System early warning level determination method and related products
By determining the topology and calculating index values in the network system, the problem of accurately assessing abnormal situations in traditional network operation and maintenance technologies is solved, enabling more accurate early warning and more efficient network operation and maintenance.
Patent Information
- Application Number
- CN202411617568.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-12
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2044-11-12
AI Technical Summary
Traditional network operation and maintenance technologies struggle to accurately assess the impact of abnormal situations in network systems, leading to incomplete early warning results and hindering accurate and timely maintenance of network systems.
By determining the topology of the network system, the first indicator value between any two non-abnormal network devices is calculated based on nodes and edges. The second indicator value of the network system is calculated by combining multiple first indicator values. Then, the warning level of the network system is determined based on the second indicator value, and the overall performance of the network system is comprehensively considered.
It enables more accurate early warning of network systems, improves the accuracy of anomaly identification and the level of automation in network operation and maintenance, and improves operation and maintenance efficiency.
Smart Images

Figure CN119696990B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network operation and maintenance, and particularly relates to a system early warning level determination method and related products. BACKGROUND
[0002] Whether there is an abnormal situation in a network system, such as whether there is an abnormal network device in the network system, has a significant impact on the operation of the network system. In the case that there is an abnormal situation in the network system, the network system needs to be accurately warned so as to accurately and timely maintain the network system to ensure that the network system can normally and efficiently operate. In the traditional network operation and maintenance technology, it is difficult to accurately evaluate the influence of the abnormal situation, such as the abnormal network device, in the network system on the operation of the network system. Furthermore, the traditional network operation and maintenance technology has the disadvantage that it is difficult to accurately warn the network system. SUMMARY
[0003] Therefore, it is necessary to provide a system early warning level determination method and related products to more accurately warn the network system in view of the above technical problems. The related products include a system early warning level determination apparatus, a computer device, a computer readable storage medium, and a computer program product.
[0004] In a first aspect, the present application provides a system early warning level determination method, which comprises:
[0005] determining a topology graph of a network system, the topology graph comprising nodes and edges, the nodes being used to represent non-abnormal network devices in the network system, and the edges being used to represent connection routes of two non-abnormal network devices in the network system;
[0006] determining a first index value between any two nodes based on the nodes and the edges, the first index value being used to represent the ability and convenience of communication interaction between any two non-abnormal network devices;
[0007] determining a second index value of the network system based on a plurality of the first index values, the second index value being used to represent the communication performance and stability of the non-abnormal network devices, and the second index value being positively correlated with the first index value;
[0008] determining an early warning level of the network system based on the second index value, the early warning level being negatively correlated with the second index value.
[0009] The system early warning level determination method provided in the first aspect first determines a topology graph of the network system, wherein the topology graph includes nodes and edges, the nodes are used to represent non-exceptional network devices in the network system, and the edges are used to represent connection routes of two non-exceptional network devices in the network system. Then, a first index value between any two nodes is determined based on the nodes and the edges, and the first index value is used to accurately represent the ability and convenience of communication interaction between any two non-exceptional network devices. Further, a second index value of the network system is determined based on a plurality of first index values. The second index value is positively correlated with the first index value. The second index value can accurately represent the communication performance and stability of each non-exceptional network device in the network system. Further, the current performance of each non-exceptional network device in the network system is comprehensively considered based on the second index value of the network system. The better the current performance of each non-exceptional network device, the smaller the influence of the abnormal situation existing in the network system, such as the existence of an abnormal network device, on the non-exceptional network device and the entire network system, the smaller the fault degree of the network system, and the lower the early warning level of the network system. The worse the current performance of each non-exceptional network device, the greater the influence of the abnormal situation existing in the network system on the non-exceptional network device and the entire network system, the greater the fault degree of the network system, and the higher the early warning level of the network system. Therefore, the early warning level of the network system can be accurately determined based on the second index value of the network system, and the early warning level of the network system is negatively correlated with the second index value.
[0010] The system early warning level determination method accurately determines the current communication performance and stability of each non-exceptional network device in the network system, considers the current performance of each non-exceptional network device in the network system, deeply analyzes and comprehensively considers the current overall performance of the network system with the abnormal situation, and can more accurately determine the early warning level of the network system. Further, it is beneficial to more accurately warn the network system.
[0011] In a second aspect, the application further provides a system early warning level determination device, which comprises:
[0012] A topology graph determination module is configured to determine a topology graph of the network system, wherein the topology graph includes nodes and edges, the nodes are used to represent non-exceptional network devices in the network system, and the edges are used to represent connection routes of two non-exceptional network devices in the network system.
[0013] An index value determination module is configured to determine a first index value between any two nodes based on the nodes and the edges, and the first index value is used to represent the ability and convenience of communication interaction between any two non-exceptional network devices.
[0014] The index value determination module is further configured to determine a second index value of the network system based on the first index values, the second index value being used to represent communication performance and stability of the non-anomalous network device, and the second index value being positively correlated with the first index value.
[0015] The grade determination module is configured to determine a pre-warning grade of the network system based on the second index value, the pre-warning grade being negatively correlated with the second index value.
[0016] In a third aspect, a computer device is provided, including a memory and a processor, wherein the memory stores program instructions; and the program instructions, when executed by the processor, cause the processor to perform the method in the first aspect or any one of the embodiments of the first aspect.
[0017] In a fourth aspect, a computer readable storage medium is provided, which stores a computer program; and when the computer program is run on one or more processors, performs the method in the first aspect or any one of the embodiments of the first aspect.
[0018] In a fifth aspect, a computer program product is provided, which includes a computer program or instructions; and when the computer program or instructions are run on a computer, cause the computer to perform the method in the first aspect or any one of the embodiments of the first aspect.
[0019] It can be understood that the system pre-warning grade determination apparatus provided in the second aspect, the computer device provided in the third aspect, the computer readable storage medium provided in the fourth aspect, and the computer program product provided in the fifth aspect can be used to execute the system pre-warning grade determination method in the first aspect or any one of the embodiments of the first aspect. Therefore, the beneficial effects that can be achieved thereby can refer to those in the system pre-warning grade determination method, which will not be described herein again. BRIEF DESCRIPTION OF DRAWINGS
[0020] In order to clearly illustrate the technical solutions in the embodiments of the present application, the following will introduce the drawings needed to be used in the embodiments.
[0021] Figure 1 One of the flowcharts of the system pre-warning grade determination method provided in the embodiments of the present application;
[0022] Figure 2 The flowchart of determining the first index value between any two nodes based on nodes and edges provided in the embodiments of the present application;
[0023] Figure 3A flowchart of a method for determining a warning level of a network system based on a second index value is provided for the embodiments of the present application.
[0024] Figure 4 A flowchart of a method for determining a warning level of a system is provided for the embodiments of the present application.
[0025] Figure 5 A flowchart of a method for inputting time domain features and frequency domain features into a model respectively and outputting an abnormal level of a network device is provided for the embodiments of the present application.
[0026] Figure 6 A schematic diagram of a residual structure is provided for the embodiments of the present application.
[0027] Figure 7 A schematic diagram of a structure of a model is provided for the embodiments of the present application.
[0028] Figure 8 A flowchart of a method for determining a warning level of a system is provided for the embodiments of the present application.
[0029] Figure 9 A schematic diagram of a structure of a device for determining a warning level of a system is provided for the embodiments of the present application.
[0030] Figure 10 A schematic diagram of a structure of a computer device is provided for the embodiments of the present application. DETAILED DESCRIPTION
[0031] In order to facilitate the understanding of the embodiments of the present application, the embodiments of the present application will be described more fully below with reference to the accompanying drawings. The preferred embodiments of the present application are shown in the drawings. However, the embodiments of the present application can be realized in many different forms and are not limited to the embodiments described herein. On the contrary, these embodiments are provided so that the disclosure of the embodiments of the present application is more thorough and complete.
