Operation and Maintenance Alarm Handling Method and System Based on Knowledge Graph Enhanced Large Model
Through a multi-dimensional feature matrix based on knowledge graph and a dynamic weight fusion algorithm, combined with hierarchical knowledge graph and incremental knowledge reasoning, the accuracy and adaptability of alarm processing in the existing technology are solved, and efficient operation and maintenance alarm analysis and processing are achieved.
Patent Information
- Application Number
- CN202510458235.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-04-14
AI Technical Summary
The existing operation and maintenance alarm processing methods lack a comprehensive analysis of the timing correlation, spatial propagation characteristics and business dependencies between alarms, which leads to low positioning accuracy, hardening rules to adapt to changes in the IT environment, and lack of intelligent reuse mechanisms, resulting in low fault processing efficiency.
Using a large model based on knowledge graph enhancement, we can realize multi-dimensional correlation analysis and root cause reasoning of alarms by constructing spatiotemporal semantic multi-dimensional feature matrix, dynamic weight fusion algorithm and incremental knowledge inference, combined with multi-objective optimization algorithm and hierarchical knowledge graph, and generate targeted processing suggestions.
It improves the accuracy and efficiency of alarm processing, reduces false alarms and missed reports, improves the work efficiency of operation and maintenance personnel, has the ability to continuously learn and optimize, and can quickly identify the source nodes of the alarm and generate targeted processing suggestions.
Smart Images

Figure CN119988154B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to knowledge graph technology, and particularly to an operation and maintenance alarm processing method and system based on a knowledge graph enhanced large model. Background Art
[0002] With the rapid development of information technology, the scale of IT infrastructure has been continuously expanding, the system architecture has become increasingly complex, and the number of operation and maintenance alarms has increased exponentially. Traditional operation and maintenance alarm processing methods mainly rely on manual experience for analysis and processing. Facing a large amount of alarm information, it is difficult for operation and maintenance personnel to accurately locate the root cause of the fault in a timely manner and take effective treatment measures. To improve operation and maintenance efficiency, the industry has begun to explore the use of artificial intelligence technology to achieve intelligent analysis and processing of alarms. Currently, the mainstream alarm processing methods include technical routes such as rule-based expert systems, machine learning-based alarm classification, and statistical analysis-based alarm correlation. These methods have improved the automation level of alarm processing to a certain extent, but there are still many limitations.
[0003] Existing alarm processing methods often treat alarms as independent events, lacking comprehensive analysis of the temporal correlation, spatial propagation characteristics, and business dependency relationships between alarms, and it is difficult to accurately restore the propagation path and impact range of the fault. This results in a low accuracy rate of root cause location and is prone to misjudgment or missed judgment.
[0004] Traditional alarm processing systems usually use a static rule library for fault diagnosis and cannot adapt to the dynamic changes of the IT environment. With the continuous evolution of business systems, new fault modes emerge continuously, and the fixed rules will soon become invalid, making it difficult to continuously improve the diagnostic ability of the system.
[0005] Existing solutions generally lack a systematic accumulation and intelligent reuse mechanism for historical processing experience. Although a large number of fault processing records have been accumulated, due to the lack of effective knowledge extraction and organization methods, it is difficult to transform expert experience into a sustainable evolving intelligent diagnostic ability, resulting in the need to repeat the manual analysis process when similar faults occur repeatedly. Summary of the Invention
[0006] Embodiments of the present invention provide an operation and maintenance alarm processing method and system based on a knowledge graph enhanced large model, which can solve the problems in the prior art.
[0007] In the first aspect of the embodiments of the present invention,
[0008] An operation and maintenance alarm processing method based on a knowledge graph enhanced large model is provided, including:
[0009] The topology information, performance metric information, and processing record information of the acquisition devices constitute the multi-source operation and maintenance alarm historical data. Adaptive hierarchical structured processing is performed on the multi-source operation and maintenance alarm historical data. Anomaly detection is achieved through time series clustering, text standardization is completed using semantic similarity, and the characteristics of the alarm propagation link, device state evolution, and business dependency relationship are extracted to construct a spatio-temporal semantic multi-dimensional feature matrix. The spatio-temporal semantic multi-dimensional feature matrix is input into the dynamic weight fusion algorithm to construct a multi-dimensional alarm association network with time series dependency intensity, spatial propagation probability, and business impact degree. Based on the multi-dimensional alarm association network, an incremental knowledge reasoning method is used to construct and continuously optimize a hierarchical knowledge graph;
[0010] The dynamic transfer analysis of alarms between different levels is realized using the hierarchical knowledge graph. Combining the time series evolution characteristics, topology propagation characteristics, and business dependency characteristics of the alarms, the dynamic credibility weights of each propagation path are calculated through a multi-objective optimization algorithm. Based on the dynamic credibility weights, a root cause reasoning rule library with threshold adaptability and impact prediction functions is constructed. The root cause reasoning rule library is deeply associated and mapped with the hierarchical knowledge graph to form a continuously evolving diagnostic reasoning system;
[0011] When real-time operation and maintenance alarm information is received, the diagnostic reasoning system is started to analyze the multi-dimensional propagation link of the alarm, and the alarm source node and the affected node group are identified. The optimal root cause set is selected from the suspected root cause nodes based on the alarm source node and the affected node group. Similar historical cases are retrieved through the hierarchical knowledge graph and combined with the current scenario characteristics to generate targeted hierarchical processing suggestions.
[0012] The spatio-temporal semantic multi-dimensional feature matrix is input into the dynamic weight fusion algorithm to construct a multi-dimensional alarm association network with time series dependency intensity, spatial propagation probability, and business impact degree. Based on the multi-dimensional alarm association network, an incremental knowledge reasoning method is used to construct and continuously optimize a hierarchical knowledge graph, including:
[0013] The information gain rate of each dimension feature in the spatio-temporal semantic multi-dimensional feature matrix is calculated, and the correlation between features is evaluated based on mutual information. The information gain rate and the correlation between features are input into a multi-objective optimizer to generate the dynamic weights of each dimension feature. The spatio-temporal semantic multi-dimensional feature matrix is weighted and fused according to the dynamic weights, the feature interaction intensity is calculated through a multi-head attention mechanism, the time series evolution pattern is captured using a gated recurrent unit, and the spatial propagation characteristics are modeled using a graph neural network. The feature interaction intensity, time series evolution pattern, and spatial propagation characteristics are input into a multi-task learning framework, and the time series dependency intensity, spatial propagation probability, and business impact degree between alarm entities are jointly optimized;
[0014] Construct a temporal correlation sub - network based on the temporal dependence intensity, construct a topological correlation sub - network based on the spatial propagation probability, and construct a service correlation sub - network based on the service impact degree; fuse the three sub - networks to form a multi - dimensional alarm correlation network, and calculate the importance distribution of network nodes through a weighted random - walk algorithm; use the importance distribution to stratify alarm entities and construct an initial hierarchical knowledge graph.
[0015] Based on the initial hierarchical knowledge graph, fuse the expert rule base and statistical learning methods for incremental knowledge reasoning; model the reasoning process as a Markov decision process, and optimize the reasoning path selection based on value - function approximation and policy - gradient methods; transfer the reasoning knowledge in known scenarios to new scenarios through transfer learning methods, and use domain - adaptation algorithms to reduce the feature - distribution offset; conduct Bayesian evaluation on the credibility of the reasoning results to generate uncertainty quantification indicators; dynamically adjust the feature - extraction parameters and weight - fusion strategies based on the uncertainty quantification indicators to achieve the continuous optimization of the knowledge graph.
[0016] Based on the initial hierarchical knowledge graph, fuse the expert rule base and statistical learning methods for incremental knowledge reasoning; model the reasoning process as a Markov decision process, and optimize the reasoning path selection based on value - function approximation and policy - gradient methods; transfer the reasoning knowledge in known scenarios to new scenarios through transfer learning methods, and use domain - adaptation algorithms to reduce the feature - distribution offset, including:
[0017] Based on the initial hierarchical knowledge graph, extract entity - relation pairs from it to generate an expert rule base, and the expert rule base records the reasoning rules and constraint conditions between entities; vectorize the entities and relationships in the knowledge graph, and use statistical learning methods to calculate the relationship probability between entity pairs; adaptively and weighted - fuse the expert rule base and the relationship probability to construct an incremental knowledge - reasoning model, and the weight assignment in the fusion process is based on rule confidence and probability - distribution consistency.
