Gateway alarm management method and system in distributed network environment

By analyzing the historical alarm data and communication processing data of gateway equipment, and formulating differentiated processing strategies, the problem of low recognition and processing efficiency of multiple gateway equipment in distributed networks is solved, and efficient operation and maintenance management is achieved.

CN120342842AActive Publication Date: 2025-07-18HANGZHOU GREEN OLIVE INTERNET OF THINGS TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510813298.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-07-18
Estimated Expiration
2045-06-18

AI Technical Summary

Technical Problem

In a distributed network environment, when multiple gateway devices alert at the same time, the identification and processing efficiency of the false alarm device is difficult to meet the requirements, resulting in difficulty in operation and maintenance management.

Method used

By analyzing the historical alarm data of the gateway device, determining the impact period of false alarms and the degree of interference of false alarm data, and formulating differentiated processing strategies based on the similarity and quantity of communication processing data of the false alarm device to optimize the analysis and processing of alarm signals.

Benefits of technology

It improves the efficiency of identification and processing of false alarms of gateway equipment, avoids the problem of untimely analysis and processing caused by false alarms, and improves the efficiency of operation and maintenance management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342842A_ABST
    Figure CN120342842A_ABST
Patent Text Reader

Abstract

The invention provides a gateway alarm management method and system in a distributed network environment, and belongs to the technical field of alarm management, and the method specifically comprises the steps: taking gateway equipment of which the false alarm frequency does not meet the requirement as target gateway equipment; according to the similar situation of communication processing data when different target gateway devices have false alarm data and the number of the target gateway devices, determining processing strategies when the different target gateway devices give alarms, and taking the gateway devices adopting a preset processing strategy as screening gateway devices, when the number of the screening gateway devices does not meet the requirement, the processing strategy when the screening gateway devices give alarms in different time periods is determined according to the matching conditions of the historical communication data of the false alarm matching intervals of the different screening gateway devices in the different time periods, and the troubleshooting processing efficiency of the alarm signals in the simultaneous alarm time periods is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of alarm management, and particularly relates to a gateway alarm management method and system in a distributed network environment. Background Art

[0002] In a distributed network environment, gateways are relatively dispersed. Therefore, once a gateway alarm occurs, especially when there are multiple gateway alarms, it often makes the operation and maintenance personnel overwhelmed and difficult to effectively implement the operation and maintenance management of gateway devices in a timely manner.

[0003] Therefore, to solve the above technical solutions, in the prior art solutions, gateway devices automatically send alarm information to the terminal management platform, and the alarm information reported by each gateway device is analyzed and compared on the terminal management platform to judge the line fault of the gateway device. However, there are the following technical problems: In a distributed network environment, when there are multiple gateway devices with alarms at the same time, there is also the technical problem of great difficulty in operation and maintenance management. Especially when there are mis-alarm devices, the recognition and processing efficiency of alarmed gateway devices may be difficult to meet the requirements. Therefore, this makes it an urgent technical problem to generate differentiated alarm management and processing strategies in different time periods according to the mis-alarm probability and distribution data of mis-alarm devices in different time periods, so as to improve the operation and maintenance processing efficiency of gateway devices.

[0004] To solve the above technical problems, the present application provides a gateway alarm management method and system in a distributed network environment. Summary of the Invention

[0005] To achieve the object of the present invention, the present invention adopts the following technical solutions: Specifically, the present application provides a gateway alarm management method in a distributed network environment, which specifically includes: S1: According to the historical alarm data of gateway devices in a distributed network environment, determine the simultaneous alarm time periods of the gateway devices, and determine the mis-alarm influence time periods in the simultaneous alarm time periods according to the deviation of the mis-alarm data of the gateway devices in different simultaneous alarm time periods from that in other simultaneous alarm time periods; S2: When the interference degree of the mis-alarm data does not meet the requirements based on the distribution data of the mis-alarm influence time periods on different dates and the alarm data of the gateway devices in different mis-alarm influence time periods, proceed to the next step; S3: Take the gateway devices with the number of mis-alarms not meeting the requirements as target gateway devices, and determine the processing strategies when different target gateway devices have alarms according to the similarity of the communication processing data of different target gateway devices when there is mis-alarm data and the number of target gateway devices; S4 will use the target gateway device with a preset processing strategy as the screening gateway device. When the number of screening gateway devices does not meet the requirements, the processing strategy when the screening gateway device generates an alarm in different time periods is determined based on the matching of the false alarm matching intervals of different screening gateway devices with the historical communication data in different time periods.

