Alarm device determination method and apparatus, and nonvolatile storage medium
By constructing an adjacency matrix and a fault probability matrix, and using graph theory and matrix theory methods, target alarm devices can be quickly identified, solving the bottleneck of alarm information processing during large-scale network failures, and realizing rapid location of faulty devices and rapid merging of alarm information.
Patent Information
- Application Number
- CN202410685206.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-29
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2044-05-29
AI Technical Summary
During large-scale network failures, network devices generate a massive amount of alarm information, making it impossible to quickly locate faulty devices and merge alarm information, thus affecting the efficiency of network repair.
By acquiring alarm information from a set of devices, determining the target pheromone, constructing an adjacency matrix and a fault probability matrix, and using graph theory and matrix theory methods, the target alarm device can be quickly identified.
It enables the rapid merging of massive alarm information and the rapid location of faulty devices, improving network repair efficiency and avoiding the risk of network paralysis.
Smart Images

Figure CN118677760B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of network security, in particular to a method and device for determining an alarm device and a nonvolatile storage medium. BACKGROUND
[0002] With the rapid development of science and technology, technology security and network security become more and more important, security is the premise and foundation of technology, and network security as an important part of national security has also been more and more attention from all sectors of society. At the same time, the development of emerging technologies also poses new challenges to network security, bringing new problems to the maintenance of network security.
[0003] When fluctuations or interruptions occur in the operator backbone network, the main telecommunication equipment will generate alarms to prompt network engineers to modify the network state. When a large-scale network failure occurs, a large number of sensitive network devices will generate a large amount of alarms in a very short time, and thousands of alarms will make engineers at a loss for a while, delaying valuable repair time, and in severe cases, it will lead to network paralysis, affecting the normal production and life of the people, and causing adverse effects on social stability and national security. A large amount of alarm information cannot be quickly merged, and the faulty device cannot be quickly located.
[0004] In view of the above problems, no effective solution has been proposed so far. SUMMARY
[0005] The embodiments of the present application provide a method and device for determining an alarm device and a nonvolatile storage medium to at least solve the technical problems of being unable to quickly locate the faulty device and quickly merge the alarm information due to a large number of alarm devices generating a large amount of alarm information when a large-area network failure occurs.
[0006] According to an aspect of an embodiment of the present application, a method for determining an alarm device is provided, comprising: obtaining alarm information corresponding to each device in a device set; determining target pheromone from the alarm information, wherein the target pheromone includes a source device type corresponding to a source device and a destination device type corresponding to a destination device that performs data interaction with the source device; determining an adjacency matrix corresponding to the alarm information based on the target pheromone and a preset device type, wherein the adjacency matrix is used to represent the number of alarm information generated in the data interaction process between any two devices in the device set; determining a fault probability matrix corresponding to the device set according to the adjacency matrix, and determining a target alarm device from the device set according to the fault probability matrix.
[0007] In some embodiments of the present application, the target pheromone is determined from the alarm information, comprising: obtaining a key pheromone in the alarm information, wherein the key pheromone contains a source device type, a destination device type, a device number corresponding to the source device, a device number corresponding to the destination device, and a protocol interface type used when the source device and the destination device are interconnected; and determining the target pheromone from the key pheromone.
[0008] In some embodiments of the present application, the adjacency matrix corresponding to the alarm information is determined based on the target pheromone and the preset device type, comprising: obtaining a first matrix composed of the preset device type; determining a transposed matrix composed of the target pheromone corresponding to each alarm information; and determining the adjacency matrix according to the first matrix and the transposed matrix.
[0009] In some embodiments of the present application, the fault probability matrix corresponding to the device set is determined according to the adjacency matrix, comprising: determining a block matrix based on the adjacency matrix, wherein the block matrix is used to distinguish the non-zero elements from the zero elements in the adjacency matrix; and determining the fault probability matrix according to the block matrix.
[0010] In some embodiments of the present application, the block matrix is determined based on the adjacency matrix, comprising: obtaining an elementary transformation matrix, wherein the elementary transformation matrix is used to block the adjacency matrix; and determining the block matrix according to the elementary transformation matrix and the adjacency matrix.
[0011] In some embodiments of the present application, the fault probability matrix is determined according to the block matrix, comprising: obtaining a sub-block matrix in which the element values are not all zero in the block matrix; obtaining a third matrix composed of the inverse of the number of alarm information corresponding to each device; and determining the fault probability matrix based on the sub-block matrix and the third matrix.
