Operation and maintenance alarm processing method and system based on knowledge graph enhanced large model
By adopting a large model based on knowledge graph enhancement in operation and maintenance alarm processing, a space-time semantic multi-dimensional feature matrix and multi-dimensional alarm association network are built, and the problems of inaccurate positioning and rule failure in the existing technology are solved, and efficient and accurate alarm processing and continuous optimization of the system are achieved.
Patent Information
- Application Number
- CN202510458235.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-04-14
AI Technical Summary
When handling operation and maintenance alarms, it is difficult for the prior art to accurately restore the propagation path and impact range of the fault, resulting in low accuracy of positioning and traditional methods that cannot adapt to dynamic changes in the IT environment, and the solidified rules are prone to failure.
A large model based on knowledge graph enhancement is adopted to collect multi-source operation and maintenance alarm historical data, build a spatiotemporal semantic multi-dimensional feature matrix to form a multi-dimensional alarm association network, and build and optimize a hierarchical knowledge graph through incremental knowledge inference methods to realize in-depth correlation analysis and dynamic transmission analysis of alarms.
It improves the accuracy and efficiency of alarm processing, significantly improves the accuracy of alarm root cause analysis, reduces false alarms and missed reports, realizes continuous learning and optimization of the system, and reduces the work burden of operation and maintenance personnel.
Smart Images

Figure CN119988154A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to knowledge graph technology, and in particular to an operation and maintenance alarm processing method and system based on a knowledge graph enhanced large model. Background Art
[0002] With the rapid development of information technology, the scale of IT infrastructure continues to expand, the system architecture is becoming increasingly complex, and the number of operation and maintenance alarms is growing exponentially. Traditional operation and maintenance alarm processing methods mainly rely on manual experience for analysis and processing. Faced with massive alarm information, it is difficult for operation and maintenance personnel to locate the root cause of the fault in a timely and accurate manner and take effective treatment measures. In order to improve operation and maintenance efficiency, the industry has begun to explore the use of artificial intelligence technology to achieve intelligent analysis and processing of alarms. The current mainstream alarm processing methods include rule-based expert systems, machine learning-based alarm classification, and statistical analysis-based alarm correlation. These methods have improved the automation level of alarm processing to a certain extent, but there are still many limitations.
[0003] Existing alarm processing methods often treat alarms as independent events, lacking comprehensive analysis of the temporal correlation, spatial propagation characteristics, and business dependencies between alarms, making it difficult to accurately restore the propagation path and impact range of the fault. This results in low accuracy in root cause location, which is prone to misjudgment or missed judgment.
[0004] Traditional alarm processing systems usually use static rule bases for fault diagnosis, which cannot adapt to the dynamic changes in the IT environment. With the continuous evolution of business systems, new failure modes continue to emerge, and the fixed rules will soon become invalid, making it difficult to continuously improve the system's diagnostic capabilities.
[0005] Existing solutions generally lack a systematic accumulation of historical processing experience and an intelligent reuse mechanism. Although a large number of fault handling records have been accumulated, due to the lack of effective knowledge extraction and organization methods, it is difficult to transform expert experience into sustainable and evolving intelligent diagnostic capabilities, resulting in the need to repeat the manual analysis process when similar faults occur repeatedly. Summary of the invention
[0006] The embodiments of the present invention provide an operation and maintenance alarm processing method and system based on a knowledge graph enhanced large model, which can solve the problems in the prior art.
[0007] According to a first aspect of the embodiments of the present invention, Provides an operation and maintenance alarm processing method based on the knowledge graph enhanced large model, including: Collect equipment topology information, performance indicator information and processing record information to form multi-source operation and maintenance alarm historical data; perform adaptive hierarchical structured processing on multi-source operation and maintenance alarm historical data, realize anomaly detection through time series clustering, use semantic similarity to complete text standardization, extract alarm propagation link characteristics, equipment state evolution characteristics and business dependency relationship characteristics to construct a spatiotemporal semantic multidimensional feature matrix; input the spatiotemporal semantic multidimensional feature matrix into the dynamic weight fusion algorithm to construct a multi-dimensional alarm association network with time series dependency strength, spatial propagation probability and business impact degree; based on the multi-dimensional alarm association network, use incremental knowledge reasoning method to construct and continuously optimize the hierarchical knowledge graph; Use hierarchical knowledge graphs to realize dynamic transmission analysis of alarms between different levels; combine the temporal evolution characteristics, topological propagation characteristics, and business dependency characteristics of alarms, and calculate the dynamic credibility weight of each propagation path through a multi-objective optimization algorithm; build a root cause reasoning rule base with threshold adaptation and impact prediction functions based on the dynamic credibility weight; deeply associate and map the root cause reasoning rule base with the hierarchical knowledge graph to form a sustainable and evolving diagnostic reasoning system; When real-time operation and maintenance alarm information is received, the diagnostic reasoning system is started to analyze the multi-dimensional propagation link of the alarm, identify the alarm source node and the affected node group; based on the alarm source node and the affected node group, the optimal root cause set is screened from the suspected root cause nodes; similar historical cases are retrieved through the hierarchical knowledge graph and combined with the current scenario characteristics to generate targeted hierarchical processing suggestions.
[0008] The spatiotemporal semantic multidimensional feature matrix is input into the dynamic weight fusion algorithm to construct a multidimensional alarm association network with temporal dependency strength, spatial propagation probability, and business impact degree; based on the multidimensional alarm association network, an incremental knowledge reasoning method is used to construct and continuously optimize the hierarchical knowledge graph, including: The information gain rate is calculated for each dimension of the spatiotemporal semantic multidimensional feature matrix, and the correlation between features is evaluated based on mutual information. The information gain rate and the correlation between features are input into the multi-objective optimizer to generate the dynamic weights of each dimension of features. The spatiotemporal semantic multidimensional feature matrix is weighted and fused according to the dynamic weights, and the feature interaction strength is calculated through the multi-head attention mechanism. The temporal evolution pattern is captured using the gated recurrent unit, and the spatial propagation characteristics are modeled using the graph neural network. The feature interaction strength, temporal evolution pattern, and spatial propagation characteristics are input into the multi-task learning framework, and the temporal dependency strength, spatial propagation probability, and business impact degree between alarm entities are jointly optimized. A time-series correlation subnetwork is constructed based on the time-series dependency strength, a topology-related subnetwork is constructed based on the spatial propagation probability, and a business-related subnetwork is constructed based on the business impact degree. The three subnetworks are integrated to form a multi-dimensional alarm correlation network, and the importance distribution of network nodes is calculated using a weighted random walk algorithm. The alarm entities are stratified using the importance distribution to construct an initial hierarchical knowledge graph. Based on the initial hierarchical knowledge graph, the expert rule base and statistical learning methods are integrated to perform incremental knowledge reasoning; the reasoning process is modeled as a Markov decision process, and the reasoning path selection is optimized based on value function approximation and policy gradient methods; the reasoning knowledge in known scenarios is transferred to new scenarios through transfer learning methods, and the feature distribution offset is reduced using domain adaptation algorithms; the credibility of the reasoning results is evaluated by Bayesian and uncertainty quantification indicators are generated; based on the uncertainty quantification indicators, the feature extraction parameters and weight fusion strategies are dynamically adjusted to achieve continuous optimization of the knowledge graph.
