination port and transmission protocol in the first five-tuple information, all the bearer network elements participating in the signaling transmission in the core network signaling link and the transmission order between these bearer network elements in the bearer network can be matched and determined in the second five-tuple information.
[0095] Finally, based on the determined all bearer network elements and transmission sequence, a bearer network element path can be formed, which reflects the bearer network elements required to be passed through and the transmission sequence between the bearer network elements from the starting core network element to the terminal core network element in the core network signaling link.
[0096] In step S400, traffic information of each bearer network element in the bearer network element path is acquired.
[0097] In the embodiments of the present application, the traffic information of each bearer network element can be acquired through the NetFlow protocol.
[0098] Specifically, in a possible implementation, the traffic information of each bearer network element includes the number of data packets and the number of data bytes of the signaling traffic passing through each bearer network element.
[0099] That is, the number of data packets and the number of data bytes of the signaling traffic passing through each bearer network element in the signaling transmission process from the starting core network element to the terminal core network element in the bearer network element path can be tracked through the NetFlow protocol to determine the traffic information of each bearer network element.
[0100] In step S500, an abnormality detection result of each bearer network element is determined according to the traffic information of each bearer network element.
[0101] In the embodiments of the present application, when the traffic information of each bearer network element in the bearer network element path is determined, there can be multiple specific implementation manners to determine the abnormality detection result of each bearer network element. For example, in some embodiments, the abnormality detection result of the current bearer network element can be determined by comparing the traffic information variation trend of adjacent bearer network elements, for example, if the number of data packets of the current bearer network element sharply decreases, it can be determined that the current bearer network element has a packet loss phenomenon, and further the abnormality detection result of the current bearer network element is determined to be abnormal.
[0102] In a possible implementation, please refer to Figure 5 , Figure 5 FIG. 1 is a flowchart of a process for determining an abnormality detection result of a bearer network element provided by the embodiments of the present application, which comprises the following steps:
[0103] In step S510, the number of data packets and the number of data bytes of any bearer network element are determined.
[0104] In step S520, when the number of data packets is equal to a first threshold value and the number of data bytes is equal to a second threshold value, the abnormality detection result of the any bearer network element is determined to be normal.
[0105] S530, when the data packet number is not equal to the first threshold value or the data byte number is not equal to the second threshold value, determining that the abnormal detection result of the any bearer network element is abnormal;
[0106] S540, returning to the step of determining the data packet number and the data byte number of the any bearer network element until the abnormal detection results of all the bearer network elements are determined.
[0107] Specifically, when determining the abnormal detection result of each bearer network element according to the traffic information of each bearer network element, the data packet number and the data byte number of each bearer network element in the bearer network monitoring data are read, and then whether the bearer network element is abnormal is determined by comparing whether the data packet number is equal to the first threshold value and whether the data byte number is equal to the second threshold value, so as to determine whether the current core network signaling link is abnormal.
[0108] When the data packet number of the any bearer network element is equal to the first threshold value and the data byte number is equal to the second threshold value, it can be determined that the signaling traffic transmission of the bearer network element is normal and does not appear fluctuation, and further, the abnormal detection result of the bearer network element is determined to be no abnormal. When the data packet number of the any bearer network element is not equal to the first threshold value or the data byte number is not equal to the second threshold value, it can be determined that the signaling traffic transmission of the bearer network element is abnormal and appears fluctuation, for example, when the data packet number is higher than the first threshold value, it may be that the bearer network element appears abnormal situation of high frequency retransmission, and when the data packet number is lower than the first threshold value, it may be that the bearer network element appears abnormal situation of packet loss, resulting in a decrease in data volume, and further, the abnormal detection result of the bearer network element is determined to be abnormal.
[0109] It can be understood that the first threshold value can also be adjusted to a first threshold value interval and the second threshold value can also be adjusted to a second threshold value interval, and further, the abnormal detection result of the any bearer network element can be determined by determining whether the data packet number is located in the first threshold value interval and whether the data byte number is located in the second threshold value interval. For example, when it is determined that the data packet number of the any bearer network element is located in the first threshold value interval and the data byte number is located in the second threshold value interval, it is determined that the abnormal detection result of the bearer network element is no abnormal; and when it is determined that the data byte number of another bearer network element is not located in the second threshold value interval, it is determined that the abnormal detection result of the bearer network element is abnormal.
