Network anomaly diagnosis method and device, computer equipment and storage medium
By dividing and classifying the description text of network exceptions and matching it with the preset knowledge graph, the cause of network exceptions is accurately determined and repaired, the problem of inaccurate diagnosis and repair of network exceptions in the prior art is solved, and network security and stability are improved.
Patent Information
- Application Number
- CN202510005601.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-02
- Publication Date
- 2025-06-03
AI Technical Summary
The prior art is difficult to accurately determine the specific causes of network exceptions and lacks an effective exception repair mechanism, especially in customized scenarios of dedicated networks.
By obtaining the exception description text of network exceptions, text division and classification processing are performed, preset network knowledge graphs are matched to determine the causes of abnormal phenomena and target abnormalities, and repair them according to the causes of abnormalities.
It realizes accurate diagnosis and repair of network exceptions, and improves network security and stability, especially in customized scenarios of dedicated networks.
Smart Images

Figure CN120087359A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a network anomaly diagnosis method, apparatus, computer device, and storage medium. Background Art
[0002] With the development of computer technology, network security has become an increasingly important security issue at present. Network security incidents involve many aspects, such as privacy leakage, paralysis of critical infrastructure, damage to device security, and other security issues. Therefore, it is necessary to diagnose abnormal problems in the network environment to determine the abnormal causes and repair them to enhance network security.
[0003] In the related art, a method based on statistical correlation is used to solve network problems. This method uses the local spatial proximity at the router level and the information extracted from system logs (syslog) and the Simple Network Management Protocol (SNMP) to detect packet loss in the network, thereby realizing the diagnosis of abnormal problems in the network environment.
[0004] However, in the related art, only the relevant parameters of network anomalies can be extracted, such as the specific information in syslog and the mib library of SNMP, and the specific causes of network anomalies cannot be inferred and manual analysis is required. In addition, the related art does not have a perfect anomaly repair mechanism. For example, some routine network repairs can be completed through the Simple Network Management Protocol, but the repair of some anomalies cannot be achieved in the customized scenarios of private networks. Therefore, in the related art, it is impossible to accurately determine the causes of network anomalies and repair the anomalies. Summary of the Invention
[0005] Embodiments of this application provide a network anomaly diagnosis method, apparatus, computer device, and storage medium, which can accurately determine the abnormal causes of network anomalies and repair them.
[0006] To achieve the above object, on the one hand, an embodiment of this application provides a network anomaly diagnosis method, including:
[0007] Obtain the network anomalies to be diagnosed in the network and the abnormal description text corresponding to the network anomalies;
[0008] Perform text partitioning processing on the abnormal description text to obtain a plurality of partitioned texts;
[0009] Perform classification processing on the plurality of partitioned texts to obtain at least one type of classified text;
[0010] Match the at least one type of classified text with a preset network knowledge graph to determine at least one matching abnormal phenomenon;
[0011] Match the abnormal phenomenon with the preset network knowledge graph to determine the target abnormal cause, and repair the network anomaly according to the network anomaly repair strategy corresponding to the target abnormal cause.
[0012] To achieve the above object, on the one hand, an embodiment of the present application provides a network anomaly diagnosis device, including:
[0013] An acquisition module, configured to acquire a network anomaly to be diagnosed in the network and the abnormal description text corresponding to the network anomaly;
[0014] A division module, configured to perform text division processing on the abnormal description text to obtain a plurality of divided texts;
[0015] A classification module, configured to classify the plurality of divided texts to obtain at least one type of classified text;
[0016] A matching module, configured to match the at least one type of classified text with a preset network knowledge graph to determine at least one matching abnormal phenomenon;
[0017] A determination module, configured to match the abnormal phenomenon with the preset network knowledge graph to determine the target abnormal cause, and repair the network anomaly according to the network anomaly repair strategy corresponding to the target abnormal cause.
[0018] In some embodiments, the network anomaly diagnosis device further includes a construction module, configured to:
[0019] Before matching the at least one type of classified text with a preset network knowledge graph to determine a plurality of matching abnormal phenomena, acquire the original network fault data collected in the network, and perform data parsing on the original network fault data to determine a plurality of types of sub-data;
[0020] Determine each type of sub-data as a node, and create a plurality of triples according to the association relationships between different nodes;
[0021] Construct a preset network knowledge graph based on the plurality of triples.
[0022] In some embodiments, the construction module is configured to:
[0023] Classify the original network fault data to obtain fault cause data, fault phenomenon data, and fault solution data;
[0024] Classify the fault cause data, the fault phenomenon data, and the fault solution data to obtain sub-data of multiple types, where the sub-data at least includes device type sub-data, execution operation sub-data, fault cause sub-data, fault location sub-data, fault warning sub-data, and fault phenomenon sub-data.
[0025] In some embodiments, a partitioning module is used for:
[0026] Perform word segmentation on the abnormal description text to obtain multiple segmented text;
[0027] Perform stop word filtering on the multiple segmented text to obtain multiple partitioned text;
[0028] A classification module is used for:
[0029] Input the multiple partitioned text into a pre-trained text classification model, and output device type classification text, execution operation classification text, and fault phenomenon classification text.
[0030] In some embodiments, a matching module is used for:
[0031] Determine the abnormal operation description content corresponding to each abnormal operation type in the preset network knowledge graph;
[0032] Calculate the similarity between the abnormal operation description content and the execution operation classification text to obtain a similarity calculation result;
[0033] Determine the abnormal operation type corresponding to the abnormal operation description content with the similarity calculation result greater than the preset similarity threshold as the target abnormal operation type;
[0034] Match the target abnormal operation type with the preset network knowledge graph to determine a first set of abnormal phenomena.
[0035] In some embodiments, a matching module is used for:
[0036] Determine the target knowledge data corresponding to the device type classification text in the preset network knowledge graph according to the device type classification text;
[0037] Classify the fault phenomenon classification text to obtain an abnormal location text and an abnormal warning text;
[0038] Match the abnormal location text with the target knowledge data to obtain a second set of abnormal phenomena;
[0039] Match the abnormal warning text with the target knowledge data to obtain a third set of abnormal phenomena.
[0040] In some embodiments, a determination module is configured to:
[0041] Perform a union operation on the first abnormal phenomenon set, the second abnormal phenomenon set, and the third abnormal phenomenon set to obtain a target abnormal phenomenon set;
[0042] Match each abnormal phenomenon in the target abnormal phenomenon set with the preset network knowledge graph to determine a target abnormal cause.
[0043] In some embodiments, a determination module is configured to:
[0044] When the number of abnormal phenomena is multiple, match each abnormal phenomenon with the preset network knowledge graph to obtain a matching abnormal cause;
[0045] Determine candidate abnormal causes and the occurrence times of each candidate abnormal cause according to the abnormal causes corresponding to each abnormal phenomenon;
[0046] Divide the occurrence times of each candidate abnormal cause by the number of abnormal phenomena to obtain the matching probability of each candidate abnormal cause;
[0047] Sort the candidate abnormal causes from high to low according to the matching probability to obtain a sorting result, and determine a target abnormal cause whose sorting is higher than a preset sorting position according to the sorting result.
[0048] To achieve the above object, an embodiment of the present application provides a computer-readable storage medium. The computer-readable storage medium stores multiple instructions, and the instructions are suitable for being loaded by a processor to execute the network anomaly diagnosis method provided by the embodiment of the present application.
[0049] To achieve the above object, an embodiment of the present application provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the network anomaly diagnosis method provided by the embodiment of the present application is implemented.
