Network scene anomaly detection algorithm based on fault tree and IMS network operation and maintenance
Through the minimum cutting set framework based on the fault tree and random particle simulation, combined with multivariate time series anomaly determination, the accuracy and efficiency of abnormal detection in IMS network operation and maintenance are solved, and high-precision positioning of abnormalities in network scenarios is achieved.
Patent Information
- Application Number
- CN202510538208.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-07-18
AI Technical Summary
The existing IMS network operation and maintenance methods have problems such as large errors, inaccurateness and low accuracy in complex scenarios in abnormal detection. Traditional algorithms such as SNMP and SSH are difficult to effectively detect when there are many abnormalities.
The minimum cutting set framework based on the fault tree is adopted, and random particles are placed in the simulation environment to determine the minimum cutting point, and combined with multivariate time series exception status determination indicators and logical judgment formulas, the precise position and cause of abnormalities in the network scene is achieved.
It improves the accuracy and efficiency of abnormal detection in IMS network operation and maintenance, and can accurately locate abnormal locations and causes in complex network scenarios.
Smart Images

Figure CN120342838A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network operation and maintenance, and particularly to a network scenario anomaly detection algorithm based on a fault tree and IMS network operation and maintenance. Background Art
[0002] As a form of multimedia service network, the IMS network has achieved rapid development in recent years. Due to the characteristics of the IMS network structure, it can simultaneously implement two modes of fixed access and mobile access. To ensure the stability of the IMS network operation, it is essential to implement corresponding operation and maintenance management.
[0003] Traditional methods for detecting network operation and maintenance scenarios include SNMP, Agent, etc. SNMP determines anomalies by detecting data and obtaining parameters, but the parameter values are large, resulting in large errors and inaccurate anomalies. Agent detects communication requests of the system through pre-downloaded scripts and feedbacks the execution results, but this technology has some fluctuations and is also easily affected by the outside world and is not stable. It is proposed to design and construct a fault tree framework of the minimum cut set, set the structure function of the fault tree through mathematical logic, collect the parameters of the minimum cut points, and determine the approximate location of each anomaly point according to the parameter values to find the cause of the anomaly, providing accurate and stable guarantee for eliminating the abnormal state of network operation and maintenance.
[0004] The fault tree framework of the minimum cut set can only show the approximate location of the anomaly, and cannot accurately locate the anomaly and the specific situation of the anomaly, and other algorithms are required for calculation. The traditional method for anomaly analysis of operation and maintenance scenarios is mainly SSH, which is an analysis method based on the SHH protocol. However, the accuracy of this algorithm is greatly reduced in the case of many anomalies and is not applicable in places with complex scenarios and many anomalies.
[0005] Therefore, a network scenario anomaly detection algorithm based on a fault tree and IMS network operation and maintenance is needed to solve the problem of anomaly detection in IMS network operation and maintenance. Summary of the Invention
[0006] Aiming at the deficiencies of the prior art, the present invention provides a network scenario anomaly detection algorithm based on a fault tree and IMS network operation and maintenance. By analyzing the minimum cut points of each fault tree to determine the problem, it simulates the environment to cast random particles around the fault tree, determines the location of the minimum cut points through the particles, thereby realizing the determination of the abnormal location of the network scenario, and improving the efficiency and accuracy.
[0007] Technical Solution: To solve the above technical problems, according to one aspect of the present invention, more specifically, a network scenario anomaly detection algorithm based on a fault tree and IMS network operation and maintenance includes a fault tree framework of the minimum cut set:
[0008] S1. Take an abnormal state in the operation and maintenance scenario as a minimum cut point, and decompose it step by step down to the corresponding cut sets according to the logical relationship of IMS network data transmission, presenting the fault tree of the operation and maintenance scenario in the form of a list of corresponding cut sets.
[0009] S2. Assume that the system conducts a state analysis. Regard the cut set as the minimum set where the fault tree shows an abnormality, and take the basic event set of an abnormal situation occurring in the fault tree as a cut set. According to the different logical relationships of the cut points, list the corresponding events into different minimum cut sets respectively; list the same events into the same minimum cut set, so as to reduce the subsequent system operation volume.
[0010] S3. When a cut set without a new cut point is used as a cut set of the fault tree, the approximate location of the abnormality can be determined. However, to accurately locate the abnormality, subsequent algorithms need to be combined.