[0110] Further, in a possible implementation, the first threshold value and the second threshold value are calculated by a weekly average trend method.
[0111] It can be understood that when the bearer network is in a normal working state, the bearer network element will be in a long-time operation state, and the first threshold and the second threshold can be calculated by a weekly average trend method, that is, the number of data packets and the number of data bytes of the bearer network element in the data transmission process in the past week are collected, and the average values are taken as the first threshold and the second threshold, respectively.
[0112] It can be understood that the first threshold and the second threshold are determined by the weekly average trend, which can better help to identify periodic changes and long-term trends, improve the reliability of using the first threshold and the second threshold as an abnormality judgment basis, and better detect whether each bearer network element is abnormal.
[0113] Finally, by traversing to determine the number of data packets and the number of data bytes of any bearer network element, the abnormal detection result of each bearer network element in the bearer network element path is determined, and the abnormal detection results of all bearer network elements can be integrated as the abnormal detection result of the current core network signaling link.
[0114] That is, when the core network signaling link is abnormal, the traffic information of the bearer network element that does not appear abnormal is at a normal level, which meets the first threshold and the second threshold, and the bearer network element that appears abnormal will not meet the first threshold and the second threshold due to the fluctuation of signaling traffic transmission, and thus can be quickly identified and located, so as to switch to a standby core network signaling link and reduce the occurrence of a signaling storm accident of the core network caused by an abnormal bearer network element.
[0115] Further, in a possible implementation, the signaling link abnormality detection method provided by the embodiment of the application further includes:
[0116] In response to the triggered update instruction, updating the first threshold and the second threshold.
[0117] It can be understood that the first threshold and the second threshold are not unchangeable after being set in advance, but can be updated in real time by responding to the triggered update instruction, so as to better meet the use requirements of users.
[0118] For example, when the first threshold and the second threshold have remained unchanged for a certain period of time, the first threshold and the second threshold can be updated by issuing an update instruction, so that the first threshold and the second threshold better reflect the normal working level of the traffic information of the bearer network element.
[0119] It should be noted that the update instruction can be triggered by a user or sent to the processor by a server, and the application does not make specific limitations.
[0120] In the embodiments of the present application, the update instruction can include a text input update instruction input through an input box, a touch update instruction triggered by a touch screen operation, a selection update instruction triggered by a selection of a pull-down menu, a button click update instruction triggered by clicking an update button, and an update instruction checked through a check box, and the like, and is not limited to the above.
[0121] Specifically, in a possible implementation, the update instruction is a text input update instruction; and in response to the triggered update instruction, the first threshold and the second threshold are updated, including:
[0122] In response to the triggered text input update instruction, text input data is acquired, the text input data is subjected to text recognition, and the first threshold and the second threshold are updated according to a result of the text recognition.
[0123] It can be understood that the text input data can be input through an input box, input through an input box matched with an application program on a smart phone terminal, or automatically acquired based on actual use environment requirements. Further, when the text input data is subjected to text recognition, the text recognition can be performed through a pre-trained text recognition model. The text recognition model can be obtained by training a text data sample with a text recognition result label.
[0124] That is, a combination of a text data sample and a corresponding text recognition result label can be determined as a training sample after the text recognition result is determined in advance, and a plurality of training samples are obtained in this way.
[0125] After the plurality of training samples are obtained, the plurality of training samples are sequentially input to the text recognition model, that is, the text data sample and the text recognition result label in each training sample are simultaneously input to the text recognition model, the model parameters in the text recognition model are adjusted according to each output result of the text recognition model, and finally the pre-training process of the text recognition model is completed.
[0126] The pre-training process of the text recognition model can be considered to be completed when a pre-set pre-training number is reached, or the pre-training process of the text recognition model can be considered to be completed when the training output result of the text recognition model converges.
[0127] Finally, the first threshold and the second threshold are updated according to the result of the text recognition. For example, the user inputs "adjust the first threshold to a" in the input box, the processor captures the text input update instruction triggered by the user, responds and acquires the text data of the user for recognition, and updates the first threshold to a.
[0128] Specifically, in a possible implementation, the update instruction is a button click update instruction; in response to the triggered update instruction, the first threshold and the second threshold are updated, including:
[0129] In response to the triggered button click update instruction, button click data is acquired, the button click data is identified, and the first threshold and the second threshold are updated according to the identification result.