[0009] Based on the initial hierarchical knowledge graph, the expert rule base and statistical learning methods are integrated to perform incremental knowledge reasoning; the reasoning process is modeled as a Markov decision process, and the reasoning path selection is optimized based on the value function approximation and policy gradient method; the reasoning knowledge in known scenarios is transferred to new scenarios through the transfer learning method, and the domain adaptation algorithm is used to reduce the feature distribution offset, including: Based on the initial hierarchical knowledge graph, entity-relationship pairs are extracted to generate an expert rule base, which records the reasoning rules and constraints between entities. The entities and relationships in the knowledge graph are vectorized, and the relationship probability between entity pairs is calculated using statistical learning methods. The expert rule base and the relationship probability are adaptively weighted and fused to construct an incremental knowledge reasoning model. The fusion process allocates weights based on the rule confidence and the consistency of the probability distribution. The incremental knowledge reasoning model is modeled as a Markov decision process, with the current reasoning entity and the historical path used to construct the state space, and the optional reasoning rules used to construct the action space; a deep neural network is used to approximate the state value function, which evaluates the long-term value of the reasoning state; the value function estimation error is calculated based on the temporal difference algorithm, and the network parameters are updated through back propagation; the policy gradient method is used to optimize the selection strategy of the reasoning rule, and the selection strategy is based on the cumulative reward maximization criterion for parameter learning; Extract reasoning patterns from the knowledge graph of known scenarios, and map the reasoning patterns to new scenarios through transfer learning methods; use domain adaptation algorithms to calculate the feature distribution differences between the source domain and the target domain, and achieve feature distribution alignment by minimizing the maximum mean deviation.
[0010] The hierarchical knowledge graph is used to realize the dynamic transmission analysis of alarms between different levels; the dynamic credibility weight of each propagation path is calculated through a multi-objective optimization algorithm by combining the temporal evolution characteristics, topological propagation characteristics, and business dependency characteristics of alarms, including: The hierarchical knowledge graph is used to realize the dynamic transmission analysis of alarms between different levels. The hierarchical knowledge graph builds a multi-level structure according to the physical layer, network layer, and business layer; the alarm transmission rules within the hierarchy are established based on the direct association relationship between nodes; the horizontal transmission path of the alarm transmission rules within the hierarchy and the vertical transmission path of the alarm nodes between the hierarchies are analyzed, and the horizontal transmission path and the vertical transmission path are combined to form an initial alarm transmission path set; Extract multi-dimensional features from each transmission path in the initial alarm transmission path set, extract temporal evolution features from the alarm time series; extract topological propagation features from the network topology structure; extract business dependency features from the business call relationship; normalize the temporal evolution features, topological propagation features, and business dependency features to construct a feature matrix; The feature matrix is input into the multi-objective optimization algorithm, with maximizing timing correlation, minimizing topological overhead, and minimizing business impact as optimization goals; the objective function value of each transmission path in the timing dimension, topological dimension, and business dimension is calculated; the optimal transmission path set is obtained based on non-dominated sorting; and the dynamic credibility weight of the transmission path is calculated by combining the objective function values of each dimension using an adaptive weight allocation strategy.
[0011] The feature matrix is input into the multi-objective optimization algorithm, with the optimization objectives of maximizing timing correlation, minimizing topological overhead, and minimizing business impact; the objective function values of each transmission path in the timing dimension, topological dimension, and business dimension are calculated, including: The standardized feature matrix is input into the multi-objective optimization algorithm, and the maximization of the time series correlation is set as the first optimization goal, which is obtained by calculating the time series correlation of adjacent alarm nodes on the transmission path, the consistency of the alarm occurrence order, and the propagation delay time; the minimization of the topology overhead is set as the second optimization goal, which is obtained by calculating the number of network hops, link bandwidth occupancy, and node processing load of the transmission path; the minimization of business impact is set as the third optimization goal, which is obtained by calculating the service interruption duration, the number of affected users, and the degree of business loss of the transmission path; Based on the three optimization objectives of the multi-objective optimization algorithm, the objective function value of each transmission path is calculated: the objective function value of the timing dimension is calculated according to the first optimization objective. The objective function value of the timing dimension is calculated based on the correlation coefficient of the alarm time series, the alarm propagation delay, and the alarm duration period, and is used to characterize the timing consistency of alarm transmission; The objective function value of the topology dimension is calculated according to the second optimization goal. The objective function value of the topology dimension is calculated based on the weighted sum of path hops, link utilization, and node load rate, and is used to characterize the network resource consumption of alarm transmission; the objective function value of the business dimension is calculated according to the third optimization goal. The objective function value of the business dimension is calculated based on business interruption loss, user impact range, and service level agreement breach degree, and is used to characterize the degree of business loss caused by alarm transmission.
[0012] Based on the alarm source node and the affected node group, the optimal root cause set is selected from the suspected root cause nodes; similar historical cases are retrieved through the hierarchical knowledge graph and combined with the current scenario characteristics to generate targeted hierarchical processing suggestions including: Obtain the characteristic parameters of the alarm source node, including the alarm occurrence time, alarm duration, and alarm severity level; analyze the propagation path of the alarm in the network based on the characteristic parameters, extract the nodes that receive the alarm to build the affected node group, record the alarm reception time of each node in the affected node group, sort the nodes in time sequence according to the alarm reception time, and generate the initial propagation sequence; Based on the initial propagation sequence, a correlation evaluation matrix is constructed. By calculating the temporal correlation, topological correlation and business correlation between the alarm source node and each node in the affected node group, the comprehensive correlation strength between nodes is obtained; the temporal correlation is calculated based on the time correlation of the alarm sequence between nodes; the topological correlation is calculated based on the network distance between nodes; and the business correlation is calculated based on the service call intensity between nodes. The influence characteristics of suspected root cause nodes are analyzed using the association evaluation matrix: the coverage of each suspected root cause node on the affected node group is calculated, and the coverage is determined by the comprehensive association strength between nodes; the redundancy between suspected root cause nodes is evaluated, and the redundancy is obtained by the overlap ratio of the node influence range; based on the coverage and redundancy, a node combination with a coverage higher than the preset coverage threshold and a redundancy lower than the preset redundancy threshold is selected as the optimal root cause set; Match the feature information of the optimal root cause set with historical cases, calculate the root cause attribute similarity, impact range similarity and processing complexity similarity, and obtain a similarity index system by weighted combination of the root cause attribute similarity, impact range similarity and processing complexity similarity; filter out historical cases with a matching degree higher than a preset similarity threshold based on the similarity index system; perform adaptive analysis on the filtered historical cases and current scenario features, which include the urgency of the alarm, the business impact and resource occupancy; extract effective processing methods and experiences from historical cases based on the results of the adaptive analysis; and generate targeted hierarchical processing suggestions in combination with the positioning results of the optimal root cause set.
[0013] Calculate the coverage of each suspected root cause node to the affected node group. The coverage is determined by the comprehensive correlation strength between nodes. Evaluate the redundancy between suspected root cause nodes. The redundancy is obtained by the overlap ratio of the node influence range, including: Obtain the comprehensive correlation strength between the suspected root cause node and each node in the affected node group; construct a network correlation matrix based on the comprehensive correlation strength; the rows of the network correlation matrix represent the suspected root cause nodes, and the columns represent the nodes in the affected node group; set the node weight coefficient according to the alarm level, business importance and resource occupancy rate of each node in the affected node group; use the sigmoid function to normalize the comprehensive correlation strength in the network correlation matrix; perform weighted calculation on the normalized comprehensive correlation strength and the node weight coefficient to obtain the coverage of the suspected root cause node to the affected node group; Determine the influence range boundary of the suspected root cause node based on a preset correlation strength threshold; extract the affected node set within its influence range for each suspected root cause node, and the normalized comprehensive correlation strength of the nodes in the affected node set with the suspected root cause node is greater than the correlation strength threshold; calculate the number of nodes in the intersection of the influence ranges of any two suspected root cause nodes; The ratio of the number of intersection nodes to the number of intersection nodes in the impact range is taken as the initial redundancy; the normalized comprehensive correlation strength difference between two suspected root cause nodes is calculated at the intersection node; the redundancy correction coefficient is set according to the normalized comprehensive correlation strength difference; the initial redundancy is multiplied by the redundancy correction coefficient to obtain the final inter-node redundancy.
[0014] According to a second aspect of the embodiments of the present invention, An electronic device is provided, comprising: processor; a memory for storing processor-executable instructions; The processor is configured to call instructions stored in the memory to execute the aforementioned method.
[0015] According to a third aspect of the embodiments of the present invention, A computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the aforementioned method is implemented.