[0018] Model the incremental knowledge - reasoning model as a Markov decision process, construct a state space with the current reasoning entity and historical paths, and construct an action space with optional reasoning rules; use a deep neural network to approximate the state - value function, and the state - value function evaluates the long - term value of the reasoning state; calculate the value - function estimation error based on the temporal - difference algorithm, and update the network parameters through backpropagation; use the policy - gradient method to optimize the selection strategy of reasoning rules, and the selection strategy conducts parameter learning based on the cumulative - reward maximization criterion.
[0019] Extract reasoning patterns from the knowledge graph of known scenarios, and map the reasoning patterns to new scenarios through transfer learning methods; use domain - adaptation algorithms to calculate the feature - distribution differences between the source domain and the target domain, and achieve feature - distribution alignment by minimizing the maximum mean discrepancy.
[0020] Use a hierarchical knowledge graph to achieve dynamic transfer analysis of alarms between different levels; combine the temporal evolution characteristics, topological propagation characteristics, and business dependency characteristics of alarms, and calculate the dynamic credibility weights of each propagation path through a multi-objective optimization algorithm, including:
[0021] Use a hierarchical knowledge graph to achieve dynamic transfer analysis of alarms between different levels. The hierarchical knowledge graph constructs a multi-level structure according to the physical layer, network layer, and business layer; establish alarm transfer rules within the level based on the direct association relationship between nodes; analyze the horizontal transfer path of the alarm transfer rules within the level and the vertical transfer path of the alarm nodes between levels, and combine the horizontal transfer path and the vertical transfer path to form an initial set of alarm transfer paths;
[0022] Extract multi-dimensional features for each transfer path in the initial set of alarm transfer paths. Extract temporal evolution features from the alarm time series; extract topological propagation features from the network topology structure; extract business dependency features from the business call relationship; normalize the temporal evolution features, topological propagation features, and business dependency features and then construct a feature matrix;
[0023] Input the feature matrix into a multi-objective optimization algorithm, with the maximization of temporal correlation, the minimization of topological overhead, and the minimization of business impact as optimization objectives; calculate the objective function values of each transfer path in the temporal dimension, topological dimension, and business dimension; obtain the optimal set of transfer paths based on non-dominated sorting; use an adaptive weight allocation strategy to calculate the dynamic credibility weights of the transfer paths by combining the objective function values of each dimension.
[0024] Input the feature matrix into a multi-objective optimization algorithm, with the maximization of temporal correlation, the minimization of topological overhead, and the minimization of business impact as optimization objectives; calculate the objective function values of each transfer path in the temporal dimension, topological dimension, and business dimension, including:
[0025] Input the standardized feature matrix into a multi-objective optimization algorithm. Set the maximization of temporal correlation as the first optimization objective, which is obtained by calculating the time series correlation degree, the consistency of alarm occurrence order, and the propagation delay time of adjacent alarm nodes on the transfer path; set the minimization of topological overhead as the second optimization objective, which is obtained by calculating the network hop count, link bandwidth occupancy, and node processing load of the transfer path; set the minimization of business impact as the third optimization objective, which is obtained by calculating the service interruption duration, the number of affected users, and the degree of business loss of the transfer path;
[0026] Based on the three optimization objectives of the multi-objective optimization algorithm, calculate the objective function values of each transmission path: Calculate the objective function value in the time series dimension according to the first optimization objective. The objective function value in the time series dimension is calculated based on the correlation coefficient of the alarm time series, the alarm propagation delay, and the alarm duration, and is used to characterize the temporal consistency of alarm transmission;
[0027] Calculate the objective function value in the topology dimension according to the second optimization objective. The objective function value in the topology dimension is calculated based on the weighted sum of path hops, link utilization rate, and node load rate, and is used to characterize the network resource consumption of alarm transmission; Calculate the objective function value in the service dimension according to the third optimization objective. The objective function value in the service dimension is calculated based on service interruption losses, user impact scope, and service level agreement violation degree, and is used to characterize the service loss degree of alarm transmission.
[0028] Screen the optimal root cause set from the suspected root cause nodes based on the alarm source node and the affected node group; Retrieve similar historical cases through a hierarchical knowledge graph and combine the current scenario characteristics to generate targeted hierarchical handling suggestions, including:
[0029] Obtain the characteristic parameters of the alarm source node, including the alarm occurrence time, alarm duration, and alarm severity level; Analyze the propagation path of the alarm in the network based on the characteristic parameters, extract the nodes that receive the alarm to construct the affected node group, record the alarm reception time of each node in the affected node group, and sort the nodes in time series according to the alarm reception time to generate the initial propagation sequence;
[0030] Construct a correlation evaluation matrix based on the initial propagation sequence. By calculating the temporal correlation, topological correlation, and service correlation between the alarm source node and each node in the affected node group, obtain the comprehensive correlation strength between nodes; The temporal correlation is calculated based on the time correlation of the alarm sequences between nodes; The topological correlation is calculated based on the network distance between nodes; The service correlation is calculated based on the service call strength between nodes;
[0031] Use the correlation evaluation matrix to analyze the influence characteristics of the suspected root cause nodes: Calculate the coverage degree of each suspected root cause node on the affected node group, and the coverage degree is determined by the comprehensive correlation strength between nodes; Evaluate the redundancy between suspected root cause nodes, and the redundancy is obtained through the overlapping ratio of the node influence ranges; Based on the coverage degree and redundancy, select the node combination with a coverage degree higher than the preset coverage threshold and a redundancy lower than the preset redundancy threshold as the optimal root cause set;
[0032] Match the characteristic information of the optimal root cause set with historical cases, calculate the similarity of root cause attributes, the similarity of impact scope, and the similarity of handling complexity, and combine the similarity of root cause attributes, the similarity of impact scope, and the similarity of handling complexity to obtain a similarity index system; screen out historical cases with a matching degree higher than a preset similarity threshold based on the similarity index system; perform an adaptability analysis on the screened historical cases and the current scenario characteristics, where the current scenario characteristics include the urgency level of the alarm, the degree of business impact, and the resource occupancy status; extract effective handling methods and experiences from the historical cases according to the results of the adaptability analysis; combine with the positioning results of the optimal root cause set to generate targeted hierarchical handling suggestions.
[0033] Calculate the coverage degree of each suspected root cause node on the affected node group, and the coverage degree is determined by the comprehensive association strength between nodes; evaluate the redundancy between suspected root cause nodes, and the redundancy is obtained by the overlapping ratio of the influence scopes of the nodes, including:
[0034] Obtain the comprehensive association strength between the suspected root cause node and each node in the affected node group; construct a network association matrix based on the comprehensive association strength; the rows of the network association matrix represent the suspected root cause nodes, and the columns represent the nodes in the affected node group; set the node weight coefficients according to the alarm level, business importance degree, and resource occupancy rate of each node in the affected node group; use the sigmoid function to normalize the comprehensive association strength in the network association matrix; perform weighted calculation on the normalized comprehensive association strength and the node weight coefficients to obtain the coverage degree of the suspected root cause node on the affected node group;
[0035] Determine the boundary of the influence scope of the suspected root cause node based on a preset association strength threshold; extract the set of affected nodes within the influence scope for each suspected root cause node, and the normalized comprehensive association strength between the nodes in the set of affected nodes and the suspected root cause node is greater than the association strength threshold; calculate the number of intersection nodes in the influence scopes of any two suspected root cause nodes;
[0036] Take the ratio of the number of intersection nodes to the number of intersection nodes in the influence scopes as the initial redundancy; calculate the difference in the normalized comprehensive association strength between two suspected root cause nodes on the intersection nodes; set the redundancy correction coefficient according to the difference in the normalized comprehensive association strength; multiply the initial redundancy by the redundancy correction coefficient to obtain the final redundancy between nodes.
[0037] In the second aspect of the embodiments of the present invention,
[0038] Provide an electronic device, including:
[0039] A processor;
[0040] A memory for storing executable instructions of the processor;
[0041] Among them, the processor is configured to call the instructions stored in the memory to execute the foregoing method.