[0130] It can be understood that when the user actively clicks the button, the processor can capture the triggered button click update instruction. In addition, multiple buttons can be configured, and different threshold update amplitudes can be set for different buttons.
[0131] Therefore, by identifying the button click data, the first threshold and the second threshold can be updated according to the identified result.
[0132] The embodiments of the present application can update the first threshold and the second threshold in response to various update instructions of the user, effectively adapt to the abnormal detection requirements of the user on the bearer network element, and improve the user experience.
[0133] Specifically, please refer to Figure 6 , Figure 6 is a flowchart for closing an abnormal bearer network element provided by the embodiments of the present application. In a possible implementation, after determining the abnormal detection results of all bearer network elements, the method further includes:
[0134] Step S550, determining all abnormal detection results of the bearer network element with an abnormality, and adding the bearer network element to an abnormal element set;
[0135] Step S560, closing each bearer network element in the abnormal element set.
[0136] In the embodiments of the present application, after determining the abnormal detection results of all bearer network elements, the bearer network element with an abnormal detection result can be further determined and added to the abnormal element set.
[0137] Further, a closing instruction is issued to each bearer network element in the abnormal element set, so as to facilitate subsequent troubleshooting and repair work of the bearer network element, and the core network signaling link can be switched quickly and timely, the quality of the core network service is ensured, and the possibility of an accident of a signaling storm is reduced.
[0138] Specifically, in a possible implementation, the core network signaling link information is any one of voice service core network signaling link information, 4G core network signaling link information, or 5G core network signaling link information.
[0139] Voice over LTE (VoLTE) is a voice service technology based on IP multimedia subsystem; the 4G core network (EPC) is a core network technology in a 4G mobile communication network, mainly responsible for storage of user data, mobility management, and data exchange, and other key functions; the 5G core network (5GC) is a core network technology in a 5G mobile network, responsible for establishing reliable and secure network connections and providing access to services.
[0140] Please refer to Figure 7 , Figure 7 is a flowchart of a voice service core network signaling link anomaly detection provided by an embodiment of the present application, as shown in Figure 7
[0141] When any voice service core network signaling link information is obtained, the bearer network monitoring data related to the voice service core network signaling link information can be obtained, and the bearer network element path related to the voice service core network can be determined according to the first five-tuple information carried in the voice service core network signaling link information and the second five-tuple information carried in the bearer network monitoring data, the traffic information of each bearer network element in the bearer network element path is read, and the anomaly detection result of each bearer network element can be determined by comparing with the pre-set threshold, and finally the anomaly detection result of the voice service core network signaling link information is determined.
[0142] For example, the VoLTE user address pool information obtained from the voice service core network signaling link information, the signaling link source address, the source port, the destination address, the destination port, the protocol type, the VoLTE IPv6 address allocated by county, the base station IP, and the tracking area code and county relationship are read from the base station information, and the second five-tuple information is read from the bearer network monitoring data, and then the bearer network element path related to the voice service core network is determined. Therefore, when the abnormal bearer network element is determined, the physical area and the number of users affected by the anomaly can also be determined.
[0143] Please refer to Figure 8 , Figure 8 is a flowchart of 4G core network and 5G core network signaling link anomaly detection provided by an embodiment of the present application, as shown in Figure 8
[0144] When any 4G core network or 5G core network signaling link information is acquired, the bearing network monitoring data related to the 4G core network or 5G core network signaling link information can be acquired, and the bearing network element path related to the 4G core network or 5G core network can be determined according to the first five-tuple information carried in the 4G core network or 5G core network signaling link information and the second five-tuple information carried in the bearing network monitoring data, the traffic information of each bearing network element in the bearing network element path is read, and the abnormal detection result of each bearing network element can be determined by comparing with the pre-set threshold, and finally the abnormal detection result of the 4G core network or 5G core network signaling link information is determined.
[0145] It should be noted that the signaling link abnormal detection method provided in the present application can not only detect the abnormality of the signaling link between the core network elements and the core network elements, but also detect the abnormality of the signaling link between the core network elements and the terminal. That is, the signaling link abnormal detection method provided in the present application can fully meet the abnormal detection of different types and different services of signaling links in the mobile communication network.
