Model training method, core network fault early warning method and device, electronic equipment and storage medium
The method improves core network fault detection by preprocessing and training models to analyze network alerts, addressing inefficiencies in manual analysis and enhancing fault prediction accuracy.
Patent Information
- Application Number
- CN202510572790.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-07-15
AI Technical Summary
In the prior art, monitoring and fault discovery of core network problems relies on manual experience and traditional data analysis, resulting in inefficiency and difficulty in quickly and accurately judging the effectiveness of alarms and the impact of faults. The lack of intelligent data analysis means makes it difficult to achieve timely fault warnings.
By obtaining historical alarm rules data of the core network, extracting and binding time and space features, generating historical alarm data sets, using fault warning models for training and optimization, combining big data analysis and machine learning algorithms, intelligent fault warning for the core network is achieved.
It realizes rapid and accurate analysis and early warning of core network faults, improves fault warning efficiency and accuracy, and can effectively respond to massive alarm data.
Smart Images

Figure CN120321101A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication network technologies, and particularly to a model training method, a core network fault warning method, a device, an electronic device, and a storage medium. Background Art
[0002] With the rapid development of communication technologies, as the key hub of communication networks, the operation and maintenance of the core network have become increasingly complex. The services cover multiple fields such as 5GC, VoLTE, and EPC. Each network carries diverse service types and a large number of devices, and the scenarios are intricate. This has led to a large number and variety of core network alarms, and at the same time, the core network is prone to generating more upper-layer alarms, and the services are vulnerable to the impact of the underlying bearer and transmission, making it difficult to directly locate the root cause of network problems.
[0003] Currently, the monitoring and fault discovery of core network problems mainly rely on manual experience and traditional data analysis methods. Facing the massive core network alarm data, manual analysis is not only inefficient but also difficult to accurately judge the effectiveness of alarms and whether they constitute faults affecting communication network services in a short time. Due to the lack of intelligent data analysis means, it has become particularly difficult to timely evaluate and warn of serious faults. Summary of the Invention
[0004] The main purpose of the embodiments of this application is to propose a model training method, a core network fault warning method, a device, an electronic device, and a storage medium, which can improve the efficiency and accuracy of core network fault warning.
[0005] On the one hand, the embodiments of this application propose a model training method, and the method includes the following steps:
[0006] Obtain a plurality of core network historical alarm rule data;
[0007] Extract spatio-temporal features from each of the core network historical alarm rule data to determine spatio-temporal feature data corresponding to each of the core network historical alarm rule data;
[0008] Bind each of the spatio-temporal feature data to the corresponding core network historical alarm rule data to generate a core network historical alarm data set;
[0009] Obtain a fault warning model, and use the core network historical alarm data set to train and optimize the fault warning model.
[0010] In some embodiments, the obtaining a plurality of core network historical alarm rule data specifically includes:
[0011] Collect a plurality of core network historical alarm data;
[0012] Preprocess the core network historical alarm data to determine the preprocessed core network historical alarm data for each one;
[0013] According to the preset regular parsing rules, perform regular feature extraction on each of the preprocessed core network historical alarm data, and output the core network historical alarm rule data corresponding to each of the preprocessed core network historical alarm data.
[0014] In some embodiments, the extracting spatio-temporal features from each of the core network historical alarm rule data to determine the spatio-temporal feature data corresponding to each of the core network historical alarm rule data specifically includes:
[0015] According to the preset time feature data types, perform time feature extraction on each of the core network historical alarm rule data to determine the time feature data corresponding to each of the core network historical alarm rule data;
[0016] According to the preset space feature data types, perform space feature extraction on each of the core network historical alarm rule data to determine the space feature data corresponding to each of the core network historical alarm rule data;
[0017] Determine the spatio-temporal feature data according to the time feature data and the space feature data corresponding to each of the core network historical alarm rule data.
[0018] In some embodiments, the binding each of the spatio-temporal feature data with the corresponding core network historical alarm rule data to generate a core network historical alarm data set specifically includes:
[0019] For each of the core network historical alarm rule data, bind the core network historical alarm rule data with the corresponding spatio-temporal feature data to generate the corresponding core network historical alarm training data;
[0020] Construct the core network historical alarm data set, and add each of the core network historical alarm training data to the core network historical alarm data set.