[0050] In the embodiments of the present application, by obtaining network anomalies that need to be diagnosed in the network and the corresponding anomaly description texts of the network anomalies; performing text partitioning processing on the anomaly description texts to obtain multiple partitioned texts; performing classification processing on the multiple partitioned texts to obtain at least one type of classified text; matching the at least one type of classified text with a preset network knowledge graph to determine at least one matching anomaly phenomenon; matching the anomaly phenomenon with the preset network knowledge graph to determine the target anomaly cause, and repairing the network anomaly according to the network anomaly repair strategy corresponding to the target anomaly cause. In this way, by dividing the anomaly description text of the network anomaly into multiple partitioned texts, and then classifying the partitioned texts into multiple classified texts, different types of classified texts are used to match the preset network knowledge graph to determine the matching anomaly phenomena from different perspectives, so as to improve the comprehensiveness of the evaluation of the anomaly phenomena of the network anomaly. By matching each anomaly phenomenon with the preset network knowledge graph, based on the matching situation of each anomaly phenomenon and the preset network knowledge graph, the target anomaly cause of the network anomaly is accurately determined, realizing the accurate diagnosis of the network anomaly. Finally, the network anomaly is repaired according to the network anomaly repair strategy corresponding to the target anomaly cause, realizing the repair of the network anomaly. Therefore, compared with the related art in which network anomalies in the network are diagnosed through logs and protocols, in the present application, the classified texts of the anomaly description text can be used to match the preset network knowledge graph from multiple perspectives, so that the target anomaly cause corresponding to the network anomaly can be more accurately determined and repaired.
[0051] Other features and advantages of the present application will be described in the following specification, and part of them will become obvious from the specification, or be understood by implementing the present application. The objectives and other advantages of the present application can be achieved and obtained through the structures specifically pointed out in the specification, claims and drawings. Brief Description of the Drawings
[0052] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those skilled in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0053] Figure 1 It is a schematic diagram of the system framework corresponding to the network anomaly diagnosis method provided by the embodiments of the present application;
[0054] Figure 2 It is a schematic diagram of the scenario of the network anomaly diagnosis method provided by the embodiments of the present application;
[0055] Figure 3It is a schematic flowchart of the network anomaly diagnosis method provided by an embodiment of the present application;
[0056] Figure 4 It is another schematic flowchart of the network anomaly diagnosis method provided by an embodiment of the present application;
[0057] Figure 5 Schematic structural diagram of the network anomaly diagnosis device provided by an embodiment of the present application;
[0058] Figure 6 It is a schematic structural diagram of a computer device provided by an embodiment of the present application. Detailed implementation manners
[0059] In order to enable those skilled in the art to better understand the solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts shall fall within the protection scope of the present application.
[0060] It can be understood that in the specific implementation manners of the present application, data related to anomaly description texts, network failures, etc. are involved. When the above embodiments of the present application are applied to specific products or technologies, user permission or consent needs to be obtained, and the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards.
[0061] It should be noted that in some processes described in the specification, claims, and the above drawings, there are multiple steps that appear in a specific order. However, it should be clearly understood that these steps may not be executed in the order in which they appear in this document or may be executed in parallel. The step numbers are only used to distinguish different steps, and the numbers themselves do not represent any execution order. In addition, descriptions such as "first", "second", or "target" in this document are used to distinguish similar objects and do not necessarily need to describe a specific order or sequence.
[0062] This application can be used in numerous general-purpose or special-purpose computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer computing devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This application can also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0063] Before further elaborating on the embodiments of this application, the nouns and terms involved in the embodiments of this application are explained. The nouns and terms involved in the embodiments of this application are applicable to the following explanations:
[0064] A Knowledge Graph (KG) is a structured knowledge base, which is essentially a labeled directed graph. Each node in the graph represents an entity, and each edge represents a relationship, represented by a standard triple (s, r, o), where s and o are the head entity and the tail entity respectively, and r is the relationship between s and o. Knowledge Graphs are widely used in many scenarios, such as semantic search, intelligent question answering, and decision-making assistance. However, although the creation and maintenance of Knowledge Graphs require a lot of costs, even the largest Knowledge Graphs face problems such as data sparsity and data missing. Therefore, in order to make the Knowledge Graph more complete and accurate, it must be continuously expanded and improved to continuously build the Knowledge Graph model. It should be noted that the initial text in the embodiments of this application can query the corresponding entity in a pre-set Knowledge Graph.
[0065] The basic forms of triples mainly include Entity 1, Relationship, Entity 2, and Concept, Attribute, Attribute Value, etc. Entities are the most basic elements in a Knowledge Graph, and there are different relationships between different entities. Concepts mainly refer to sets, categories, object types, types of things, such as people, geography, etc.; Attributes mainly refer to the attributes, characteristics, features, traits, and parameters that an object may have, such as nationality, birthday, etc.; Attribute Values mainly refer to the values of the specified attributes of an object, such as China, 1988-09-08, etc. Each entity (the extension of a concept) can be identified by a globally unique determined ID, each attribute-attribute value pair (AVP) can be used to describe the internal characteristics of an entity, and relationships can be used to connect two entities and describe the association between them.
[0066] A Smart Mobile Router (SMR) is a router with mobility. It can flexibly switch in different network environments to ensure the stability of network connections.
[0067] A Smart Aggregation Router (SAR) is a router that can aggregate multiple network connections. It can integrate multiple network links together to provide a faster and more stable network service.
[0068] A Client is a machine that accesses information from others on the network. The client part is specific to the object, responsible for executing foreground functions and interacting with the object, and can be understood as a sending device in this application.
[0069] A Server is a machine that provides information for people to access. The server part is information and functions shared by multiple objects, executing background services, and can be understood as a receiving device in this application.
[0070] The Internet refers to the world's largest computer network, composed of many local area networks and wide area networks, and uses the TCP / IP protocol for communication. The Internet connects computers globally, enabling them to communicate and exchange information with each other. The development of the Internet has brought great changes to people's lives and work, and has also greatly promoted the development of information technology.
[0071] First, introduce the technical problems existing in the related technologies:
[0072] With the development of computer technology, network security has become an increasingly important security issue. Network security incidents involve many aspects, such as privacy leakage, paralysis of critical infrastructure, damage to device security, and other security problems. Therefore, it is necessary to diagnose abnormal problems in the network environment to determine the abnormal reasons and repair them to enhance network security.
[0073] In the related technologies, a method based on statistical correlation is used to solve network problems. This method uses the local spatial proximity at the router level and the information extracted from system logs (syslog) and the Simple Network Management Protocol (SNMP) to detect packet loss in the network, thereby realizing the diagnosis of abnormal problems in the network environment.
[0074] However, in the related art, only relevant parameters of network anomalies can be extracted, such as specific information in syslog and the MIB library of SNMP. It is impossible to infer the specific reasons for network anomalies and manual analysis is required. In addition, the related art does not have a perfect anomaly repair mechanism. For example, some routine network repairs can be completed through the Simple Network Management Protocol, but the repair of some anomalies cannot be achieved in the customized scenarios of private networks. Therefore, in the related art, there are problems in accurately determining the reasons for network anomalies and repairing anomalies.
[0075] To solve this technical problem, the embodiments of the present application provide a network anomaly diagnosis method, device, computer device, and storage medium. By matching the classification text of the anomaly description text with the preset network knowledge graph from multiple perspectives, it is possible to more accurately determine the target anomaly reason corresponding to the network anomaly and repair the target anomaly reason. In the following text, the network anomaly diagnosis method, device, computer device, and storage medium provided by the embodiments of the present application will be described in detail.