[0006] The beneficial effects of the present invention are: Based on the similar situations of communication processing data of different gateway devices when false alarm data exists and the number of gateway devices, the processing strategies of different gateway devices when alarms occur are determined, thereby realizing the evaluation of the degree of obviousness of the characteristics of the communication traffic when false alarms occur from the perspective of the similar situations of the communication processing data. At the same time, further combined with the number of gateway devices, it is possible to evaluate the analysis and processing requirements of different gateway devices when alarms occur from the perspective of the deviation degree of the false alarm communication traffic and the number of gateway devices, thereby ensuring the efficiency of the analysis and processing of the alarm signal.

[0007] According to the matching of false alarm matching intervals of different screening gateway devices with historical communication data in different time periods, the processing strategies when the screening gateway devices generate alarms in different time periods are determined, thereby avoiding the technical problem of untimely parsing and processing of the alarm data of the gateway devices when there are a large number of screening gateway devices. By combining the matching of false alarm matching intervals with historical communication data, the screening of screening gateway devices with a high probability of generating false alarms at the same time is achieved, and the processing strategies are updated in a targeted manner, thereby improving the efficiency of identifying and processing the alarm data.

[0008] A further technical solution is that the historical alarm data includes the historical alarm times of different gateway devices and the alarm time periods corresponding to the different historical alarm times.

[0009] A further technical solution is that the simultaneous alarm period is a period during which more than a target number of gateway devices alarm simultaneously.

[0010] A further technical solution is that the value of the target number is 3.

[0011] A further technical solution is that the false alarm data of the gateway device includes the number of gateway devices that give false alarms in the simultaneous alarm period.

[0012] A further technical solution is that the method for determining the false alarm influence period in the simultaneous alarm period is: Determine the gateway device of the false alarm in the simultaneous alarm period based on the false alarm data of the gateway device in the simultaneous alarm period, and use it as the false alarm device; According to the deviation situation between the false alarm device and other simultaneous alarm periods, determine the same number of false alarm devices in other simultaneous alarm periods and the false alarm devices in the simultaneous alarm devices, and take the maximum value of the same number of false alarm devices in other simultaneous alarm periods as the maximum value of the same number; Determine whether the simultaneous alarm period is a false alarm impact period through the maximum value of the same number and the false alarm devices in the simultaneous alarm period.

[0013] A further technical solution lies in that determining whether the simultaneous alarm period is a false alarm impact period through the maximum value of the same number and the false alarm devices in the simultaneous alarm period specifically includes: Take the difference between the number of false alarm devices in the simultaneous alarm period and the maximum value of the same number as the quantity difference; When the quantity difference is greater than the preset difference threshold, determine that the simultaneous alarm period is a false alarm impact period.

[0014] A further technical solution lies in that the method for determining the processing strategy when the gateway device issues an alarm is: Determine the communication processing data volume in different false alarm periods based on the false alarm periods of different gateway devices; According to the similarity of the communication processing data volume between different false alarm periods, divide the false alarm periods into different communication processing data volume intervals, and take the communication processing data volume interval with the most false alarm periods as the false alarm matching interval; Determine the processing strategy when the gateway device issues an alarm through the proportion of the false alarm periods in the false alarm matching interval in the number of false alarm periods of the gateway device and the number of gateway devices.