[0021] In some embodiments, the obtaining a fault warning model and training and optimizing the fault warning model by using the core network historical alarm data set specifically includes:
[0022] Construct the fault warning model;
[0023] Divide the core network historical alarm data set to obtain a training set and a validation set;
[0024] Use the training set to train the fault warning model to obtain a trained fault warning model;
[0025] Use the validation set to verify the trained fault warning model, determine the model verification result, and determine whether to continue training the trained fault warning model according to the model verification result.
[0026] In some embodiments, the using the validation set to verify the trained fault warning model, determining the model verification result, and determining whether to continue training the trained fault warning model according to the model verification result specifically includes:
[0027] Obtain preset model verification metrics;
[0028] Use the validation set to verify the trained fault warning model and determine the current metric calculation values corresponding to the model verification metrics.
[0029] When the current metric calculation values corresponding to the model evaluation metrics are all greater than the corresponding metric verification thresholds, stop training the trained fault warning model; otherwise, continue training the trained fault warning model.
[0030] On the other hand, an embodiment of the present application proposes a core network fault warning method, and the method includes the following steps:
[0031] Obtain a fault warning model, where the fault warning model is trained by the above model training method;
[0032] Perform dynamic data monitoring on the core network to determine core network exception alarm data;
[0033] Use the fault warning model to perform fault analysis on the core network exception alarm data, generate a fault analysis result and issue a warning, where the fault analysis result includes a fault type, a fault cause, and a fault impact range.
[0034] On the other hand, an embodiment of the present application proposes a core network fault warning device, and the device includes:
[0035] A first module, configured to obtain a fault warning model, where the fault warning model is trained by the above model training method;
[0036] A second module, configured to perform dynamic data monitoring on the core network to determine core network exception alarm data;
[0037] A third module, configured to use the fault warning model to perform fault analysis on the core network exception alarm data, generate a fault analysis result and issue a warning, where the fault analysis result includes a fault type, a fault cause, and a fault impact range.
[0038] On the other hand, an embodiment of the present application provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the foregoing model training method or core network fault warning method is implemented.
[0039] On the other hand, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the foregoing model training method or core network fault warning method is implemented.
[0040] The embodiments of the present application at least include the following beneficial effects: A model training method, a core network fault warning method, a device, an electronic device, and a storage medium provided by the present application obtain multiple core network historical alarm rule data, extract spatio-temporal features from each core network historical alarm rule data, determine spatio-temporal feature data corresponding to each core network historical alarm rule data, bind each spatio-temporal feature data to the corresponding core network historical alarm rule data to generate a core network historical alarm data set, use the core network historical alarm data set to train and optimize a fault warning model, and use the fault warning model to perform fault analysis on core network abnormal alarm data, generate a fault analysis result, and issue a warning. The present application can realize intelligent core network fault warning, effectively cope with a large amount of core network alarm data, and improve the efficiency and accuracy of core network fault warning. Description of the Drawings
[0041] The drawings here are incorporated into the description and form a part of this description, showing embodiments consistent with the present invention and used together with the description to explain the principles of the present invention.
[0042] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0043] Figure 1 is a flowchart of a model training method provided by an embodiment of the present application;
[0044] Figure 2 is a flowchart of step S101 in an embodiment of the present application;
[0045] Figure 3 is a schematic diagram of feature alarms in an embodiment of the present application;
[0046] Figure 4 is a schematic diagram of core network historical alarm rule data in an embodiment of the present application;
[0047] Figure 5 It is the flowchart of step S102 in the embodiment of the present application;
[0048] Figure 6 It is the flowchart of step S104 in the embodiment of the present application;
[0049] Figure 7 It is the flowchart of a core network fault warning method provided by the embodiment of the present application;
[0050] Figure 8 It is the schematic diagram for realizing core network fault warning in the embodiment of the present application;
[0051] Figure 9 It is the structural schematic diagram of a core network fault warning device provided by the embodiment of the present application;
[0052] Figure 10 It is the hardware structural schematic diagram of an electronic device provided by the embodiment of the present application. Detailed implementation manners
[0053] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the embodiments of the present application. They are only examples of devices and methods consistent with some aspects of the embodiments of the present application detailed in the appended claims.