[0076] Please refer to Figure 1 , Figure 1 which is a schematic diagram of the system framework corresponding to the network anomaly diagnosis method provided by the embodiments of the present application. The network anomaly diagnosis method provided by the embodiments of the present application can be applied to this system framework.
[0077] Specifically, please refer to Figure 1 , Figure 1 which is the system architecture diagram to which the network anomaly diagnosis method provided by the embodiments of the present application is applied. It includes a terminal 140, the Internet 130, network devices 120, a server 110, etc.
[0078] The terminal 140, network devices 120, and server 110 can all be devices that execute the network anomaly diagnosis method.
[0079] The terminal 140 includes, but is not limited to, mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle-mounted terminals, aircraft, etc. The embodiments of the present application can be applied to various scenarios, including but not limited to cloud office, enterprise management, etc. In addition, it can be a single device or a collection of multiple devices combined. For example, multiple desktop computers are connected to each other through a local area network and share a monitor, etc. to work collaboratively, jointly constituting a terminal 140. The terminal 140 can communicate with the Internet 130 in a wired or wireless manner to exchange data.
[0080] Server 110 refers to a computer system that can provide certain services to terminal 140. Compared with ordinary terminal 140, server 110 has higher requirements in terms of stability, security, performance, etc. Server 110 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, as well as big data and artificial intelligence platforms.
[0081] The message sent by terminal 140 to server 110 needs to be sent to the corresponding server 110 through network device 120. The message sent by server 110 to terminal 140 also needs to be sent to the corresponding terminal 140 through network device 120. Network device 120 can be an intelligent mobile router.
[0082] Specifically, network device 120 can also be a gateway. A gateway is also called an internetwork connector and protocol converter. A gateway realizes network interconnection at the transport layer and is a computer system or device that acts as a converter. Between two systems using different communication protocols, data formats or languages, and even completely different architectures, a gateway is a translator. At the same time, a gateway can also provide filtering and security functions.
[0083] The network anomaly diagnosis method in the embodiments of the present application can be applied to various scenarios, such as network security scenarios. The scenarios to which the network anomaly diagnosis method in the present application is applied are not limited herein.
[0084] Please refer to Figure 2 , Figure 2 which is a schematic diagram of the scenario of the network anomaly diagnosis method provided by the embodiments of the present application.
[0085] As Figure 2 shown, there are intelligent mobile routers and intelligent aggregation routers in some private networks.
[0086] In the embodiments of the present application, the intelligent aggregation router can obtain the network anomalies to be diagnosed in the network and the anomaly description text corresponding to the network anomalies; perform text partitioning processing on the anomaly description text to obtain multiple partition texts; perform classification processing on the multiple partition texts to obtain at least one type of classification text; match the at least one type of classification text with a preset network knowledge graph to determine at least one matching anomaly phenomenon; match the anomaly phenomenon with the preset network knowledge graph to determine the target anomaly cause, and repair the network anomaly according to the network anomaly repair strategy corresponding to the target anomaly cause.
[0087] In some embodiments, the intelligent aggregation router may be the main device that executes the network anomaly diagnosis method in the embodiments of the present application, mainly providing the function of anomaly diagnosis, and sending the determined target anomaly cause of the network anomaly and the network anomaly repair strategy corresponding to the target anomaly cause to the intelligent mobile router to repair the network anomaly. The intelligent mobile router may be a device for repairing network anomalies.
[0088] In some embodiments, the intelligent aggregation router may directly determine the target anomaly cause of the network anomaly and the network anomaly repair strategy corresponding to the target anomaly cause, and attempt to repair the network anomaly through the network anomaly repair strategy corresponding to the target anomaly cause.
[0089] The network anomaly diagnosis method provided in the present application will be described in detail below.
[0090] Please refer to Figure 3 , Figure 3 which is a schematic flowchart of network anomaly diagnosis provided by the embodiments of the present application. The network anomaly diagnosis method may include the following steps:
[0091] Step 210: Obtain the network anomaly to be diagnosed in the network and the anomaly description text corresponding to the network anomaly;
[0092] Step 220: Perform text partitioning processing on the anomaly description text to obtain multiple partitioned texts;
[0093] Step 230: Perform classification processing on the multiple partitioned texts to obtain at least one type of classified text;
[0094] Step 240: Match at least one type of classified text with a preset network knowledge graph to determine at least one matching anomaly phenomenon;
[0095] Step 250: Match the anomaly phenomenon with the preset network knowledge graph to determine the target anomaly cause, and repair the network anomaly according to the network anomaly repair strategy corresponding to the target anomaly cause.
[0096] The steps 210 to 250 will be described in detail below. The execution subject of this network anomaly diagnosis method may be a computer device, such as an intelligent aggregation router, a terminal, or a server.
[0097] In step 210, obtain the network anomaly to be diagnosed in the network and the anomaly description text corresponding to the network anomaly.
[0098] During the operation of the network, due to the complex network connections between different devices, network anomalies are likely to occur between different devices, such as various network anomalies like inability to access the Internet, network lag, abnormal page loading, network traffic hijacking, network information theft, etc. These network anomalies may be caused by hardware, software, external network attacks, or unstable internal networks. Therefore, for a network anomaly, it may be caused by multiple reasons.
[0099] In this application, a computer device can obtain the network anomalies to be diagnosed in the network and the corresponding anomaly description text. The anomaly description text contains relevant descriptions of the network anomaly phenomenon. The anomaly description text can be manually input text or can be an anomaly description text actively generated by other devices based on their own network anomaly situations through system logs. For example, the anomaly description text is: When the network device is transmitting data, the network latency increases significantly. Operations that originally only took a few milliseconds to complete, such as web page loading and file downloading, have a latency time soar to hundreds of milliseconds or even seconds, and it may be necessary to restart the network device.
[0100] Another example is that the anomaly description text is: Frequently encounter problems where the client device loses connection to the network. Whether connected by wired or wireless means, there have been sudden disconnections.
[0101] Another example is that the anomaly description text is: A large number of data packet loss phenomena occur. When sending and receiving network data packets, many data packets are lost during the transmission process, resulting in incomplete data transmission.
[0102] That is to say, the anomaly description text contains a text description of the network anomaly, which can include the fault phenomenon, the fault cause, and a temporarily determined fault solution.
[0103] In step 220, the anomaly description text is processed by text partitioning to obtain multiple partitioned texts.
[0104] Among them, the anomaly description text belongs to a long text, and it is necessary to partition the text content therein to obtain multiple partitioned texts, and then parse the anomaly description text through the multiple partitioned texts, which can improve the speed and accuracy of parsing the anomaly description text. During the process of partitioning the anomaly description text, various methods such as word segmentation processing, filtering processing, and regular expression splitting can be used to implement the text partitioning processing of the anomaly description text, so as to obtain multiple partitioned texts.
[0105] In some embodiments, processing the anomaly description text by text partitioning to obtain multiple partitioned texts includes:
[0106] (1.1) Tokenize the abnormal description text to obtain multiple tokenized texts;
[0107] (1.2) Filter out stop words from the multiple tokenized texts to obtain multiple segmented texts.
[0108] For example, first construct a network vocabulary. Collect professional terms in the network field, such as "router", "switch", "firewall", "IP address", "subnet mask", "gateway", "DNS server", "Wi-Fi", "Ethernet", "bandwidth", "delay", "packet loss", "port", etc.