[0012] In some embodiments of the present application, the target alarm device is determined according to the fault probability matrix, comprising: determining an information entropy corresponding to the fault probability matrix; determining a target value according to the information entropy and the total number of devices in the device set; and determining the target alarm device according to the target value and the fault probability matrix.
[0013] According to another aspect of the embodiments of this application, an alarm device determination apparatus is also provided, comprising: an acquisition module, configured to acquire alarm information corresponding to each device in a device set; a first determination module, configured to determine a target pheromone from the alarm information, wherein the target pheromone includes a source device type corresponding to a source device and a destination device type corresponding to a destination device that interacts with the source device; a second determination module, configured to determine an adjacency matrix corresponding to the alarm information based on the target pheromone and a preset device type, wherein the adjacency matrix is used to represent the number of alarm information generated during data interaction between any two devices in the device set; and a third determination module, configured to determine a fault probability matrix corresponding to the device set based on the adjacency matrix, and determine a target alarm device from the device set based on the fault probability matrix.
[0014] According to another aspect of the embodiments of this application, a non-volatile storage medium is also provided, wherein a program is stored in the non-volatile storage medium, wherein the program controls the device where the non-volatile storage medium is located to execute the above-mentioned alarm device determination method when it runs.
[0015] According to another aspect of the embodiments of this application, an electronic device is also provided, including: a memory and a processor, wherein the processor is configured to run a program stored in the memory, wherein the program executes the above-described method for determining an alarm device when it runs.
[0016] According to another aspect of the embodiments of this application, a computer program product is also provided, including computer instructions that, when executed by a processor, implement the above-described method for determining an alarm device.
[0017] In this embodiment, the following methods are employed: acquiring alarm information corresponding to each device in the device set; determining target pheromones from the alarm information, wherein the target pheromones include the source device type corresponding to the source device and the destination device type corresponding to the destination device interacting with the source device; determining the adjacency matrix corresponding to the alarm information based on the target pheromones and preset device types, wherein the adjacency matrix represents the number of alarm information generated during data interaction between any two devices in the device set; determining the fault probability matrix corresponding to the device set based on the adjacency matrix, and determining the target alarm device from the device set based on the fault probability matrix. By extracting pheromones from the alarm information of all alarm devices, establishing an adjacency matrix based on the pheromones, and obtaining the fault probability matrix through the adjacency matrix, the aim of obtaining the target alarm device through the fault probability matrix is achieved. This realizes the technical effect of quickly merging massive amounts of alarm information to the target alarm device and quickly locating faulty devices, thereby solving the problem of being unable to quickly locate faulty devices and quickly merge alarm information when a large number of alarm devices generate a large amount of alarm information during a large-scale network failure. Attached Figure Description
[0018] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and together with the description serve to explain the application. In the drawings:
[0019] Figure 1 Fig. 1 is a hardware structure block diagram of a computer terminal for implementing a determination method of an alarm device according to an embodiment of the application;
[0020] Figure 2 Fig. 2 is a flowchart of a determination method of an alarm device according to an embodiment of the application;
[0021] Figure 3 Fig. 3 is a module schematic diagram of a determination method of an alarm device according to an embodiment of the application;
[0022] Figure 4 Fig. 4 is a key device type schematic diagram of a 5G core gateway of an alarm device according to an embodiment of the application;
[0023] Figure 5 Fig. 5 is a determination device schematic diagram of an alarm device according to an embodiment of the application. DETAILED DESCRIPTION
[0024] In order to make the personnel in the technical field better understand the application scheme, the technical scheme in the embodiments of the application will be clearly and completely described below in conjunction with the drawings in the embodiments of the application. Obviously, the described embodiments are only a part of the embodiments of the application, not all the embodiments. Based on the embodiments in the application, all other embodiments obtained by those of ordinary skill in the art without creative labor should be within the scope of protection of the application.
[0025] It should be noted that the terms "first", "second", and the like in the specification and claims of the application and the above-described drawings are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0026] In order to better understand the embodiments of the application, the technical terms involved in the embodiments of the application are explained as follows:
[0027] Adjacency matrix: a data structure used to describe a graph, which describes the connection between a set of vertices and their edges. In the embodiments of the present application, the adjacency matrix refers to a directed graph adjacency matrix.