[0016] The beneficial effects of this application are as follows: 1. The present invention performs adaptive hierarchical structured processing on multi-source operation and maintenance alarm historical data, constructs a spatiotemporal semantic multidimensional feature matrix, and forms a multidimensional alarm association network based on a dynamic weight fusion algorithm, thereby realizing deep association analysis of alarm data and improving the accuracy and efficiency of alarm processing. At the same time, an incremental knowledge reasoning method is used to construct and continuously optimize a hierarchical knowledge graph, so that the system has the ability to continuously learn and optimize.
[0017] 2. The present invention establishes a dynamic credibility weight calculation mechanism by analyzing the temporal evolution characteristics, topological propagation characteristics, and business dependency characteristics of alarms, and constructs a root cause reasoning rule base with threshold adaptation and impact prediction functions. This method significantly improves the accuracy of alarm root cause analysis, reduces false positives and missed positives, and effectively reduces the workload of operation and maintenance personnel.
[0018] 3. When processing real-time operation and maintenance alarms, the present invention can quickly identify the alarm source node and the affected node group, and filter out the optimal root cause set from the suspected root cause nodes. By retrieving similar historical cases through hierarchical knowledge graphs and combining the current scene characteristics, the system can generate more targeted hierarchical processing suggestions, improve the intelligence level and efficiency of alarm processing, and reduce operation and maintenance costs. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 It is a flowchart of an operation and maintenance alarm processing method based on a knowledge graph enhanced large model according to an embodiment of the present invention; Figure 2 This is a schematic diagram of comprehensive evaluation of multi-dimensional knowledge reasoning performance according to an embodiment of the present invention; Figure 3 The figure is a schematic diagram of redundancy calculation performance in different scenarios of an embodiment of the present invention. DETAILED DESCRIPTION
[0020] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0021] The technical solution of the present invention is described in detail with specific embodiments below. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments.
[0022] Figure 1 Schematic diagram of the process of the operation and maintenance alarm processing method based on the knowledge graph enhanced large model according to an embodiment of the present invention. Figure 1 As shown, the method includes: Collect equipment topology information, performance indicator information and processing record information to form multi-source operation and maintenance alarm historical data; perform adaptive hierarchical structured processing on multi-source operation and maintenance alarm historical data, realize anomaly detection through time series clustering, use semantic similarity to complete text standardization, extract alarm propagation link characteristics, equipment state evolution characteristics and business dependency relationship characteristics to construct a spatiotemporal semantic multidimensional feature matrix; input the spatiotemporal semantic multidimensional feature matrix into the dynamic weight fusion algorithm to construct a multi-dimensional alarm association network with time series dependency strength, spatial propagation probability and business impact degree; based on the multi-dimensional alarm association network, use incremental knowledge reasoning method to construct and continuously optimize the hierarchical knowledge graph; Use hierarchical knowledge graphs to realize dynamic transmission analysis of alarms between different levels; combine the temporal evolution characteristics, topological propagation characteristics, and business dependency characteristics of alarms, and calculate the dynamic credibility weight of each propagation path through a multi-objective optimization algorithm; build a root cause reasoning rule base with threshold adaptation and impact prediction functions based on the dynamic credibility weight; deeply associate and map the root cause reasoning rule base with the hierarchical knowledge graph to form a sustainable and evolving diagnostic reasoning system; When real-time operation and maintenance alarm information is received, the diagnostic reasoning system is started to analyze the multi-dimensional propagation link of the alarm, identify the alarm source node and the affected node group; based on the alarm source node and the affected node group, the optimal root cause set is screened from the suspected root cause nodes; similar historical cases are retrieved through the hierarchical knowledge graph and combined with the current scenario characteristics to generate targeted hierarchical processing suggestions.
[0023] In an optional implementation, the spatiotemporal semantic multidimensional feature matrix is input into a dynamic weight fusion algorithm to construct a multidimensional alarm association network with temporal dependency strength, spatial propagation probability, and business impact degree; based on the multidimensional alarm association network, an incremental knowledge reasoning method is used to construct and continuously optimize a hierarchical knowledge graph, including: The information gain rate is calculated for each dimension of the spatiotemporal semantic multidimensional feature matrix, and the correlation between features is evaluated based on mutual information. The information gain rate and the correlation between features are input into the multi-objective optimizer to generate the dynamic weights of each dimension of features. The spatiotemporal semantic multidimensional feature matrix is weighted and fused according to the dynamic weights, and the feature interaction strength is calculated through the multi-head attention mechanism. The temporal evolution pattern is captured using the gated recurrent unit, and the spatial propagation characteristics are modeled using the graph neural network. The feature interaction strength, temporal evolution pattern, and spatial propagation characteristics are input into the multi-task learning framework, and the temporal dependency strength, spatial propagation probability, and business impact degree between alarm entities are jointly optimized. A time-series correlation subnetwork is constructed based on the time-series dependency strength, a topology-related subnetwork is constructed based on the spatial propagation probability, and a business-related subnetwork is constructed based on the business impact degree. The three subnetworks are integrated to form a multi-dimensional alarm correlation network, and the importance distribution of network nodes is calculated using a weighted random walk algorithm. The alarm entities are stratified using the importance distribution to construct an initial hierarchical knowledge graph. Based on the initial hierarchical knowledge graph, the expert rule base and statistical learning methods are integrated to perform incremental knowledge reasoning; the reasoning process is modeled as a Markov decision process, and the reasoning path selection is optimized based on value function approximation and policy gradient methods; the reasoning knowledge in known scenarios is transferred to new scenarios through transfer learning methods, and the feature distribution offset is reduced using domain adaptation algorithms; the credibility of the reasoning results is evaluated by Bayesian and uncertainty quantification indicators are generated; based on the uncertainty quantification indicators, the feature extraction parameters and weight fusion strategies are dynamically adjusted to achieve continuous optimization of the knowledge graph.
[0024] In the dynamic weight fusion process based on the spatiotemporal semantic multidimensional feature matrix, the feature information gain evaluation module is first constructed. This module calculates the information gain rate for the time dimension features, space dimension features and semantic dimension features respectively. For the time dimension features, the time series information such as the occurrence time, duration, and periodic pattern of the alarm is extracted; for the space dimension features, the spatial information such as the physical location of the alarm device, the network topology relationship, and the resource dependency relationship is extracted; for the semantic dimension features, the semantic information such as the type, level, and description text of the alarm is extracted. The information gain rate of each dimensional feature is calculated by the decision tree splitting criterion, and the correlation between features is evaluated by the mutual information measurement method.
[0025] In the feature weight optimization stage, a multi-objective optimization framework is constructed. This framework uses the information gain rate as a feature importance indicator and the feature relevance as a redundancy indicator. It balances the two objectives through the Pareto optimal principle and generates dynamic weight values for features in each dimension. The weight value is dynamically adjusted as the distribution of alarm data changes to ensure the adaptability of feature fusion.
[0026] The feature fusion module uses a multi-head attention mechanism to realize the interaction modeling between features. Features of different dimensions are mapped to a unified representation space, and the feature interaction strength matrix is obtained through attention calculation. At the same time, the gated recurrent unit is used to capture the temporal dependency of the alarm sequence and establish a temporal evolution model. Based on the message passing mechanism of the graph neural network, the propagation characteristics of the alarm on the spatial network are modeled.
[0027] The multi-task learning framework jointly optimizes three tasks: feature interaction, temporal evolution, and spatial propagation. The framework consists of a shared layer and a task-specific layer. The shared layer learns general feature representations, and the task-specific layer outputs temporal dependency strength, spatial propagation probability, and business impact. The correlation and difference between tasks are balanced through a soft parameter sharing mechanism.
[0028] In the knowledge graph construction stage, subnetworks are constructed based on the above three correlation indicators. The time-series correlation subnetwork describes the causal evolution relationship between alarms, the space-related subnetwork describes the propagation and diffusion mode of alarms, and the business-related subnetwork reflects the impact path of alarms on business systems. The node importance of the fused multi-dimensional network is calculated through the random walk algorithm to realize the hierarchical organization of alarm entities.