[0054] It can be understood that the terms "first", "second", etc. used in the present application can be used herein to describe various concepts, but unless otherwise specified, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiments of the present application, the first information can also be called the second information, and similarly, the second information can also be called the first information. Depending on the context, the words "if", "when" as used herein can be interpreted as "when...", "when...", or "in response to determining".
[0055] The terms "at least one", "multiple", "each", "any one", etc. used in the present application, at least one includes one, two or more, multiple includes two or more, each refers to each of the corresponding multiple, and any one refers to any one of the multiple.
[0056] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the technical field to which this application belongs. The terms used herein are for the purpose of describing the embodiments of this application only and are not intended to limit this application.
[0057] It should be noted that in each specific embodiment of this application, when it comes to relevant processing based on data related to the user's identity or characteristics, such as user information, user behavior data, user historical data, and user location information, the user's permission or consent will be obtained first. Moreover, the collection, use, and processing of these data will comply with relevant laws, regulations, and standards. In addition, when the embodiments of this application need to obtain the user's sensitive personal information, the user's separate permission or separate consent will be obtained through methods such as pop-up windows or redirecting to a confirmation page. After clearly obtaining the user's separate permission or separate consent, the necessary user-related data for the normal operation of the embodiments of this application will be obtained.
[0058] Before elaborating on the embodiments of this application in detail, some nouns and terms involved in the embodiments of this application are first explained. The nouns and terms involved in the embodiments of this application are applicable to the following explanations.
[0059] 1) Core Network: The core network is the core of the communication network, located within the network subsystem, responsible for data transmission and exchange between the base station and the user. It connects different networks to enable communication between users, and its functions cover call control, mobility management, data transmission, and service logic processing. In mobile communication, it is also responsible for core tasks such as user identity authentication, location registration, and call routing.
[0060] 2) Spatial-temporal big data: Big data that is based on a unified spatio-temporal reference and exists or occurs in time and space and is directly or indirectly related to location. Accordingly, spatial-temporal big data consists of two major categories of data: spatio-temporal framework data and spatio-temporal change data. Through data multi-dimensional fusion, correlation analysis, and data mining, the essential laws of things are revealed, and more rapid, comprehensive, accurate, and effective judgments and predictions can be made about things.
[0061] 3) Isolation Forest: Isolation Forest is an unsupervised machine learning algorithm for anomaly detection. Its core idea is to detect anomalies by leveraging the isolation characteristics of abnormal data points, that is, abnormal points are usually fewer in number and have significant differences from most data points, so they are more likely to be isolated; Isolation Forest identifies outliers by constructing multiple isolation trees (iTrees). Each tree recursively partitions the data by randomly selecting features and cut points until only one data point remains in each leaf node. Due to the differences between abnormal points and normal points, abnormal points are usually isolated earlier, that is, they are closer to the root node of the tree; Isolation Forest has wide applications in fields such as attack detection in network security and fraud behavior mining in financial institutions.
[0062] 4) Regular Expression (abbreviated as Regex): It is a powerful tool for efficiently matching, searching, and operating on text. By defining specific string patterns (Patterns), it can quickly extract, verify, or replace target content from complex text; Its core is to describe the character combination rules with symbolic syntax and is widely used in fields such as programming, data processing, and log analysis; Regular expressions consist of ordinary characters and special characters (referred to as "meta-characters") for specifying matching rules.
[0063] 5) Parsing Regular: It refers to using Regular Expression (Regex) to extract, match, or verify data of specific patterns from unstructured or semi-structured text; Its core is to efficiently locate and structure key information in the original text through predefined regularized string patterns.
[0064] 6) Network Element Information: Network Element Information is the structured data that describes the attributes, status, and functions of network devices (network elements) in a communication network and is the core basis for network management, fault analysis, and resource scheduling. In scenarios such as the core network (such as 5GC / EPC) and the transmission network, Network Element Information is the basic data unit of the operation and maintenance system. In core network alarm analysis, Network Element Information is the key context for associating spatio-temporal features and locating the root cause.