[0032] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the embodiments of the present application belong. The terminology used in the description of the embodiments of the present application herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the embodiments of the present application.
[0033] The terms "first", "second", and the like as used herein are used to distinguish different objects, rather than to describe a particular sequential order. For the purpose of distinguishing different objects, a "first indicator value" can be described as a "second indicator value", and a "second indicator value" can be described as a "first indicator value". In use, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising", when used in this specification, specify the presence of stated features, integers, steps, operations, parts, and / or combinations thereof, but do not preclude the presence or addition of one or more other features, integers, steps, operations, parts, and / or combinations thereof.
[0034] Whether there is an abnormal situation in the network system, such as whether there is an abnormal network device in the network system, has a significant impact on the operation of the network system. In the case of an abnormal situation in the network system, the network system needs to be accurately warned in order to accurately and timely maintain the network system to ensure that the network system can operate normally and efficiently. In the traditional network operation and maintenance technology, in the case of determining that there is an abnormal situation in the network system, the network system may be ignored. Or, if the existing abnormal situation is an abnormal network device, the network system may be simply warned according to the importance of the abnormal network device in the network system. Thus, the network system is warned, only the performance of the abnormal network device is concerned, which lacks in-depth analysis and comprehensive consideration of the overall performance of the network system, and it is difficult to accurately evaluate the influence of the abnormal situation on the operation of the network system. The obtained warning result is one-sided, and it is difficult to accurately warn the network system. Based on this, the embodiment of the present application provides a system warning level determination method which can perform in-depth analysis and comprehensive consideration on the overall performance of the network system, so as to more accurately warn the network system.
[0035] As shown in Figure 1 The system warning level determination method includes the following steps S101-S104.
[0036] S101, determine the topology graph of the network system. The topology graph includes nodes and edges, the nodes are used to represent non-abnormal network devices in the network system, and the edges are used to represent the connection route of two non-abnormal network devices in the network system.
[0037] The system warning level determination method in the embodiment strives to comprehensively and accurately evaluate abnormal situations existing in the network system, such as abnormal network devices, and the influence on the operation of the network system. For this purpose, the performance of each non-abnormal network device in the network system is determined. The performance of each non-abnormal network device in the network system can be used to represent the current overall performance of the network system. The network availability of the network system is used as a parameter for representing the overall performance of the network system. This network availability can comprehensively and accurately reflect the influence of abnormal situations such as abnormal network devices on the operation of the network system. If the performance of each non-abnormal network device is good and the network availability is high, it indicates that the influence of abnormal situations in the network system on the operation of the network system is small, the fault degree of the network system is low, and the system warning level is low. Conversely, it indicates that the influence of abnormal situations in the network system on the operation of the network system is large, the fault degree of the network system is high, and the system warning level is high. Further, based on the performance of each non-abnormal network device in the network system, that is, based on the network availability of the network system, the warning level of the network system is determined. Based on the warning level of the network system, the network system can be more accurately warned.
[0038] Specifically, the topology graph of the network system is determined first. The topology graph includes nodes and edges. The nodes are used to represent non-abnormal network devices in the network system, and the edges are used to represent the connection routes of two non-abnormal network devices in the network system.
[0039] The network device refers to a special hardware device that connects nodes such as various servers, personal computers (PCs), application terminals, and the like to each other to form an information communication network. Common network devices include switches, routers, servers, firewalls, network bridges, hubs, gateways, network interface cards, wireless access points, modems, and the like. In this embodiment, the method for determining whether the network device is abnormal can be that the network device is identified by an abnormality identification model to determine whether the network device is abnormal. The abnormality identification model is obtained by supervised training of the first model based on the abnormality of the network device marked by artificial, and the abnormality identification model can identify the abnormality of the network device. It should be noted that the abnormality of the network device is defined by artificial. In the definition process, artificial determines the abnormality of the network device according to the application scenario, network environment, business demand, and the like of the network device. In addition, it can also involve analyzing the historical data of the network device, and identifying and marking the potential abnormality. After artificial defines and marks the abnormality of the network device, a machine learning model can be trained to identify the abnormality of the network device, that is, the above abnormality identification model is obtained. It should be understood that the abnormality of different network devices can be different. For example, for a router, the abnormality can be that the packet loss rate suddenly increases, and for a server, the abnormality can be that the central processing unit usage rate has an abnormal peak. The abnormality of the same network device in different application scenarios or business demands can also be different. The meaning of "abnormality" is not limited in this embodiment. If the network device is set to be unavailable when the network device is abnormal, the abnormal network device refers to the network device that is abnormal, and the non-abnormal network device refers to the network device that is not abnormal. If the network device is set to be unavailable when the network device is abnormal and the abnormal level reaches the corresponding level threshold, the abnormal network device refers to the network device that is abnormal and the abnormal level reaches the corresponding level threshold, and the non-abnormal network device includes the network device that is not abnormal and the network device that is abnormal but the abnormal level is lower than the corresponding level threshold. The abnormal level of the network device is related to the type and number of abnormality, and the abnormal level definition standard of different network devices is different. The abnormal network device corresponds to the network device that is unavailable, and the non-abnormal network device corresponds to the network device that is available. The specific definition of the abnormal network device and the non-abnormal network device can be determined according to the specific network scenario, the specific business carried by each network device, and the like. The topology graph generally refers to a network structure graph composed of network devices and communication media, which is used to describe and display the structure and connection mode of the computer network. The topology graph of the network system determined in this embodiment refers to a network structure graph composed of non-abnormal network devices in the network system and connection routes of two non-abnormal network devices.
[0040] S102, determine a first index value between any two nodes based on the nodes and edges. The first index value is used to represent the ability and convenience of communication interaction between any two non-anomalous network devices.
[0041] The first index value representing the ability and convenience of communication interaction between any two non-anomalous network devices can be determined by the path redundancy and path complexity between any two nodes, that is, by the nodes and edges in the topology graph. Specifically, the path redundancy is embodied based on the number of connection paths between any two nodes. Each connection path between any two nodes includes at least one edge. For example, there is a connection path between the first node and the third node through the second node, and the connection path is composed of an edge connecting the first node and the second node and an edge connecting the second node and the third node, and the connection path includes two edges. The path redundancy can also be understood as the connection strength between any two nodes. The more connection paths, the higher the connection strength and the path redundancy, and the stronger the communication performance of the non-anomalous network devices corresponding to the two nodes. If there is an abnormal network device in the network system, even if the unusable abnormal network device is excluded, the non-anomalous network devices can still maintain high communication ability. If a communication path fails, communication can still continue through other communication paths. The path complexity is embodied based on the number of nodes included in the connection path between any two nodes. The fewer the number of nodes included in a connection path, the lower the path complexity of the connection path and the fewer the potential failure points. The smaller the probability of network failure of the non-anomalous network devices corresponding to the two nodes in the communication process, the stronger the stability of the non-anomalous network devices. Based on the path redundancy and path complexity between any two nodes included in the topology graph, the first index value between any two nodes determined can accurately represent the ability and convenience of communication interaction between any two non-anomalous network devices, and can accurately represent the communication performance and stability of any two non-anomalous network devices in the network system.
[0042] S103, determine a second index value of the network system based on a plurality of first index values. The second index value is used to represent the communication performance and stability of the non-anomalous network devices, and the second index value is positively correlated with the first index value.
[0043] Based on the first index value between any two nodes, a second index value of the network system for representing the communication performance and stability of each non-exceptional network device can be determined, and the second index value is positively correlated with the first index value. It should be understood that if there are three nodes in the topology graph, by pairwise combination, a first index value between any two nodes corresponds, and three first index values can be obtained. The second index value determined thereby can comprehensively and accurately reflect the influence of abnormal network devices and other abnormal situations on the operation of the network system. Specifically, the higher the first index value between any two nodes, the more stable the corresponding non-exceptional network device connection, and the stronger the communication performance and stability. The higher the second index value of the network system determined based on multiple first index values, the stronger the communication performance and stability of each non-exceptional network device in the network system, and the smaller the influence of abnormal network devices and other abnormal situations on the operation of the network system.