[0028] Bayes formula: also known as Bayes theorem, is an important concept in probability theory. It describes how to calculate the probability of an event given some related information. The meaning of Bayes formula is: given the condition that event B has occurred, the probability of event A occurring is equal to the probability of event B occurring given the condition that event A has occurred (likelihood) multiplied by the probability of event A occurring (prior probability), and then divided by the probability of event B occurring (evidence). Bayes formula has wide applications in various fields such as machine learning, artificial intelligence, medical diagnosis, and financial risk assessment. By adjusting the prior probability and likelihood, the Bayes method can help us update the estimate of the probability of an event occurring, so as to make more accurate predictions and decisions.
[0029] Information entropy: used to eliminate redundant information and quantitatively analyze the uncertainty of various probability events.
[0030] TS23.501 is a protocol standard developed by the 3rd Generation Partnership Project (3GPP) organization for the specification of 5G system architecture. This protocol specification includes the core network architecture, interfaces and protocols related to 5G system, to support the deployment and operation of 5G network. The content of TS23.501 covers the specification of 5G system core network architecture, network slicing, user and device management, security mechanism, quality of service management, etc. These specifications provide guidance and standardized reference for the design, deployment and operation of 5G network, and help the interoperability and uniformity between different manufacturers and operators.
[0031] In the related art, when a large-scale network failure occurs, a large number of devices will generate a large amount of alarm information in a very short time. The large amount of alarm information cannot be quickly processed by relevant personnel to solve the network failure problem, so there is a problem of a large amount of alarm information that cannot be quickly merged and a large amount of fault devices that cannot be quickly located. In order to solve this problem, the present application provides a related solution, which is described in detail below.
[0032] According to the embodiments of the present application, a method for determining an alarm device is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order from that shown here.
[0033] The methods and embodiments provided in this application can be executed on mobile terminals, computer terminals, or similar computing devices. Figure 1 A hardware block diagram of a computer terminal for implementing a method for determining alarm devices is shown. Figure 1 As shown, the computer terminal 10 may include one or more processors 102 (shown as 102a, 102b, ..., 102n in the figure) 102 (processor 102 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 104 for storing data, and a transmission module 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 10 may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.
[0034] It should be noted that the aforementioned one or more processors 102 and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 10. As involved in the embodiments of this application, the data processing circuits serve as a form of processor control (e.g., selection of a variable resistor termination path connected to an interface).
[0035] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the alarm device determination method in this embodiment. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby realizing the alarm device determination method described above. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0036] The transmission device 106 is configured to receive or send data via a network. The network can include a wireless network provided by a communication provider of the computer terminal 10. In an example, the transmission device 106 includes a network interface controller (NIC) that can be connected to other network devices through a base station to communicate with the Internet. In an example, the transmission device 106 can be a radio frequency (RF) module configured to communicate with the Internet wirelessly.
[0037] The display can be a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the computer terminal 10 (or mobile device).
[0038] In the above operating environment, the embodiments of the present application provide a method for determining an alarm device, Figure 2 is a flow diagram of a method for determining an alarm device according to an embodiment of the present application, as shown in Figure 2 The method includes the following steps:
[0039] In step S202, alarm information corresponding to each device in the device set is obtained.
[0040] In the technical solution provided in step S202, when a large fluctuation occurs in the network, the alarm information corresponding to each device in the device set is obtained, and the information flow of the alarm information generated by the subsequent device will also be continuously received. In an optional embodiment, the alarm information corresponding to each device in the 5G network environment can be obtained through the above step S202.
[0041] In step S204, target pheromones are determined from the alarm information.
[0042] In the technical solution provided in step S204, the target pheromones include a source device type corresponding to a source device and a destination device type corresponding to a destination device that performs data interaction with the source device. The target pheromones are obtained by obtaining key pheromones in the alarm information and then merging the key pheromones. For example, the target pheromones can be obtained in the following manner:
[0043] First, key pheromones in the alarm information are obtained, wherein the key pheromones include a source device type, a destination device type, a device number corresponding to the source device, a device number corresponding to the destination device, and a protocol interface type used when the source device and the destination device are interconnected. The target pheromones are determined from the key pheromones. For example, the key pheromones can be represented in the following manner:
[0044] Alarm detail
[0045] = (Source device type, Destination device type, Source device ID, Destination device ID, Protocol interface type)
[0046] =(Src type ,Dst type ,Src id ,Dst id protocol)
[0047] Among them, Alarm detail Src represents the key pheromone. type Indicates the source device type corresponding to the source device, Dst type Src indicates the destination device type of the destination device that is interconnected with the source device. id Dst represents the source device number corresponding to the source device. id The destination device number represents the destination device, and the protocol represents the protocol interface type used when the source device and the destination device are interconnected.