[0109] Then determine the delimiters. In the abnormal description text of network anomalies, words such as "unable", "cannot", "error", "abnormal", "fault", "interrupt" and punctuation marks (such as commas, periods, semicolons) can usually be used as delimiter signs. For example, for the text "Network connection interrupted, unable to access external websites, IP address acquisition failed", it can be divided into "Network connection", "interrupted", "unable to access", "external websites", "IP address", "acquisition failed" according to these delimiters and words.
[0110] Finally, perform entry matching according to the longest matching principle. When a word can match multiple entries in the network vocabulary, tokenize it in the longest matching way. For example, for "Ethernet interface fault", preferentially match the longer term "Ethernet interface", and then divide out "fault". Through this method, multiple tokenized texts can be matched.
[0111] Another example is to assist with part-of-speech tagging first. Perform part-of-speech tagging on the words in the text. Common parts of speech in network anomaly descriptions include nouns (such as device names, network protocols, etc.), verbs (such as connect, send, receive, etc.), and adjectives (such as normal, abnormal, stable, unstable, etc.). For example, for "Network signal is very weak", after part-of-speech tagging, it can be determined that "Network signal" (noun phrase), "very" (adverb), "weak" (adjective), and then these words can be divided out.
[0112] Then tokenize according to the network architecture and process rules. Understanding the basic network architecture and data transmission process helps with tokenization. For example, when describing network communication failures, tokenization can be performed according to the "client-server" communication model. For "The client is unable to send data to the server", it can be divided into "client", "unable", "to", "server", "send", "data". Through this method, multiple segmented texts can be divided out.
[0113] For another example, by using a pre-trained word embedding model (such as a model fine-tuned on network domain texts by Word2Vec or Bert), each word or character in the network anomaly description text is converted into a vector representation. Different-sized convolutional kernels slide over the text vector sequence to extract local features. For some fixed phrases in the network anomaly description, such as "network congestion" and "Wi-Fi disconnection", the convolutional layer can learn the corresponding feature patterns of these phrases. The pooling layer is used to compress the features after convolution, and then classification is performed through a fully connected layer to determine whether each position is the boundary of a word, and finally the segmented text is output.
[0114] After obtaining multiple segmented texts, the multiple segmented texts can be processed by stop word filtering to obtain multiple segmented texts. For example, some words without practical meaning can be filtered out, such as words like "very", "of", and "between", so as to obtain multiple segmented texts.
[0115] The advantage of doing this is that some useless texts can be deleted and long texts can be segmented, thereby improving the efficiency of subsequent text classification processing.
[0116] In step 230, the multiple segmented texts are classified to obtain at least one type of classified text.
[0117] Among them, the multiple segmented texts can be classified into different types such as device type, execution operation, and fault phenomenon. There is a certain number of classified texts corresponding to each type.
[0118] In some embodiments, classifying the multiple segmented texts to obtain at least one type of classified text includes:
[0119] Inputting the multiple segmented texts into a pre-trained text classification model, and outputting device type classified text, execution operation classified text, and fault phenomenon classified text.
[0120] Specifically, a pre-trained word embedding model (such as a model pre-trained by Word2Vec applied to network domain texts, or directly using a general model such as Bert) can be used to convert each word in the segmented text into a vector representation of a fixed dimension. For example, the word "router" becomes a vector of, say, 300 dimensions after word embedding, and then the word vectors of the entire segmented text are integrated into a vector representation of the segmented text through a suitable method (such as average pooling) for subsequent input into a deep learning model.
[0121] Then, input the word vectors of each segmented text into a pre-trained text classification model, and the model can output the device type, operation performed, or category of fault phenomenon to which it belongs, generating corresponding classification text. For example, in the classification text, the classification text corresponding to the device type is: Zhirong mobile router. The classification text corresponding to the operation performed is: After powering on and starting up. The classification text corresponding to the fault phenomenon is: The dialing program fails to start.
[0122] Also, for example, the classification text corresponding to the device type is: 2U device. The classification text corresponding to the operation performed is: After restarting. The classification text corresponding to the fault phenomenon is: The IP tunnel is not accessible.
[0123] In some embodiments, before step 240, that is, before matching at least one type of classification text with a preset network knowledge graph to determine multiple matching abnormal phenomena, it further includes:
[0124] (1.1) Obtain the original network fault data collected in the network, and perform data parsing on the original network fault data to determine multiple types of sub-data;
[0125] (1.2) Determine each type of sub-data as a node, and create multiple triples according to the association relationships between different nodes;
[0126] (1.3) Construct a preset network knowledge graph based on the multiple triples.
[0127] Among them, various network faults will occur in the network, and the original network fault data corresponding to these network faults can be obtained. These original network fault data can be understood as the historical network fault data collected. Then, perform data parsing on the original network fault data to determine multiple types of sub-data. For example, the sub-data at least includes sub-data of device type, sub-data of operation performed, sub-data of fault cause, sub-data of fault location, sub-data of fault alarm, and sub-data of fault phenomenon.
[0128] After obtaining the sub-data of each type, these sub-data can be labeled. For example, label them in the form of numbers, and each sub-data corresponds to a corresponding number. Then, generate the labeled data in a specified file format, such as data in Json, CSV, etc. formats. The data in these specified file formats are semi-structured data.
[0129] In a knowledge graph, nodes are the basic components of the knowledge graph, used to represent various entities or concepts. Each type of sub-data can be used as a node in the preset network knowledge graph, and then the association relationships between nodes are created. Based on the association relationships, multiple triples are created. Triples are the basic building blocks of the knowledge graph, and the preset network knowledge graph is constructed based on multiple triples.
[0130] For example, the association relationships between nodes can be expressed as: (Abnormal operation)-[Causes]->(Abnormal phenomenon), (Abnormal phenomenon)-[Alarm information]->(Abnormal alarm), (Abnormal phenomenon)-[Abnormal part]->(Phenomenon part), (Abnormal phenomenon)-[Direct / indirect cause]->(Abnormal cause), (Abnormal phenomenon)-[Related]->(Abnormal phenomenon), etc. Multiple triples can be created based on these association relationships.
[0131] Each node corresponds to semi-structured data, and each node corresponds to sub-data under the relevant type. There are association relationships between nodes. Therefore, the preset network knowledge graph can be constructed through semi-structured data, sub-data, and association relationships.
[0132] In some embodiments, the original network fault data is parsed to determine multiple types of sub-data, including:
[0133] (1.1.1) Classify the original network fault data to obtain fault cause data, fault phenomenon data, and fault solution data;
[0134] (1.1.2) Classify the fault cause data, fault phenomenon data, and fault solution data to obtain multiple types of sub-data. The sub-data at least includes device type sub-data, execution operation sub-data, fault cause sub-data, fault part sub-data, fault alarm sub-data, and fault phenomenon sub-data.
[0135] Among them, the original network fault data is classified to obtain fault cause data, fault phenomenon data, and fault solution data. For example, a pre-trained semantic analysis model can be used to input the original network fault data into the pre-trained semantic analysis model, so as to output the fault cause data, fault phenomenon data, and fault solution data corresponding to the three major types of fault cause, fault phenomenon, and fault solution respectively.