[0044] It should be noted that the network system in the foregoing description is that the performance of each non-exceptional network device in the network system can be used to represent the overall performance of the network system at present, and the network availability of the network system is used as a parameter for representing the overall performance of the network system. Thus, the network availability refers to the ability of the non-exceptional network devices in the network system to maintain communication ability and stability in network operation. Since the second index value is used to represent the communication performance and stability of the non-exceptional network devices in the network system, the second index value can be regarded as the numerical value of the network availability parameter.
[0045] In S104, a warning level of the network system is determined based on the second index value. The warning level is negatively correlated with the second index value.
[0046] Further, based on the second index value, that is, based on the network availability of the network system, the current communication performance and stability of each non-exceptional network device in the network system are comprehensively considered, and the overall performance of the network system is comprehensively considered, and thus the warning level of the network system can be accurately determined. The better the performance of each non-exceptional network device at present, the smaller the influence of abnormal situations in the network system on the non-exceptional network device and the entire network system, the smaller the fault degree of the network system, and the lower the warning level of the network system; the worse the performance of each non-exceptional network device at present, the greater the influence of abnormal situations on the non-exceptional network device and the entire network system, the greater the fault degree of the network system, and the higher the warning level of the network system.
[0047] The system early warning level determination method in the embodiment can accurately determine the current communication performance and stability of each non-exceptional network device in the network system, consider the current performance of each non-exceptional network device in the network system, in-depth analyze and comprehensively consider the current network availability of the network system in which an exception exists, for example, an abnormal network device exists, and more accurately determine the early warning level of the network system. When the exception is that an abnormal network device exists, the influence of the abnormal network device on the operation of the network system is comprehensively and accurately evaluated, and the one-sidedness of determining the early warning level of the network system based on the performance of the abnormal network device is avoided. Further, the network system is more accurately warned, the network availability is more comprehensively evaluated, the influence of the exception on the operation of the network system is more accurately reflected, the network system is more accurately warned, and more accurate and timely warning information is provided for the operation and maintenance personnel, so that the network system is accurately and timely maintained, the accuracy of exception identification and the automation level of network operation and maintenance are improved, network operation and maintenance automation is more accurately and efficiently realized, the operation and maintenance personnel can more quickly locate and solve network exception problems, and the operation and maintenance efficiency is improved. The development of the network operation and maintenance technical field has important positive significance.
[0048] In one embodiment, as shown in FIG. 1, step S102, determining the first index value between any two nodes based on the nodes and edges includes steps S201 to S203. Figure 2
[0049] S201, determining the connection path between any two nodes according to the edges. The connection paths are not intersected.
[0050] As described in the foregoing embodiments, the number of connection paths between any two nodes is used to represent the path redundancy degree, and each connection path between any two nodes includes at least one edge. Therefore, the connection path between any two nodes can be determined according to the edge. At this time, the number of determined connection paths is at least one. The number of connection paths refers to the number of non-intersected connection paths between any two nodes in the topology graph, that is, in the case where the number of connection paths is at least two, there is no intersection point of edges and no intersection point of nodes between at least two connection paths between any two nodes.
[0051] S202, determining the number of nodes contained in the connection path.
[0052] The number of nodes contained in the connection path between any two nodes, i.e., the node number, is used to represent the path complexity of the corresponding connection path. It should be noted that the node number contained in the connection path is the number of nodes excluding any two nodes, i.e., the number of nodes separated by any two nodes in the corresponding connection path. In the case of at least one connection path, determining the node number contained in the connection path is actually determining the node number contained in each connection path between any two nodes, respectively.
[0053] In S203, a first index value is obtained based on the node number. The first index value is negatively correlated with the node number.
[0054] Obtaining the first index value based on the node number means that the first index value is obtained based on the node number contained in each connection path between any two nodes, respectively. This process not only involves the node number contained in each connection path, but also involves the number of connection paths between any two nodes, i.e., not only the path complexity of each connection path between any two nodes, but also the path redundancy between any two nodes. This process can be understood as obtaining the first index value between any two nodes based on the path redundancy and the path complexity between any two nodes. As described in the foregoing embodiments, the higher the path redundancy, the stronger the communication performance of the non- abnormal network device corresponding to any two nodes, and the higher the first index value; the lower the path complexity, the stronger the stability of the non- abnormal network device corresponding to any two nodes, and the higher the first index value. That is, the first index value between any two nodes is positively correlated with the path redundancy, and the first index value is negatively correlated with the path complexity. Specifically, the first index value between any two nodes can be obtained based on the node number contained in each connection path between any two nodes, respectively, wherein the first index value is positively correlated with the number of connection paths between any two nodes, and the first index value is negatively correlated with the node number contained in each connection path.
[0055] For example, the first index value between any two nodes is equal to the sum of the reciprocals of the node numbers contained in each connection path plus a constant. Specifically, it can be represented by the following formula:
[0056]
[0057] Wherein, v(i, j) represents the first index value between the ith node and the jth node in the topology graph, and in this embodiment, it represents the first index value between any two nodes. t represents the tth connection path between any two nodes. q represents the number of disjoint connection paths between any two nodes, and the greater the q, the stronger the connection strength between any two nodes, the higher the path redundancy degree, the higher the first index value, and the higher the availability and robustness of the network. Ms(t) represents the number of interval nodes contained in the tth connection path, and the smaller the Ms(t), the lower the path complexity of the tth connection path between any two nodes, the higher the first index value between the two nodes, and the higher the availability and reliability of the network. a is a constant greater than 0, which can be 1.
[0058] Exemplarily, the first index value between any two nodes is equal to the weighted sum of the reciprocals of the number of nodes contained in each connection path plus a constant. Specifically, based on the importance of each connection path between any two nodes in the communication process, the reciprocals of the number of nodes contained in the connection path plus a constant are weighted. Wherein, the importance of the connection path in the communication process can be determined based on the path complexity of the connection path, the services carried by the interval nodes contained in the connection path, the importance of the interval nodes in the network system, etc.
[0059] In this embodiment, based on the number of nodes contained in the connection path between any two nodes in the topology graph, the first index value between the two nodes can be obtained. The first index value between any two nodes calculated by this calculation method can accurately represent the communication performance and stability of any two non-exceptional network devices in the network system. Further, the second index value determined based on the plurality of first index values can accurately represent the communication performance and stability of each non-exceptional network device in the network system, can fully and accurately reflect the influence of abnormal situations such as abnormal network devices on the operation of the network system, and is beneficial to accurately determining the warning level of the network system and accurately warning the network system.
[0060] In one of the embodiments, the step S103 of determining the second index value of the network system based on the plurality of first index values comprises the following steps:
[0061] Summing the plurality of first index values to obtain the second index value of the network system.
[0062] Exemplarily, if the topology graph contains three nodes, three different first index values can be obtained based on the first index values between any two nodes in the topology graph through pairwise combination, and the second index value of the network system can be obtained by summing the three different first index values. If the topology graph contains four nodes, six different first index values can be obtained through pairwise combination, and the second index value of the network system can be obtained by summing the six different first index values.
[0063] The first index value between any two nodes is used to represent the communication performance and stability of any two non-exceptional network devices in the network system. The higher the first index value, the higher the communication performance and stability between any two non-exceptional network devices, and the higher the communication performance and stability of each non-exceptional network device in the network system. Therefore, the second index value of the network system is positively correlated with the first index value between any two nodes.
[0064] Specifically, the second index value of the network system can be calculated by the following formula:
[0065]
[0066] wherein V is the second index value of the network system, i.e., the numerical value of the network availability of the network system. v(i,j) represents the first index value between the ith node and the jth node in the topology graph, and the ith node and the jth node are any two nodes in the topology graph. n is the total number of nodes in the topology graph, i.e., the number of non-exceptional network devices included in the network system. The higher the first index value between any two nodes, the more stable the connection between the two nodes, and the higher the network availability of the network system.