[0042] In the third aspect of the embodiments of the present invention,
[0043] a computer-readable storage medium is provided, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the foregoing method is implemented.
[0044] The beneficial effects of this application are as follows:
[0045] 1. By adaptively grading and structuring the historical data of multi-source operation and maintenance alerts, constructing a spatio-temporal semantic multi-dimensional feature matrix, and forming a multi-dimensional alert association network based on the dynamic weight fusion algorithm, the present invention realizes the in-depth correlation analysis of alert data, improves the accuracy and efficiency of alert processing. At the same time, an incremental knowledge reasoning method is used to construct and continuously optimize a hierarchical knowledge graph, enabling the system to have the ability of continuous learning and optimization.
[0046] 2. By analyzing the temporal evolution characteristics, topological propagation characteristics, and business dependency characteristics of alerts, the present invention establishes a dynamic credibility weight calculation mechanism and constructs a root cause reasoning rule base with threshold adaptability and impact prediction functions. This method significantly improves the accuracy of alert root cause analysis, reduces false alarms and missed alarms, and effectively reduces the workload of operation and maintenance personnel.
[0047] 3. When processing real-time operation and maintenance alerts, the present invention can quickly identify the alert source node and the affected node group, and screen out the optimal root cause set from the suspected root cause nodes. By retrieving similar historical cases through the hierarchical knowledge graph and combining the current scenario characteristics, the system can generate more targeted hierarchical processing suggestions, improve the intelligence level and efficiency of alert processing, and reduce the operation and maintenance cost. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Figure 1 is a schematic flowchart of the operation and maintenance alert processing method based on the knowledge graph enhanced large model according to the embodiments of the present invention;
[0049] Figure 2 is a schematic diagram of the comprehensive evaluation of multi-dimensional knowledge reasoning performance according to the embodiments of the present invention;
[0050] Figure 3 is a schematic diagram of the redundancy calculation performance under different scenarios according to the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0051] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0052] The technical solutions of the present invention will be described in detail below with specific embodiments. These specific embodiments may be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.
[0053] Figure 1 It is a schematic flowchart of the operation and maintenance alarm processing method based on the knowledge graph enhanced large model in the embodiments of the present invention. As Figure 1 shown, the method includes:
[0054] Collect device topology information, performance index information, and processing record information to form multi-source operation and maintenance alarm historical data; perform adaptive hierarchical structured processing on the multi-source operation and maintenance alarm historical data, achieve anomaly detection through time series clustering, complete text standardization using semantic similarity, and extract alarm propagation link features, device status evolution features, and business dependency relationship features to construct a spatio-temporal semantic multi-dimensional feature matrix; input the spatio-temporal semantic multi-dimensional feature matrix into the dynamic weight fusion algorithm to construct a multi-dimensional alarm association network with time series dependence intensity, spatial propagation probability, and business impact degree; based on the multi-dimensional alarm association network, use the incremental knowledge reasoning method to construct and continuously optimize the hierarchical knowledge graph;
[0055] Use the hierarchical knowledge graph to realize the dynamic transmission analysis of alarms between different levels; combine the time series evolution features, topology propagation features, and business dependency features of the alarms, and calculate the dynamic credibility weights of each propagation path through the multi-objective optimization algorithm; based on the dynamic credibility weights, construct a root cause reasoning rule base with threshold adaptability and impact prediction functions; deeply associate and map the root cause reasoning rule base with the hierarchical knowledge graph to form a continuously evolving diagnostic reasoning system;
[0056] When receiving real-time operation and maintenance alarm information, start the diagnostic reasoning system to analyze the multi-dimensional propagation link of the alarm, identify the alarm source node and the affected node group; screen the optimal root cause set from the suspected root cause nodes based on the alarm source node and the affected node group; retrieve similar historical cases through the hierarchical knowledge graph and combine the current scenario features to generate targeted hierarchical processing suggestions.
[0057] In an alternative embodiment, the spatio-temporal semantic multi-dimensional feature matrix is input into a dynamic weight fusion algorithm to construct a multi-dimensional alarm correlation network with temporal dependence intensity, spatial propagation probability, and business impact degree; based on the multi-dimensional alarm correlation network, an incremental knowledge reasoning method is used to construct and continuously optimize a hierarchical knowledge graph, including:
[0058] Calculate the information gain rate for each dimension feature in the spatio-temporal semantic multi-dimensional feature matrix, and evaluate the correlation between features based on mutual information; input the information gain rate and the correlation between features into a multi-objective optimizer to generate the dynamic weights of each dimension feature; perform weighted fusion on the spatio-temporal semantic multi-dimensional feature matrix according to the dynamic weights, calculate the feature interaction intensity through a multi-head attention mechanism, capture the temporal evolution pattern using a gated recurrent unit, and model the spatial propagation characteristics using a graph neural network; input the feature interaction intensity, temporal evolution pattern, and spatial propagation characteristics into a multi-task learning framework, and jointly optimize to obtain the temporal dependence intensity, spatial propagation probability, and business impact degree between alarm entities;
[0059] Construct a temporal correlation sub-network based on the temporal dependence intensity, construct a topological correlation sub-network based on the spatial propagation probability, and construct a business correlation sub-network based on the business impact degree; fuse the three sub-networks to form a multi-dimensional alarm correlation network, and calculate the importance distribution of network nodes through a weighted random walk algorithm; use the importance distribution to stratify the alarm entities and construct an initial hierarchical knowledge graph;
[0060] Based on the initial hierarchical knowledge graph, fuse the expert rule base and statistical learning methods for incremental knowledge reasoning; model the reasoning process as a Markov decision process, and optimize the reasoning path selection based on the value function approximation and policy gradient methods; transfer the reasoning knowledge in the known scenario to the new scenario through transfer learning methods, and use the domain adaptation algorithm to reduce the feature distribution shift; perform Bayesian evaluation on the credibility of the reasoning results to generate an uncertainty quantification index; based on the uncertainty quantification index, dynamically adjust the feature extraction parameters and weight fusion strategy to achieve continuous optimization of the knowledge graph.
[0061] During the dynamic weight fusion based on the spatio-temporal semantic multi-dimensional feature matrix, first construct a feature information gain evaluation module. This module calculates the information gain rate for the time dimension feature, space dimension feature, and semantic dimension feature respectively. For the time dimension feature, extract temporal information such as the occurrence time, duration, and periodic pattern of the alarm; for the space dimension feature, extract spatial information such as the physical location of the alarm device, network topology relationship, and resource dependence relationship; for the semantic dimension feature, extract semantic information such as the type, level, and description text of the alarm. Calculate the information gain rate of each dimension feature through the decision tree splitting criterion, and at the same time use the mutual information measurement method to evaluate the correlation between features.
[0062] In the feature weight optimization stage, a multi-objective optimization framework is constructed. This framework takes the information gain ratio as the feature importance index and the feature correlation as the redundancy index, and balances the two objectives through the Pareto optimal principle to generate the dynamic weight values of features in each dimension. The weight values are dynamically adjusted with the change of the alarm data distribution to ensure the self-adaptability of feature fusion.
[0063] The feature fusion module uses the multi-head attention mechanism to realize the interactive modeling between features. The features in different dimensions are mapped to a unified representation space, and the feature interaction intensity matrix is obtained through attention calculation. At the same time, the gated recurrent unit is used to capture the temporal dependence relationship of the alarm sequence to establish a temporal evolution model. Based on the message passing mechanism of the graph neural network, the propagation characteristics of alarms on the spatial network are modeled.
[0064] The multi-task learning framework jointly optimizes the three tasks of feature interaction, temporal evolution, and spatial propagation. The framework includes a shared layer and task-specific layers. The shared layer learns the general feature representation, and the task-specific layers respectively output the temporal dependence intensity, spatial propagation probability, and business impact degree. The soft parameter sharing mechanism is used to balance the correlation and difference between tasks.