[0065] 7) Spatio-Temporal Data Mining: Spatio-Temporal Data Mining is a technology for extracting implicit patterns, anomalies, or predicting future states from data that simultaneously contains spatial dimensions (geographical location, topological relationships) and time dimensions (temporal changes, event evolution). Its core goal is to discover the laws of data under spatio-temporal coupling to provide support for decision-making.
[0066] 8) Spatiotemporal Focus: Spatiotemporal aggregation refers to the non-random concentration phenomenon presented by data in both the spatial and temporal dimensions, that is, certain events or characteristics occur significantly densely in specific geographical locations and specific time periods. It is one of the core concepts in spatiotemporal data analysis, used to reveal hidden laws, anomalies or causal relationships, capable of identifying hotspots and peak occurrence periods, assisting in decision-making, locating the source through aggregation, and predicting future risks based on historical aggregation patterns.
[0067] With the rapid development of communication technologies, the core network, as the key hub of the communication network, has become increasingly complex in its operation and maintenance. The services cover multiple fields such as 5GC, VoLTE, and EPC. Each network carries diverse service types and a large number of devices, with intricate scenarios. This has led to a large variety and quantity of core network alarms. At the same time, the core network is prone to generating more upper-layer alarms, and the services are easily affected by the underlying bearer and transmission, making it difficult to directly locate the root cause of network problems.
[0068] Currently, the monitoring and fault discovery of core network problems mainly rely on manual experience and traditional data analysis methods. Facing a large amount of alarm data, manual analysis is not only inefficient but also difficult to accurately judge the effectiveness of alarms and whether they constitute faults affecting communication network services in a short time. Due to the lack of intelligent data analysis means, it has become particularly difficult to timely evaluate and warn of serious faults.
[0069] Based on this, the embodiments of this application propose a model training method, a core network fault warning method, a device, an electronic device, and a storage medium. Combining big data analysis, advanced machine learning algorithms, and spatiotemporal data mining technologies, etc., it realizes comprehensive, real-time, and accurate monitoring of the core network operation status, realizes rapid fault warning and efficient and accurate analysis and disposal of the core network, and provides a strong guarantee for the stable operation of the communication network.
[0070] Refer to Figure 1 , Figure 1 is an optional flowchart of a model training method provided by the embodiments of this application. The method may include steps S101 to S104:
[0071] Step S101, obtain a plurality of core network historical alarm rule data;
[0072] Step S102, perform spatiotemporal feature extraction on each core network historical alarm rule data to determine the spatiotemporal feature data corresponding to each core network historical alarm rule data;
[0073] Step S103, bind each spatiotemporal feature data with the corresponding core network historical alarm rule data to generate a core network historical alarm dataset;
[0074] Step S104, obtain a fault warning model, and train and optimize the fault warning model by using the core network historical alarm data set.
[0075] In some embodiments, referring to Figure 2 , Figure 2 is an optional flowchart of step S101 in the embodiments of the present application. Step S101 may include but is not limited to steps S201 to S203:
[0076] Step S201, collect a plurality of core network historical alarm data;
[0077] Step S202, perform data preprocessing on each core network historical alarm data to determine each preprocessed core network historical alarm data;
[0078] Step S203, according to the preset regular parsing rule, perform regular feature extraction on each preprocessed core network historical alarm data, and output the core network historical alarm rule data corresponding to each preprocessed core network historical alarm data.
[0079] In some embodiments, collect a plurality of core network historical alarm data through real-time dynamic collection or database collection, etc., perform data preprocessing on each core network historical alarm data, and the data preprocessing includes data cleaning, data normalization, etc., to improve the data quality of the core network historical alarm data, and obtain the preprocessed core network historical alarm data.
[0080] Then, based on the preset regular parsing rule, such as regular expression, etc., perform structured parsing on each preprocessed core network historical alarm data, determine a plurality of parsing regulars corresponding to each preprocessed core network historical alarm data, and bind each parsing regular to the corresponding core network historical alarm data to obtain the core network historical alarm rule data corresponding to the core network historical alarm data, and realize the regular feature extraction of the core network historical alarm data.