[0136] Then, classify the fault cause data, fault phenomenon data, and fault solution data to obtain sub-data of multiple types. The sub-data includes at least equipment type sub-data, execution operation sub-data, fault cause sub-data, fault location sub-data, fault alarm sub-data, and fault phenomenon sub-data. For example, use methods such as deep learning classifiers and regular pattern matching to split the fault cause data, fault phenomenon data, and fault solution data into equipment type sub-data, execution operation sub-data, fault cause sub-data, fault location sub-data, fault alarm sub-data, and fault phenomenon sub-data, and save them by classification.
[0137] After obtaining the sub-data of each type, these sub-data can be labeled. For example, label them in the form of numbers, and each sub-data corresponds to a corresponding number. Then, generate the labeled data in a specified file format, such as data in Json, CSV, etc. formats. The data in these specified file formats is semi-structured data.
[0138] The advantage of doing this is that more nodes can be generated from the perspective of multiple sub-data, and richer node relationships can be established, so that the knowledge contained in the preset network knowledge graph is more abundant, providing a more reliable theoretical support basis for subsequent search for relevant knowledge.
[0139] In step 240, match at least one type of classified text with the preset network knowledge graph to determine at least one matching abnormal phenomenon.
[0140] Among them, each type of classified text can be matched with the preset network knowledge graph. For example, determine the most similar node corresponding to the classified text in the preset network knowledge graph, and then determine the matching abnormal phenomenon (i.e., fault phenomenon) corresponding to the classified text according to the association relationship between the most similar node and other nodes.
[0141] In some embodiments, matching at least one type of classified text with the preset network knowledge graph to determine at least one matching abnormal phenomenon includes:
[0142] (1.1) Determine the abnormal operation description content corresponding to each abnormal operation type in the preset network knowledge graph;
[0143] (1.2) Calculate the similarity between the abnormal operation description content and the execution operation classified text to obtain the similarity calculation result;
[0144] (1.3) Determine the abnormal operation type corresponding to the abnormal operation description content with the similarity calculation result greater than the preset similarity threshold as the target abnormal operation type;
[0145] (1.4) Match the target abnormal operation type with the preset network knowledge graph to determine the first set of abnormal phenomena.
[0146] Among them, determine the abnormal operation description content corresponding to each abnormal operation type in the preset network knowledge graph. For example, determine the target node corresponding to the abnormal operation type in the preset network knowledge graph, then determine the semi-structured data corresponding to the target node, and then parse the semi-structured data to determine the abnormal operation description content corresponding to each abnormal operation type.
[0147] Then calculate the similarity between the abnormal operation description content and the execution operation classification text to obtain the similarity calculation result. For example, determine the first vector corresponding to each abnormal operation description content, determine the second vector corresponding to each execution operation classification text, calculate the cosine distance between each pair of the first vector and the second vector, and finally determine the similarity calculation result between the abnormal operation description content and the execution operation classification text according to the cosine distance.
[0148] Next, determine the abnormal operation type corresponding to the abnormal operation description content with a similarity calculation result greater than the preset similarity threshold as the target abnormal operation type. Then, according to the node relationship of (abnormal operation)-[causes]->(abnormal phenomenon) in the preset network knowledge graph, match the target abnormal operation type with the preset network knowledge graph to determine multiple first abnormal phenomena, and generate the first set of abnormal phenomena according to the multiple first abnormal phenomena.
[0149] The advantage of doing this is that the abnormal phenomena corresponding to network anomalies can be determined from the perspective of abnormal operations.
[0150] In some embodiments, match at least one type of classification text with the preset network knowledge graph to determine at least one matching abnormal phenomenon, including:
[0151] (2.1) Determine the target knowledge data corresponding to the device type classification text in the preset network knowledge graph according to the device type classification text;
[0152] (2.2) Classify the fault phenomenon classification text to obtain the abnormal part text and the abnormal alarm text;
[0153] (2.3) Match the abnormal part text with the target knowledge data to obtain the second set of abnormal phenomena;
[0154] (2.4) Match the abnormal alarm text with the target knowledge data to obtain the third set of abnormal phenomena.
[0155] Among them, the target knowledge data corresponding to the device type classification text can be determined in the preset network knowledge graph according to the device type classification text first. For example, if the device indicated by the device type classification text is a smart mobile router, then all the data associated with the node corresponding to the smart mobile router can be determined in the preset network knowledge graph, and these data are determined as the target knowledge data. The target knowledge data can be understood as a part of the data in the preset network knowledge graph, and this part of the data is related to the device type classification text.
[0156] Then, classify the fault phenomenon classification text to obtain the abnormal part text and the abnormal alarm text, and then match the abnormal part text with the target knowledge data to obtain the second abnormal phenomenon set. For example, through the node relationship of (abnormal phenomenon)-[abnormal part]-(phenomenon part), the abnormal part text and the target knowledge data are matched, and multiple second abnormal phenomena can be determined. The multiple second abnormal phenomena form the second abnormal phenomenon set.
[0157] Match the abnormal alarm text with the target knowledge data to obtain the third abnormal phenomenon set. For example, through the node relationship of (abnormal phenomenon)-[alarm information]-(abnormal alarm), the abnormal alarm text and the target knowledge data are matched, and multiple third abnormal phenomena can be determined. The multiple third abnormal phenomena form the third abnormal phenomenon set.
[0158] The advantage of doing this is that the target knowledge data can be limited in the preset network knowledge graph according to the device type, and then in the target knowledge data, the corresponding abnormal phenomena can be determined as much as possible from the two perspectives of the abnormal alarm text and the abnormal part text. The richness of the determined abnormal phenomena can be improved.
[0159] In step 250, match the abnormal phenomena with the preset network knowledge graph to determine the target abnormal cause, and repair the network anomaly according to the network anomaly repair strategy corresponding to the target abnormal cause.
[0160] Among them, each abnormal phenomenon can be matched with the preset network knowledge graph to determine multiple matched abnormal causes, then determine the target abnormal cause among the multiple abnormal causes, and finally repair the network anomaly according to the network anomaly repair strategy corresponding to the target abnormal cause.
[0161] In some embodiments, matching the abnormal phenomena with the preset network knowledge graph to determine the target abnormal cause includes:
[0162] (1.1) Perform a union operation on the first abnormal phenomenon set, the second abnormal phenomenon set, and the third abnormal phenomenon set to obtain the target abnormal phenomenon set;
[0163] (1.2)Match each abnormal phenomenon in the target abnormal phenomenon set with the preset network knowledge graph to determine the target abnormal cause.
[0164] Among them, the first abnormal phenomenon set, the second abnormal phenomenon set, and the third abnormal phenomenon set can be combined, and some duplicate abnormal phenomena can be deleted to obtain the target abnormal phenomenon set.
[0165] Then, according to the node relationship of (abnormal phenomenon)-[direct / indirect cause]->(abnormal cause), match each abnormal phenomenon in the target abnormal phenomenon set with the preset network knowledge graph to determine the abnormal cause matched by each abnormal phenomenon, and then determine the target abnormal cause from multiple abnormal causes.
[0166] The advantage of doing this is that all abnormal causes of network anomalies can be determined, thus realizing a more comprehensive diagnosis of network anomalies.
[0167] In some embodiments, matching the abnormal phenomenon with the preset network knowledge graph to determine the target abnormal cause includes:
[0168] (2.1)When the number of abnormal phenomena is multiple, match each abnormal phenomenon with the preset network knowledge graph to obtain the matched abnormal cause;
[0169] (2.2)Determine the candidate abnormal causes and the occurrence times of each candidate abnormal cause according to the abnormal cause corresponding to each abnormal phenomenon;
[0170] (2.3)Divide the occurrence times of each candidate abnormal cause by the number of abnormal phenomena to obtain the fit probability of each candidate abnormal cause;
[0171] (2.4)Sort each candidate abnormal cause from high to low according to the fit probability to obtain the sorting result, and determine the target abnormal cause whose sorting is higher than the preset sorting position according to the sorting result.