[0065] In the knowledge graph construction stage, sub-networks are constructed based on the above three correlation indicators respectively. The temporal correlation sub-network depicts the causal evolution relationship between alarms, the spatial correlation sub-network describes the propagation and diffusion mode of alarms, and the business correlation sub-network reflects the impact path of alarms on the business system. The importance of nodes in the fused multi-dimensional network is calculated by the random walk algorithm to realize the hierarchical organization of alarm entities.
[0066] In the incremental knowledge reasoning process, hybrid reasoning is carried out by combining expert rules and statistical models. Expert rules include prior knowledge such as fault diagnosis experience and alarm handling processes; the statistical model learns the alarm pattern through historical data. The selection of the reasoning path is optimized by the value function approximation method to ensure the convergence of the reasoning process. For new scenarios, the transfer learning method is used to realize knowledge transfer, and the domain adaptation algorithm is used to reduce the performance degradation caused by the feature distribution shift.
[0067] Based on the Bayesian framework, the credibility of the reasoning results is evaluated to generate the confidence interval and uncertainty index. According to the evaluation results, the feature extraction and weight fusion strategies are dynamically adjusted to realize the continuous optimization and evolution of the knowledge graph.
[0068] The solution of this application can:
[0069] Through the dynamic weight fusion algorithm, the adaptive fusion of spatio-temporal semantic multi-dimensional features is realized, which improves the discriminability and robustness of feature representation, making the alarm correlation analysis more accurate and reliable. The multi-task learning framework is adopted to jointly optimize multiple correlation indicators, fully utilizing the correlation between tasks, enhancing the generalization ability of the model, and reducing the computational overhead. Based on the incremental knowledge reasoning method, the combination of expert experience and data-driven is realized to achieve the dynamic evolution of the knowledge graph, improving the interpretability and adaptability of the system.
[0070] In an optional implementation manner, based on the initial hierarchical knowledge graph, the expert rule base and statistical learning methods are fused for incremental knowledge reasoning; the reasoning process is modeled as a Markov decision process, and the reasoning path selection is optimized based on the value function approximation and policy gradient methods; the reasoning knowledge in the known scenario is transferred to the new scenario through the transfer learning method, and the domain adaptation algorithm is used to reduce the feature distribution offset, including:
[0071] Based on the initial hierarchical knowledge graph, entity-relationship pairs are extracted from it to generate an expert rule base, and the expert rule base records the reasoning rules and constraint conditions between entities; the entities and relationships in the knowledge graph are vectorized, and the statistical learning method is used to calculate the relationship probability between entity pairs; the expert rule base and the relationship probability are adaptively weighted and fused to construct an incremental knowledge reasoning model, and the weight distribution is carried out based on the rule confidence and probability distribution consistency during the fusion process;
[0072] The incremental knowledge reasoning model is modeled as a Markov decision process, with the current reasoning entity and historical path constructing the state space and the optional reasoning rules constructing the action space; a deep neural network is used to approximate the state value function, and the state value function evaluates the long-term value of the reasoning state; the value function estimation error is calculated based on the temporal difference algorithm, and the network parameters are updated through backpropagation; the policy gradient method is used to optimize the selection strategy of the reasoning rules, and the selection strategy performs parameter learning based on the cumulative reward maximization criterion;
[0073] The reasoning patterns are extracted from the knowledge graph of the known scenario and mapped to the new scenario through the transfer learning method; the domain adaptation algorithm is used to calculate the feature distribution difference between the source domain and the target domain, and the feature distribution alignment is achieved by minimizing the maximum mean discrepancy.
[0074] Entity-relationship pairs are extracted from the initial hierarchical knowledge graph to construct an expert rule base. First, the key entity nodes in the knowledge graph are identified, including device nodes, alarm nodes, service nodes, etc. The association relationships between these entity nodes are analyzed, including causal relationships, dependency relationships, composition relationships, etc. For each pair of associated entity nodes, information such as their association type, association strength, and constraint conditions is extracted to form reasoning rules. The extracted reasoning rules are stored in the expert rule base, and each rule contains attributes such as preconditions, conclusions, and confidence levels.
[0075] Implement vectorized representation of the knowledge graph. Use a deep learning model to map entity nodes into a high-dimensional vector space, and the vector dimension is usually set to 128 or 256 dimensions. Also perform vectorized representation on the relationship types between entities. Based on entity vectors and relationship vectors, construct triple training samples. Use statistical learning methods, such as transposed convolutional networks, to train the triple samples to obtain the relationship probability distribution between entity pairs.
[0076] Realize the adaptive fusion of expert rules and statistical probabilities. Set the rule weight and probability weight as fusion parameters, and their initial values are both 0.5. Statistically calculate the accuracy rate of each rule in historical data as the rule confidence. Calculate the degree of consistency between the rule inference result and the probability distribution prediction result. Dynamically adjust the fusion weight according to the rule confidence and prediction consistency. When the rule confidence is high and the prediction results are consistent, increase the rule weight; otherwise, increase the probability weight.
[0077] Construct a Markov decision process framework. The state space includes information such as the attribute features of the currently to-be-inferred entity, the selected inference rule sequence, and the historical inference path. The action space includes the set of available expert rules and statistical prediction methods. Use a deep neural network as the value function approximator, with the network input being the state features and the output being the state value evaluation score.
[0078] Optimize the value function network and decision-making strategy. Record the state transition sequence and the obtained reward values during the inference process. Calculate the value function prediction error based on the temporal difference algorithm and backpropagate the error to update the network parameters. The design of the reward value considers multiple aspects such as inference accuracy, path length, and computational overhead. Use the policy gradient method to optimize the rule selection strategy, and the policy network outputs the selection probabilities of each action.
[0079] Realize cross-scenario knowledge transfer. Extract typical inference patterns from the source scenario knowledge graph, including entity type mapping relationships, relationship path patterns, constraint rules, etc. Construct a feature extractor to map entities in the source domain and the target domain into the same feature space. Calculate the difference in feature distributions between the two domains through a domain adaptation algorithm and use an adversarial training method to achieve feature distribution alignment.
[0080] Figure 2 This is a schematic diagram for the comprehensive evaluation of the multi-dimensional knowledge inference performance of the embodiments of the present invention:
[0081] This figure shows the performance comparison of three technical solutions under different node scales. From the overall data, this technical solution performs the best in the range of node scales from 0 to 2000. The performance index steadily rises from the initial 0.68 to 0.97 and maintains high stability throughout the process. Especially after the node scale reaches 1000, the performance index can still remain at a high level above 0.91, showing strong scalability. In contrast, the performance of the traditional method A is relatively weak. Its performance index starts from 0.60 and only reaches 0.80 when the node scale reaches 2000. The overall improvement is small, and the performance improvement tends to level off in large-scale scenarios. Although the improved method B performs better than the traditional method A in the initial stage, with an initial performance of 0.65 and quickly rising to 0.89 when the node scale reaches 800 and finally reaching a performance index of 0.96 at the 2000-node scale, it still fails to exceed the performance level of this technical solution. Through comparison, it can be clearly seen that this technical solution has obvious advantages in terms of performance index, scalability, and stability. Especially in large-scale node scenarios, it shows its excellent technological advancement and practical value. These data fully prove the effectiveness and reliability of this technical solution in solving the problem of scale expansion.
[0082] The solution of this application can:
[0083] By integrating the expert rule base and statistical learning methods, making full use of the advantages of prior knowledge and data-driven, it improves the accuracy and robustness of knowledge reasoning, and realizes the continuous accumulation and optimization of knowledge. Using Markov decision process to model the reasoning process, combining value function approximation and policy gradient methods, it optimizes the selection strategy of the reasoning path, improves the reasoning efficiency, and reduces the consumption of computing resources. Introducing transfer learning and domain adaptation mechanisms, it realizes the transfer and reuse of knowledge between different scenarios, improves the generalization ability of the model, and reduces the adaptation cost of new scenarios.