[0048] After obtaining the aforementioned key pheromones, the target pheromone can be represented as follows:
[0049] Alarm simp
[0050] = (Source device type, Destination device type)
[0051] =(Src type ,Dst type )
[0052] Among them, Alarm simp Src represents the target pheromone. type Indicates the source device type, Dst type Indicates the type of device to be used.
[0053] The reason for simplifying the five-tuple abstracted from the key pheromone into a binary tuple corresponding to the pheromone is that there are at least a few and at most hundreds of devices of each type. In order to improve the performance of subsequent processes, the specific number of the device can be ignored, and the key pheromone can be simplified to a binary tuple containing only the source device type and the destination device type, thereby obtaining the target pheromone mentioned above.
[0054] Step S206: Determine the adjacency matrix corresponding to the alarm information based on the target pheromone and the preset device type.
[0055] In the technical solution provided in step S206, for example, in a 5G network, the preset device types are set according to the provisions of 3GPP protocol TS23.501. The 5G network device types to which the present application applies can be, for example, 14 types, including: Access and Mobility Management Function (AMF), Session Management Function (SMF), Policy Control Function (PCF), Network Slice Selection Function (NSSF), Authentication Server Function (AUSF), Unified Data Management (UDM), Network Capability Exposure Function (NCG), Security Management Function (SMSF), 5G Equipment Identity Register (5G-EIR), User Equipment (UE), Radio Access Network (RAN), User Plane Function (UPF), Data Network (DN), and Application Function (AF). It should be noted that in the above-mentioned 5G network or other environment, other network device types can also be included. The above-mentioned 14 network device types are only illustrative and do not represent a limitation. In actual network environments, the device types included in the preset device types can be increased or decreased according to the environment. The preset device types can be represented by Type. The matrix composed of the above-mentioned preset device types is the first matrix in the present application. Specifically, Type can be represented by the following way:
[0056] Type = (AMF, SMF, PCF, NSSF, AUSF, UDM, NCG, SMSF, 5G-EIR, UE, RAN, UPF, DN, AF)
[0057] Src type ,Dst type = t i ∈ Type
[0058] Wherein, Src typeIndicates the source device type, Dst type Indicates the type of destination device, t i This indicates the i-th device, and Type represents the preset device type. Each field in Type represents the selectable device types.
[0059] Based on the preset device type (Type), target pheromones are grouped into pheromone tuples:
[0060] Alarm simp
[0061] =(Src type ,Dst type )
[0062] =(t i ,t j )
[0063] Here, the pheromone binary represents a pheromone from device t. i To the device t j The alarm information indicates the source device type, the destination device type, and t. i Let t represent the i-th device. j This represents the j-th device, and when i = j, it represents device t. i When a fault occurs, it generates its own alarm information.
[0064] Assuming the total number of alarm messages is N, there will be N such alarm records. Since each record only needs to be extracted once, the time complexity of extracting alarm messages is linear and O(N).
[0065] In the technical solution provided in step S206, determining the adjacency matrix corresponding to the alarm information based on the target pheromone and the preset device type includes: obtaining a first matrix composed of preset device types; determining a transpose matrix composed of the target pheromone corresponding to each alarm information; and determining the adjacency matrix based on the first matrix and the transpose matrix.
[0066] Specifically, determining the adjacency matrix corresponding to the alarm information is for the purpose of using the directed adjacency matrix in graph theory, that is, determining the adjacency matrix to count the number of devices of any device type t. i Start to any device type t j The number of terminated alarm messages. Taking the above-mentioned preset device types containing 14 network device types as an example, since the preset device type 'Type' contains 14 network device types, the size of the first matrix is 14 rows × 14 columns. The first matrix can be represented by M. 14*14 express.
[0067] In this embodiment of the application, the total number of alarm messages can be represented by N, that is, all mi,j The accumulation of the N pieces of alarm information is also represented by N, and N can be specifically represented by the following manner:
[0068]
[0069] Wherein, m i,j represents the number of alarm information from device t i to device t j .