[0081] In some embodiments, set a plurality of feature alarms in advance. The feature alarms include information such as feature alarm number, alarm type, alarm name, and the network to which it belongs. Referring to Figure 3 , Figure 3 is an optional schematic diagram of the feature alarm in the embodiments of the present application. Suppose there are feature alarms 1 to K. Feature alarm 1 includes feature alarm number 1, alarm type 1, alarm name 1, and the network 1 to which it belongs. Feature alarm 2 includes feature alarm number 2, alarm type 2, alarm name 2, and the network 2 to which it belongs, and so on.
[0082] Optionally, obtain the specific information of a plurality of feature alarms, as shown in Table 1. Table 1 is specifically as follows:
[0083] Table 1 Feature Alarm Information Table
[0084]
[0085]
[0086]
[0087] Multiple feature alarms can be obtained from Table 1, and each feature alarm has a corresponding feature alarm number. For example, the feature alarm with the feature alarm number 1 includes alarm name: GTPC path failure, alarm type: link, and the network it belongs to: EPC, etc.
[0088] Then, obtain the regular expressions corresponding to each feature alarm. For each core network historical alarm data, use the regular expressions of each feature alarm to structurally extract the key feature fields in the core network historical alarm data, and obtain the parsing regulars corresponding to each feature alarm in the core network historical alarm data. Integrate all the parsing regulars to obtain the core network historical alarm rule data corresponding to the core network historical alarm data. Optionally, obtain several parsing objects included in the core network historical alarm data, and bind the parsing regulars corresponding to each feature alarm to each parsing object to obtain the core network historical alarm rule data, as shown in Table 2. Table 2 is specifically as follows:
[0089] Table 2 Core Network Historical Alarm Rule Data Table
[0090]
[0091]
[0092]
[0093]
[0094] Through the binding information between each parsing object included in the core network historical alarm data and multiple parsing regulars, data integration is performed to obtain the core network historical alarm rule data corresponding to the core network historical alarm data. The core network historical alarm rule data includes each parsing object and all the parsing regulars corresponding to it.
[0095] Exemplarily, referring to Figure 4 , Figure 4 is an optional schematic diagram of the core network historical alarm rule data in the embodiments of the present application. Assuming that the core network historical alarm data includes parsing objects 1 to N, the core network historical alarm rule data includes all the parsing regulars corresponding to parsing objects 1 to N. Among them, parsing object 1 includes parsing regulars 11 to 1M, parsing object 2 includes parsing regulars 21 to 2M, and so on.
[0096] In some embodiments, referring to Figure 5 , Figure 5 is an optional flowchart of step S102 in the embodiments of the present application. Step S102 may include but is not limited to steps S301 to S303:
[0097] Step S301, extract time features from each core network historical alarm rule data according to the preset time feature data type, and determine the time feature data corresponding to each core network historical alarm rule data;
[0098] Step S302, extract spatial features from each core network historical alarm rule data according to the preset spatial feature data type, and determine the spatial feature data corresponding to each core network historical alarm rule data;
[0099] Step S303, determine the spatio-temporal feature data according to the time feature data and spatial feature data corresponding to each core network historical alarm rule data.
[0100] In some embodiments, using spatio-temporal data mining technology, capture data changes in the time dimension and network features in the space dimension, and extract spatio-temporal feature data that can reflect changes in the core network operation state from the core network historical alarm rule data. The spatio-temporal feature data may include but is not limited to spatio-temporal aggregation, spatio-temporal sequence pattern, spatio-temporal anomaly score, and abnormal event association, etc., providing a data basis for the training of subsequent fault warning models.
[0101] Optionally, the spatio-temporal data mining technology includes spatio-temporal pattern mining, spatio-temporal prediction and interpolation, spatio-temporal anomaly detection, and trajectory data mining, etc. The time feature data may include but is not limited to alarm time series features, alarm frequency features, and time series association features (such as alarm interval time, etc.), and the spatial feature data may include but is not limited to physical topology features (including network element location information and network hierarchy relationship, etc.), logical link features (including link identification and virtualized resource location, etc.), and service impact range, etc. Then, according to the time feature data and spatial feature data, perform spatio-temporal joint feature analysis to obtain spatio-temporal feature data.
[0102] In step S103 of some embodiments, for each core network historical alarm rule data, bind the core network historical alarm rule data with the corresponding spatio-temporal feature data to generate the corresponding core network historical alarm training data. Then, construct a core network historical alarm data set, and add each core network historical alarm training data to the core network historical alarm data set.