[0067] Exemplarily, the second index value of the network system is obtained by weighted sum of a plurality of first index values. Specifically, based on the importance of the two nodes in network communication, the weighting coefficient of the first index value between the two nodes is determined. The importance of the two nodes in network communication can be determined based on the business carried by the two nodes, the importance of the nodes in the network system, and other factors.
[0068] In the case that the first index value v(i,j) between any two nodes is determined by the path redundancy and the path complexity between the two nodes, the second index value of the network system, i.e. the value of the network availability, calculated based on the method in the embodiment, comprehensively considers the number of non-exceptional network devices in the network system, the communication performance between any two non-exceptional network devices, the stability of each non-exceptional network device, the number of communication paths between any two non-exceptional network devices, the number of non-exceptional network devices in the interval included in each communication path, and the like. The number of non-exceptional network devices is related to the total number of network devices in the network system and the number of exceptional network devices. Based on in-depth analysis and comprehensive consideration, the network availability of the network system can comprehensively and accurately evaluate the influence of the abnormal situation such as the existence of the exceptional network device on the network system. Further, based on the network availability of the network system, the warning level of the network system can be accurately determined to more accurately warn the network system.
[0069] In one of the embodiments, the network system includes non-exceptional network devices and exceptional network devices. As shown in Figure 3 The step S104 of determining the warning level of the network system based on the second index value includes the following steps S301-S303.
[0070] S301, determining a third index value of the exceptional network device according to the performance index of the exceptional network device. The third index value is used to represent the importance of the exceptional network device to the network system.
[0071] The importance of the network device in the network system refers to the criticality and influence of the network device in the network, which can be measured by the performance index of the network device. The performance index includes bandwidth, delay, throughput, frequency range, frequency resolution, test port output frequency characteristics, output characteristics, test port input characteristics, group delay characteristics, and measurement parameters, and the like.
[0072] S302, performing weighted summation on the second index value and the third index value to obtain a fourth index value.
[0073] As described in the foregoing embodiments, based on in-depth analysis and comprehensive consideration, the network availability of the network system can comprehensively and accurately evaluate the influence of the abnormal situation such as the existence of the exceptional network device on the network system. On this basis, in the case that the abnormal situation in the network device is the existence of the exceptional network device, the performance of the exceptional network device can be further considered to determine the warning level of the network system in combination with the importance of the exceptional network device in the network system.
[0074] Specifically, the second indicator value for representing network availability and the third indicator value for representing the importance of the abnormal network device are weighted and summed, and in the case where there are multiple abnormal network devices, the second indicator value and the third indicator value of each abnormal network device are weighted and summed to obtain a fourth indicator value. The weighting coefficients of the second indicator value and the third indicator value of each abnormal network device can be learned by analyzing historical network data. Based on the relationship between the second indicator value of the network system, the third indicator value of the abnormal network device, and the actual warning level of the network system in the historical situation, the corresponding weighting coefficients are learned.
[0075] In S303, a warning level of the network system is obtained according to an indicator threshold interval to which the fourth indicator value belongs. The indicator threshold interval and the warning level are in one-to-one correspondence.
[0076] According to the indicator threshold interval to which the fourth indicator value belongs, the corresponding warning level of the network system can be obtained. The indicator threshold interval and the warning level are in one-to-one correspondence, and the larger the indicator threshold interval, the higher the warning level.
[0077] In the embodiment, the fourth indicator value obtained by weighting and summing the second indicator value for representing network availability and the third indicator value for representing the importance of the abnormal network device can comprehensively and accurately evaluate the influence of the abnormal network device on the network system, and also considers the performance of the abnormal network device. Through the corresponding relationship between the indicator threshold interval to which the fourth indicator value belongs and the warning level, the warning level of the network system can be accurately determined, and the network system can be more accurately warned.
[0078] In one of the embodiments, the step S104 of determining the warning level of the network system based on the second indicator value includes the following steps: obtaining the warning level of the network system according to a preset threshold interval to which the second indicator value belongs, and the preset threshold interval and the warning level are in one-to-one correspondence. The preset threshold interval refers to a threshold interval of the numerical value of network availability, and the larger the preset threshold interval, the lower the warning level.
[0079] In the embodiment, based on in-depth analysis and comprehensive consideration, the second indicator value for representing the numerical value of network availability of the network system can comprehensively and accurately evaluate the influence of abnormal situations such as the presence of abnormal network devices on the network system. Through the corresponding relationship between the preset threshold interval to which the second indicator value belongs and the warning level, the warning level of the network system can be accurately determined, and the network system can be more accurately warned.
[0080] To accurately give an early warning to the network system containing abnormal network devices, before determining the topology graph of the network system to determine the second index value of the network system based on the information contained in the topology graph, it is necessary to first determine which network devices in the network system are unavailable. To distinguish the unavailable network devices in the network system, the topology graph is obtained based on the available non-abnormal network devices. That is, the abnormal network devices need to be determined first. Based on this, the system early warning level determination method in the following embodiments supplements the technical process of determining abnormal network devices in the case where the network system contains abnormal network devices.
[0081] In one of the embodiments, the network system includes non-abnormal network devices and abnormal network devices. As shown in Figure 4 The system early warning level determination method further includes the following steps S401-S407. Among them, steps S404-S407 correspond one by one to steps S101-S104 in the foregoing embodiments. The specific discussion about steps S404-S407 in this embodiment can refer to the specific discussion about steps S101-S104 in the foregoing embodiments, and this embodiment will not be repeated.
[0082] S401, the operation and maintenance data of the network devices in the network system are preprocessed to obtain the time domain features and frequency domain features of the network devices.
[0083] The operation and maintenance data refers to the periodic data generated by the network devices in the operation process of the network system. Under the condition that the operation and maintenance data is the periodic data generated by the network devices, the specific data type of the operation and maintenance data is not limited in this embodiment. For example, the operation and maintenance data can be the traffic data, memory usage, central processing unit usage, etc. generated by the network devices. The time domain features and frequency domain features are the data features of the operation and maintenance data under different modalities. Based on the periodic characteristics of the operation and maintenance data, the operation and maintenance data can usually describe the change trend through curves and other forms. Feature extraction of the operation and maintenance data of the network devices in the network system can extract the data features in the time domain and the frequency domain. Among them, the time domain features are sequence features, and the frequency domain features are graph features. The information contained in the time domain features and the frequency domain features is rich and diverse.
[0084] For ease of description, in this embodiment, the operation and maintenance data will be taken as the traffic data as an example. When the operation and maintenance data is other periodic data generated by a network device, the processing mode of the corresponding data can refer to the processing mode of the traffic data. Taking the operation and maintenance data as the traffic data as an example, the time domain feature can be understood as a data feature in the time domain obtained by performing feature extraction on the traffic data of the network device. The time domain feature is a sequence feature, and includes at least one of a traffic time sequence, a traffic change rate sequence, a traffic periodic component sequence, and a traffic protocol proportion sequence. The traffic time sequence is the most basic sequence feature of traffic and time, and directly records the network traffic value at each time point. The traffic change rate sequence records the traffic change rate between each time point and the previous time point. The traffic periodic component sequence extracts the periodic components of the traffic, such as daily cycles and weekly cycles, through time series analysis. For example, if the daily cycle component of the traffic is extracted, the unit of the time axis is defined as one day. The traffic protocol proportion sequence records the proportion of different network protocol traffic at each time point. The frequency domain feature can be understood as a data feature in the frequency domain obtained by performing feature extraction on the traffic data of the network device. The frequency domain feature is a graph feature, and includes a traffic spectrum graph.
[0085] In S402, the time domain feature and the frequency domain feature are respectively input into a model, and an abnormal level of the network device is output. The model is used for feature fusion on the time domain feature and the frequency domain feature of the network device, and maps out the abnormal level of the network device based on the fused features.