[0015] A further technical solution lies in that determining the processing strategy when the gateway device issues an alarm through the proportion of the false alarm periods in the false alarm matching interval in the number of false alarm periods of the gateway device and the number of gateway devices specifically includes: When the number of gateway devices is less than the preset device number threshold, ignore the alarms when different gateway devices issue alarms until the alarm duration is greater than the preset alarm duration, and then perform fault troubleshooting; When the number of gateway devices is not less than the preset device number threshold, take the proportion of the false alarm periods in the false alarm matching interval in the number of false alarm periods of the gateway device as the false alarm signal matching value of the gateway device, and determine the processing strategy when the gateway device issues an alarm based on the false alarm signal matching value.

[0016] A further technical solution lies in determining a processing strategy when the gateway device issues an alarm based on the false alarm signal matching value, specifically including: When the false alarm signal matching value of the gateway device is greater than a preset matching threshold, it is determined whether neglect processing is required by analyzing the communication processing data volume of the gateway device when the gateway device issues an alarm; When the false alarm signal matching value of the gateway device is not greater than the preset matching threshold, neglect processing is performed when the gateway device issues an alarm, and troubleshooting processing is performed until the alarm duration is greater than the preset alarm duration.

[0017] A further technical solution lies in that the preset processing strategy is to determine whether neglect processing is required by analyzing the communication processing data volume of the gateway device when the gateway device issues an alarm.

[0018] In a second aspect, the present invention provides a computer system, including: a memory and a processor connected by communication, and a computer program stored on the memory and capable of running on the processor. When the processor runs the computer program, it executes the above-mentioned method for managing gateway alarms in a distributed network environment.

[0019] Other features and advantages will be described in the following specification. The objectives and other advantages of the present invention are achieved and obtained by the structures specifically pointed out in the specification and the drawings.

[0020] To make the above objectives, features, and advantages of the present invention more obvious and understandable, the following specific preferred embodiments are given in conjunction with the accompanying drawings and described in detail as follows. Description of the Drawings

[0021] By referring to the drawings and describing its exemplary embodiments in detail, the above and other features and advantages of the present invention will become more obvious.

[0022] Figure 1 is a flowchart of a method for managing gateway alarms in a distributed network environment; Figure 2 is a flowchart of a method for determining the false alarm impact period in the simultaneous alarm period; Figure 3 is a flowchart for determining that the interference degree of false alarm data does not meet the requirements; Figure 4 is a flowchart of a method for determining the gateway device in the gateway device; Figure 5 is a framework diagram of a computer system. Detailed Embodiments

[0023] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. Based on the embodiments of this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this specification.

[0024] In this application, by considering the similarity of communication processing data when a gateway device generates false alarms and the number of gateway devices, the gateway device with obvious characteristics of communication processing data when a false alarm occurs in the gateway device is determined, and then a differentiated alarm processing strategy is determined, thereby improving the processing efficiency of the alarm device.

[0025] The false alarm impact period is the simultaneous alarm period when the number of alarms of the gateway device is more than 3 and is inconsistent with the false alarms of other gateway devices in the simultaneous alarm period.

[0026] The gateway device with false alarms is a gateway device that does not have an abnormality but generates false alarms due to errors caused by delays in communication data under circumstances such as a large amount of communication data.

[0027] When there is a false alarm impact period in each date, it is determined that the interference degree of the false alarm data does not meet the requirements.

[0028] The target gateway device is a gateway device whose number of false alarms is greater than the preset false alarm number threshold.

[0029] Determine the communication processing data volume in different false alarm periods based on the false alarm periods of different target gateway devices. According to the similarity of the communication processing data volume between different false alarm periods, divide the false alarm periods into different communication processing data volume intervals, and take the communication processing data volume interval with the most false alarm periods as the false alarm matching interval. When the number of the target gateway devices is less than the preset device number threshold, ignore the alarms when different target gateway devices generate alarms until the alarm duration is greater than the preset alarm duration, and then perform fault troubleshooting. When the number of the target gateway devices is not less than the preset device number threshold, take the proportion of the false alarm periods in the false alarm matching interval in the number of false alarm periods of the gateway device as the false alarm signal matching value of the target gateway device, and determine the processing strategy when the target gateway device generates an alarm based on the false alarm signal matching value.