[0070] The adjacency matrix calculated by the N pieces of alarm information can be determined by the following formula:
[0071]
[0072] Wherein, M is the adjacency matrix, M 14*14 is the first matrix, with a size of 14 rows * 14 columns, and Alarm simp T represents the transposed matrix composed of the pheromone corresponding to each alarm information, and the second equation can be obtained by substituting the corresponding parameters, m i,j represents the number of alarm information from device t i to device t j , and i and j are both [1, 14].
[0073] Step S208, determining the fault probability matrix corresponding to the device set according to the adjacency matrix, and determining the target alarm device from the device set according to the fault probability matrix.
[0074] In the technical scheme provided in step S208, the 5G network is a mature network environment, and it has a certain resistance to network fluctuations. When the network fluctuation comes, it is impossible to affect all network devices. In fact, even in the case of network paralysis, only a few network devices are abnormal. Therefore, the key is how to find these few devices from a large number of network devices and alarm records, and therefore, the adjacency matrix needs to be merged to obtain a block matrix.
[0075] Specifically, the adjacency matrix can be merged to obtain a block matrix in the following manner: an elementary transformation matrix is obtained, wherein the elementary transformation matrix is used to block the adjacency matrix; and the block matrix is determined according to the elementary transformation matrix and the adjacency matrix.
[0076] In this embodiment, since the types of devices that can cause exceptions are relatively few in actual applications, most elements in Type are 0. Therefore, the vast majority of elements in the adjacency matrix M are also 0, meaning that the adjacency matrix M is a sparse matrix. Thus, the adjacency matrix can be divided into blocks after elementary row and column transformations in linear time complexity O(N), transforming all rows and columns with non-zero values to the top left corner of the matrix. The resulting block matrix is as follows:
[0077]
[0078] Among them, M block Let A represent a block matrix, where R and C are elementary transformation matrices, O is a matrix of all zeros, and matrix A is a block matrix. m*n Let m be a matrix with any number of rows and columns not all equal to 0, and let m*n be a matrix whose size is less than the size of its adjacency matrix M.
[0079] If alarm information N contains a large proportion of devices of type t, then... j The total number is s i The alarm records, then t j It is highly likely that this is the source of the malfunction. Due to the different types of t i Number of devices i Because of inconsistencies, a weighted normalization process is needed to calculate the proportion of devices. Specifically, this involves obtaining a sub-block matrix where not all elements are zero; obtaining a third matrix composed of the reciprocals of the number of alarm messages for each device; and determining the fault probability matrix based on the sub-block matrix and the third matrix. This can be expressed by the following formula:
[0080]
[0081] Where P represents the failure probability matrix, t n Indicates the device type, p n Indicates device type t n The probability of failure, and S m This represents the third matrix mentioned above.
[0082] Since the probability distribution in the fault probability matrix P is not uniform, the fault probability matrix P can be converged to identify the device or multiple devices most likely to cause the fault. Specifically, determining the target alarm device based on the fault probability matrix includes: determining the information entropy corresponding to the fault probability matrix; determining the target value based on the information entropy and the total number of devices in the device set, which is the k numbers with the highest relative probability; and determining the target alarm device based on the target value and the fault probability matrix, which is the device or multiple devices most likely to cause the fault.
[0083] In the embodiments of the present application, the target value k and the target alarm device can be determined by the following formula:
[0084]
[0085] wherein represents the information entropy of the failure probability matrix P, k represents the first k numbers with the largest probability, that is, the target value, n is the maximum value of the number of devices that can be obtained in the device set, that is, the total number of the number of devices in the device set, t max-k is the target alarm device, the target alarm device can include one or more alarm devices, is the device, p1…pt n is the device t1 to t n corresponding failure probability.
[0086] The above information entropy reflects the average situation of a group of probability value distribution, and the device with the largest probability value can be considered as the most fundamental cause of the failure. The minimum k is 1, that is, only one device is most likely to cause the failure; the maximum k is n, that is, all devices have almost equal influence on network fluctuation, and finally the total number of alarm information N converges to the k devices with the largest probability. The overall time complexity of the above steps S202-S208 is linear complexity time O(N), that is,
[0087] The overall time complexity T = T (extraction module) + T (merging module) + T (convergence module)
[0088] = O(N) + O(N) + O(1)
[0089] = O(N)
[0090] Wherein, the extraction module corresponds to step S202, the merging module corresponds to steps S204 and S206, and the convergence module corresponds to step S208.