[0086] The conventional method for determining an abnormal network device mainly relies on a single modal feature for abnormal evaluation, and has obvious limitations. First, it ignores the complementarity of information among different modalities and the importance of modal fusion for abnormal evaluation, and fails to fully utilize the rich information provided by multi-modal data features. Second, when performing abnormal evaluation, it only focuses on local features, and lacks comprehensive consideration of the overall network state.
[0087] Based on this, after extracting the time domain features and the frequency domain features of the operation and maintenance data of the network device under different modalities, the embodiment fully considers the complementarity of the time domain features and the frequency domain features under different modalities and the importance of modal fusion for abnormal evaluation. The time domain feature and the frequency domain feature are respectively input into a model, and the multi-modal features of the network device are fused by the model, that is, the time domain feature and the frequency domain feature are fused. Then, the fused features are used for abnormal evaluation to determine the abnormal level of the network device. This process fully utilizes the rich information provided by multi-modal data features. Moreover, compared with being based on a single, local modal feature, the embodiment based on the time domain features and the frequency domain features under different modalities can more comprehensively consider the overall network state from different levels and angles.
[0088] S403, in a case where the abnormality level is greater than or equal to the level threshold, determining the network device as an abnormal network device.
[0089] Referring to the foregoing embodiments discussed, if the network device is set to exist an abnormality and the abnormality level reaches the corresponding level threshold, the network device is unavailable, the abnormal network device refers to the network device that exists an abnormality and the abnormality level reaches the corresponding level threshold. Wherein, the abnormality level reaches the level threshold refers to the abnormality level is greater than or equal to the level threshold, which is used to represent that the abnormality degree of the network device is greater than or equal to the abnormality degree corresponding to the level threshold. If the abnormality level is divided into 0, 1, 2 three levels in which the abnormality degree increases in turn, 1 level is the level threshold, the abnormality level greater than or equal to the level threshold includes two cases that the abnormality level is 1 level and 2 level. If the abnormality level is divided into 0, 1, 2 three levels in which the abnormality degree decreases in turn, 1 level is the level threshold, the abnormality level greater than or equal to the level threshold includes two cases that the abnormality level is 1 level and 0 level. Based on this, after determining the abnormality level of the network device, in a case where the abnormality level is greater than or equal to the level threshold, the network device can be determined as an abnormal network device. It can be understood that if the level threshold corresponding to the network device is the lowest level, it can be understood that when the network device exists an abnormality, it can be considered as an abnormal network device that is unavailable.
[0090] S404, determining a topology graph of the network system. The topology graph includes nodes and edges, the nodes are used to represent non-abnormal network devices in the network system, and the edges are used to represent connection routes of two non-abnormal network devices in the network system.
[0091] S405, determining a first index value between any two nodes based on the nodes and the edges. The first index value is used to represent the ability and convenience degree of communication interaction between any two non-abnormal network devices.
[0092] S406, determining a second index value of the network system based on a plurality of first index values. The second index value is used to represent the communication performance and stability of the non-abnormal network devices, and the second index value is positively correlated with the first index value.
[0093] S407, determining a warning level of the network system based on the second index value. The warning level is negatively correlated with the second index value.
[0094] The embodiment fully considers the complementarity of time domain features and frequency domain features under different modalities and the importance of modality fusion for anomaly evaluation, performs feature fusion on the time domain features and the frequency domain features of the network device through a model, and then performs anomaly evaluation based on the fused features to determine the anomaly level of the network device. The time domain features and the frequency domain features have wide and diverse information coverage. By extracting the time domain features and the frequency domain features of the network device operation and maintenance data, the rich information provided by the time domain features and the frequency domain features is fully utilized, which is beneficial to more comprehensively consider the overall network state from different levels and angles, can more comprehensively capture abnormal behaviors in network operation and maintenance, and reduce the missed and false alarm cases. It is beneficial to enrich the information contained in the fused features, to more accurately evaluate the anomaly of the network device and determine the anomaly level of the network device, and then more accurately determine the unusable abnormal network device. By accurately determining the abnormal network device, it is beneficial to more accurately warn the network system. The system warning level determination method in the embodiment combines the multi-modal information fusion technology and the network availability evaluation method. In addition to being able to more accurately evaluate the anomaly of the network device and the network system, and comprehensively and accurately warning the network system, it also has the following technical effects. The automatic acquisition and preprocessing of the target operation and maintenance data can be realized, the manual intervention is reduced, and the automation level and operation and maintenance efficiency of network operation and maintenance are improved; the multi-modal information fusion technology and the network availability evaluation method are used to comprehensively and accurately warn the network system, so that the operation and maintenance personnel can more quickly locate and solve network anomaly problems, which is also beneficial to improve the automation level and operation and maintenance efficiency of network operation and maintenance, and to more accurately and efficiently realize network operation and maintenance automation; and has important positive significance for the development of network operation and maintenance technical field.
[0095] In one embodiment, as shown in Figure 5 The step S402 is shown as follows. The time domain features and the frequency domain features are respectively input into a model to output the anomaly level of the network device, including the following steps S501-S503.
[0096] S501, the time domain features and the frequency domain features are respectively input into a neural network in the model to perform feature extraction on high-dimensional data, and first features of the time domain features and second features of the frequency domain features are output.
[0097] In order to improve the accuracy of determining the abnormal level of the network device based on the fused features, the fused features can be made to reflect the essential information and structural information of the operation and maintenance data of the network device as much as possible. In other words, the more comprehensive information contained in the fused features, the more accurate the abnormal level of the network device determined based on the features. Based on this, the convolutional neural network is used to extract features of high-dimensional data, and automatically extract data features containing essential information and structural information of the data. The high-dimensional data refers to data with a large number of dimensions. In the case of inputting the time domain features and the frequency domain features into the model respectively, the time domain features and the frequency domain features are input into the neural network of the model, and the feature extraction of the two high-dimensional data is performed by the neural network respectively, and the first feature of the time domain features and the second feature of the frequency domain features are output. In this way, the first feature capable of effectively representing the internal structure and mode of the time domain features and the second feature capable of effectively representing the internal structure and mode of the frequency domain features are obtained, and the first feature and the second feature contain the essential information and structural information of the operation and maintenance data.
[0098] Specifically, the time domain features and the frequency domain features are input into two neural networks in the model in parallel, and the feature extraction of the high-dimensional data is performed by the two neural networks. The first neural network in the two neural networks outputs the first feature of the time domain features, and the second neural network in the two neural networks outputs the second feature of the frequency domain features. The two neural networks include the first neural network and the second neural network. The number of neural networks in the model is the same as the number of input features, so that the model can simultaneously capture and analyze data features from different modalities, which is beneficial to enhance the understanding and processing ability of the model for data, and is beneficial to the model to more comprehensively understand and analyze the behavior of the network device, thereby improving the accuracy and efficiency of the abnormal evaluation of the network device.
[0099] The neural network in the model contains a residual structure, and by introducing a skip connection, the depth of the network is fully utilized to learn more complex and deep feature representations, and then generate the first feature and the second feature containing the essential information and structural information of the data. In order to learn more complex and deep feature representations, and then generate the features of high-dimensional data containing the essential information and structural information of the data, the residual structure is not specifically limited in the embodiment.
[0100] For example, for the residual structure, since an odd convolution kernel helps to maintain the symmetry of the spatial hierarchy, too few channels are not conducive to capturing more feature information, and the increase in the number of channels usually means that more feature information can be captured, but also increases the risk of overfitting and computational complexity. Therefore, the residual structure shown in Figure 6 can be used to extract features of high-dimensional data. As shown in Figure 6As shown, ReLU represents an activation function, "1x1, 32" represents a convolutional layer with a 1x1 convolution kernel and 32 channels, "3x3, 64" represents a convolutional layer with a 3x3 convolution kernel and 64 channels, and "1x1, 64" represents a convolutional layer with a 1x1 convolution kernel and 64 channels. The two 1x1 convolution kernels in the residual structure are used for dimension reduction and dimension increase to reduce the number of parameters, and the convolutional layer in the middle uses an odd convolution kernel 3x3 to help maintain the symmetry of the spatial hierarchy. Moreover, the channel numbers of 32 and 64 are appropriate and can well balance the expression ability and computational efficiency of the model.