[0029] In the incremental knowledge reasoning process, hybrid reasoning is performed by combining expert rules and statistical models. Expert rules contain prior knowledge such as fault diagnosis experience and alarm processing procedures; statistical models learn alarm patterns through historical data. The selection of reasoning paths is optimized using the value function approximation method to ensure the convergence of the reasoning process. For new scenarios, knowledge transfer is achieved using the transfer learning method, and the performance degradation caused by feature distribution offset is reduced through the domain adaptation algorithm.
[0030] Based on the Bayesian framework, the credibility of the inference results is evaluated to generate confidence intervals and uncertainty indicators. According to the evaluation results, the feature extraction and weight fusion strategies are dynamically adjusted to achieve continuous optimization and evolution of the knowledge graph.
[0031] The solution of this application can: Through the dynamic weight fusion algorithm, the adaptive fusion of spatiotemporal semantic multi-dimensional features is achieved, the distinguishability and robustness of feature representation are improved, and the alarm correlation analysis is made more accurate and reliable. The multi-task learning framework is used to jointly optimize multiple correlation indicators, fully utilize the correlation between tasks, improve the generalization ability of the model, and reduce computational overhead. Based on the incremental knowledge reasoning method, expert experience is combined with data-driven to achieve the dynamic evolution of the knowledge graph, which improves the interpretability and adaptability of the system.
[0032] In an optional implementation, based on the initial hierarchical knowledge graph, the expert rule base and the statistical learning method are integrated to perform incremental knowledge reasoning; the reasoning process is modeled as a Markov decision process, and the reasoning path selection is optimized based on the value function approximation and policy gradient method; the reasoning knowledge in the known scenario is transferred to the new scenario through the transfer learning method, and the feature distribution offset is reduced by the domain adaptation algorithm, including: Based on the initial hierarchical knowledge graph, entity-relationship pairs are extracted to generate an expert rule base, which records the reasoning rules and constraints between entities. The entities and relationships in the knowledge graph are vectorized, and the relationship probability between entity pairs is calculated using statistical learning methods. The expert rule base and the relationship probability are adaptively weighted and fused to construct an incremental knowledge reasoning model. The fusion process allocates weights based on the rule confidence and the consistency of the probability distribution. The incremental knowledge reasoning model is modeled as a Markov decision process, with the current reasoning entity and the historical path used to construct the state space, and the optional reasoning rules used to construct the action space; a deep neural network is used to approximate the state value function, which evaluates the long-term value of the reasoning state; the value function estimation error is calculated based on the temporal difference algorithm, and the network parameters are updated through back propagation; the policy gradient method is used to optimize the selection strategy of the reasoning rule, and the selection strategy is based on the cumulative reward maximization criterion for parameter learning; Extract reasoning patterns from the knowledge graph of known scenarios, and map the reasoning patterns to new scenarios through transfer learning methods; use domain adaptation algorithms to calculate the feature distribution differences between the source domain and the target domain, and achieve feature distribution alignment by minimizing the maximum mean deviation.
[0033] Entity relationship pairs are extracted from the initial hierarchical knowledge graph to construct an expert rule base. First, key entity nodes in the knowledge graph are identified, including device nodes, alarm nodes, service nodes, etc. The association relationships between these entity nodes are analyzed, including causal relationships, dependency relationships, composition relationships, etc. For each pair of associated entity nodes, information such as association type, association strength, and constraints is extracted to form inference rules. The extracted inference rules are stored in the expert rule base, and each rule contains attributes such as premise conditions, conclusions, and confidence levels.
[0034] Vectorize the knowledge graph. Use a deep learning model to map entity nodes to a high-dimensional vector space, where the vector dimension is usually set to 128 or 256. Vectorize the relationship types between entities. Construct triple training samples based on entity vectors and relationship vectors. Use statistical learning methods, such as transposed convolutional networks, to train triple samples and obtain the probability distribution of relationships between entity pairs.
[0035] Implement adaptive fusion of expert rules and statistical probability. Set rule weight and probability weight as fusion parameters, with initial values of 0.5. Count the accuracy of each rule in historical data as the rule confidence. Calculate the consistency between the rule reasoning result and the probability distribution prediction result. Dynamically adjust the fusion weight according to the rule confidence and prediction consistency. When the rule confidence is high and the prediction results are consistent, increase the rule weight; otherwise, increase the probability weight.
[0036] Construct a Markov decision process framework. The state space contains the attribute characteristics of the current entity to be inferred, the selected inference rule sequence, the historical inference path and other information. The action space contains the optional expert rule set and statistical prediction method. A deep neural network is used as the value function approximator, the network input is the state feature, and the output is the state value evaluation score.
[0037] Optimize the value function network and decision-making strategy. Record the state transition sequence and the reward value obtained during the reasoning process. Calculate the value function prediction error based on the temporal difference algorithm, and back-propagate the error to update the network parameters. The reward value design takes into account multiple aspects such as reasoning accuracy, path length, and computational overhead. Use the policy gradient method to optimize the rule selection strategy, and the policy network outputs the selection probability of each action.
[0038] Realize cross-scenario knowledge transfer. Extract typical reasoning patterns from the source scene knowledge graph, including entity type mapping relationships, relationship path patterns, constraint rules, etc. Build a feature extractor to map entities in the source domain and target domain to the same feature space. Calculate the feature distribution differences between the two domains through the domain adaptation algorithm, and use adversarial training to achieve feature distribution alignment.
[0039] Figure 2 This is a schematic diagram of comprehensive evaluation of multi-dimensional knowledge reasoning performance according to an embodiment of the present invention: This figure shows the performance comparison of the three technical solutions at different node scales. From the overall data, this technical solution performs best in the range of node scales from 0 to 2000, and the performance index steadily increases from the initial 0.68 to 0.97, and maintains a high stability throughout the process. Especially after the node scale reaches 1000, the performance index can still be maintained at a high level above 0.91, showing extremely strong scalability. In comparison, the performance of traditional method A is relatively weak. Its performance index starts from 0.60 and can only reach 0.80 when the node scale reaches 2000. The overall improvement is small, and the performance improvement tends to be flat in large-scale scenarios. Although the improved method B performs better than the traditional method A in the initial stage, with an initial performance of 0.65, and quickly increases to 0.89 when the node scale reaches 800, and finally reaches a performance index of 0.96 at a scale of 2000 nodes, it still fails to surpass the performance level of this technical solution. Through comparison, it can be clearly seen that this technical solution has obvious advantages in performance indicators, scalability and stability, especially in large-scale node scenarios, which shows its outstanding technical advancement and practical value. These data fully prove the effectiveness and reliability of this technical solution in solving the problem of scale expansion.
[0040] The solution of this application can: By integrating the expert rule base and statistical learning methods, the advantages of prior knowledge and data-driven are fully utilized to improve the accuracy and robustness of knowledge reasoning, and achieve continuous accumulation and optimization of knowledge. The Markov decision process is used to model the reasoning process, combined with the value function approximation and policy gradient method, to optimize the selection strategy of the reasoning path, improve the reasoning efficiency, and reduce the consumption of computing resources. The introduction of transfer learning and domain adaptation mechanisms realizes the transfer and reuse of knowledge between different scenarios, improves the generalization ability of the model, and reduces the adaptation cost of new scenarios.
[0041] In an optional implementation, a hierarchical knowledge graph is used to implement dynamic transmission analysis of alarms between different levels; combining the temporal evolution characteristics, topological propagation characteristics, and business dependency characteristics of alarms, a multi-objective optimization algorithm is used to calculate the dynamic credibility weight of each propagation path, including: The hierarchical knowledge graph is used to realize the dynamic transmission analysis of alarms between different levels. The hierarchical knowledge graph builds a multi-level structure according to the physical layer, network layer, and business layer; the alarm transmission rules within the hierarchy are established based on the direct association relationship between nodes; the horizontal transmission path of the alarm transmission rules within the hierarchy and the vertical transmission path of the alarm nodes between the hierarchies are analyzed, and the horizontal transmission path and the vertical transmission path are combined to form an initial alarm transmission path set; Extract multi-dimensional features from each transmission path in the initial alarm transmission path set, extract temporal evolution features from the alarm time series; extract topological propagation features from the network topology structure; extract business dependency features from the business call relationship; normalize the temporal evolution features, topological propagation features, and business dependency features to construct a feature matrix; The feature matrix is input into the multi-objective optimization algorithm, with maximizing timing correlation, minimizing topological overhead, and minimizing business impact as optimization goals; the objective function value of each transmission path in the timing dimension, topological dimension, and business dimension is calculated; the optimal transmission path set is obtained based on non-dominated sorting; and the dynamic credibility weight of the transmission path is calculated by combining the objective function values of each dimension using an adaptive weight allocation strategy.