[0146] Next, the signaling link abnormal detection method provided in the present application will be described in detail in combination with a specific application implementation process:
[0147] In the embodiment of the present application, a signaling link abnormal detection method is provided, which can be applied in the field of communication technology. By determining the traffic information of each bearing network element on the bearing network element path related to the core network signaling link, the accuracy of detecting whether the core network signaling link is abnormal is realized, and when the signaling link appears abnormal condition, the abnormal bearing network element appearing abnormal condition can be quickly located according to the abnormal detection result of each bearing network element, which effectively improves the stability of the core network signaling link and reduces the possibility of occurrence of core network signaling storm and other accidents.
[0148] Specifically, first, any core network signaling link information and bearing network monitoring data are acquired, then the first five-tuple information is determined by reading the core network signaling link information, and the second five-tuple information is determined by reading the bearing network monitoring data.
[0149] Further, the bearing network element path related to the core network signaling link is calculated and associated according to the first five-tuple information of the core network and the second five-tuple information of the bearing network.
[0150] Further, the traffic information of each bearing network element in the bearing network element path can be determined by the NetFlow protocol, specifically, the data packet number and the data byte number of each bearing network element in the bearing network element path can be determined.
[0151] Further, the abnormality of each bearer network element is determined by judging whether the data packet number is equal to the first threshold value and / or the data byte number is equal to the second threshold value, that is, when the data packet number is equal to the first threshold value and / or the data byte number is equal to the second threshold value, it is determined that the abnormality detection result of the bearer network element is normal.
[0152] Finally, all the bearer network elements with abnormality detection results of abnormality can be determined by screening, and a closing instruction is uniformly issued so as to troubleshoot and repair these abnormal bearer network elements, and it is helpful to realize active triggering of signaling link switching and achieve the purpose of quickly recovering core network service.
[0153] Please refer to Figure 9 The embodiment of the present application also provides a signaling link abnormality detection device 900, which can realize the above signaling link abnormality detection method, and the device comprises:
[0154] A link information acquisition module 910 is configured to acquire any core network signaling link information, wherein the core network signaling link information comprises a starting core network element and a terminal core network element.
[0155] A monitoring data acquisition module 920 is configured to acquire bearer network monitoring data.
[0156] A network element path determination module 930 is configured to determine a bearer network element path according to the core network signaling link information and the bearer network monitoring data.
[0157] A flow information acquisition module 940 is configured to acquire flow information of each bearer network element in the bearer network element path.
[0158] An abnormality detection result module 950 is configured to determine an abnormality detection result of each bearer network element according to the flow information of each bearer network element.
[0159] It can be understood that the contents in the above method embodiments are all applicable to the device embodiments, the device embodiments specifically realize the same functions as the above method embodiments, and achieve the same beneficial effects as the above method embodiments.
[0160] Please refer to Figure 10 , Figure 10 The hardware structure of the electronic device provided by the present application is illustrated, and the electronic device comprises:
[0161] The processor 1001 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an ASIC (Application Specific Integrated Circuit), or one or more integrated circuits, and is configured to execute related programs to implement the technical solutions provided by the embodiments of the present application.
[0162] The memory 1002 can be implemented by a ROM (ReadOnly Memory), a static storage device, a dynamic storage device, or a RAM (Random Access Memory), and the like. The memory 1002 can store an operating system and other application programs. When the technical solutions provided by the embodiments of the present application are implemented by software or firmware, the related program codes are stored in the memory 1002 and are called and executed by the processor 1001 to implement the signaling link exception detection method of the embodiments of the present application.
[0163] The input / output interface 1003 is configured to implement information input and output.
[0164] The communication interface 1004 is configured to implement the communication interaction between the device and other devices. The communication can be realized by a wired manner (for example, a USB, a network cable, and the like) or a wireless manner (for example, a mobile network, WIFI, Bluetooth, and the like).
[0165] The bus 1005 is configured to transmit information between various components (for example, the processor 1001, the memory 1002, the input / output interface 1003, and the communication interface 1004) of the device.
[0166] The processor 1001, the memory 1002, the input / output interface 1003, and the communication interface 1004 are connected to each other through the bus 1005 to realize the communication connection between the device.
[0167] It can be understood that the content in the above method embodiments is applicable to the device embodiments. The device embodiments specifically implement the same functions as the above method embodiments, and achieve the same beneficial effects as the above method embodiments.
[0168] The embodiments of the present application further provide a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to implement the above signaling link exception detection method.