[0103] In some embodiments, optionally, according to information such as the keyword of the area to which the alarm belongs, the keyword of the alarm device name, and the keyword of the alarm IP address included in the spatio-temporal feature data corresponding to the core network historical alarm rule data, combining the core network historical alarm rule data and the alarm analysis metrics, an index calculation value of the core network historical alarm rule data corresponding to the alarm analysis metrics is obtained, and the index calculation value of the alarm analysis metrics, the core network historical alarm rule data, and the spatio-temporal feature data are bound to generate corresponding core network historical alarm training data, where the alarm analysis metrics may include, but are not limited to, the number of alarms within a unit time in different regions, the alarm clearance rate, and the number of faulty network elements, etc.
[0104] In some embodiments, referring to Figure 6 , Figure 6 is an optional flowchart of step S104 in the embodiments of the present application. Step S104 may include, but is not limited to, steps S401 to S404:
[0105] Step S401, construct a fault warning model;
[0106] Step S402, divide the core network historical alarm data set to obtain a training set and a validation set;
[0107] Step S403, use the training set to train the fault warning model to obtain a trained fault warning model;
[0108] Step S404, use the validation set to perform model verification on the trained fault warning model, determine the model verification result, and determine whether to continue training the trained fault warning model according to the model verification result.
[0109] In some embodiments, based on the isolation forest, construct a fault warning model, and use the fault warning model to perform fault identification and warning on user-level abnormal events and abnormal detection of sudden increases in link alarms. Optionally, use the training set to iteratively train the fault warning model so that the fault warning model can learn the data distribution law in the normal state and have the ability to identify abnormal data.
[0110] In step S404 of some embodiments, specifically, obtain a preset model verification metric, use the validation set to perform model verification on the trained fault warning model, determine the current metric calculation value corresponding to each model verification metric, and when the current metric calculation value corresponding to each model evaluation metric is greater than the corresponding metric verification threshold, stop training the trained fault warning model, otherwise, continue training the trained fault warning model.
[0111] Optionally, the model evaluation metrics include the Dice coefficient, Intersection over Union (IoU), and Accuracy of the model when training the fault warning model using the validation set, etc.
[0112] Refer to Figure 7 , Figure 7 which is an optional flowchart of a core network fault warning method provided by an embodiment of the present application. The method may include but is not limited to steps S1 to S3:
[0113] Step S1: Obtain a fault warning model, which has been trained by the above model training method;
[0114] Step S2: Dynamically monitor the core network to determine the core network abnormal alarm data;
[0115] Step S3: Use the fault warning model to perform fault analysis on the core network abnormal alarm data, generate a fault analysis result and issue a warning. Among them, the fault analysis result includes the fault type, fault cause, and fault impact scope.
[0116] In some embodiments, the fault warning model is deployed to the production environment to perform real-time monitoring on the core network. When the fault warning model detects the core network abnormal alarm data, it immediately triggers the fault warning mechanism to generate a fault analysis result, including the fault type, fault impact scope, fault cause, and recommended handling measures, etc. At the same time, according to the fault analysis result, a corresponding fault work order is generated to achieve the warning effect, facilitating the operation and maintenance personnel to respond in a timely manner.
[0117] A core network fault warning method provided by an embodiment of the present application quickly analyzes and converges a large amount of core network abnormal alarm data through the fault warning model, generates a fault analysis result and pushes it, solving the problems that network alarms are complex and scattered and cannot be focused, and it is difficult to comprehensively judge and quickly predict core network faults.
[0118] In some embodiments, by way of example, refer to Figure 8 , Figure 8 which is an optional schematic diagram for realizing core network fault warning in an embodiment of the present application. Monitor the core network for data, determine and obtain the corresponding core network abnormal alarm data, input the core network abnormal alarm data into the fault warning model, use the fault warning model to generate a fault analysis result, and push the fault analysis result to the operation and maintenance management terminal, and the operation and maintenance management terminal reminds the operation and maintenance personnel to perform fault troubleshooting and handling.