[0042] Construct a multi-level structure of hierarchical knowledge graph. The physical layer includes physical entity nodes such as servers, network devices, and storage devices; the network layer includes virtual resource nodes such as virtual machines, containers, and network links; the business layer includes business component nodes such as application services, microservices, and databases. Within each level, direct associations between nodes are established based on relationships such as physical connections between devices, network communications, and service calls.
[0043] Analyze the alarm transmission rules within the layer. At the physical layer, determine the alarm transmission direction based on the upstream and downstream connection relationship of the device; at the network layer, determine the alarm diffusion range based on the network topology; at the business layer, determine the alarm impact path based on the call dependency between services. At the same time, identify the vertical association relationship between different layers, such as the carrying relationship between physical devices and virtual resources, and the deployment relationship between virtual resources and business services.
[0044] Combine to form an initial set of transmission paths. Combine and connect the horizontal transmission paths within a layer with the vertical transmission paths between layers. For each source alarm, traverse the possible transmission paths through the depth-first search algorithm to generate an initial set of paths. Preprocess the path set to remove loop paths and redundant paths.
[0045] Extract multi-dimensional features of the transmission path. The time series evolution features include time attributes such as the alarm occurrence time interval, alarm duration, and alarm repetition frequency; the topology propagation features include network attributes such as node degree distribution, path hop count, and link bandwidth; the business dependency features include performance indicators such as service response time, concurrent calls, and error rate.
[0046] Normalize the extracted features. Convert features of different dimensions to a unified numerical range. Time series features are normalized by maximum and minimum values; topological features are processed by logarithmic transformation; business features are standardized by Z-score. The normalized features form a feature matrix, and each row of the matrix corresponds to a transmission path.
[0047] A multi-objective optimization process is implemented. The timing correlation target is obtained by calculating the order and conditional probability of the alarm occurrence time; the topology cost target is obtained by accumulating the link load and network delay on the path; the business impact target is obtained by evaluating the degree of service performance degradation and user experience loss.
[0048] The transfer paths are hierarchical using the non-dominated sorting method. The first layer contains the set of non-dominated solutions, that is, the set of solutions where no other path is better than this path in all objectives. The non-dominated solutions are removed layer by layer to obtain a complete hierarchical structure.
[0049] Dynamic weights are assigned based on hierarchical results. The comprehensive score is calculated by combining the non-dominated level of the path, the normalized score of the objective function value, and the historical transfer success rate. The score is converted into a probability distribution using the softmax function as the credibility weight of the transfer path. The weight is adjusted dynamically as the system operating status and alarm distribution change.
[0050] The solution of this application can: Through the hierarchical knowledge graph, the dynamic transmission analysis of alarms between different levels is realized, the propagation law of alarms is accurately grasped, and the accuracy of root cause location is improved. Multi-dimensional analysis is carried out by combining the characteristics of time evolution, topological propagation, and business dependency, which comprehensively describes the characteristics of alarm transmission and enhances the reliability of the analysis results. The multi-objective optimization algorithm is used to dynamically calculate the credibility weight of the transmission path, achieving a balance between multiple objectives such as time correlation, topological overhead, and business impact, and improving the practicality of alarm analysis.
[0051] In an optional implementation, the feature matrix is input into a multi-objective optimization algorithm, with maximizing timing correlation, minimizing topological overhead, and minimizing business impact as optimization goals; calculating the objective function value of each transmission path in the timing dimension, topological dimension, and business dimension includes: The standardized feature matrix is input into the multi-objective optimization algorithm, and the maximization of the time series correlation is set as the first optimization goal, which is obtained by calculating the time series correlation of adjacent alarm nodes on the transmission path, the consistency of the alarm occurrence order, and the propagation delay time; the minimization of the topology overhead is set as the second optimization goal, which is obtained by calculating the number of network hops, link bandwidth occupancy, and node processing load of the transmission path; the minimization of business impact is set as the third optimization goal, which is obtained by calculating the service interruption duration, the number of affected users, and the degree of business loss of the transmission path; Based on the three optimization objectives of the multi-objective optimization algorithm, the objective function value of each transmission path is calculated: the objective function value of the timing dimension is calculated according to the first optimization objective. The objective function value of the timing dimension is calculated based on the correlation coefficient of the alarm time series, the alarm propagation delay, and the alarm duration period, and is used to characterize the timing consistency of alarm transmission; The objective function value of the topology dimension is calculated according to the second optimization goal. The objective function value of the topology dimension is calculated based on the weighted sum of path hops, link utilization, and node load rate, and is used to characterize the network resource consumption of alarm transmission; the objective function value of the business dimension is calculated according to the third optimization goal. The objective function value of the business dimension is calculated based on business interruption loss, user impact range, and service level agreement breach degree, and is used to characterize the degree of business loss caused by alarm transmission.
[0052] When the standardized feature matrix is input into the multi-objective optimization algorithm, the alarm time series feature matrix is first constructed. For each alarm node, the time series features such as timestamp, duration, and alarm level are extracted to form a feature vector. The Pearson correlation coefficient is calculated for adjacent alarm nodes to determine the consistency of the alarm occurrence sequence and calculate the alarm propagation delay time. For example, the time series correlation coefficient of alarm A and alarm B is 0.85, the alarm occurrence sequence is consistent, and the propagation delay is 30 seconds.
[0053] Next, we calculate the topological dimension features. We count the number of network hops in the transmission path, such as path P contains 4 hops; we analyze the link bandwidth occupancy, such as link utilization is 65%; we evaluate the node processing load, such as CPU utilization is 75%. We normalize these topological features to form a topological feature vector.
[0054] Then extract business dimension features. Record the duration of service interruption, such as 5 minutes of interruption; count the number of affected users, such as 1,000 users; assess the extent of business loss, such as a transaction loss of 100,000 yuan. Standardize business features and construct business feature vectors.
[0055] Based on the feature vectors of the above three dimensions, the objective function value of each transmission path is calculated. The objective function value of the timing dimension comprehensively considers the correlation coefficient, propagation delay, and duration period. For example, the timing objective value of path P is 0.82. The objective function value of the topology dimension comprehensively considers the number of hops, link utilization, and node load rate. For example, the topology objective value of path P is 0.68. The objective function value of the business dimension comprehensively considers interruption loss, user impact, and SLA breach degree. For example, the business objective value of path P is 0.75.
[0056] Finally, based on the above three objective function values, multi-objective optimization is performed to obtain the Pareto optimal solution set and select the optimal alarm transmission path.
[0057] The solution of this application can: The accuracy and timeliness of alarm transmission are improved through timing correlation analysis, avoiding timing disorder and delay accumulation in the alarm transmission process. The topology overhead optimization reduces the occupation of network resources by alarm transmission, improves network transmission efficiency, and reduces network congestion. The alarm transmission path is optimized from the perspective of business impact, minimizing business interruption losses, improving the level of service quality assurance, and reducing user complaint rates.