[0084] In an optional implementation, a hierarchical knowledge graph is used to realize the dynamic transfer analysis of alarms between different levels; combined with the temporal evolution characteristics, topological propagation characteristics, and business dependency characteristics of alarms, the dynamic credibility weights of each propagation path are calculated through a multi-objective optimization algorithm, including:
[0085] Using a hierarchical knowledge graph to realize the dynamic transfer analysis of alarms between different levels, the hierarchical knowledge graph constructs a multi-level structure according to the physical layer, network layer, and business layer; based on the direct association relationship between nodes, establish the alarm transfer rules within the level; analyze the horizontal transfer path of the alarm transfer rules within the level and the vertical transfer path of the alarm nodes between levels, and combine the horizontal transfer path and the vertical transfer path to form an initial alarm transfer path set;
[0086] Extract multi-dimensional features for each transmission path in the initial alarm transmission path set. Extract temporal evolution features from the alarm time series; extract topological propagation features from the network topology structure; extract service dependency features from the service call relationship; normalize the temporal evolution features, topological propagation features, and service dependency features, and then construct a feature matrix.
[0087] Input the feature matrix into a multi-objective optimization algorithm, with the maximization of temporal correlation, the minimization of topological overhead, and the minimization of service impact as the optimization objectives; calculate the objective function values of each transmission path in the temporal dimension, topological dimension, and service dimension; obtain the optimal transmission path set based on non-dominated sorting; use an adaptive weight allocation strategy to calculate the dynamic credibility weights of the transmission paths by combining the objective function values of each dimension.
[0088] Construct a multi-level structure of a hierarchical knowledge graph. The physical layer contains physical entity nodes such as servers, network devices, and storage devices; the network layer contains virtual resource nodes such as virtual machines, containers, and network links; the service layer contains service component nodes such as application services, microservices, and databases. Inside each level, establish direct association relationships between nodes based on relationships such as physical connections, network communications, and service calls between devices.
[0089] Analyze the alarm transmission rules within the levels. In the physical layer, determine the alarm transmission direction based on the upstream and downstream connection relationships of devices; in the network layer, determine the alarm diffusion range according to the network topology structure; in the service layer, determine the alarm impact path based on the call dependencies between services. At the same time, identify the vertical association relationships between different levels, such as the hosting relationship between physical devices and virtual resources, and the deployment relationship between virtual resources and service services.
[0090] Combine to form an initial transmission path set. Combine and connect the horizontal transmission paths within the levels with the vertical transmission paths between the levels. For each source alarm, traverse the possible transmission paths through a depth-first search algorithm to generate an initial path set. Preprocess the path set to remove loop paths and redundant paths.
[0091] Extract multi-dimensional features of the transmission paths. Temporal evolution features include time attributes such as alarm occurrence time intervals, alarm duration, and alarm repetition frequencies; topological propagation features include network attributes such as node degree distributions, path hops, and link bandwidths; service dependency features include performance metrics such as service response times, call concurrency numbers, and error rates.
[0092] Normalize the extracted features. Convert features with different dimensions to a unified numerical interval. Temporal features are normalized by the maximum and minimum values; topological features are processed by logarithmic transformation; service features are standardized by Z-score. The normalized features form a feature matrix, and each row of the matrix corresponds to a transmission path.
[0093] Implement the multi-objective optimization process. The temporal correlation objective is obtained by calculating the order of alarm occurrence time and conditional probability; the topology overhead objective is obtained by accumulating the link load and network latency on the path; the service impact objective is obtained by evaluating the degree of service performance degradation and user experience loss.
[0094] Use the non-dominated sorting method to layer the transmission paths. The first layer contains the set of non-dominated solutions, that is, the solution set where there is no other path that is superior to this path in all objectives. Remove the non-dominated solutions layer by layer to obtain the complete hierarchical structure.
[0095] Allocate dynamic weights based on the layering results. Combine the non-dominated level where the path is located, the normalized score of the objective function value, and the historical transmission success rate to calculate the comprehensive score. Use the softmax function to convert the score into a probability distribution as the credibility weight of the transmission path. The weights are dynamically adjusted according to the changes in the system operating state and alarm distribution.
[0096] The solution of this application can:
[0097] Through the hierarchical knowledge graph, it realizes the dynamic transmission analysis of alarms between different levels, accurately grasps the propagation law of alarms, and improves the accuracy of root cause location. Combining temporal evolution characteristics, topological propagation characteristics, and service dependency characteristics for multi-dimensional analysis comprehensively depicts the characteristics of alarm transmission and enhances the reliability of the analysis results. Using the multi-objective optimization algorithm to dynamically calculate the credibility weight of the transmission path achieves an equilibrium among multiple objectives such as temporal correlation, topology overhead, and service impact, and improves the practicality of alarm analysis.
[0098] In an alternative implementation, input the feature matrix into the multi-objective optimization algorithm, with maximizing temporal correlation, minimizing topology overhead, and minimizing service impact as the optimization objectives; calculate the objective function values of each transmission path in the temporal dimension, topological dimension, and service dimension, including:
[0099] Input the standardized feature matrix into the multi-objective optimization algorithm. Set maximizing temporal correlation as the first optimization objective, which is obtained by calculating the time series correlation degree of adjacent alarm nodes on the transmission path, the consistency of alarm occurrence order, and the propagation delay time; set minimizing topology overhead as the second optimization objective, which is obtained by calculating the network hop count, link bandwidth occupancy, and node processing load of the transmission path; set minimizing service impact as the third optimization objective, which is obtained by calculating the service interruption duration, the number of affected users, and the degree of business loss of the transmission path.
[0100] Based on the three optimization objectives of the multi-objective optimization algorithm, calculate the objective function values of each transmission path: Calculate the objective function value of the timing dimension according to the first optimization objective. The objective function value of the timing dimension is calculated based on the correlation coefficient of the alarm time series, the alarm propagation delay, and the alarm duration, and is used to characterize the timing consistency of alarm transmission;
[0101] Calculate the objective function value of the topology dimension according to the second optimization objective. The objective function value of the topology dimension is calculated based on the weighted sum of path hops, link utilization rate, and node load rate, and is used to characterize the network resource consumption of alarm transmission; Calculate the objective function value of the service dimension according to the third optimization objective. The objective function value of the service dimension is calculated based on the service interruption loss, the user impact range, and the service level agreement violation degree, and is used to characterize the service loss degree of alarm transmission.
[0102] When inputting the standardized feature matrix into the multi-objective optimization algorithm, first construct the alarm timing feature matrix. Extract timing features such as timestamps, durations, and alarm levels for each alarm node to form feature vectors. Calculate the Pearson correlation coefficient for adjacent alarm nodes to judge the consistency of the alarm occurrence order and calculate the alarm propagation delay time. For example, the time series correlation coefficient between alarm A and alarm B is 0.85, the alarm occurrence order is consistent, and the propagation delay is 30 seconds.
[0103] Then calculate the topology dimension features. Count the network hops of the transmission path, such as path P contains 4 hops; analyze the link bandwidth occupancy, such as the link utilization rate is 65%; evaluate the node processing load, such as the CPU utilization rate is 75%. After normalizing these topology features, form a topology feature vector.
[0104] Then extract the service dimension features. Record the service interruption duration, such as the interruption lasts for 5 minutes; count the number of affected users, such as 1000 users are affected; evaluate the service loss degree, such as a transaction amount loss of 100,000 yuan is caused. After standardizing the service features, construct a service feature vector.
[0105] Based on the feature vectors of the above three dimensions, calculate the objective function values of each transmission path. The objective function value of the timing dimension comprehensively considers the correlation coefficient, propagation delay, and duration. For example, the timing objective value of path P is 0.82. The objective function value of the topology dimension comprehensively considers the number of hops, link utilization rate, and node load rate. For example, the topology objective value of path P is 0.68. The objective function value of the service dimension comprehensively considers the interruption loss, user impact, and SLA violation degree. For example, the service objective value of path P is 0.75.
[0106] Finally, perform multi-objective optimization based on the above three objective function values to obtain the Pareto optimal solution set and select the optimal alarm transmission path.
[0107] The solution of this application can:
[0108] The accuracy and timeliness of alarm transmission are improved through time series correlation analysis, avoiding time series disorder and delay accumulation during alarm transmission. Based on topology overhead optimization, the network resources occupied by alarm transmission are reduced, the network transmission efficiency is improved, and network congestion is reduced. From the perspective of business impact, the alarm transmission path is optimized, minimizing the loss of service interruption, improving the service quality guarantee level, and reducing the user complaint rate.