[0011] The algorithm design based on IMS network operation and maintenance technology:
[0012] S1. Construct the minimum cut sets of the fault tree, and combine with the IMS network operation and maintenance scenario to complete the construction of the fault tree for abnormal analysis of the IMS network operation and maintenance scenario. When analyzing the abnormal state of the IMS network operation and maintenance scenario, obtain the accurate data and environmental thresholds of the scene to be detected, and determine the time when the abnormality occurs based on the original setting values of the corresponding network.
[0013] S2. Use the method of comparative testing to verify the data in the first step, and take the abnormal state of the multi-variable time series as the judgment index to analyze the detection effect of the designed algorithm. Assume that the load situation of the IMS network is set to the low-load state, representing that the test environment is normal.
[0014] S3. Simulate the environment to drop random particles around the fault tree, so that the particles enter the minimum cut sets in the same row and column, and then determine the position of the minimum cut point. Through this algorithm, calculate and analyze the specific reasons for the abnormality, and achieve the accurate determination of the abnormal position and reasons in the network scenario.
[0015] Furthermore, in the fault tree framework of the minimum cut sets, a logical judgment formula is used to quantitatively analyze the activation state of the cut sets, specifically as follows:
[0016] Define the minimum cut set C i ={e i1 ,e i2 ,…,e in}, where e ij is the jth basic event in the ith cut set, and construct the cut set activation function:
[0017] V represents the logical OR operation. When any event in the cut set is triggered, the cut set is activated;
[0018] w ij ∈ [0, 1] is the event weight coefficient, which is dynamically assigned according to the influence degree of the basic event on the abnormal state, and is determined by training through historical operation and maintenance data or simulated particle optimization algorithm;
[0019] s ij is the event status variable, s ij = 1 indicates that the event occurs, s ij = 0 indicates that the event does not occur; Determine whether the cut set triggers an abnormality through the activation function, and realize the quantitative analysis of the minimum cut points of the fault tree.
[0020] Furthermore, the calculation method of the "abnormal state of multivariate time series as the judgment index" is as follows:
[0021] For each detection index χ κ (t)(κ = 1, 2,..., m), calculate its standardized abnormal value:
[0022]
[0023] where, μ κ is the historical mean of index k, σ κ is the historical standard deviation;
[0024] Construct an abnormal score function:
[0025] α κ is the index weight, satisfying Dynamically adjusted through the simulated particle optimization algorithm (such as the random particle placement described in step S6);
[0026] When S(t)>τ (τ is the preset abnormal threshold), it is determined that there is a network abnormality at the current moment;
[0027] Integrate multi-dimensional indicators through the score function to realize the quantitative determination of the abnormal state in complex network scenarios.
[0028] Furthermore, in the fault tree framework construction step S2 of the minimum cut set, the "listing events into different minimum cut sets according to the difference in the logical relationship of cut points" specifically includes:
[0029] For device type events that cause abnormal states (such as router failures, server outages), divide them into different cut sets according to device type (core device / edge device) or device location (aggregation layer / access layer);
[0030] For link type events (such as bandwidth congestion, signal attenuation), divide them into different cut sets according to link level (backbone link / access link) or transmission protocol (TCP / UDP);
[0031] For events of the same type (such as port failures of devices of the same model), they are included in the same minimal cut set, and the system operation amount is reduced through classification and aggregation.
[0032] Furthermore, in the process of "releasing random particles to determine the position of the minimal cut point" in the simulation environment, the particle release rules satisfy the following conditions:
[0033] Particles are only released in a low-load test environment (such as the low-load state of the IMS network defined in the algorithm based on IMS network operation and maintenance technology) to avoid interference from high-load noise on anomaly location;
[0034] The particle release density is positively correlated with the historical anomaly occurrence frequency of the cut set, that is, the number of particle releases is increased for the cut set with a high historical anomaly probability to improve the detection sensitivity;
[0035] The particle movement trajectory is constrained by the fault tree logic and only propagates on the basic event association path within the cut set to ensure that the positioning result conforms to the IMS network data transmission logic.
[0036] Furthermore, in step S1 of the algorithm based on IMS network operation and maintenance technology, "obtaining accurate data of the scene to be detected" includes real-time collection of the following multi-dimensional data:
[0037] Network device status data: device CPU utilization rate, memory occupancy rate, port traffic rate, firmware version number;
[0038] Link quality data: link packet loss rate, round-trip time (RTT), bit error rate, channel utilization rate;
[0039] Service layer data: IMS session establishment success rate, media stream delay jitter, user complaint frequency;
[0040] Through multi-dimensional data correlation analysis and combined with the minimal cut set of the fault tree, accurate positioning of the abnormal state is achieved.