[0030] The preset processing strategy is to determine whether to perform an ignore process by analyzing the communication processing data volume of the target gateway device when the target gateway device generates an alarm.

[0031] When the number of screened gateway devices is greater than the preset threshold of the number of screened gateway devices, it is determined that the number of the screened gateway devices does not meet the requirements.

[0032] The false alarm matching interval is the interval of the communication processing data volume with the most false alarm time periods.

[0033] Taking the historical moments when the historical communication data in a time period falls into the false alarm matching interval of the target alarm device as the alarm risk moments, and taking the screened gateway devices with the number of alarm risk moments greater than the risk moment number threshold as the risk alarm devices.

[0034] When the number of risk alarm devices in a time period is not greater than a certain threshold, that is, less than 6, then for all screened alarm devices, a preset processing strategy is adopted for fault troubleshooting. When the number of risk alarm devices in the time period is relatively large, that is, greater than 6, at this time, if the number of alarmed gateway devices is greater than the preset device number, then for all screened alarm devices, a preset processing strategy is adopted for fault troubleshooting. If the number of alarmed gateway devices is not greater than the preset device number, then the alarm signals of the screened alarm devices with the false alarm signal matching value less than the matching preset value are immediately subjected to fault troubleshooting, and the others are subjected to fault troubleshooting using the preset processing strategy.

[0035] Embodiment 1 As Figure 1 shown, the present application provides a method for gateway alarm management in a distributed network environment, which specifically includes: S1. According to the historical alarm data of the gateway devices in the distributed network environment, determine the simultaneous alarm time periods of the gateway devices, and determine the false alarm influence time periods in the simultaneous alarm time periods according to the deviation of the false alarm data of the gateway devices in different simultaneous alarm time periods from that of other simultaneous alarm time periods; Further, the historical alarm data includes the historical alarm times of different gateway devices and the alarm time periods corresponding to different historical alarm times.

[0036] Specifically, the simultaneous alarm time period is the time period when there are more than a target number of gateway devices alarmed simultaneously.

[0037] Further, the value of the target number is 3.

[0038] It should be noted that the false alarm data of the gateway devices includes the number of gateway devices with false alarms in the simultaneous alarm time period.

[0039] Specifically, as Figure 2 shown, the method for determining the false alarm influence time period in the simultaneous alarm time period is: Determine the gateway devices with false alarms during the simultaneous alarm period based on the false alarm data of the gateway devices during the simultaneous alarm period, and use them as false alarm devices; Based on the deviation of the false alarm devices from other simultaneous alarm periods, determine the same number of false alarm devices in other simultaneous alarm periods and the false alarm devices in the simultaneous alarm period, and use the maximum value of the same number of false alarm devices in other simultaneous alarm periods as the maximum value of the same number; Based on the maximum value of the same number and the false alarm devices during the simultaneous alarm period, determine whether the simultaneous alarm period is a false alarm impact period.

[0040] Furthermore, based on the maximum value of the same number and the false alarm devices during the simultaneous alarm period, determining whether the simultaneous alarm period is a false alarm impact period specifically includes: Use the difference between the number of false alarm devices during the simultaneous alarm period and the maximum value of the same number as the quantity difference; When the quantity difference is greater than the preset difference threshold, determine that the simultaneous alarm period is a false alarm impact period.

[0041] It can be understood that when there is no false alarm impact period, ignore the gateway devices with false alarm times greater than the preset false alarm times threshold until the alarm duration is greater than the preset alarm duration, and then perform fault troubleshooting on the alarm signals, and perform real-time fault troubleshooting on the alarm signals of the remaining gateway devices.