[0091] Through the above steps S202-S208, the problem of massive alarms that cannot be quickly merged and quickly located is solved by using graph theory and Bayes theorem, and the important principles of graph theory, matrix theory, probability theory and information theory are organically combined with rigorous mathematical derivation. The algorithm theory is combined with the actual situation of the 5G core network to realize the rapid convergence of massive alarm information, which is still feasible in the case of uneven data distribution.
[0092] Figure 3 is a module schematic diagram of a method for determining an alarm device according to the embodiments of the present application, as shown in Figure 3 , comprising an extraction module, a merging module and a convergence module.
[0093] Firstly, the extraction module is executed to extract pheromones from massive alarms (i.e., alarm information, obtained by reporting alarms on network devices) in network devices (i.e., a device set), i.e., to obtain alarm information corresponding to each device in the device set; target pheromones are determined from the alarm information, wherein the target pheromones include a source device type corresponding to a source device and a destination device type corresponding to a destination device that performs data interaction with the source device; the target pheromones are determined from the alarm information, including: obtaining key pheromones in the alarm information, wherein the key pheromones include the source device type, the destination device type, a device number corresponding to the source device, a device number corresponding to the destination device, and a protocol interface type used when the source device and the destination device are interconnected; and the target pheromones are determined from the key pheromones.
[0094] The merging module is used to merge the target pheromones to obtain an information tuple table and construct a directed graph to obtain a directed adjacency matrix. Specifically, a first matrix composed of preset device types is obtained; a transposed matrix composed of target pheromones corresponding to each alarm information is determined; and an adjacency matrix, i.e., a directed adjacency matrix, is determined according to the first matrix and the transposed matrix.
[0095] The convergence module is used to row-column simplify the adjacency matrix to obtain a block matrix, and obtain a probability matrix based on the block matrix to obtain a converged fault device, i.e., a target alarm device.
[0096] It should be noted that, Figure 3 The module schematic diagram of the alarm device determination method shown in Figure 2 is the same as the principle of the flowchart of the alarm device determination method shown in Figure 2 Therefore, Figure 3 the related explanations and descriptions in also apply to
[0097] , which will not be described here. Figure 4 is a key device type schematic diagram of a 5G core gateway of an alarm device provided by an embodiment of the present application, as Figure 4 shown, the diagram includes AMF, SMF, PCF, NSSF, AUSF, UDM, NCG, SMSF, 5G-EIR, UE, RAN, UPF, DN, AF, a total of 14 devices, and the interaction relationship N1-N28 between each device.
[0098] Figure 5 is a determination apparatus schematic diagram of an alarm device provided by an embodiment of the present application, as Figure 5 shown, including:
[0099] The acquisition module 50 is used to obtain alarm information corresponding to each device in the device set;
[0100] The first determining module 52 is configured to determine target pheromones from the alarm information, wherein the target pheromones include a source device type corresponding to the source device and a destination device type corresponding to a destination device that interacts with the source device;
[0101] The second determining module 54 is configured to determine an adjacency matrix corresponding to the alarm information based on the target pheromones and preset device types, wherein the adjacency matrix is used to represent the number of alarm information generated in the data interaction process between any two devices in the device set.
[0102] The third determining module 56 is configured to determine a failure probability matrix corresponding to the device set according to the adjacency matrix, and determine the target alarm device from the device set according to the failure probability matrix.
[0103] The first determining module 52 is further configured to obtain key pheromones in the alarm information, wherein the key pheromones include the source device type, the destination device type, a device number corresponding to the source device, a device number corresponding to the destination device, and a protocol interface type used when the source device and the destination device are interconnected; and determine the target pheromones from the key pheromones.
[0104] The second determining module 54 is further configured to obtain a first matrix composed of the preset device types; determine a transposed matrix composed of the target pheromones corresponding to each alarm information; and determine the adjacency matrix according to the first matrix and the transposed matrix.
[0105] The third determining module 56 is further configured to determine a block matrix based on the adjacency matrix, wherein the block matrix is used to distinguish non-zero elements from zero elements in the adjacency matrix; and determine the failure probability matrix according to the block matrix.
[0106] The third determining module 56 is further configured to obtain an elementary transformation matrix, wherein the elementary transformation matrix is used to block the adjacency matrix; and determine the block matrix according to the elementary transformation matrix and the adjacency matrix.