[0172] Among them, when the number of abnormal phenomena is multiple, match each abnormal phenomenon with the preset network knowledge graph to obtain the matched abnormal cause.
[0173] Then, determine the candidate abnormal causes and the occurrence times of each candidate abnormal cause according to the abnormal cause corresponding to each abnormal phenomenon. For example, all types of abnormal causes can be determined first. The abnormal cause corresponding to abnormal phenomenon A is abnormal cause a1, and the abnormal cause corresponding to abnormal phenomenon B is also abnormal cause a1. Then the occurrence times corresponding to abnormal cause a1 is two, and abnormal cause a1 is a candidate abnormal cause.
[0174] Similarly, the occurrence times corresponding to each candidate abnormal cause can be determined in this way. Finally, the occurrence times of each candidate abnormal cause are divided by the number of abnormal phenomena to obtain the fitting probability of each candidate abnormal cause. For example, if the abnormal cause a1 appears 10 times and the number of abnormal phenomena is 100 times, then the fitting probability corresponding to the abnormal cause a1 is 10%.
[0175] Finally, sort each candidate abnormal cause from high to low according to the fitting probability to obtain the sorting result, and determine the target abnormal cause whose sorting is higher than the preset sorting position according to the sorting result. For example, the first five candidate abnormal causes with the highest sorting can be selected as the target abnormal causes.
[0176] The advantage of doing this is that all abnormal causes of network anomalies can be determined as much as possible, and some target abnormal causes with higher fitting probabilities are used as the main inducements for network anomalies. Finally, the network anomaly repair strategies corresponding to each target abnormal cause can be determined from high to low according to the fitting probability.
[0177] First, try to repair the network anomaly with the network anomaly repair strategy corresponding to the target abnormal cause with the highest fitting probability. If the repair is successful, then do not try the network anomaly repair strategies corresponding to the subsequent target abnormal causes. If the repair is not successful, then try to repair the network anomaly with the network anomaly repair strategy corresponding to the next target abnormal cause in the sorting. Finally, the repair of the network anomaly is achieved.
[0178] In an embodiment of the present application, by obtaining network anomalies to be diagnosed in a network and the corresponding anomaly description text of the network anomalies; performing text partitioning processing on the anomaly description text to obtain multiple partitioned texts; performing classification processing on the multiple partitioned texts to obtain at least one type of classified text; matching the at least one type of classified text with a preset network knowledge graph to determine at least one matching anomaly phenomenon; matching the anomaly phenomenon with the preset network knowledge graph to determine a target anomaly cause, and repairing the network anomaly according to the network anomaly repair strategy corresponding to the target anomaly cause. In this way, by dividing the anomaly description text of the network anomaly into multiple partitioned texts, and then classifying the partitioned texts into multiple classified texts, using different types of classified texts to match the preset network knowledge graph, so as to determine the matching anomaly phenomena from different perspectives, to improve the comprehensiveness of the anomaly phenomenon evaluation of the network anomaly. By matching each anomaly phenomenon with the preset network knowledge graph, through the matching situation of each anomaly phenomenon and the preset network knowledge graph, accurately determine the target anomaly cause of the network anomaly, realize the accurate diagnosis of the network anomaly, and finally repair the network anomaly according to the network anomaly repair strategy corresponding to the target anomaly cause, realizing the repair of the network anomaly. Therefore, compared with the related art of diagnosing network anomalies in a network through logs and protocols, in the present application, the classified texts of the anomaly description text can be used to match the preset network knowledge graph from multiple perspectives, so as to more accurately determine the target anomaly cause corresponding to the network anomaly and repair the target anomaly cause.
[0179] Please refer to Figure 4 , Figure 4 which is another schematic flowchart of the network anomaly diagnosis method provided by the embodiment of the present application. The network anomaly diagnosis method may include the following steps:
[0180] Step 301, obtain the original network fault data collected in the network, and perform data parsing on the original network fault data to determine multiple types of sub-data;
[0181] Step 302, determine each type of sub-data as a node, and create multiple triples according to the association relationship between different nodes, and construct a preset network knowledge graph based on the multiple triples;
[0182] Step 303, obtain the network anomalies to be diagnosed in the network and the corresponding anomaly description text of the network anomalies;
[0183] Step 304, perform text partitioning processing on the anomaly description text to obtain multiple partitioned texts, perform classification processing on the multiple partitioned texts to obtain at least one type of classified text, and the classified text includes device type classified text, execution operation classified text, and fault phenomenon classified text;
[0184] Step 305: Determine the abnormal operation description content corresponding to each abnormal operation type in the preset network knowledge graph;
[0185] Step 306: Calculate the similarity between the abnormal operation description content and the execution operation classification text to obtain the similarity calculation result;
[0186] Step 307: Determine the target abnormal operation type as the abnormal operation type corresponding to the abnormal operation description content whose similarity calculation result is greater than the preset similarity threshold;
[0187] Step 308: Match the target abnormal operation type with the preset network knowledge graph to determine the first abnormal phenomenon set;
[0188] Step 309: Determine the target knowledge data corresponding to the device type classification text in the preset network knowledge graph according to the device type classification text;
[0189] Step 310: Classify the fault phenomenon classification text to obtain the abnormal part text and the abnormal alarm text;
[0190] Step 311: Match the abnormal part text with the target knowledge data to obtain the second abnormal phenomenon set, and match the abnormal alarm text with the target knowledge data to obtain the third abnormal phenomenon set;
[0191] Step 312: Perform a union operation on the first abnormal phenomenon set, the second abnormal phenomenon set, and the third abnormal phenomenon set to obtain the target abnormal phenomenon set;
[0192] Step 313: Match each abnormal phenomenon in the target abnormal phenomenon set with the preset network knowledge graph to determine the target abnormal cause;
[0193] Step 314: Match each abnormal phenomenon with the preset network knowledge graph to obtain the matching abnormal cause;
[0194] Step 315: Determine the candidate abnormal causes and the occurrence times of each candidate abnormal cause according to the abnormal cause corresponding to each abnormal phenomenon;
[0195] Step 316: Divide the occurrence times of each candidate abnormal cause by the number of abnormal phenomena to obtain the fit probability of each candidate abnormal cause;
[0196] Step 317: Sort each candidate abnormal cause from high to low according to the fit probability to obtain the sorting result, and determine the target abnormal cause whose sorting is higher than the preset sorting position according to the sorting result. Repair the network anomaly according to the network anomaly repair strategy corresponding to the target abnormal cause.
[0197] In the above embodiments, the descriptions of the various embodiments have their own focuses. For parts not described in detail in a certain embodiment, reference may be made to the detailed description of the above network anomaly diagnosis method, which will not be elaborated here.
[0198] Please refer to Figure 5 , Figure 5 which is a schematic structural diagram of a network anomaly diagnosis device provided by an embodiment of the present application. The network anomaly diagnosis device is used to execute the above network anomaly diagnosis method.
[0199] In the embodiments of the present application, the term "module" or "unit" refers to a computer program with a predetermined function or a part of a computer program, which works together with other related parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as a processing circuit or a memory), or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of an overall module or unit that includes the function of the module or unit.