[0119] Refer to Figure 9 , Figure 9FIG. 0 is an alternative structural schematic diagram of a core network fault warning device provided by an embodiment of the present application. The device is used to implement the above-mentioned core network fault warning method, and the device may include:
[0120] A first module, configured to obtain a fault warning model, and the fault warning model is trained by the above-mentioned model training method;
[0121] A second module, configured to perform dynamic data monitoring on the core network to determine core network abnormal alarm data;
[0122] A third module, configured to perform fault analysis on the core network abnormal alarm data by using the fault warning model, generate a fault analysis result and issue a warning, where the fault analysis result includes a fault type, a fault cause, and a fault impact range.
[0123] It can be understood that the content in the above-mentioned embodiments of the core network fault warning method is applicable to the embodiments of this device. The functions specifically implemented by the embodiments of this device are the same as those of the above-mentioned embodiments of the core network fault warning method, and the beneficial effects achieved are also the same as those of the above-mentioned method embodiments.
[0124] An embodiment of the present application further provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the above-mentioned model training method or core network fault warning method is implemented. The electronic device may be any intelligent terminal including a tablet computer, etc.
[0125] It can be understood that the content in the above-mentioned method embodiments is applicable to the embodiments of this device. The functions specifically implemented by the embodiments of this device are the same as those of the above-mentioned method embodiments, and the beneficial effects achieved are also the same as those of the above-mentioned method embodiments.
[0126] Please refer to Figure 10 , Figure 10 FIG. shows the hardware structure of an electronic device according to another embodiment. The electronic device includes:
[0127] A processor 901, which can be implemented by using a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is configured to execute relevant programs to implement the technical solutions provided by the embodiments of the present application;
[0128] The memory 902 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM), etc. The memory 902 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 902 and are called by the processor 901 to execute the model training method or the core network fault warning method of the embodiments of this application;
[0129] The input / output interface 903 is used to implement information input and output;
[0130] The communication interface 904 is used to implement communication and interaction between this device and other devices. It can implement communication through a wired method (such as USB, network cable, etc.) or through a wireless method (such as a mobile network, WIFI, Bluetooth, etc.);
[0131] The bus 905 transmits information between various components of the device (such as the processor 901, the memory 902, the input / output interface 903, and the communication interface 904);
[0132] Among them, the processor 901, the memory 902, the input / output interface 903, and the communication interface 904 are communicatively connected to each other inside the device through the bus 905.
[0133] The embodiments of this application also provide a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the above-mentioned model training method or core network fault warning method.
[0134] It can be understood that the content in the above method embodiments is applicable to the embodiments of this storage medium. The functions specifically implemented by the embodiments of this storage medium are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those of the above method embodiments.
[0135] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include high-speed random access memory, and can also include non-transitory memory, such as at least one disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory optionally includes a memory remotely set relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0136] A model training method, a core network fault warning method, a device, an electronic device and a storage medium provided by an embodiment of the present application can realize intelligent core network fault warning, effectively cope with a large amount of core network alarm data, and improve the efficiency and accuracy of core network fault warning.
[0137] The embodiments described in the embodiments of the present application are for more clearly explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.
[0138] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than those shown in the figures, or combine some steps, or different steps.
[0139] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0140] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware and their appropriate combinations.
[0141] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0142] It should be understood that in this application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one (one)" or its similar expression below refers to any combination of these items, including any combination of single item (one) or plural items (ones). For example, at least one (one) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0143] In several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the above-mentioned unit division is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical or other forms.
[0144] The units described above as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0145] In addition, each functional unit in various embodiments of this application can be integrated in one processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0146] It should be recognized that the embodiments of the present invention can be implemented or carried out by computer hardware, a combination of hardware and software, or by computer instructions stored in a non-transitory computer-readable memory. The method can be implemented in a computer program using standard programming techniques including a non-transitory computer-readable storage medium configured with the computer program, wherein the storage medium so configured causes the computer to operate in a specific and predefined manner - according to the methods and drawings described in the specific embodiments. Each program can be implemented in a high-level procedural or object-oriented programming language to communicate with the computer system. However, if desired, the program can be implemented in assembly or machine language. In any case, the language can be a compiled or interpreted language. In addition, for this purpose the program is capable of running on a dedicated integrated circuit programmed for this purpose.
[0147] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store programs.