[0107] The third determining module 56 is further configured to obtain a sub-block matrix in which element values are not all zero in the block matrix; obtain a third matrix composed of inverse numbers of the number of alarm information corresponding to each device; and determine the failure probability matrix based on the sub-block matrix and the third matrix.
[0108] The third determining module 56 is further configured to determine information entropy corresponding to the failure probability matrix; determine a target value according to the information entropy and a total number of devices in the device set; and determine the target alarm device according to the target value and the failure probability matrix.
[0109] It should be noted that each module in the alarm device determination apparatus described above can be a program module (for example, a program instruction set for implementing a certain specific function) or a hardware module. For the latter, it can be in the following form, but is not limited to this: each module is in the form of a processor, or the functions of each module are implemented by a processor.
[0110] In addition, Figure 5 The alarm device determination apparatus shown is used to execute Figure 2 The alarm device determination method shown is therefore Figure 2 The relevant explanations in the above description also apply to the alarm device determination apparatus, and will not be repeated here.
[0111] The embodiments of the present application also provide a non-volatile storage medium, which comprises a stored program, wherein when the program is running, the non-volatile storage medium controls a device in which the non-volatile storage medium is located to execute the following alarm device determination method: obtaining alarm information corresponding to each device in a device set; determining target pheromones from the alarm information, wherein the target pheromones comprise a source device type corresponding to a source device and a destination device type corresponding to a destination device that performs data interaction with the source device; determining an adjacency matrix corresponding to the alarm information based on the target pheromones and a preset device type, wherein the adjacency matrix is used to represent the number of alarm information generated in a data interaction process of any two devices in the device set; determining a fault probability matrix corresponding to the device set according to the adjacency matrix, and determining a target alarm device from the device set according to the fault probability matrix.
[0112] The embodiments of the present application also provide an electronic device, which comprises a processor, and the processor is used to run a program, wherein when the program is running, the following alarm device determination method is executed: obtaining alarm information corresponding to each device in a device set; determining target pheromones from the alarm information, wherein the target pheromones comprise a source device type corresponding to a source device and a destination device type corresponding to a destination device that performs data interaction with the source device; determining an adjacency matrix corresponding to the alarm information based on the target pheromones and a preset device type, wherein the adjacency matrix is used to represent the number of alarm information generated in a data interaction process of any two devices in the device set; determining a fault probability matrix corresponding to the device set according to the adjacency matrix, and determining a target alarm device from the device set according to the fault probability matrix.
[0113] According to a further aspect of the embodiments of the present application, a computer program product is also provided, which comprises a computer program, and the computer program, when executed by a processor, implements the following method for determining an alarm device: obtaining alarm information corresponding to each device in a device set; determining target pheromones from the alarm information, wherein the target pheromones comprise a source device type corresponding to a source device and a destination device type corresponding to a destination device that performs data interaction with the source device; determining an adjacency matrix corresponding to the alarm information based on the target pheromones and a preset device type, wherein the adjacency matrix is used to represent the number of alarm information generated in a data interaction process between any two devices in the device set; determining a fault probability matrix corresponding to the device set according to the adjacency matrix, and determining a target alarm device from the device set according to the fault probability matrix.
[0114] In the above-described embodiments of the present application, the description of each embodiment focuses on different aspects, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.
[0115] In several embodiments provided in the present application, it should be understood that the disclosed technical contents can be implemented by other means. Among them, the above-described device embodiments are only schematic, for example, the division of the units can be a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units or modules shown or discussed can be indirect coupling or communication connection through some interfaces, units or modules, which can be electrical or other forms.
[0116] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, that is, they can be located in one place, or they can be distributed to multiple units. Part or all of the units can be selected according to actual needs to achieve the purpose of the present embodiment.
[0117] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The above integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0118] The integrated unit, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application or the part that essentially contributes to the related art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in the embodiments of the present application. The aforementioned storage medium includes a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.
[0119] The above only describes the preferred embodiments of the present application. It should be noted that, for those skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, which should also be considered as the protection scope of the present application.