[0109] In an alternative embodiment, the optimal root cause set is screened from the suspected root cause nodes based on the alarm source node and the affected node group; similar historical cases are retrieved through a hierarchical knowledge graph and combined with the current scenario characteristics to generate targeted hierarchical handling suggestions, including:
[0110] Obtain the characteristic parameters of the alarm source node, including the alarm occurrence time, alarm duration, and alarm severity level; analyze the propagation path of the alarm in the network based on the characteristic parameters, extract the nodes that receive the alarm to construct the affected node group, record the alarm reception time of each node in the affected node group, sort the nodes according to the alarm reception time to generate the initial propagation sequence;
[0111] Construct a correlation degree evaluation matrix based on the initial propagation sequence. By calculating the time series correlation degree, topology correlation degree, and service correlation degree between the alarm source node and each node in the affected node group, obtain the comprehensive correlation strength between nodes; the time series correlation degree is calculated based on the time correlation of the alarm sequence between nodes; the topology correlation degree is calculated based on the network distance between nodes; the service correlation degree is calculated based on the service call intensity between nodes;
[0112] Use the correlation degree evaluation matrix to analyze the influence characteristics of the suspected root cause nodes: calculate the coverage degree of each suspected root cause node on the affected node group, and the coverage degree is determined by the comprehensive correlation strength between nodes; evaluate the redundancy between the suspected root cause nodes, and the redundancy is obtained through the overlapping ratio of the node influence ranges; based on the coverage degree and redundancy, select the node combination with a coverage degree higher than the preset coverage threshold and a redundancy lower than the preset redundancy threshold as the optimal root cause set;
[0113] Match the characteristic information of the optimal root cause set with historical cases, calculate the similarity of root cause attributes, influence range similarity, and processing complexity similarity, and combine the similarity of root cause attributes, influence range similarity, and processing complexity similarity through weighting to obtain a similarity index system; screen out historical cases with a matching degree higher than the preset similarity threshold based on the similarity index system; conduct an adaptability analysis of the screened historical cases and the current scenario characteristics, where the current scenario characteristics include the urgency of the alarm, the degree of business impact, and the resource occupancy status; according to the results of the adaptability analysis, extract effective handling methods and experiences from the historical cases; combine with the positioning results of the optimal root cause set to generate targeted hierarchical handling suggestions.
[0114] First, obtain the characteristic parameter information of the alarm source node. Taking a certain data center network as an example, the source node A generated an alarm of excessive CPU usage at 10:30:25 on October 15, 2023. The duration of the alarm was 30 minutes, and the alarm level was severe. By analyzing the network topology structure and service call relationships, it was found that nodes B, C, and D directly connected to node A received relevant alarms at 10:30:35, 10:30:40, and 10:30:45 respectively, forming an affected node group. According to the order of alarm reception time, an initial propagation sequence of A->B->C->D was generated.
[0115] Next, construct a correlation evaluation matrix. For nodes A and B, based on an alarm time interval of 10 seconds, the temporal correlation was calculated as 0.9; based on a network hop count of 1 hop, the topological correlation was calculated as 0.8; based on 100 service calls per second, the service correlation was calculated as 0.85. The same method was used to calculate the correlation between A and C, D, and finally, a comprehensive correlation strength matrix between nodes was obtained.
[0116] Then, analyze the influence characteristics of suspected root cause nodes. Assume that there are suspected root cause nodes E and F. The coverage degree of node E for the affected node group is 85%, and that of node F is 75%. The overlapping ratio of their influence ranges is 30%. Setting a coverage threshold of 80% and a redundancy threshold of 40%, node E is selected into the optimal root cause set.
[0117] Finally, perform historical case matching. Retrieve 5 historical cases from the knowledge graph and calculate the similarity with the current scenario. Among them, the similarity of the root cause attribute of case 1 is 0.9, the similarity of the influence range is 0.85, and the similarity of the processing complexity is 0.8. After weighted calculation, the comprehensive similarity is 0.85. Setting a similarity threshold of 0.8, case 1 is screened out. Combining the characteristics of the current alarm being severe, affecting core services, and CPU resource tension, the processing method is extracted from case 1 to generate a hierarchical processing suggestion.
[0118] The solution of this application can:
[0119] By constructing a correlation evaluation matrix and analyzing the influence characteristics of nodes, the true root cause of the fault can be accurately identified, avoiding false alarms and missed alarms, and improving the accuracy of root cause location. Retrieving historical cases from the hierarchical knowledge graph and performing similarity matching can quickly find the processing experience matching the current scenario and improve the fault handling efficiency. By adopting the method of hierarchical processing suggestions and giving a targeted processing plan combined with the characteristics of the current scenario, the complexity of fault handling is effectively reduced, and the work efficiency of operation and maintenance personnel is improved.
[0120] In an alternative embodiment, the coverage degree of each suspected root cause node on the affected node group is calculated, and the coverage degree is determined by the comprehensive association strength between nodes; the redundancy between the suspected root cause nodes is evaluated, and the redundancy is obtained by the overlapping ratio of the node influence ranges, including:
[0121] Obtain the comprehensive association strength between the suspected root cause node and each node in the affected node group; construct a network association matrix based on the comprehensive association strength; the rows of the network association matrix represent the suspected root cause nodes, and the columns represent the nodes in the affected node group; set the node weight coefficient according to the alarm level, service importance and resource occupancy rate of each node in the affected node group; use the sigmoid function to normalize the comprehensive association strength in the network association matrix; perform weighted calculation on the normalized comprehensive association strength and the node weight coefficient to obtain the coverage degree of the suspected root cause node on the affected node group;
[0122] Determine the boundary of the influence range of the suspected root cause node based on a preset association strength threshold; extract the set of affected nodes within the influence range for each suspected root cause node, and the normalized comprehensive association strength between the nodes in the set of affected nodes and the suspected root cause node is greater than the association strength threshold; calculate the number of intersection nodes in the influence ranges of any two suspected root cause nodes;
[0123] Take the ratio of the number of intersection nodes to the number of intersection nodes in the influence range as the initial redundancy; calculate the difference in the normalized comprehensive association strength between two suspected root cause nodes on the intersection nodes; set the redundancy correction coefficient according to the difference in the normalized comprehensive association strength; multiply the initial redundancy by the redundancy correction coefficient to obtain the final redundancy between nodes.
[0124] First, obtain the comprehensive association strength between the suspected root cause node and each node in the affected node group. The comprehensive association strength is calculated by the direct association strength and the indirect association strength between nodes. The direct association strength is determined based on the physical connection, call relationship, etc. between nodes, and the indirect association strength is calculated by the transfer relationship between nodes. For example, the direct association strength between node A and node B is 0.8, and the direct association strength between node B and node C is 0.6, then the indirect association strength between node A and node C is 0.48.
[0125] Next, construct a network association matrix, where the rows of the matrix represent the suspected root cause nodes, and the columns represent the nodes in the affected node group. The element value in the matrix is the comprehensive association strength between the corresponding nodes. For example, there are 3 suspected root cause nodes R1, R2, R3, and the affected node group contains 4 nodes N1, N2, N3, N4, then a 3×4 association matrix is constructed.
[0126] Then, set the weight coefficients according to the alarm level, business importance degree, and resource occupancy rate of the affected nodes. The alarm level is divided into three levels: severe, warning, and prompt, with corresponding weights of 0.5, 0.3, and 0.2 respectively. The business importance degree is divided into three levels: core, important, and general, with corresponding weights of 0.5, 0.3, and 0.2. The resource occupancy rate is divided into intervals by percentage. The weight is 0.5 for above 90%, 0.3 for 50% - 90%, and 0.2 for below 50%. Add the weights of the three dimensions to obtain the final weight coefficient of the node.
[0127] Normalize the comprehensive association strength in the association matrix. Use the sigmoid function to map the association strength to the 0 - 1 interval. Multiply the normalized association strength by the node weight coefficient to obtain the coverage degree of the suspected root cause node to the affected node group. The higher the coverage degree, the closer the association between the suspected root cause node and the affected node group.