[0200] The network anomaly diagnosis device 400 includes:
[0201] An acquisition module 410, configured to acquire network anomalies that need to be diagnosed in the network and anomaly description texts corresponding to the network anomalies;
[0202] A division module 420, configured to perform text division processing on the anomaly description texts to obtain a plurality of divided texts;
[0203] A classification module 430, configured to perform classification processing on the plurality of divided texts to obtain at least one type of classified text;
[0204] A matching module 440, configured to match at least one type of classified text with a preset network knowledge graph to determine at least one matching anomaly phenomenon;
[0205] A determination module 450, configured to match the anomaly phenomenon with the preset network knowledge graph to determine a target anomaly cause, and repair the network anomaly according to a network anomaly repair strategy corresponding to the target anomaly cause.
[0206] In some embodiments, the network anomaly diagnosis device further includes a construction module, configured to:
[0207] Before matching at least one type of classified text with a preset network knowledge graph to determine a plurality of matching anomaly phenomena, acquire original network fault data collected in the network, and perform data parsing on the original network fault data to determine a plurality of types of sub-data;
[0208] Determine the sub-data of each type as a node, and create multiple triples according to the association relationships between different nodes;
[0209] Construct a preset network knowledge graph based on multiple triples.
[0210] In some embodiments, a construction module is used for:
[0211] Classify the original network fault data to obtain fault cause data, fault phenomenon data, and fault solution data;
[0212] Classify the fault cause data, fault phenomenon data, and fault solution data to obtain sub-data of multiple types, where the sub-data at least includes device type sub-data, execution operation sub-data, fault cause sub-data, fault location sub-data, fault alarm sub-data, and fault phenomenon sub-data.
[0213] In some embodiments, a partitioning module 420 is used for:
[0214] Perform word segmentation on the abnormal description text to obtain multiple segmented text;
[0215] Perform stop word filtering on the multiple segmented text to obtain multiple partitioned text;
[0216] A classification module 430 is used for:
[0217] Input the multiple partitioned text into a pre-trained text classification model, and output device type classification text, execution operation classification text, and fault phenomenon classification text.
[0218] In some embodiments, a matching module 440 is used for:
[0219] Determine the abnormal operation description content corresponding to each abnormal operation type in the preset network knowledge graph;
[0220] Calculate the similarity between the abnormal operation description content and the execution operation classification text to obtain a similarity calculation result;
[0221] Determine the abnormal operation type corresponding to the abnormal operation description content with a similarity calculation result greater than a preset similarity threshold as the target abnormal operation type;
[0222] Match the target abnormal operation type with the preset network knowledge graph to determine a first set of abnormal phenomena.
[0223] In some embodiments, a matching module 440 is used for:
[0224] Determine the target knowledge data corresponding to the device type classification text in the preset network knowledge graph according to the device type classification text;
[0225] Classify the text of the fault phenomenon to obtain the text of the abnormal part and the text of the abnormal alarm;
[0226] Match the text of the abnormal part with the target knowledge data to obtain the second set of abnormal phenomena;
[0227] Match the text of the abnormal alarm with the target knowledge data to obtain the third set of abnormal phenomena.
[0228] In some embodiments, the determination module 450 is configured to:
[0229] Perform a union operation on the first set of abnormal phenomena, the second set of abnormal phenomena, and the third set of abnormal phenomena to obtain a target set of abnormal phenomena;
[0230] Match each abnormal phenomenon in the target set of abnormal phenomena with a preset network knowledge graph to determine the target abnormal cause.
[0231] In some embodiments, the determination module 450 is configured to:
[0232] When the number of abnormal phenomena is multiple, match each abnormal phenomenon with a preset network knowledge graph to obtain the matching abnormal causes;
[0233] Determine the candidate abnormal causes and the occurrence times of each candidate abnormal cause according to the abnormal causes corresponding to each abnormal phenomenon;
[0234] Divide the occurrence times of each candidate abnormal cause by the number of abnormal phenomena to obtain the fitting probability of each candidate abnormal cause;
[0235] Sort each candidate abnormal cause from high to low according to the fitting probability to obtain a sorting result, and determine the target abnormal cause whose sorting is higher than the preset sorting position according to the sorting result.
[0236] In the above embodiments, the descriptions of the various embodiments have their own focuses. For the parts not detailed in a certain embodiment, reference may be made to the detailed description of the above network anomaly diagnosis method, which will not be elaborated here.
[0237] In the embodiment of the present application, the acquisition module 410 acquires network anomalies that need to be diagnosed in the network and the anomaly description text corresponding to the network anomalies; the division module 420 performs text division processing on the anomaly description text to obtain a plurality of divided texts; the classification module 430 performs classification processing on the plurality of divided texts to obtain at least one type of classified text; the matching module 440 matches at least one type of classified text with a preset network knowledge graph to determine at least one matching anomaly phenomenon; the determination module 450 matches the anomaly phenomenon with the preset network knowledge graph to determine the target anomaly cause, and repairs the network anomaly according to the network anomaly repair strategy corresponding to the target anomaly cause. In this way, by dividing the anomaly description text of the network anomaly into a plurality of divided texts, and then classifying the divided texts into a plurality of classified texts, different types of classified texts are used to match the preset network knowledge graph, so as to determine the matching anomaly phenomenon from different perspectives, so as to improve the comprehensiveness of the anomaly phenomenon evaluation of the network anomaly. By matching each anomaly phenomenon with the preset network knowledge graph, and through the matching situation between each anomaly phenomenon and the preset network knowledge graph, the target anomaly cause of the network anomaly is accurately determined, realizing the accurate diagnosis of the network anomaly. Finally, the network anomaly is repaired according to the network anomaly repair strategy corresponding to the target anomaly cause, realizing the repair of the network anomaly. Therefore, compared with the related art that diagnoses network anomalies in the network through logs and protocols, in the present application, the preset network knowledge graph can be matched from multiple perspectives according to the classified text of the anomaly description text, so that the target anomaly cause corresponding to the network anomaly can be determined more accurately and the target anomaly cause can be repaired.
[0238] Please refer to Figure 6 , Figure 6 illustrates the hardware structure of a computer device in another embodiment. The computer device includes:
[0239] A processor 501, which can be implemented by using a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided by the embodiments of the present application;
[0240] The memory 502 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM), etc. The memory 502 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 502 and are called by the processor 501 to execute the network anomaly diagnosis method of the embodiments of this application;
[0241] The input / output interface 503 is used to implement information input and output;
[0242] The communication interface 504 is used to implement communication interaction between this device and other devices. Communication can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.);
[0243] The bus 505 transmits information between various components of the device (such as the processor 501, the memory 502, the input / output interface 503, and the communication interface 504);
[0244] Among them, the processor 501, the memory 502, the input / output interface 503, and the communication interface 504 are communicatively connected to each other inside the device through the bus 505.
[0245] The embodiments of this application also provide a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above-mentioned network anomaly diagnosis method is implemented.