[0101] Based on the characteristics of the residual structure, the residual structure directly connects the input to the subsequent layer by introducing a skip connection, and the output feature of the residual structure is the sum of the input feature input to the residual structure and the feature obtained after a series of convolution operations on the input feature. Based on this, the dimension of the first feature generated by the residual structure is related to the dimension of the time domain feature, and the dimension of the second feature is related to the dimension of the frequency domain feature. The dimensions of the first feature and the second feature are usually represented in the form of a one-dimensional vector after being processed by the fully connected layer of the residual structure, such as 1x128 and 1x1024. Among them, the dimension of the feature is usually set according to actual needs, and the larger the data volume, the larger the information dimension; the smaller the data volume, the smaller the information dimension.
[0102] S502, the first feature and the second feature are fused by the joint architecture in the model to output a fused feature.
[0103] After extracting the first feature and the second feature containing the essential information and structural information of the operation and maintenance data, considering the complementarity of the time domain feature and the frequency domain feature under different modalities and the importance of modal fusion for abnormal evaluation, the model also includes a joint architecture. The joint architecture is used to combine the outputs of the fully connected layers of the residual structures of the two neural networks, that is, to combine the first feature and the second feature to output a fused feature. For example, if the fully connected layers of the two residual structures output the first feature with a one-dimensional vector of 1x128 and the second feature with a one-dimensional vector of 1x1024, the fused feature vector has a dimension of 1x1152.
[0104] Specifically, the joint architecture includes a concatenation layer, a fully connected layer, an activation function, and a batch normalization layer. The concatenation layer is used to concatenate the first feature and the second feature along the feature dimension; the fully connected layer is used to further nonlinearly transform the feature concatenated by the concatenation layer; the activation function such as ReLU introduces nonlinearity into the model to enhance the feature expression ability; and the batch normalization layer is used to normalize the feature output by the foregoing structure to improve the training efficiency and model stability. The concatenation layer, the fully connected layer, the activation function, and the batch normalization layer together realize the effective fusion of the first feature and the second feature to output a fused feature.
[0105] The first and second features contain the essential and structural information of the data. The fused feature obtained by fusing the first and second features also contains the essential and structural information of the data. It can effectively represent the inherent structure and patterns of time-domain features, frequency-domain features, and network device operation and maintenance data, providing richer feature representations and helping to improve the accuracy of determining the anomaly level of network devices based on fused features.
[0106] S503 maps the anomaly level of the fused features through the normalization layer in the model and outputs the anomaly level of the network device.
[0107] Furthermore, the model includes a normalization layer (Softmax) to map the anomaly level of network devices based on fused features, thereby accurately determining the anomaly level of network devices.
[0108] Specifically, a normalization layer maps the fused features output by the joint architecture onto the probability distribution of each anomaly level of the network device. That is, it calculates the probability of each anomaly level based on the information from the fused features and outputs a probability distribution vector. Then, the anomaly level with the highest probability is taken as the prediction result, i.e., it is output as the current anomaly level of the network device.
[0109] For example, Figure 7 This is a schematic diagram of the structure of the model provided in an embodiment of this application. For example... Figure 7 As shown, the model includes a neural network, a joint architecture, and a normalization layer (Softmax). Time-domain and frequency-domain features are used as data features of network device operation and maintenance data in two different modalities, and are respectively input into the neural network in the model. The neural network extracts the first feature from the time-domain features and the second feature from the frequency-domain features; the joint architecture fuses the first and second features output by the neural network to obtain a fused feature; the normalization layer maps the anomaly level of the network device based on the fused feature output by the joint architecture, enabling the model to accurately output the anomaly level of the network device.
[0110] For example, the model can be trained as follows: historical time-domain features and historical frequency-domain features extracted from the historical operation and maintenance data of network devices are used as training data and input into the initial model. Then, after feature extraction, feature fusion, and anomaly level mapping of the network devices from the high-dimensional data, the anomaly level of the network devices corresponding to the historical operation and maintenance data is predicted based on the initial model. Further, using the actual anomaly level of the network devices as supervision data, the initial model is subjected to parametric supervised training based on the predicted anomaly level and the actual anomaly level to obtain the final model.
[0111] In the embodiment, the complementarity of the time domain features and the frequency domain features under different modalities, the importance of modality fusion for anomaly evaluation, and the features obtained by the neural network for feature extraction of high-dimensional data can contain essential information and structural information of the data, effectively represent the characteristics of the internal structure and mode of the data, and the like, so that the model contains a neural network, a joint architecture, and a normalization layer. The model extracts features of high-dimensional data from the time domain features and the frequency domain features respectively, fuses the extracted features, and makes the fused features information-rich and comprehensive, which can effectively represent the internal structure and mode of the operation and maintenance data of the network device. Further, based on the fused features, the anomaly level of the network device is mapped, which can accurately determine the anomaly level of the network device, and is beneficial to more accurately determine the unusable abnormal network device. In addition, the number of neural networks in the model is the same as the number of input features, so that the model can simultaneously capture and analyze data features from different modalities, which is beneficial to enhance the understanding and processing ability of the model for data, so that the model can more comprehensively understand and analyze the behavior of the network device, thereby improving the accuracy and efficiency of anomaly evaluation of the network device.
[0112] In one of the embodiments, the network system includes a non-abnormal network device and an abnormal network device. As shown in Figure 8 The system warning level determination method further includes the following steps S801 to S808.
[0113] Among them, steps S801, S804 to S808 correspond one by one to steps S401, S403 to S407 in the foregoing embodiments. The specific discussion of steps S801, S804 to S808 in the present embodiment can refer to the specific discussion of steps S401, S403 to S407 in the foregoing embodiments, and the present embodiment will not be repeated.
[0114] S801, the operation and maintenance data of the network device in the network system is preprocessed to obtain time domain features and frequency domain features of the network device.
[0115] S802, the feature distance between the time domain features and the reference features is calculated to obtain the difference features. The reference features refer to the time domain data features obtained by preprocessing the operation and maintenance data of the network device that has not appeared abnormal in the time domain.
[0116] When evaluating the anomaly of the network device, the deviation between the operation and maintenance data of the network device to be evaluated and the operation and maintenance data of the network device that has not appeared abnormal can also be considered, so as to determine the anomaly level of the network device based on the deviation of the operation and maintenance data of the network device to be evaluated. In this way, it is beneficial to more intuitively and efficiently evaluate the anomaly of the network device, and the anomaly level of the network device can also be accurately determined.
[0117] In order to determine the deviation between the operation and maintenance data of the current network device to be evaluated and the operation and maintenance data of the network device without exception, based on the characteristics of time series data facilitating comparison, the data features of the operation and maintenance data in the time domain can be processed. That is, the deviation between the time domain features of the operation and maintenance data of the network device to be evaluated and the data features in the time domain of the operation and maintenance data of the network device without exception is determined. Through the deviation between the data features in the time domain, the difference between the operation and maintenance data is fed back, and then the difference between the network devices is fed back. Based on this, the data features in the time domain of the operation and maintenance data of the network device without exception are taken as reference features, and the feature distance between the time domain features and the reference features is calculated to determine the difference between the time domain features and the reference features. This difference is represented by a difference feature.