[0169] It can be understood that the contents in the above method embodiments are all applicable to the present storage medium embodiments, the present storage medium embodiments specifically implement the functions same as those of the above method embodiments, and achieve the same beneficial effects as those of the above method embodiments.
[0170] The memory, as a non-transitory computer readable storage medium, can be used to store non-transitory software programs and non-transitory computer executable programs. In addition, the memory can include a high-speed random access memory, and can also include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some embodiments, the memory can optionally include a memory remotely arranged relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0171] The signaling link anomaly detection method and device, the electronic device, and the storage medium provided by the embodiments of the present application acquire any core network signaling link information, acquire bearer network monitoring data, determine a bearer network element path according to the core network signaling link information and the bearer network monitoring data, acquire traffic information of each bearer network element in the bearer network element path, and determine an anomaly detection result of each bearer network element according to the traffic information of each bearer network element. The embodiments of the present application determine the traffic information of each bearer network element on the bearer network element path related to the core network signaling link, accurately detect whether the core network signaling link is abnormal, and quickly locate the bearer network element with the abnormal condition according to the anomaly detection result of each bearer network element when the signaling link is in an abnormal condition, thereby effectively improving the stability of the core network signaling link and reducing the possibility of occurrence of core network signaling storm and other accidents.
[0172] The embodiments described in the embodiments of the present application are used to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that, with the evolution of technology and the appearance of new application scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.
[0173] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and can include more or fewer steps than those shown in the figures, or combine certain steps or different steps.
[0174] The apparatus embodiments described above are merely exemplary, and the units described as separate units can or can not be physically separate, i.e., can be located in one place, or can be distributed over multiple network units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the embodiment.
[0175] Those skilled in the art can understand that all or some of the steps in the method disclosed above, the functional modules / units in the system and the device can be implemented as software, firmware, hardware and appropriate combinations thereof.
[0176] The terms "first", "second", "third", "fourth" and the like in the description of the application and in the claims of the foregoing drawings, if any, are used for distinguishing between similar objects and not necessarily for describing a particular sequential or chronological order. It is to be understood that the use of the terms so
[0177] It should be understood that in the present application, "at least one" means one or more, and "multiple" means two or more. "And / or" is used to describe the relationship between the associated objects, which means that there can be three relationships, for example, "A and / or B" can mean that there are three cases: only A, only B, and A and B at the same time, where A and B can be singular or plural. The character " / " generally represents that the associated objects before and after are in an "or" relationship. "At least one of the following" or the like means any combination of these items, including any combination of single or multiple items. For example, at least one of a, b or c, can mean a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0178] In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can be implemented by other manners. For example, the apparatus embodiments described above are merely illustrative, for example, the division of the above units is merely a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units or components shown or discussed can be indirect coupling or communication connection through some interfaces, apparatuses or units, and can be electrical, mechanical or other forms.
[0179] The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e. they can be located in one place or distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0180] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0181] If the integrated unit is realized in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part of the prior art that makes a contribution or the whole or part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method of each embodiment of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various program storage media.
[0182] The preferred embodiments of the embodiments of the present application are described above with reference to the accompanying drawings, but this does not limit the scope of the embodiments of the present application. Any modifications, equivalent replacements and improvements made by those skilled in the art without departing from the scope and essence of the embodiments of the present application shall be within the scope of the embodiments of the present application.
Claims
1. A method of signaling link anomaly detection, the method comprising: The method comprises: acquiring any core network signaling link information; the core network signaling link information comprises a starting core network element and a terminal core network element; acquiring bearer network monitoring data; determining a bearer network element path according to the core network signaling link information and the bearer network monitoring data; acquiring traffic information of each bearer network element in the bearer network element path; determining an abnormality detection result of each bearer network element according to the traffic information of each bearer network element; the traffic information of each bearer network element comprises a data packet number and a data byte number of signaling traffic passing through each bearer network element; the determining of the abnormality detection result of each bearer network element according to the traffic information of each bearer network element comprises: determining a data packet number and a data byte number of any bearer network element; when the data packet number is equal to a first threshold value and the data byte number is equal to a second threshold value, determining that the abnormality detection result of the any bearer network element is normal; when the data packet number is not equal to the first threshold value or the data byte number is not equal to the second threshold value, determining that the abnormality detection result of the any bearer network element is abnormal; returning to the step of determining a data packet number and a data byte number of any bearer network element until the abnormality detection results of all bearer network elements are determined.