Claims
1. A method for determining an alarm device, characterized in that, include: Retrieve alarm information for each device in the device set; The target pheromone is determined from the alarm information, wherein the target pheromone includes the source device type corresponding to the source device and the destination device type corresponding to the destination device that interacts with the source device. Based on the target pheromone and the preset device type, the adjacency matrix corresponding to the alarm information is determined, wherein the adjacency matrix is used to represent the number of alarm information generated during data interaction between any two devices in the device set; The fault probability matrix corresponding to the device set is determined based on the adjacency matrix, and the target alarm device is determined from the device set based on the fault probability matrix. Determining the fault probability matrix corresponding to the device set based on the adjacency matrix includes: A block matrix is determined based on the adjacency matrix, wherein the block matrix is used to distinguish non-zero elements from zero elements in the adjacency matrix; The fault probability matrix is determined based on the block matrix; Determining the block matrix based on the adjacency matrix includes: Obtain the elementary transformation matrix, wherein the elementary transformation matrix is used to divide the adjacency matrix into blocks; The block matrix is determined based on the elementary transformation matrix and the adjacency matrix; Determining the fault probability matrix based on the block matrix includes: Obtain a sub-block matrix in the block matrix where not all elements are zero; Obtain the third matrix composed of the reciprocals of the number of alarm messages corresponding to each device; The fault probability matrix is determined based on the sub-block matrix and the third matrix.
2. The method for determining alarm devices according to claim 1, characterized in that, Determining the target pheromone from the alarm information includes: Obtain key pheromones from the alarm information, wherein the key pheromones include source device type, destination device type, device number corresponding to the source device, device number corresponding to the destination device, and protocol interface type used when the source device and the destination device are interconnected; The target pheromone is determined from the key pheromones.
3. The method for determining alarm devices according to claim 1, characterized in that, Determining the adjacency matrix corresponding to the alarm information based on the target pheromone and the preset device type includes: Obtain the first matrix composed of preset device types; Determine the transpose matrix consisting of the target pheromones corresponding to each alarm message; The adjacency matrix is determined based on the first matrix and the transpose matrix.
4. The method for determining alarm devices according to claim 1, characterized in that, The target alarm devices determined based on the fault probability matrix include: Determine the information entropy corresponding to the fault probability matrix; The target value is determined based on the information entropy and the total number of devices in the device set; The target alarm device is determined based on the target value and the fault probability matrix.
5. A device for determining an alarm device, characterized in that, include: The acquisition module is used to acquire alarm information corresponding to each device in the device set; The first determining module is used to determine the target pheromone from the alarm information, wherein the target pheromone includes the source device type corresponding to the source device and the destination device type corresponding to the destination device that interacts with the source device. The second determining module is used to determine the adjacency matrix corresponding to the alarm information based on the target pheromone and the preset device type, wherein the adjacency matrix is used to represent the number of alarm information generated during data interaction between any two devices in the device set; The third determining module determines the fault probability matrix corresponding to the device set based on the adjacency matrix, and determines the target alarm device from the device set based on the fault probability matrix. Determining the fault probability matrix corresponding to the device set based on the adjacency matrix includes: determining a block matrix based on the adjacency matrix, wherein the block matrix is used to distinguish non-zero elements from zero elements in the adjacency matrix; determining the fault probability matrix based on the block matrix; determining the block matrix based on the adjacency matrix includes: obtaining an elementary transformation matrix, wherein the elementary transformation matrix is used to divide the adjacency matrix into blocks; determining the block matrix based on the elementary transformation matrix and the adjacency matrix; determining the fault probability matrix based on the block matrix includes: obtaining a sub-block matrix in the block matrix where all element values are not zero; obtaining a third matrix composed of the reciprocal of the number of alarm messages corresponding to each device; and determining the fault probability matrix based on the sub-block matrices and the third matrix.
6. A non-volatile storage medium, characterized in that, The non-volatile storage medium stores a program, wherein when the program is executed, it controls the device where the non-volatile storage medium is located to execute the alarm device determination method according to any one of claims 1 to 4.
7. An electronic device, characterized in that, include: A memory and a processor, the processor being configured to run a program stored in the memory, wherein the program, when running, executes the method for determining an alarm device as described in any one of claims 1 to 4.
8. A computer program product comprising computer instructions, characterized in that, When the computer instructions are executed by the processor, they implement the method for determining the alarm device according to any one of claims 1 to 4.
Citation Information
Patent Citations
Alarm association method and device, computing equipment and computer storage medium
CN112202584A
Method and device for determining alarm level of network node and calculation equipment
CN113825148A