[0058] In an optional implementation, the optimal root cause set is selected from the suspected root cause nodes based on the alarm source node and the affected node group; similar historical cases are retrieved through the hierarchical knowledge graph and combined with the current scene characteristics to generate targeted hierarchical processing suggestions including: Obtain the characteristic parameters of the alarm source node, including the alarm occurrence time, alarm duration, and alarm severity level; analyze the propagation path of the alarm in the network based on the characteristic parameters, extract the nodes that receive the alarm to build the affected node group, record the alarm reception time of each node in the affected node group, sort the nodes in time sequence according to the alarm reception time, and generate the initial propagation sequence; Based on the initial propagation sequence, a correlation evaluation matrix is constructed. By calculating the temporal correlation, topological correlation and business correlation between the alarm source node and each node in the affected node group, the comprehensive correlation strength between nodes is obtained; the temporal correlation is calculated based on the time correlation of the alarm sequence between nodes; the topological correlation is calculated based on the network distance between nodes; and the business correlation is calculated based on the service call intensity between nodes. The influence characteristics of suspected root cause nodes are analyzed using the association evaluation matrix: the coverage of each suspected root cause node on the affected node group is calculated, and the coverage is determined by the comprehensive association strength between nodes; the redundancy between suspected root cause nodes is evaluated, and the redundancy is obtained by the overlap ratio of the node influence range; based on the coverage and redundancy, a node combination with a coverage higher than the preset coverage threshold and a redundancy lower than the preset redundancy threshold is selected as the optimal root cause set; Match the feature information of the optimal root cause set with historical cases, calculate the root cause attribute similarity, impact range similarity and processing complexity similarity, and obtain a similarity index system by weighted combination of the root cause attribute similarity, impact range similarity and processing complexity similarity; filter out historical cases with a matching degree higher than a preset similarity threshold based on the similarity index system; perform adaptive analysis on the filtered historical cases and current scenario features, which include the urgency of the alarm, the business impact and resource occupancy; extract effective processing methods and experiences from historical cases based on the results of the adaptive analysis; and generate targeted hierarchical processing suggestions in combination with the positioning results of the optimal root cause set.
[0059] First, obtain the characteristic parameter information of the alarm source node. Taking a data center network as an example, the source node A generates an alarm of excessive CPU usage at 10:30:25 on October 15, 2023. The alarm lasts for 30 minutes and the alarm level is severe. By analyzing the network topology and business call relationship, it is found that nodes B, C, and D directly connected to node A received relevant alarms at 10:30:35, 10:30:40, and 10:30:45, respectively, forming an affected node group. According to the order of alarm reception time, the initial propagation sequence is generated as A->B->C->D.
[0060] Then, the correlation evaluation matrix is constructed. For nodes A and B, the temporal correlation is calculated to be 0.9 based on the alarm time interval of 10 seconds; the topological correlation is calculated to be 0.8 based on the number of network hops of 1 hop; and the business correlation is calculated to be 0.85 based on the number of service calls per second of 100 times. The same method is used to calculate the correlation between A and C and D, and finally the comprehensive correlation strength matrix between nodes is obtained.
[0061] Then analyze the influence characteristics of the suspected root cause nodes. Assume that there are suspected root cause nodes E and F, the coverage of node E to the affected node group is 85%, the coverage of node F is 75%, and the overlap ratio of the two influence ranges is 30%. Set the coverage threshold to 80% and the redundancy threshold to 40%, then node E is selected into the optimal root cause set.
[0062] Finally, historical case matching is performed. Five historical cases are retrieved from the knowledge graph and their similarity with the current scenario is calculated. The root cause attribute similarity of Case 1 is 0.9, the impact range similarity is 0.85, and the processing complexity similarity is 0.8. The weighted calculation results in a comprehensive similarity of 0.85. When the similarity threshold is set to 0.8, Case 1 is screened out. Combined with the characteristics of the current alarm being at a serious level, affecting core business, and CPU resource shortage, the processing method is extracted from Case 1 to generate graded processing suggestions.
[0063] The solution of this application can: By constructing a correlation evaluation matrix and analyzing node impact characteristics, the real root cause of the fault can be accurately identified, false positives and false negatives can be avoided, and the accuracy of root cause location can be improved. Based on the hierarchical knowledge graph, historical cases can be retrieved and similarity matching can be performed to quickly find processing experience that matches the current scenario and improve fault handling efficiency. By adopting a hierarchical processing suggestion method and combining the current scenario characteristics to give targeted processing solutions, the complexity of fault handling can be effectively reduced and the work efficiency of operation and maintenance personnel can be improved.
[0064] In an optional implementation, the coverage of each suspected root cause node to the affected node group is calculated, and the coverage is determined by the comprehensive association strength between the nodes; the redundancy between the suspected root cause nodes is evaluated, and the redundancy is obtained by the overlap ratio of the node influence range, including: Obtain the comprehensive correlation strength between the suspected root cause node and each node in the affected node group; construct a network correlation matrix based on the comprehensive correlation strength; the rows of the network correlation matrix represent the suspected root cause nodes, and the columns represent the nodes in the affected node group; set the node weight coefficient according to the alarm level, business importance and resource occupancy rate of each node in the affected node group; use the sigmoid function to normalize the comprehensive correlation strength in the network correlation matrix; perform weighted calculation on the normalized comprehensive correlation strength and the node weight coefficient to obtain the coverage of the suspected root cause node to the affected node group; Determine the influence range boundary of the suspected root cause node based on a preset correlation strength threshold; extract the affected node set within its influence range for each suspected root cause node, and the normalized comprehensive correlation strength of the nodes in the affected node set with the suspected root cause node is greater than the correlation strength threshold; calculate the number of nodes in the intersection of the influence ranges of any two suspected root cause nodes; The ratio of the number of intersection nodes to the number of intersection nodes in the impact range is taken as the initial redundancy; the normalized comprehensive correlation strength difference between two suspected root cause nodes is calculated at the intersection node; the redundancy correction coefficient is set according to the normalized comprehensive correlation strength difference; the initial redundancy is multiplied by the redundancy correction coefficient to obtain the final inter-node redundancy.
[0065] First, the comprehensive correlation strength between the suspected root cause node and each node in the affected node group is obtained. The comprehensive correlation strength is calculated by the direct correlation strength and indirect correlation strength between nodes. The direct correlation strength is determined based on the physical connection and call relationship between nodes, and the indirect correlation strength is calculated by the transfer relationship between nodes. For example, the direct correlation strength between node A and node B is 0.8, and the direct correlation strength between node B and node C is 0.6, then the indirect correlation strength between node A and node C is 0.48.
[0066] Next, we construct a network association matrix, where the rows represent the suspected root cause nodes and the columns represent the nodes in the affected node group. The element values in the matrix are the comprehensive association strengths between the corresponding nodes. For example, if there are three suspected root cause nodes R1, R2, and R3, and the affected node group contains four nodes N1, N2, N3, and N4, then we construct a 3×4 association matrix.
[0067] Then, the weight coefficient is set according to the alarm level, business importance and resource utilization of the affected node. The alarm level is divided into three levels: severe, warning, and prompt, with corresponding weights of 0.5, 0.3, and 0.2 respectively. The business importance is divided into three levels: core, important, and general, with corresponding weights of 0.5, 0.3, and 0.2. The resource utilization rate is divided into intervals by percentage, with a weight of 0.5 for more than 90%, 0.3 for 50%-90%, and 0.2 for less than 50%. The weights of the three dimensions are added together to get the final weight coefficient of the node.
[0068] The comprehensive correlation strength in the correlation matrix is normalized. The sigmoid function is used to map the correlation strength to the range of 0-1. The normalized correlation strength is multiplied by the node weight coefficient to obtain the coverage of the suspected root cause node to the affected node group. The higher the coverage, the closer the correlation between the suspected root cause node and the affected node group.
[0069] Determine the influence range of the suspected root cause node based on a preset correlation strength threshold (such as 0.6). Extract the set of affected nodes within the influence range of each suspected root cause node, and the normalized comprehensive correlation strength of these nodes with the suspected root cause node is greater than the threshold. Calculate the number of intersection nodes of the influence ranges of any two suspected root cause nodes. For example, the influence range of R1 includes N1, N2, and N3, and the influence range of R2 includes N2, N3, and N4, then the number of intersection nodes is 2.
[0070] The ratio of the number of intersection nodes to the number of nodes in the affected area is taken as the initial redundancy. The normalized comprehensive correlation strength difference between the two suspected root cause nodes is calculated at the intersection node. The greater the difference in correlation strength, the greater the difference in the degree of influence of the two nodes on the intersection area, and the lower the redundancy. The redundancy correction coefficient is set according to the difference in correlation strength. The coefficient is 0.2 when the correlation strength difference is above 0.8, 0.5 when it is between 0.5 and 0.8, and 0.8 when it is below 0.5. The final redundancy is obtained by multiplying the initial redundancy by the correction coefficient.