2. The signaling link anomaly detection method of claim 1, wherein, the determining of the bearer network element path according to the core network signaling link information and the bearer network monitoring data comprises: determining first five-tuple information of a core network according to the core network signaling link information; determining second five-tuple information of a bearer network according to the bearer network monitoring data; associatively calculating all bearer network elements participating in signaling transmission and a transmission sequence in the bearer network according to the first five-tuple information and the second five-tuple information; determining the bearer network element path based on the all bearer network elements and the transmission sequence.
3. The signaling link anomaly detection method of claim 1, wherein, the acquiring of the bearer network monitoring data comprises: acquiring NetFlow data of each bearer network element in the bearer network by using a NetFlow protocol; extracting signaling transmission parameters in the NetFlow data of each bearer network element as monitoring data of each bearer network element by traversal; determining bearer network monitoring data according to the monitoring data of all bearer network elements.
4. The signaling link anomaly detection method of claim 3, wherein, the signaling transmission parameters comprise a source address, a source port, a destination address, a destination port, a transmission protocol, a transmission direction, a data packet number and a data byte number.
5. The signaling link anomaly detection method of claim 1, wherein, the first threshold value and the second threshold value are calculated by a weekly average trend method.
6. The signaling link anomaly detection method of claim 1, wherein, the method further comprises: updating the first threshold value and the second threshold value in response to a triggered update instruction.
7. The signaling link anomaly detection method of claim 6, wherein, the update instruction comprises a text input update instruction; the updating of the first threshold value and the second threshold value in response to the triggered update instruction comprises: acquiring text input data in response to the triggered text input update instruction, performing text recognition on the text input data, and updating the first threshold value and the second threshold value according to a result of the text recognition.
8. The signaling link anomaly detection method of claim 6, wherein, the update instruction comprises a button click update instruction; the updating of the first threshold value and the second threshold value in response to the triggered update instruction comprises: In response to the triggered button click updating instruction, button click data is acquired, the button click data is identified, and the first threshold value and the second threshold value are updated according to the identification result.
9. The signaling link anomaly detection method of claim 1, wherein, After determining the abnormality detection results of all the bearer network elements, the method further comprises: determining that all the abnormality detection results are the bearer network elements with abnormalities, and adding the bearer network elements with abnormalities into an abnormal element set; turning off each bearer network element in the abnormal element set.
10. The signaling link anomaly detection method of claim 1, wherein, The core network signaling link information is any one of voice service core network signaling link information, 4G core network signaling link information or 5G core network signaling link information.
11. An apparatus for signaling link anomaly detection, the apparatus comprising: The apparatus comprises: a link information acquisition module configured to acquire any core network signaling link information; the core network signaling link information comprises a starting core network element and a terminal core network element; a monitoring data acquisition module configured to acquire bearer network monitoring data; an element path determination module configured to determine a bearer network element path according to the core network signaling link information and the bearer network monitoring data; a traffic information acquisition module configured to acquire traffic information of each bearer network element in the bearer network element path; an abnormality detection result module configured to determine an abnormality detection result of each bearer network element according to the traffic information of each bearer network element; the traffic information of each bearer network element comprises a data packet number and a data byte number of signaling traffic passing through each bearer network element; the determination of the abnormality detection result of each bearer network element according to the traffic information of each bearer network element comprises: determining the data packet number and the data byte number of any bearer network element; when the data packet number is equal to a first threshold value and the data byte number is equal to a second threshold value, determining that the abnormality detection result of the any bearer network element is normal; when the data packet number is not equal to the first threshold value or the data byte number is not equal to the second threshold value, determining that the abnormality detection result of the any bearer network element is abnormal; returning to the step of determining the data packet number and the data byte number of any bearer network element until the abnormality detection results of all the bearer network elements are determined.
12. An electronic device, comprising: The electronic device comprises a memory and a processor, the memory stores a computer program, and the processor implements the signaling link abnormality detection method of any one of claims 1 to 10 when executing the computer program.
13. A computer-readable storage medium, the computer-readable storage medium storing a computer program, characterized in that, The computer program is executed by the processor to implement the signaling link abnormality detection method of any one of claims 1 to 10.
Citation Information
Patent Citations
Network abnormality detection method, device, equipment or storage media
CN108667856A
Network abnormity detection method based on situation awareness prediction method
CN110460622A