[0246] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include a high-speed random access memory, and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory optionally includes a memory remotely set relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above-mentioned network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0247] The embodiments of the present application provide a network anomaly diagnosis method, apparatus, computer device, and storage medium. It obtains network anomalies to be diagnosed in the network and the corresponding anomaly description text of the network anomalies; performs text partitioning processing on the anomaly description text to obtain multiple partitioned texts; performs classification processing on the multiple partitioned texts to obtain at least one type of classified text; matches the at least one type of classified text with a preset network knowledge graph to determine at least one matching anomaly phenomenon; matches the anomaly phenomenon with the preset network knowledge graph to determine the target anomaly cause, and repairs the network anomaly according to the network anomaly repair strategy corresponding to the target anomaly cause. In this way, by dividing the anomaly description text of the network anomaly into multiple partitioned texts, and then classifying the partitioned texts into multiple classified texts, different types of classified texts are used to match the preset network knowledge graph to determine the matching anomaly phenomenon from different perspectives, so as to improve the comprehensiveness of the evaluation of the anomaly phenomenon of the network anomaly. By matching each anomaly phenomenon with the preset network knowledge graph, based on the matching situation of each anomaly phenomenon and the preset network knowledge graph, the target anomaly cause of the network anomaly is accurately determined, realizing the accurate diagnosis of the network anomaly. Finally, the network anomaly is repaired according to the network anomaly repair strategy corresponding to the target anomaly cause, realizing the repair of the network anomaly. Therefore, compared with diagnosing network anomalies in the network through logs and protocols in the related art, in the present application, the classified text of the anomaly description text can be used to match the preset network knowledge graph from multiple perspectives, so that the target anomaly cause corresponding to the network anomaly can be determined more accurately and the target anomaly cause can be repaired.
[0248] The embodiments described in the embodiments of the present application are for more clearly explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.
[0249] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or combine some steps, or different steps.
[0250] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0251] Those of ordinary skill in the art will understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or a suitable combination thereof.
[0252] As used in the specification of this application and the above drawings, the terms "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present application described here can be implemented in an order different from those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that comprises a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0253] It should be understood that in this application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects and indicates that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Here, A and B can be singular or plural. The character " / " generally means that the associated objects before and after are in an "or" relationship. "At least one (one) of the following" or a similar expression means any combination of these items, including any combination of single items (ones) or plural items (ones). For example, at least one (one) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0254] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the above division of units is only a logical functional division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces, and the indirect coupling or communication connection of devices or units can be in electrical, mechanical, or other forms.
[0255] The units described above as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0256] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0257] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present application. The aforementioned storage medium includes: various media that can store programs, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.
[0258] The preferred embodiments of the embodiments of the present application have been described above with reference to the accompanying drawings. However, this does not limit the scope of the rights of the embodiments of the present application. Any modification, equivalent replacement, and improvement made by those skilled in the art without departing from the scope and essence of the embodiments of the present application shall be within the scope of the rights of the embodiments of the present application.
Claims
1. A network anomaly diagnosis method, characterized in that: include: Obtain a network anomaly that needs to be diagnosed in the network and an anomaly description text corresponding to the network anomaly; Performing text segmentation processing on the exception description text to obtain multiple segmented texts; Classifying the multiple divided texts to obtain at least one type of classified text; Matching the at least one type of classified text with a preset network knowledge graph to determine at least one matching anomaly; The abnormal phenomenon is matched with the preset network knowledge graph to determine the target abnormal cause, and the network abnormality is repaired according to the network abnormality repair strategy corresponding to the target abnormal cause.
2. The network anomaly diagnosis method according to claim 1, characterized in that: Before matching the at least one type of classified text with a preset network knowledge graph to determine a plurality of matched abnormal phenomena, the method further includes: Acquire original network fault data collected in the network, and perform data analysis on the original network fault data to determine multiple types of sub-data; Determine each type of sub-data as a node, and create multiple triples based on the association relationship between different nodes; A preset network knowledge graph is constructed based on the multiple triples.
3. The network anomaly diagnosis method according to claim 2, characterized in that: The data parsing of the original network fault data to determine multiple types of sub-data includes: Classifying the original network fault data to obtain fault cause data, fault phenomenon data and fault solution data; The fault cause data, the fault phenomenon data and the fault solution data are classified to obtain multiple types of sub-data, and the sub-data at least include equipment type sub-data, execution operation sub-data, fault cause sub-data, fault location sub-data, fault alarm sub-data and fault phenomenon sub-data.
4. The network anomaly diagnosis method according to claim 1, characterized in that: The text segmentation process is performed on the exception description text to obtain a plurality of segmentation texts, including: Performing word segmentation processing on the abnormal description text to obtain multiple word segmentation texts; Performing stop word filtering processing on the multiple segmented texts to obtain multiple segmented texts; The classifying the multiple divided texts to obtain at least one type of classified text includes: The multiple segmented texts are input into a pre-trained text classification model, and device type classification text, execution operation classification text and fault phenomenon classification text are output.
5. The network anomaly diagnosis method according to claim 4, characterized in that: The step of matching the at least one type of classified text with a preset network knowledge graph to determine at least one matching abnormal phenomenon includes: Determining abnormal operation description content corresponding to each abnormal operation type in the preset network knowledge graph; Performing similarity calculation on the abnormal operation description content and the executed operation classification text to obtain a similarity calculation result; Determine the abnormal operation type corresponding to the abnormal operation description content whose similarity calculation result is greater than a preset similarity threshold as the target abnormal operation type; The target abnormal operation type is matched with a preset network knowledge graph to determine a first abnormal phenomenon set.
6. The network anomaly diagnosis method according to claim 5, characterized in that: The step of matching the at least one type of classified text with a preset network knowledge graph to determine at least one matching abnormal phenomenon includes: Determine, according to the device type classification text, target knowledge data corresponding to the device type classification text in the preset network knowledge graph; Classify the fault phenomenon classification text to obtain abnormal part text and abnormal alarm text; Matching the abnormal part text with the target knowledge data to obtain a second abnormal phenomenon set; The abnormal warning text is matched with the target knowledge data to obtain a third abnormal phenomenon set.
7. The network anomaly diagnosis method according to claim 6, characterized in that: The matching of the abnormal phenomenon with the preset network knowledge graph to determine the cause of the target abnormality includes: Performing a union process on the first abnormal phenomenon set, the second abnormal phenomenon set and the third abnormal phenomenon set to obtain a target abnormal phenomenon set; The cause of the target anomaly is determined by matching each anomaly in the target anomaly set with the preset network knowledge graph.
8. The network anomaly diagnosis method according to claim 1, characterized in that: The matching of the abnormal phenomenon with the preset network knowledge graph to determine the cause of the target abnormality includes: When there are multiple abnormal phenomena, each abnormal phenomenon is matched with the preset network knowledge graph to obtain a matching abnormal cause; Determine candidate abnormal causes and the number of occurrences of each candidate abnormal cause according to the abnormal causes corresponding to each abnormal phenomenon; Divide the number of occurrences of each candidate abnormal cause by the number of abnormal phenomena to obtain a matching probability of each candidate abnormal cause; According to the matching probability, each candidate abnormal cause is sorted from high to low to obtain a sorting result, and according to the sorting result, a target abnormal cause ranked higher than a preset sorting position is determined.
9. A network anomaly diagnosis device, characterized in that: include: An acquisition module is used to acquire a network anomaly that needs to be diagnosed in the network and an anomaly description text corresponding to the network anomaly; A segmentation module, used for performing text segmentation processing on the exception description text to obtain a plurality of segmented texts; A classification module, used for classifying the multiple divided texts to obtain at least one type of classified text; A matching module, used to match the at least one type of classified text with a preset network knowledge graph to determine at least one matching anomaly; The determination module is used to match the abnormal phenomenon with the preset network knowledge graph, determine the target abnormal cause, and repair the network abnormality according to the network abnormality repair strategy corresponding to the target abnormal cause.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor to execute the network anomaly diagnosis method according to any one of claims 1 to 8.
11. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the network anomaly diagnosis method according to any one of claims 1 to 8 is implemented.