[0071] Figure 3 The following is a schematic diagram of redundancy calculation performance in different scenarios of the embodiment of the present invention: This figure shows a comparative analysis of redundancy calculation errors based on association strength thresholds. The analysis results show that as the association strength threshold increases from 0.1 to 1.0, the calculation errors of different technical solutions show an overall downward trend. The initial error of this technical solution in the cross-domain scenario is 0.09, which eventually drops to 0.045, a decrease of 50%; the initial error in the single-domain scenario is 0.04, which eventually drops to 0.01, a decrease of 75%. In contrast, the initial error of the comparison solution in the cross-domain scenario is 0.08, which eventually drops to 0.035, a decrease of 56.25%; the initial error in the single-domain scenario is 0.04, which eventually drops to 0.01, a decrease of 75%. The data shows that this technical solution exhibits better performance advantages in cross-domain scenarios, especially when the association strength threshold is low (in the range of 0.1-0.4), the calculation error of this technical solution is significantly lower than that of the comparison solution, with an average lower error of about 0.01-0.015. This fully demonstrates that this technical solution has higher calculation accuracy and stability when dealing with complex cross-domain scenarios. In addition, all solutions have similar performance in single-domain scenarios, showing good error convergence characteristics, but the error reduction curve of this technical solution is smoother, indicating that it has better predictability and robustness. Overall, this technical solution has shown superior performance in various scenarios, and is particularly suitable for handling complex cross-domain analysis tasks.
[0072] The solution of this application can: By calculating the coverage of the suspected root cause nodes to the affected node group, the correlation between the suspected root cause nodes and the fault range can be accurately evaluated, and the real fault root cause nodes can be effectively identified. The redundancy between the suspected root cause nodes can be evaluated based on the overlap ratio of the node impact range, which can eliminate redundant root cause nodes and improve the accuracy and efficiency of root cause location. The multi-dimensional weight coefficient and normalization processing method are used to make the calculation of coverage and redundancy more reasonable and scientific, ensuring the reliability of the root cause location results.
[0073] According to a second aspect of the embodiments of the present invention, An electronic device is provided, comprising: processor; a memory for storing processor-executable instructions; The processor is configured to call instructions stored in the memory to execute the aforementioned method.
[0074] According to a third aspect of the embodiments of the present invention, A computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the aforementioned method is implemented.
[0075] The present invention may be a method, an apparatus, a system and / or a computer program product. The computer program product may include a computer-readable storage medium carrying computer-readable program instructions for executing various aspects of the present invention.
[0076] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. The operation and maintenance alarm processing method based on the knowledge graph enhanced large model is characterized by: include: Collect equipment topology information, performance indicator information and processing record information to form multi-source operation and maintenance alarm historical data; perform adaptive hierarchical structured processing on multi-source operation and maintenance alarm historical data, realize anomaly detection through time series clustering, complete text standardization using semantic similarity, extract alarm propagation link characteristics, equipment state evolution characteristics and business dependency relationship characteristics to construct a spatiotemporal semantic multidimensional feature matrix; input the spatiotemporal semantic multidimensional feature matrix into the dynamic weight fusion algorithm to construct a multi-dimensional alarm association network with time series dependency strength, spatial propagation probability and business impact degree; Based on the multi-dimensional alarm association network, an incremental knowledge reasoning method is used to build and continuously optimize the hierarchical knowledge graph; Use hierarchical knowledge graphs to realize dynamic transmission analysis of alarms between different levels; combine the temporal evolution characteristics, topological propagation characteristics, and business dependency characteristics of alarms, and calculate the dynamic credibility weight of each propagation path through a multi-objective optimization algorithm; build a root cause reasoning rule base with threshold adaptation and impact prediction functions based on the dynamic credibility weight; deeply associate and map the root cause reasoning rule base with the hierarchical knowledge graph to form a sustainable and evolving diagnostic reasoning system; When real-time operation and maintenance alarm information is received, the diagnostic reasoning system is started to analyze the multi-dimensional propagation link of the alarm, identify the alarm source node and the affected node group; based on the alarm source node and the affected node group, the optimal root cause set is screened from the suspected root cause nodes; similar historical cases are retrieved through the hierarchical knowledge graph and combined with the current scenario characteristics to generate targeted hierarchical processing suggestions.
2. The method according to claim 1, characterized in that The spatiotemporal semantic multidimensional feature matrix is input into the dynamic weight fusion algorithm to construct a multidimensional alarm association network with temporal dependency intensity, spatial propagation probability, and business impact degree; Based on the multi-dimensional alarm association network, the incremental knowledge reasoning method is used to build and continuously optimize the hierarchical knowledge graph, including: The information gain rate is calculated for each dimension of the spatiotemporal semantic multidimensional feature matrix, and the correlation between features is evaluated based on mutual information. The information gain rate and the correlation between features are input into the multi-objective optimizer to generate the dynamic weights of each dimension of features. The spatiotemporal semantic multidimensional feature matrix is weighted and fused according to the dynamic weights, and the feature interaction strength is calculated through the multi-head attention mechanism. The temporal evolution pattern is captured using the gated recurrent unit, and the spatial propagation characteristics are modeled using the graph neural network. The feature interaction strength, temporal evolution pattern, and spatial propagation characteristics are input into the multi-task learning framework, and the temporal dependency strength, spatial propagation probability, and business impact degree between alarm entities are jointly optimized. A time-series correlation subnetwork is constructed based on the time-series dependency strength, a topology-related subnetwork is constructed based on the spatial propagation probability, and a business-related subnetwork is constructed based on the business impact degree. The three subnetworks are integrated to form a multi-dimensional alarm correlation network, and the importance distribution of network nodes is calculated using a weighted random walk algorithm. The alarm entities are stratified using the importance distribution to construct an initial hierarchical knowledge graph. Based on the initial hierarchical knowledge graph, the expert rule base and statistical learning methods are integrated to perform incremental knowledge reasoning; the reasoning process is modeled as a Markov decision process, and the reasoning path selection is optimized based on value function approximation and policy gradient methods; the reasoning knowledge in known scenarios is transferred to new scenarios through transfer learning methods, and the feature distribution offset is reduced using domain adaptation algorithms; the credibility of the reasoning results is evaluated by Bayesian and uncertainty quantification indicators are generated; based on the uncertainty quantification indicators, the feature extraction parameters and weight fusion strategies are dynamically adjusted to achieve continuous optimization of the knowledge graph.
3. The method according to claim 2, characterized in that Based on the initial hierarchical knowledge graph, the expert rule base and statistical learning methods are integrated to perform incremental knowledge reasoning; the reasoning process is modeled as a Markov decision process, and the reasoning path selection is optimized based on value function approximation and policy gradient method; The transfer learning method is used to transfer the reasoning knowledge in the known scene to the new scene, and the domain adaptation algorithm is used to reduce the feature distribution offset, including: Based on the initial hierarchical knowledge graph, entity-relationship pairs are extracted to generate an expert rule base, which records the reasoning rules and constraints between entities. The entities and relationships in the knowledge graph are vectorized, and the relationship probability between entity pairs is calculated using statistical learning methods. The expert rule base and the relationship probability are adaptively weighted and fused to construct an incremental knowledge reasoning model. The fusion process allocates weights based on the rule confidence and the consistency of the probability distribution. The incremental knowledge reasoning model is modeled as a Markov decision process, with the current reasoning entity and the historical path used to construct the state space, and the optional reasoning rules used to construct the action space; a deep neural network is used to approximate the state value function, which evaluates the long-term value of the reasoning state; the value function estimation error is calculated based on the temporal difference algorithm, and the network parameters are updated through back propagation; the policy gradient method is used to optimize the selection strategy of the reasoning rule, and the selection strategy is based on the cumulative reward maximization criterion for parameter learning; Extract reasoning patterns from the knowledge graph of known scenarios, and map the reasoning patterns to new scenarios through transfer learning methods; use domain adaptation algorithms to calculate the feature distribution differences between the source domain and the target domain, and achieve feature distribution alignment by minimizing the maximum mean deviation.