[0128] Determine the influence range of the suspected root cause node based on a preset association strength threshold (such as 0.6). Extract the set of affected nodes within the influence range of each suspected root cause node, and the normalized comprehensive association strength between these nodes and the suspected root cause node is greater than the threshold. Calculate the number of intersection nodes in the influence ranges of any two suspected root cause nodes. For example, if the influence range of R1 includes N1, N2, N3, and the influence range of R2 includes N2, N3, N4, then the number of intersection nodes is 2.
[0129] Take the ratio of the number of intersection nodes to the number of nodes in the influence range as the initial redundancy. Calculate the difference in the normalized comprehensive association strength of two suspected root cause nodes on the intersection nodes. The greater the difference in the association strength, the greater the difference in the influence degree of the two nodes on the intersection area, and the lower the redundancy. Set the redundancy correction coefficient according to the difference in the association strength. The coefficient is 0.2 for above 0.8, 0.5 for between 0.5 - 0.8, and 0.8 for below 0.5. Multiply the initial redundancy by the correction coefficient to obtain the final redundancy.
[0130] Figure 3 This is a schematic diagram of the redundancy calculation performance under different scenarios of the embodiment of the present invention:
[0131] This figure shows a comparative analysis of the redundancy calculation error based on the correlation strength threshold. The analysis results indicate that as the correlation strength threshold increases from 0.1 to 1.0, the calculation errors of different technical solutions generally show a downward trend. For this technical solution, the initial error in the cross-domain scenario is 0.09 and finally drops to 0.045, a decrease of 50%; in the single-domain scenario, the initial error is 0.04 and finally drops to 0.01, a decrease of 75%. In contrast, for the comparative solution, the initial error in the cross-domain scenario is 0.08 and finally drops to 0.035, a decrease of 56.25%; in the single-domain scenario, the initial error is 0.04 and finally drops to 0.01, a decrease of 75%. The data shows that this technical solution exhibits better performance advantages in the cross-domain scenario. Especially when the correlation strength threshold is relatively low (in the range of 0.1 - 0.4), the calculation error of this technical solution is significantly lower than that of the comparative solution, with an average difference of about 0.01 - 0.015. This fully demonstrates that this technical solution has higher calculation accuracy and stability when dealing with complex cross-domain scenarios. Additionally, the performance of all solutions in the single-domain scenario is similar, all showing good error convergence characteristics, but the error decline curve of this technical solution is smoother, indicating better predictability and robustness. Overall, this technical solution demonstrates superior performance in various scenarios and is particularly suitable for handling complex cross-domain analysis tasks.
[0132] The solution of this application can:
[0133] By calculating the coverage degree of suspected root cause nodes for the affected node group, the correlation between the suspected root cause nodes and the fault scope can be accurately evaluated, and the real fault root cause nodes can be effectively identified. Based on the overlapping ratio of the node influence ranges to evaluate the redundancy between suspected root cause nodes, redundant root cause nodes can be eliminated, improving the accuracy and efficiency of root cause location. The use of multi-dimensional weight coefficients and normalization processing methods makes the calculation of the coverage degree and redundancy more reasonable and scientific, ensuring the reliability of the root cause location result.
[0134] In the second aspect of the embodiments of the present invention,
[0135] Provide an electronic device, including:
[0136] A processor;
[0137] A memory for storing instructions executable by the processor;
[0138] Wherein, the processor is configured to call the instructions stored in the memory to execute the foregoing method.
[0139] In the third aspect of the embodiments of the present invention,
[0140] Provided is a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the foregoing method.
[0141] The present invention may be a method, an apparatus, a system, and / or a computer program product. The computer program product may include a computer-readable storage medium having thereon computer-readable program instructions for performing various aspects of the present invention.
[0142] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A method for processing operation and maintenance alarms based on a knowledge graph-enhanced large model, characterized in that, Including: Collecting device topology information, performance metric information, and processing record information to form multi-source operation and maintenance alarm historical data; performing adaptive hierarchical structured processing on the multi-source operation and maintenance alarm historical data, implementing anomaly detection through time series clustering, completing text standardization using semantic similarity, and extracting alarm propagation link features, device state evolution features, and business dependency relationship features to construct a spatio-temporal semantic multi-dimensional feature matrix; inputting the spatio-temporal semantic multi-dimensional feature matrix into a dynamic weight fusion algorithm to construct a multi-dimensional alarm association network with time series dependency intensity, spatial propagation probability, and business impact degree; Based on the multi-dimensional alarm association network, using an incremental knowledge reasoning method to construct and continuously optimize a hierarchical knowledge graph; Utilizing the hierarchical knowledge graph to achieve dynamic transmission analysis of alarms between different levels; combining the time series evolution characteristics, topology propagation characteristics, and business dependency characteristics of alarms, calculating the dynamic credibility weights of each propagation path through a multi-objective optimization algorithm; based on the dynamic credibility weights, constructing a root cause reasoning rule base with threshold adaptability and impact prediction functions; deeply associating and mapping the root cause reasoning rule base with the hierarchical knowledge graph to form a continuously evolving diagnostic reasoning system; When receiving real-time operation and maintenance alarm information, starting the diagnostic reasoning system to analyze the multi-dimensional propagation link of the alarm, identifying the alarm source node and the affected node group; screening the optimal root cause set from the suspected root cause nodes based on the alarm source node and the affected node group; retrieving similar historical cases through the hierarchical knowledge graph and combining with the current scenario characteristics to generate targeted hierarchical processing suggestions.
2. The method according to claim 1, wherein Inputting the spatio-temporal semantic multi-dimensional feature matrix into a dynamic weight fusion algorithm to construct a multi-dimensional alarm association network with time series dependency intensity, spatial propagation probability, and business impact degree; Based on the multi-dimensional alarm association network, using an incremental knowledge reasoning method to construct and continuously optimize a hierarchical knowledge graph including: Calculating the information gain rate for each dimension feature in the spatio-temporal semantic multi-dimensional feature matrix and evaluating the correlation between features based on mutual information; inputting the information gain rate and the correlation between features into a multi-objective optimizer to generate the dynamic weights of each dimension feature; performing weighted fusion on the spatio-temporal semantic multi-dimensional feature matrix according to the dynamic weights, calculating the feature interaction intensity through a multi-head attention mechanism, capturing the time series evolution pattern using a gated recurrent unit, and modeling the spatial propagation characteristics using a graph neural network; inputting the feature interaction intensity, time series evolution pattern, and spatial propagation characteristics into a multi-task learning framework to jointly optimize and obtain the time series dependency intensity, spatial propagation probability, and business impact degree between alarm entities; Constructing a time series association sub-network based on the time series dependency intensity, a topology association sub-network based on the spatial propagation probability, and a business association sub-network based on the business impact degree; fusing the three sub-networks to form a multi-dimensional alarm association network, calculating the importance distribution of network nodes through a weighted random walk algorithm; using the importance distribution to layer the alarm entities and constructing an initial hierarchical knowledge graph; Based on the initial hierarchical knowledge graph, integrate the expert rule base and statistical learning methods for incremental knowledge reasoning; model the reasoning process as a Markov decision process, and optimize the selection of reasoning paths based on value function approximation and policy gradient methods; transfer the reasoning knowledge in the known scenario to the new scenario through transfer learning methods, and use domain adaptation algorithms to reduce the feature distribution shift; conduct Bayesian evaluation on the credibility of the reasoning results to generate uncertainty quantification indicators; based on the uncertainty quantification indicators, dynamically adjust the feature extraction parameters and weight fusion strategies to achieve the continuous optimization of the knowledge graph.