[0041] The beneficial effects of the network scenario anomaly detection algorithm based on the fault tree and IMS network operation and maintenance of the present invention are as follows:
[0042] (1) The present invention obtains abnormal data through the minimal cut set framework based on the fault tree, draws the fault tree through the structure function, determines the minimal cut point according to the logical relationship of IMS network data transmission, and thus draws the minimal cut set to predict the real-time situation of anomalies. The operation process has low energy consumption and improves stability and efficiency.
[0043] (2) The present invention designs a research on an algorithm based on IMS network operation and maintenance technology, which can accurately locate each minimum cut point in a complex cut set; by casting particles around the minimum cut point on the minimum cut set of the generated scenario anomaly detection fault tree, the exact position and cause of the anomaly can be obtained, improving the accuracy of the anomaly position and cause. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] The present invention will be further described in detail below with reference to the drawings and specific implementation methods.
[0045] Figure 1 It is a schematic structural diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0046] The present invention will be described in detail below with reference to the drawings and embodiments. It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other.
[0047] To make the technical solution of the present invention clearer, the present invention will be further described in detail below with reference to the drawings and specific embodiments.
[0048] Refer to Figure 1 , a network scenario anomaly detection algorithm based on a fault tree and IMS network operation and maintenance, including steps for constructing a fault tree framework of minimum cut sets:
[0049] S1. In an actual IMS network operation and maintenance scenario, when a certain abnormal state is detected, such as excessive network latency, it is set as a minimum cut point. According to the logic of IMS network data transmission, starting from the data sending end and along the data transmission path, relevant network nodes, links and other elements are decomposed level by level to form corresponding cut sets. These cut sets are recorded in a list form to construct a fault tree for the operation and maintenance scenario.
[0050] S2. Analyze the system state to clarify the relationship between the cut set and the fault tree anomaly. For example, in the case of network packet loss anomaly, the basic event set related to network device failures, link quality problems, etc. related to packet loss is used as a cut set. According to the cut point logical relationship, events corresponding to different device failures are included in different minimum cut sets, while events of the same type for different port failures of the same device are included in the same minimum cut set.
[0051] S3. Continuously perform the above operations until no new cut points are generated, and at this time, the approximate location of the anomaly is determined.
[0052] It also includes steps for implementing the algorithm based on IMS network operation and maintenance technology:
[0053] S1. Combine with the actual IMS network operation and maintenance scenario, construct the minimal cut sets of the fault tree, and build an abnormal analysis fault tree. When detecting network anomalies, obtain the real-time data of the network, including bandwidth utilization, signal strength, etc., as well as environmental thresholds, such as the normal bandwidth utilization range, etc. Compare with the original network setting values to determine the time when the anomaly occurs.
[0054] S2. Adopt the comparative test method and set the multi-variable time series abnormal state indicators. In the test environment, set the IMS network load to the low load state to simulate the normal environment. Compare the detection results of the designed algorithm with the actual situation to evaluate the detection effect of the algorithm.
[0055] S3. In the simulation environment, cast random particles around the fault tree. By tracking the movement trajectories of the particles in the minimal cut sets, determine the positions of the minimal cut points. Use the algorithm to deeply analyze relevant data, such as network traffic changes, device logs, etc., and accurately find out the specific reasons for the anomalies, such as network anomalies caused by signal attenuation due to the aging of a certain link.
[0056] Preferably, in the fault tree framework of the minimal cut sets, a logical decision formula is used to quantitatively analyze the activation state of the cut sets. Specifically:
[0057] Define the minimal cut set C i ={e i1 ,e i2 ,…,e in}, where e ij is the j-th basic event in the i-th cut set, and construct the cut set activation function:
[0058] V represents the logical OR operation, and the cut set is activated when any event in the cut set is triggered;
[0059] w ij ∈[0,1] is the event weight coefficient, which is dynamically assigned according to the influence degree of the basic event on the abnormal state, and is determined by training through historical operation and maintenance data or simulated particle optimization algorithm;
[0060] s ij is the event state variable, s ij =1 indicates that the event occurs, s ij =0 indicates that the event does not occur; determine whether the cut set triggers an anomaly through the activation function, and realize the quantitative analysis of the minimal cut point of the fault tree.