4. The method according to claim 1, characterized in that The hierarchical knowledge graph is used to realize the dynamic transmission analysis of alarms between different levels; the dynamic credibility weight of each propagation path is calculated through a multi-objective optimization algorithm by combining the temporal evolution characteristics, topological propagation characteristics, and business dependency characteristics of alarms, including: The hierarchical knowledge graph is used to realize the dynamic transmission analysis of alarms between different levels. The hierarchical knowledge graph builds a multi-level structure according to the physical layer, network layer, and business layer; the alarm transmission rules within the hierarchy are established based on the direct association relationship between nodes; the horizontal transmission path of the alarm transmission rules within the hierarchy and the vertical transmission path of the alarm nodes between the hierarchies are analyzed, and the horizontal transmission path and the vertical transmission path are combined to form an initial alarm transmission path set; Extract multi-dimensional features from each transmission path in the initial alarm transmission path set, extract temporal evolution features from the alarm time series; extract topological propagation features from the network topology structure; extract business dependency features from the business call relationship; normalize the temporal evolution features, topological propagation features, and business dependency features to construct a feature matrix; The feature matrix is input into the multi-objective optimization algorithm, with maximizing timing correlation, minimizing topological overhead, and minimizing business impact as optimization goals; the objective function value of each transmission path in the timing dimension, topological dimension, and business dimension is calculated; the optimal transmission path set is obtained based on non-dominated sorting; and the dynamic credibility weight of the transmission path is calculated by combining the objective function values of each dimension using an adaptive weight allocation strategy.
5. The method according to claim 4, characterized in that The feature matrix is input into the multi-objective optimization algorithm, with the optimization objectives of maximizing timing correlation, minimizing topology overhead, and minimizing business impact; Calculating the objective function value of each transmission path in the timing dimension, topology dimension, and business dimension includes: The standardized feature matrix is input into the multi-objective optimization algorithm, and the maximization of the time series correlation is set as the first optimization goal, which is obtained by calculating the time series correlation of adjacent alarm nodes on the transmission path, the consistency of the alarm occurrence order, and the propagation delay time; the minimization of the topology overhead is set as the second optimization goal, which is obtained by calculating the number of network hops, link bandwidth occupancy, and node processing load of the transmission path; the minimization of business impact is set as the third optimization goal, which is obtained by calculating the service interruption duration, the number of affected users, and the degree of business loss of the transmission path; Based on the three optimization objectives of the multi-objective optimization algorithm, the objective function value of each transmission path is calculated: the objective function value of the timing dimension is calculated according to the first optimization objective. The objective function value of the timing dimension is calculated based on the correlation coefficient of the alarm time series, the alarm propagation delay, and the alarm duration period, and is used to characterize the timing consistency of alarm transmission; The objective function value of the topology dimension is calculated according to the second optimization goal. The objective function value of the topology dimension is calculated based on the weighted sum of path hops, link utilization, and node load rate, and is used to characterize the network resource consumption of alarm transmission; the objective function value of the business dimension is calculated according to the third optimization goal. The objective function value of the business dimension is calculated based on business interruption loss, user impact range, and service level agreement breach degree, and is used to characterize the degree of business loss caused by alarm transmission.
6. The method according to claim 1, characterized in that Based on the alarm source node and the affected node group, the optimal root cause set is selected from the suspected root cause nodes; similar historical cases are retrieved through the hierarchical knowledge graph and combined with the current scenario characteristics to generate targeted hierarchical processing suggestions including: Obtain the characteristic parameters of the alarm source node, including the alarm occurrence time, alarm duration, and alarm severity level; analyze the propagation path of the alarm in the network based on the characteristic parameters, extract the nodes that receive the alarm to build the affected node group, record the alarm reception time of each node in the affected node group, sort the nodes in time sequence according to the alarm reception time, and generate the initial propagation sequence; Based on the initial propagation sequence, a correlation evaluation matrix is constructed. By calculating the temporal correlation, topological correlation and business correlation between the alarm source node and each node in the affected node group, the comprehensive correlation strength between nodes is obtained; the temporal correlation is calculated based on the time correlation of the alarm sequence between nodes; the topological correlation is calculated based on the network distance between nodes; and the business correlation is calculated based on the service call intensity between nodes. The influence characteristics of suspected root cause nodes are analyzed using the association evaluation matrix: the coverage of each suspected root cause node on the affected node group is calculated, and the coverage is determined by the comprehensive association strength between nodes; the redundancy between suspected root cause nodes is evaluated, and the redundancy is obtained by the overlap ratio of the node influence range; based on the coverage and redundancy, a node combination with a coverage higher than the preset coverage threshold and a redundancy lower than the preset redundancy threshold is selected as the optimal root cause set; Match the feature information of the optimal root cause set with historical cases, calculate the root cause attribute similarity, impact range similarity and processing complexity similarity, and obtain a similarity index system by weighted combination of the root cause attribute similarity, impact range similarity and processing complexity similarity; filter out historical cases with a matching degree higher than a preset similarity threshold based on the similarity index system; perform adaptive analysis on the filtered historical cases and current scenario features, which include the urgency of the alarm, the business impact and resource occupancy; extract effective processing methods and experiences from historical cases based on the results of the adaptive analysis; and generate targeted hierarchical processing suggestions in combination with the positioning results of the optimal root cause set.
7. The method according to claim 6, characterized in that Calculate the coverage of each suspected root cause node to the affected node group. The coverage is determined by the comprehensive correlation strength between nodes. Evaluate the redundancy between suspected root cause nodes. The redundancy is obtained by the overlap ratio of the node influence range, including: Obtain the comprehensive correlation strength between the suspected root cause node and each node in the affected node group; construct a network correlation matrix based on the comprehensive correlation strength; the rows of the network correlation matrix represent the suspected root cause nodes, and the columns represent the nodes in the affected node group; set the node weight coefficient according to the alarm level, business importance and resource occupancy rate of each node in the affected node group; use the sigmoid function to normalize the comprehensive correlation strength in the network correlation matrix; perform weighted calculation on the normalized comprehensive correlation strength and the node weight coefficient to obtain the coverage of the suspected root cause node to the affected node group; Determine the influence range boundary of the suspected root cause node based on a preset correlation strength threshold; extract the affected node set within its influence range for each suspected root cause node, and the normalized comprehensive correlation strength of the nodes in the affected node set with the suspected root cause node is greater than the correlation strength threshold; calculate the number of nodes in the intersection of the influence ranges of any two suspected root cause nodes; The ratio of the number of intersection nodes to the number of intersection nodes in the impact range is taken as the initial redundancy; the normalized comprehensive correlation strength difference between two suspected root cause nodes is calculated at the intersection node; the redundancy correction coefficient is set according to the normalized comprehensive correlation strength difference; the initial redundancy is multiplied by the redundancy correction coefficient to obtain the final inter-node redundancy.
8. An electronic device, characterized in that: include: processor; a memory for storing processor-executable instructions; The processor is configured to call instructions stored in the memory to execute the method of any one of claims 1 to 7.
9. A computer-readable storage medium having computer program instructions stored thereon, characterized in that: The computer program instructions, when executed by a processor, implement the method of any one of claims 1 to 7.
Citation Information
Patent Citations
Internet of Things system
CN116368355A
Mobile robot operation efficiency evaluation method and system based on industrial internet
CN119272063A
Network attack link tracking and threat situation reasoning method based on knowledge graph
CN119544327A
Network detection method and device, computer equipment, readable storage medium and program product
CN119696995A
Cited By
Battery module early abnormity early warning method and system fused with time sequence knowledge graph
CN120142960A
Method and System for Early Abnormality Warning of Battery Modules Incorporating Temporal Knowledge Graphs
CN120142960B
Large model prompt project optimization system and method fusing domain knowledge graph
CN120196734A
Large model-based engineering optimization system and method integrating domain knowledge graph
CN120196734B
Cloud monitoring service operation and maintenance dynamic optimization system and method based on AI intelligent agent
CN120223501A