[0148] The preferred embodiments of the embodiments of this application have been described above with reference to the drawings, and thus do not limit the scope of the rights of the embodiments of this application. Any modifications, equivalent replacements, and improvements made by those skilled in the art without departing from the scope and essence of the embodiments of this application shall be within the scope of the rights of the embodiments of this application.
Claims
1. A model training method, characterized in that, The method includes the following steps: Obtain a plurality of core network historical alarm rule data; Extract spatio-temporal features from each of the core network historical alarm rule data to determine the spatio-temporal feature data corresponding to each of the core network historical alarm rule data; Bind each of the spatio-temporal feature data to the corresponding core network historical alarm rule data to generate a core network historical alarm data set; Obtain a fault warning model, and use the core network historical alarm data set to train and optimize the fault warning model.
2. The model training method according to claim 1, wherein The obtaining of a plurality of core network historical alarm rule data specifically includes: Collect a plurality of core network historical alarm data; Perform data preprocessing on each of the core network historical alarm data to determine each preprocessed core network historical alarm data; According to a preset regular parsing rule, perform regular feature extraction on each of the preprocessed core network historical alarm data, and output the core network historical alarm rule data corresponding to each of the preprocessed core network historical alarm data.
3. The model training method according to claim 1, wherein The extracting of spatio-temporal features from each of the core network historical alarm rule data to determine the spatio-temporal feature data corresponding to each of the core network historical alarm rule data specifically includes: Extract time features from each of the core network historical alarm rule data according to a preset time feature data type to determine the time feature data corresponding to each of the core network historical alarm rule data; Extract space features from each of the core network historical alarm rule data according to a preset space feature data type to determine the space feature data corresponding to each of the core network historical alarm rule data; Determine the spatio-temporal feature data according to the time feature data and the space feature data corresponding to each of the core network historical alarm rule data.
4. The model training method according to claim 1, wherein The binding of each of the spatio-temporal feature data to the corresponding core network historical alarm rule data to generate a core network historical alarm data set specifically includes: For each of the core network historical alarm rule data, bind the core network historical alarm rule data to the corresponding spatio-temporal feature data to generate corresponding core network historical alarm training data; Construct the core network historical alarm data set, and add each of the core network historical alarm training data to the core network historical alarm data set.
5. The model training method according to claim 1, wherein The obtaining of a fault warning model, and using the core network historical alarm data set to train and optimize the fault warning model specifically includes: Construct the fault warning model; Divide the core network historical alarm data set to obtain a training set and a validation set; Use the training set to train the fault warning model to obtain a trained fault warning model; Use the validation set to perform model verification on the trained fault warning model to determine the model verification result, and determine whether to continue training the trained fault warning model according to the model verification result.
6. The model training method according to claim 5, wherein The using of the validation set to perform model verification on the trained fault warning model to determine the model verification result, and determining whether to continue training the trained fault warning model according to the model verification result specifically includes: Obtain a preset model verification index; Use the validation set to validate the trained fault warning model, and determine the current index calculation values corresponding to each of the model validation metrics; When the current index calculation values corresponding to each of the model evaluation metrics are all greater than the corresponding index validation thresholds, stop training the trained fault warning model; otherwise, continue to train the trained fault warning model.
7. A core network fault warning method, characterized in that, The method includes the following steps: Obtain a fault warning model, where the fault warning model is trained by the model training method according to any one of claims 1 to 6; Perform dynamic data monitoring on the core network to determine core network abnormal alarm data; Use the fault warning model to perform fault analysis on the core network abnormal alarm data, generate a fault analysis result and issue a warning, where the fault analysis result includes the fault type, fault cause, and fault impact scope.
8. A core network fault warning device, characterized in that, The device includes: A first module for obtaining a fault warning model, where the fault warning model is trained by the model training method according to any one of claims 1 to 6; A second module for performing dynamic data monitoring on the core network to determine core network abnormal alarm data; A third module for using the fault warning model to perform fault analysis on the core network abnormal alarm data, generate a fault analysis result and issue a warning, where the fault analysis result includes the fault type, fault cause, and fault impact scope.
9. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, it implements the model training method according to any one of claims 1 to 6 or the core network fault warning method according to claim 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the model training method according to any one of claims 1 to 6 or the core network fault warning method according to claim 7.