[0061] Preferably, the calculation method of the "multi-variable time series abnormal state as the determination index" is:
[0062] For each detection index χ κ(t) (κ = 1, 2,..., m), calculate its standardized outlier value:
[0063]
[0064] where μ κ is the historical mean of index k, and σ κ is the historical standard deviation;
[0065] Construct an anomaly score function:
[0066] α κ is the index weight, satisfying Dynamically adjusted by the simulated particle optimization algorithm (such as the random particle placement described in step S6);
[0067] When S(t) > τ (τ is the preset anomaly threshold), it is determined that there is a network anomaly at the current moment;
[0068] Quantitatively determine the anomaly state in complex network scenarios by integrating multi-dimensional indicators through the described score function.
[0069] Preferably, in step S2 of constructing the fault tree framework of the minimum cut set, the "listing events into different minimum cut sets according to the difference in cut point logical relationships" specifically includes:
[0070] For device type events (such as router failures, server outages) that cause abnormal states, divide them into different cut sets according to device type (core device / edge device) or device location (aggregation layer / access layer);
[0071] For link type events (such as bandwidth congestion, signal attenuation), divide them into different cut sets according to link level (backbone link / access link) or transmission protocol (TCP / UDP);
[0072] For events of the same type (such as port failures of the same model device), list them in the same minimum cut set to reduce the system operation amount through classification aggregation.
[0073] Preferably, in the process of "determining the position of the minimum cut point by placing random particles" in the simulation environment, the particle placement rules meet the following conditions:
[0074] Only place particles in a low-load test environment (such as the low-load state of the IMS network defined in the algorithm based on IMS network operation and maintenance technology) to avoid interference from high-load noise on anomaly location;
[0075] The particle placement density is positively correlated with the historical anomaly occurrence frequency of the cut set, that is, increase the particle placement quantity for the cut set with a high historical anomaly probability to improve the detection sensitivity;
[0076] The particle motion trajectory is constrained by the fault tree logic and only propagates along the basic event association paths within the cut set, ensuring that the positioning result conforms to the IMS network data transmission logic.
[0077] Preferably, in the algorithm step S1 based on the IMS network operation and maintenance technology, "obtaining accurate data of the scene to be detected" includes real-time collection of the following multi-dimensional data:
[0078] Network device status data: device CPU utilization rate, memory occupancy rate, port traffic rate, firmware version number;
[0079] Link quality data: link packet loss rate, round-trip time (RTT), bit error rate, channel utilization rate;
[0080] Service layer data: IMS session establishment success rate, media stream delay jitter, user complaint frequency;
[0081] Through multi-dimensional data correlation analysis and in combination with the minimum cut set of the fault tree, accurate positioning of the abnormal state is achieved.
[0082] The above embodiments only represent several implementation manners of the present invention, and the description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the present invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several deformations and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the present invention patent shall be subject to the appended claims.
Claims
1. Network scenario anomaly detection algorithm based on fault tree and IMS network operation and maintenance, including the fault tree framework of the minimum cut set, characterized in that: The construction steps of the fault tree framework of the minimum cut set are as follows: S1. Select an abnormal state in the operation and maintenance scenario as the minimum cut point, and decompose the abnormal state step by step downward according to the IMS network data transmission logic to form the corresponding cut sets, and construct a fault tree in the form of a cut set list; S2. Set the system state analysis rule, define the cut set as the minimum set of abnormal conditions of the fault tree, regard the basic event set of a single abnormal condition of the fault tree as a cut set, and according to the differences in the logical relationships of the cut points, list the corresponding events into different minimum cut sets respectively, and list the same events into the same minimum cut set to reduce the system operation volume; S3. Continuously perform the above operations until the cut set without new cut points appears as the cut set of the fault tree, so as to determine the approximate location of the abnormality.
2. The network scenario anomaly detection algorithm based on a fault tree and IMS network operation and maintenance according to claim 1, wherein: The design steps of the algorithm based on IMS network operation and maintenance technology are as follows: S4. Construct multiple minimum cut sets of the fault tree, and combine the actual situation of the IMS network operation and maintenance scenario to build a fault tree for abnormality analysis. When analyzing the abnormal state, obtain the accurate data and environmental thresholds of the scene to be detected, compare with the original network setting values, and determine the time of occurrence of the abnormality; S5. Use the comparison test method to verify the data, use the abnormal state of the multi-variable time series as the judgment index, evaluate the detection effect of the designed algorithm, and set the low-load state of the IMS network to represent the normal test environment; S6. Put random particles around the fault tree in the simulation environment, let the particles enter the minimum cut sets in the same row and column, determine the position of the minimum cut point, and through algorithm analysis and calculation, clarify the specific cause of the abnormality, and realize the accurate determination of the abnormal position and cause in the network scenario. In the design process of the fault tree framework of the minimum cut set, the structure function algorithm is used to calculate the minimum cut sets in the cut sets of the fault tree to eliminate the influence of interference factors on the detection results of the cut points.