[0118] In order to calculate the feature distance between the time domain features and the reference features, the calculation method is not limited in the embodiment. Exemplarily, the calculation can be performed by a dynamic time warping (DTW) algorithm. Specifically, the sequences of the time domain features and the reference features are p and q respectively, and the contained elements are u and v respectively, that is:
[0119]
[0120] The sequences of the time domain features and the reference features can be aligned by the DTW algorithm. First, a u×v matrix is constructed, and the element at the matrix position (i, j) is the Euclidean distance d e (p i ,q j ) between the two features. Wherein, i = 1, 2, …, u; j = 1, 2, …, v. At this time, the cumulative distortion distance from the starting position i = 1, j = 1 to i = u, j = v is:
[0121] D e = min{D e (i-1,j-1),D e (i-1,j),D e (i,j-1)}+d e (i,j)
[0122] Wherein, a set of values of i and j corresponds to a cumulative distortion distance D e , which is a sequence element in the difference feature. Thus, the difference feature can be determined.
[0123] S803, respectively input the difference feature and the frequency domain feature into the model, and output the abnormal level of the network device. Wherein, the model is used for feature fusion of the difference feature and the frequency domain feature of the network device, and maps the abnormal level of the network device based on the fused features.
[0124] Exemplarily, the difference feature and the frequency domain feature are respectively input into the model, and a specific implementation process of obtaining the abnormal level of the network device can refer to the foregoing Figure 5 In the embodiment shown, the time domain feature and the frequency domain feature are respectively input into the model, and a specific implementation process of obtaining the abnormal level of the network device. After the difference feature and the frequency domain feature are sequentially processed by the neural network, the joint architecture and the normalization layer in the model, the abnormal level of the network device can be accurately obtained. This example will not be described again.
[0125] S804, in the case where the abnormal level is greater than or equal to the level threshold, the network device is determined as an abnormal network device in the network system.
[0126] S805, determine the topology graph of the network system. The topology graph includes nodes and edges, the nodes are used to represent non-abnormal network devices in the network system, and the edges are used to represent the connection route of two non-abnormal network devices in the network system.
[0127] S806, determine the first index value between any two nodes based on the nodes and the edges. The first index value is used to represent the ability and convenience of communication interaction between any two non-abnormal network devices.
[0128] S807, based on a plurality of first index values, determine a second index value of the network system. The second index value is used to represent the communication performance and stability of the non-abnormal network device, and the second index value is positively correlated with the first index value.
[0129] S808, determine the warning level of the network system based on the second index value. The warning level is negatively correlated with the second index value.
[0130] In this embodiment, based on the characteristics of time series data that facilitate comparison, the data features of the operation and maintenance data of the network device to be evaluated in the time domain are processed, and the deviation between the time domain features of the operation and maintenance data of the network device to be evaluated and the operation and maintenance data of the network device that does not appear abnormal in the time domain is determined. The difference between the operation and maintenance data is fed back through the deviation between the data features in the time domain, and then the difference between the network devices is fed back. The feature distance between the time domain features and the reference features of the operation and maintenance data of the network device that does not appear abnormal in the time domain is determined. That is, the difference feature is determined. Then the difference between the current network device to be evaluated and the network device that does not appear abnormal is reflected through the difference feature. Further, the difference feature and the frequency domain feature under different modalities are used to evaluate the abnormality of the network device to be evaluated. Considering the deviation between the current network device to be evaluated and the network device that does not appear abnormal, it is beneficial to accurately evaluate the abnormality of the network device while more intuitively and efficiently evaluating the abnormality of the network device.
[0131] This application also provides a system early warning level determination device 900. For example... Figure 9 As shown, the system early warning level determination device 900 includes a topology map determination module 901, an indicator value determination module 902, and a level determination module 903. The topology map determination module 901 determines the topology map of the network system, which includes nodes and edges. Nodes represent non-abnormal network devices in the network system, and edges represent the connection routes between two non-abnormal network devices. The indicator value determination module 902 determines a first indicator value between any two nodes based on the nodes and edges. The first indicator value represents the communication capability and ease of interaction between any two non-abnormal network devices. The indicator value determination module 902 also determines a second indicator value for the network system based on multiple first indicator values. The second indicator value represents the communication performance and stability of the non-abnormal network devices, and the second indicator value is positively correlated with the first indicator value. The level determination module 903 determines the early warning level of the network system based on the second indicator value, and the early warning level is negatively correlated with the second indicator value.
[0132] In one embodiment, the aforementioned index value determination module 902 is further configured to determine the connection path between any two nodes based on the edge, wherein the connection paths do not intersect; determine the number of nodes contained in the connection path; and obtain a first index value based on the number of nodes, wherein the first index value is negatively correlated with the number of nodes.
[0133] In one embodiment, the index value determination module 902 is further used to sum multiple first index values to obtain a second index value of the network system.
[0134] In one embodiment, the network system includes non-abnormal network devices and abnormal network devices. The aforementioned level determination module 903 is further configured to determine a third indicator value for the abnormal network device based on its performance indicators, the third indicator value representing the importance of the abnormal network device to the network system; to perform a weighted summation of the second and third indicator values to obtain a fourth indicator value; and to obtain the warning level of the network system based on the indicator threshold range to which the fourth indicator value belongs, with each indicator threshold range corresponding to a warning level.
[0135] In one of the embodiments, the system early warning level determination apparatus 900 further comprises a preprocessing module, a model application module, and an anomaly determination module. The preprocessing module is configured to preprocess the operation and maintenance data of the network device in the network system to obtain the time domain feature and the frequency domain feature of the network device. The model application module is configured to input the time domain feature and the frequency domain feature into the model respectively, and output the anomaly level of the network device. The model is configured to perform feature fusion on the time domain feature and the frequency domain feature of the network device, and map the anomaly level of the network device based on the fused feature. The anomaly determination module is configured to determine the network device as an abnormal network device when the anomaly level is greater than or equal to the level threshold.
[0136] In one of the embodiments, the model application module is further configured to input the time domain feature and the frequency domain feature into the neural network in the model respectively to perform feature extraction on the high-dimensional data, and output the first feature of the time domain feature and the second feature of the frequency domain feature; perform fusion on the first feature and the second feature through the joint architecture in the model, and output the fused feature; and perform anomaly level mapping on the fused feature through the normalization layer in the model, and output the anomaly level of the network device.
[0137] In one of the embodiments, the system early warning level determination apparatus 900 further comprises a distance calculation module configured to calculate the feature distance between the time domain feature and the reference feature to obtain the difference feature, wherein the reference feature refers to the time domain data feature obtained by preprocessing the operation and maintenance data of the network device that does not appear abnormal in the time domain. The model application module is further configured to input the difference feature and the frequency domain feature into the model respectively, and output the anomaly level of the network device.
[0138] The explanations of the terms can refer to the related descriptions in the foregoing system early warning level determination method embodiments, which will not be described in detail herein.
[0139] It should be noted that the specific execution process of the system early warning level determination apparatus 900 can refer to the specific description of the embodiments shown in Figures 1 to 8 The specific execution process of the system early warning level determination apparatus 900 can refer to the specific description of the embodiments shown in
[0140] The modules in the system early warning level determination apparatus 900 can be all or partially implemented by software, hardware, and their combination. The modules can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory in the computer device in software form, so as to be called and executed by the processor to perform the operations corresponding to the modules.
[0141] As Figure 10As shown, the embodiments of the present application further provide a computer device 1000. As an example, the computer device 1000 can include a processor 1001, a communication interface 1002, a communication bus 1003 and a memory 1004. Specifically, the computer device 1000 can include:
[0142] at least one processor 1001, for example, a CPU, at least one communication interface 1002, a memory 1004, at least one communication bus 1003. Wherein, the communication bus 1003 is used to realize the connection communication between these components. The communication interface 1002 can optionally include a standard wired interface, a wireless interface (such as a WI-FI interface or a Bluetooth interface, etc.). The memory 1004 can be a high-speed RAM memory, or a non-volatile memory, for example, at least one disk memory. The memory 1004 can optionally be at least one storage device located away from the aforementioned processor 1001. For example, Figure 10 As shown, the memory 1004 as a computer storage medium can include an operating system and program instructions.