3. The method according to claim 2, wherein Based on the initial hierarchical knowledge graph, integrate the expert rule base and statistical learning methods for incremental knowledge reasoning; model the reasoning process as a Markov decision process, and optimize the selection of reasoning paths based on value function approximation and policy gradient methods; Transfer the reasoning knowledge in the known scenario to the new scenario through transfer learning methods, and use domain adaptation algorithms to reduce the feature distribution shift, including: Based on the initial hierarchical knowledge graph, extract entity-relationship pairs to generate an expert rule base, and the expert rule base records the reasoning rules and constraint conditions between entities; vectorize the entities and relationships in the knowledge graph, and use statistical learning methods to calculate the relationship probabilities between entity pairs; adaptively and weightedly fuse the expert rule base and the relationship probabilities to construct an incremental knowledge reasoning model, and the weight allocation in the fusion process is based on rule confidence and probability distribution consistency; Model the incremental knowledge reasoning model as a Markov decision process, construct the state space with the current reasoning entity and historical paths, and construct the action space with optional reasoning rules; use a deep neural network to approximate the state value function, and the state value function evaluates the long-term value of the reasoning state; calculate the value function estimation error based on the temporal difference algorithm, and update the network parameters through backpropagation; use the policy gradient method to optimize the selection strategy of reasoning rules, and the selection strategy performs parameter learning based on the cumulative reward maximization criterion; Extract the reasoning patterns from the knowledge graph of the known scenario, and map the reasoning patterns to the new scenario through transfer learning methods; use the domain adaptation algorithm to calculate the feature distribution differences between the source domain and the target domain, and achieve feature distribution alignment by minimizing the maximum mean discrepancy.
4. The method according to claim 1, characterized in that, Use the hierarchical knowledge graph to achieve dynamic transfer analysis of alarms between different levels; combine the temporal evolution characteristics, topological propagation characteristics, and business dependency characteristics of alarms, and calculate the dynamic credibility weights of each propagation path through a multi-objective optimization algorithm, including: Use the hierarchical knowledge graph to achieve dynamic transfer analysis of alarms between different levels. The hierarchical knowledge graph constructs a multi-level structure according to the physical layer, network layer, and business layer; establish alarm transfer rules within the level based on the direct association relationship between nodes; analyze the horizontal transfer paths of the alarm transfer rules within the level and the vertical transfer paths of alarm nodes between levels, and combine the horizontal transfer paths and vertical transfer paths to form an initial set of alarm transfer paths; Extract multi-dimensional features for each transmission path in the initial alarm transmission path set, extract temporal evolution features from the alarm time series; extract topological propagation features from the network topology structure; extract service dependency features from the service call relationship; normalize the temporal evolution features, topological propagation features, and service dependency features and then construct a feature matrix; Input the feature matrix into a multi-objective optimization algorithm, with maximizing temporal correlation, minimizing topological overhead, and minimizing service impact as the optimization objectives; calculate the objective function values of each transmission path in the temporal dimension, topological dimension, and service dimension; obtain the optimal transmission path set based on non-dominated sorting; use an adaptive weight allocation strategy to calculate the dynamic credibility weights of the transmission paths by combining the objective function values of each dimension.
5. The method according to claim 4, characterized in that Input the feature matrix into a multi-objective optimization algorithm, with maximizing temporal correlation, minimizing topological overhead, and minimizing service impact as the optimization objectives; Calculating the objective function values of each transmission path in the temporal dimension, topological dimension, and service dimension includes: Input the standardized feature matrix into a multi-objective optimization algorithm. Set maximizing temporal correlation as the first optimization objective, which is obtained by calculating the time series correlation degree, alarm occurrence order consistency, and propagation delay time of adjacent alarm nodes on the transmission path; set minimizing topological overhead as the second optimization objective, which is obtained by calculating the network hop count, link bandwidth occupancy, and node processing load of the transmission path; set minimizing service impact as the third optimization objective, which is obtained by calculating the service interruption duration, number of affected users, and degree of business loss of the transmission path. Based on the three optimization objectives of the multi-objective optimization algorithm, calculate the objective function value of each transmission path: calculate the objective function value in the temporal dimension according to the first optimization objective, and the objective function value in the temporal dimension is calculated based on the correlation coefficient of the alarm time series, alarm propagation delay, and alarm duration period, and is used to characterize the temporal consistency of alarm transmission; Calculate the objective function value in the topological dimension according to the second optimization objective, and the objective function value in the topological dimension is calculated based on the weighted sum of path hops, link utilization rate, and node load rate, and is used to characterize the network resource consumption of alarm transmission; calculate the objective function value in the service dimension according to the third optimization objective, and the objective function value in the service dimension is calculated based on the business interruption loss, user impact range, and service level agreement violation degree, and is used to characterize the business loss degree of alarm transmission.
6. The method according to claim 1, characterized in that, Screen the optimal root cause set from the suspected root cause nodes based on the alarm source node and the affected node group; retrieve similar historical cases through a hierarchical knowledge graph and combine the current scenario features to generate targeted hierarchical processing suggestions, including: Obtain the characteristic parameters of the alarm source node, including the alarm occurrence time, alarm duration, and alarm severity level; analyze the propagation path of the alarm in the network based on the characteristic parameters, extract the nodes that receive the alarm to construct the affected node group, record the alarm reception time of each node in the affected node group, and sort the nodes in chronological order according to the alarm reception time to generate the initial propagation sequence; Construct a correlation evaluation matrix based on the initial propagation sequence. By calculating the temporal correlation, topological correlation, and service correlation between the alarm source node and each node in the affected node group, obtain the comprehensive correlation strength between nodes. The temporal correlation is calculated based on the time correlation of the alarm sequences between nodes. The topological correlation is calculated based on the network distance between nodes. The service correlation is calculated based on the service call intensity between nodes. Use the correlation evaluation matrix to analyze the influence characteristics of suspected root cause nodes: Calculate the coverage of each suspected root cause node on the affected node group, where the coverage is determined by the comprehensive correlation strength between nodes. Evaluate the redundancy between suspected root cause nodes, where the redundancy is obtained through the overlapping ratio of the node influence ranges. Based on the coverage and redundancy, select the node combination with a coverage higher than the preset coverage threshold and a redundancy lower than the preset redundancy threshold as the optimal root cause set. Match the characteristic information of the optimal root cause set with historical cases, calculate the similarity of root cause attributes, influence range similarity, and processing complexity similarity, and combine the similarity of root cause attributes, influence range similarity, and processing complexity similarity through weighting to obtain a similarity index system. Based on the similarity index system, screen out historical cases with a matching degree higher than the preset similarity threshold. Conduct an adaptability analysis of the screened historical cases with the current scenario characteristics, where the current scenario characteristics include the urgency of the alarm, the degree of business impact, and the resource occupancy status. According to the results of the adaptability analysis, extract effective handling methods and experiences from historical cases. Combine with the positioning results of the optimal root cause set to generate targeted hierarchical handling suggestions.
7. The method according to claim 6, characterized in that Calculate the coverage of each suspected root cause node on the affected node group, where the coverage is determined by the comprehensive correlation strength between nodes. Evaluate the redundancy between suspected root cause nodes, where the redundancy is obtained through the overlapping ratio of the node influence ranges, including: Obtain the comprehensive correlation strength between the suspected root cause nodes and each node in the affected node group. Construct a network correlation matrix based on the comprehensive correlation strength. The rows of the network correlation matrix represent the suspected root cause nodes, and the columns represent the nodes in the affected node group. Set node weight coefficients according to the alarm levels, business importance levels, and resource occupancy rates of the nodes in the affected node group. Use the sigmoid function to normalize the comprehensive correlation strength in the network correlation matrix. Perform weighted calculation on the normalized comprehensive correlation strength and the node weight coefficients to obtain the coverage of the suspected root cause nodes on the affected node group. Determine the boundary of the influence range of the suspected root cause nodes based on the preset correlation strength threshold. For each suspected root cause node, extract the set of affected nodes within its influence range, where the normalized comprehensive correlation strength between the nodes in the affected node set and the suspected root cause node is greater than the correlation strength threshold. Calculate the number of intersection nodes in the influence ranges of any two suspected root cause nodes. Take the ratio of the number of intersection nodes to the number of intersection nodes in the influence scope as the initial redundancy; calculate the normalized comprehensive correlation strength difference between two suspected root cause nodes on the intersection nodes; set a redundancy correction coefficient according to the normalized comprehensive correlation strength difference; multiply the initial redundancy by the redundancy correction coefficient to obtain the final redundancy between nodes.
8. An electronic device, characterized in that, Including: A processor; A memory for storing instructions executable by the processor; Wherein, the processor is configured to call the instructions stored in the memory to execute the method according to any one of claims 1 to 7.
9. A computer-readable storage medium having computer program instructions stored thereon, characterized in that, When the computer program instructions are executed by the processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Internet of Things system
CN116368355A
Network detection method and device, computer equipment, readable storage medium and program product
CN119696995A