3. The network scenario anomaly detection algorithm based on fault tree and IMS network operation and maintenance according to claim 2, characterized in that: In the design steps of the algorithm based on IMS network operation and maintenance technology, when constructing the minimum cut sets of the fault tree, the actual factors such as the network device status and link quality in the IMS network operation and maintenance scenario are fully considered.
4. The network scenario anomaly detection algorithm based on a fault tree and IMS network operation and maintenance according to claim 3, characterized in that: In the fault tree framework of the minimum cut set, the activation state of the cut set is quantitatively analyzed using a logical decision formula. Specifically: Define the minimum cut set C i ={e i1 ,e i2 ,…,e in}, where e ij is the j-th basic event in the i-th cut set, and construct the cut set activation function: V represents the logical OR operation, and the cut set is activated when any event in the cut set is triggered; w ij ∈ [0, 1] is the event weight coefficient, which is dynamically assigned according to the influence degree of the basic event on the abnormal state and determined by training with historical operation and maintenance data or simulated particle optimization algorithm; s ij is an event status variable, s ij = 1 indicates that the event has occurred, s ij = 0 indicates that the event has not occurred; determining whether the cut set triggers an exception through the activation function to achieve quantitative analysis of the minimum cut points of the fault tree.
5. The network scenario anomaly detection algorithm based on a fault tree and IMS network operation and maintenance according to claim 2, characterized in that: The calculation method of the "abnormal state of the multi-variable time series as the judgment index" is as follows: For each detection index χ κ (t)(κ = 1, 2,..., m), calculate its standardized outlier value: where μ κ is the historical mean of index k, and σ κ is the historical standard deviation; Construct an anomaly score function: α κ is the index weight, satisfying dynamically adjusted by the simulated particle optimization algorithm; When S(t)>τ (τ is the preset abnormal threshold), it is determined that there is a network abnormality at the current moment; The score function is used to synthesize multi-dimensional indexes to realize the quantitative determination of the abnormal state in complex network scenarios.
6. The network scenario abnormality detection algorithm based on the fault tree and IMS network operation and maintenance according to claim 1, characterized in that: In step S2 of the construction of the fault tree framework of the minimum cut set, the "listing events into different minimum cut sets according to the differences in the logical relationships of the cut points" specifically includes: For device type events that cause abnormal states, they are divided into different cut sets according to device types or device locations; For link type events, they are divided into different cut sets according to link levels or transmission protocols; For events of the same type, they are listed into the same minimum cut set, and the system operation volume is reduced through classification and aggregation.
7. The network scenario abnormality detection algorithm based on the fault tree and IMS network operation and maintenance according to claim 2, characterized in that: In the process of "determining the position of the minimum cut point by randomly releasing particles" in the simulation environment, the particle release rules satisfy the following conditions: Particles are only released in a low-load test environment to avoid interference from high-load noise on anomaly localization; The particle release density is positively correlated with the historical anomaly occurrence frequency of the cut set, that is, the number of particles released is increased for the cut set with a high historical anomaly probability to improve the detection sensitivity; The particle movement trajectory is restricted by the fault tree logic and only propagates on the basic event association path within the cut set to ensure that the positioning result conforms to the IMS network data transmission logic.
8. The network scenario anomaly detection algorithm based on the fault tree and IMS network operation and maintenance according to claim 2, characterized in that: In the algorithm step S1 based on the IMS network operation and maintenance technology, "obtaining accurate data of the scene to be detected" includes real-time collection of the following multi-dimensional data: Network device status data: device CPU utilization rate, memory occupancy rate, port traffic rate, firmware version number; Link quality data: link packet loss rate, round-trip time, bit error rate, channel utilization rate; Service layer data: IMS session establishment success rate, media stream delay jitter, user complaint frequency; Through multi-dimensional data correlation analysis and combined with the minimum cut set of the fault tree, accurate positioning of the abnormal state is achieved.