[0143] As an example, the processor 1001 can be used to implement the steps or methods performed by the topology graph determination module 901, the index value determination module 902 and the level determination module 903 in the above Figure 9 .
[0144] It can be understood that the above manner is only an example, and the processor 1001 and other modules in the above computer device 1000 can also cooperate to perform the steps or methods performed by the topology graph determination module 901, the index value determination module 902 and the level determination module 903 in the above Figure 9 , and this article does not limit it.
[0145] In the computer device 1000 shown in Figure 10 , the processor 1001 can be used to load the program instructions stored in the memory 1004, and specifically perform the following operations:
[0146] determine the topology graph of the network system, the topology graph includes nodes and edges, the nodes are used to represent non-abnormal network devices in the network system, and the edges are used to represent the connection route of two non-abnormal network devices in the network system;
[0147] determine the first index value between any two nodes based on the nodes and the edges, the first index value is used to represent the ability and convenience of communication interaction between any two non-abnormal network devices;
[0148] Based on the plurality of first indicator values, a second indicator value of the network system is determined, the second indicator value being used to represent the communication performance and stability of the non-anomalous network device, and the second indicator value being positively correlated with the first indicator value.
[0149] Based on the second indicator value, an early warning level of the network system is determined, the early warning level being negatively correlated with the second indicator value.
[0150] The explanations of the terms can refer to the related descriptions in the foregoing system early warning level determination method embodiments, and will not be described in detail herein.
[0151] It should be noted that the specific execution process can refer to the specific description of the embodiment shown in Figures 1 to 8 , and will not be described in detail herein.
[0152] The embodiment of the present application further provides a computer readable storage medium, the computer readable storage medium can store a plurality of instructions, the instructions are suitable for being loaded and executed by a processor, and the method steps of the embodiment shown in Figures 1 to 8 , and the specific execution process can refer to the specific description of the embodiment shown in Figures 1 to 8 , and will not be described in detail herein.
[0153] In the foregoing embodiments, according to the context, the term “when” can be interpreted as meaning “if” or “after” or “in response to determining” or “in response to detecting”. Similarly, according to the context, the phrase “upon determining” or “if detecting (the stated condition or event)” can be interpreted as meaning “if determining” or “in response to determining” or “upon detecting (the stated condition or event)” or “in response to detecting (the stated condition or event)”.
[0154] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer readable storage medium or transferred from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transferred from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. that includes one or more available media sets. The available media can be magnetic media (for example, floppy disk, hard disk, magnetic tape), optical media (for example, DVD), or semiconductor media (for example, solid state disk) and the like.
[0155] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by a computer program to instruct the relevant hardware, and the program can be stored in a computer readable storage medium. When the program is executed, it can include the processes of the above-mentioned method embodiments. The aforementioned storage medium includes ROM or random access memory (RAM), magnetic disk or optical disk and various media that can store program codes.
[0156] The technical features of the above embodiments can be combined in any way. In order to make the description simple, not all possible combinations of the technical features in the above embodiments are described, but as long as the combination of the technical features does not exist contradictory, it should be considered as the scope of the present application.
[0157] The above embodiments only express several implementation manners of the present application, and the description is more specific and detailed, but it should not be understood as a limitation on the scope of the patent of the present application. It should be pointed out that for ordinary skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of protection of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A method for determining a system alert level, the method comprising: The method comprises: determining a topology graph of a network system, the topology graph comprising nodes and edges, the nodes being used to represent non-anomalous network devices in the network system, and the edges being used to represent connection routes of two non-anomalous network devices in the network system; determining a first index value between any two nodes based on the nodes and the edges, the first index value being used to represent the ability and convenience of communication interaction between any two non-anomalous network devices; determining a second index value of the network system based on a plurality of the first index values, the second index value being used to represent the communication performance and stability of the network system, and the second index value being positively correlated with the first index value; determining a warning level of the network system based on the second index value, the warning level being negatively correlated with the second index value.
2. The method of claim 1, wherein, The determination of the first index value between any two nodes based on the nodes and the edges comprises: determining a connection path between the any two nodes according to the edges, the connection paths being mutually exclusive; determining the number of nodes contained in the connection path; obtaining the first index value based on the number of nodes, the first index value being negatively correlated with the number of nodes.
3. The method according to claim 1 or 2, characterized in that, The determination of the second index value of the network system based on a plurality of the first index values comprises: summing a plurality of the first index values to obtain the second index value of the network system.
4. The method according to claim 1 or 2, characterized in that, The network system comprises the non-anomalous network devices and anomalous network devices; and the determination of the warning level of the network system based on the second index value comprises: determining a third index value of the anomalous network device according to a performance index of the anomalous network device, the third index value being used to represent the importance of the anomalous network device to the network system; performing weighted summation on the second index value and the third index value to obtain a fourth index value; obtaining the warning level of the network system according to an index threshold interval to which the fourth index value belongs, the index threshold interval being one-to-one corresponding to the warning level.
5. The method according to claim 1 or 2, characterized in that, The network system comprises the non-anomalous network devices and anomalous network devices; Before the determination of the topology graph of the network system, the method further comprises: preprocessing operation and maintenance data of network devices in the network system to obtain time domain features and frequency domain features of the network devices; inputting the time domain features and the frequency domain features into a model respectively to output an anomaly level of the network device, the model being used to perform feature fusion on the time domain features and the frequency domain features of the network device, and map the anomaly level of the network device based on the fused features; in a case where the anomaly level is greater than or equal to a level threshold, determining the network device as the anomalous network device.
6. The method of claim 5, wherein, The inputting of the time domain features and the frequency domain features into the model respectively to output the anomaly level of the network device comprises: inputting the time domain features and the frequency domain features into a neural network in the model respectively to perform feature extraction on high-dimensional data, and output first features of the time domain features and second features of the frequency domain features; The first feature and the second feature are fused by a joint architecture in the model to output a fused feature; The fused feature is mapped to an abnormality level of the network device by a normalization layer in the model.
7. The method of claim 5, wherein, Before the time domain feature and the frequency domain feature are respectively input into the model to output the abnormality level of the network device, the method further comprises: A feature distance between the time domain feature and a reference feature is calculated to obtain a difference feature, the reference feature being a time domain data feature obtained by preprocessing operation and maintenance data of a network device without an abnormality in a time domain; The time domain feature and the frequency domain feature are respectively input into the model to output the abnormality level of the network device, comprising: The difference feature and the frequency domain feature are respectively input into the model to output the abnormality level of the network device.
8. A system alert level determination apparatus characterized by comprising: The apparatus comprises: a topology graph determination module configured to determine a topology graph of a network system, the topology graph comprising nodes and edges, the nodes being configured to represent non-abnormal network devices in the network system, and the edges being configured to represent connection routes between two non-abnormal network devices in the network system; an index value determination module configured to determine a first index value between any two nodes based on the nodes and the edges, the first index value being configured to represent a capability and a degree of convenience of communication interaction between any two non-abnormal network devices; the index value determination module is further configured to determine a second index value of the network system based on a plurality of the first index values, the second index value being configured to represent a communication performance and stability of the network system, and the second index value being positively correlated with the first index value; a level determination module configured to determine a pre-warning level of the network system based on the second index value, the pre-warning level being negatively correlated with the second index value.
9. A computer device, comprising: comprise: a memory and a processor, wherein the memory stores program instructions; the program instructions are executed by the processor to perform the method in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program; when the computer program runs on one or more processors, the method in any one of claims 1 to 7 is executed.
11. A computer program product, characterised in that, The computer program product comprises a computer program or instructions; in the case where the computer program or instructions run on a computer, the computer is caused to perform the method in any one of claims 1 to 7.
Citation Information
Patent Citations
Network performance detection method and system
CN116866218A
Smart campus data monitoring application system based on Internet of Things
CN117670239A