[0042] In another possible embodiment, the method for determining the false alarm impact period during the simultaneous alarm period is: Determine the gateway devices with false alarms during the simultaneous alarm period based on the false alarm data of the gateway devices during the simultaneous alarm period, and use them as false alarm devices; Based on the deviation of the false alarm devices from other simultaneous alarm periods, determine the same number of false alarm devices in other simultaneous alarm periods and the false alarm devices in the simultaneous alarm period, and use it as the false alarm same number; Determine the false alarm similarity value of other simultaneous alarm periods through the ratio of the false alarm same number of other simultaneous alarm periods to the number of false alarm devices during the simultaneous alarm period, and determine whether the simultaneous alarm period is a false alarm impact period based on the false alarm similarity value of other simultaneous alarm periods.

[0043] It should be noted that when the number of other simultaneous alarm periods with false alarm similarity values greater than the preset similarity threshold is less than the preset alarm period quantity threshold, determine that the simultaneous alarm period belongs to the false alarm impact period.

[0044] In another possible embodiment, the method for determining the false alarm impact period in the simultaneous alarm period is as follows: S11 Use the false alarm data of the gateway device in the simultaneous alarm period to determine the gateway devices with false alarms in the simultaneous alarm period, and regard them as false alarm devices, and determine the number of false alarms of different false alarm devices in other simultaneous alarm periods; It should be noted that before proceeding to the next step, it is also necessary to further determine whether there are false alarm devices in the simultaneous alarm period, whether the number of false alarm devices and the proportion of the number of false alarm devices meet the requirements, and whether the number of false alarm devices with fewer false alarms in other simultaneous alarm periods, that is, less than the number threshold, meets the requirements. Specifically, it is determined whether the threshold meets the requirements.

[0045] It can be understood that if there are no false alarm devices in the simultaneous alarm period, it can be directly determined that the simultaneous alarm period does not belong to the false alarm response period. Only when there are false alarm devices, it is necessary to determine whether the number of false alarm devices and the proportion of the number of false alarm devices meet the requirements.

[0046] When the number of false alarm devices and the proportion of the number of alarm gateway devices of the false alarm devices in the simultaneous alarm period are both large, that is, do not meet the requirements, then because the number of false alarm devices is large, it can be determined that the simultaneous alarm period belongs to the false alarm response period.

[0047] In addition, when the number of false alarm devices is small, the number of false alarm devices with fewer false alarms in other simultaneous alarm periods, that is, less than the number threshold, does not meet the requirements, that is, the number is greater than a certain threshold, then because the deviation degree from the false alarm devices in other simultaneous alarm periods is large, it can be determined that the simultaneous alarm period belongs to the false alarm impact period. In other cases, the number of false alarm devices in other simultaneous alarm periods that is the same as the number of false alarm devices of the simultaneous alarm devices is determined.

[0048] S12 Determine the number of false alarm devices in other simultaneous alarm periods that is the same as the number of false alarm devices of the simultaneous alarm devices according to the deviation of the false alarm devices from other simultaneous alarm periods; It can be understood that in the above step S12, it is also necessary to further determine the number of false alarm devices in other simultaneous alarm periods that is the same as the number of false alarm devices of the simultaneous alarm devices, and regard it as the same number of false alarms. When the same number of false alarms in different other simultaneous alarm periods are all small, that is, less than a certain threshold, then because the deviation degree from the false alarm devices in other simultaneous alarm periods is large, it can be determined that the simultaneous alarm period belongs to the false alarm impact period.

[0049] In other cases, the false alarm similarity value of other simultaneous alarm periods is determined by the ratio of the same number of false alarms in other simultaneous alarm periods to the number of false alarm devices in the simultaneous alarm period. Specifically, if the number of other simultaneous alarm periods with a false alarm similarity value greater than the preset similarity threshold is less than the preset alarm period quantity threshold, it is determined that the simultaneous alarm period belongs to the false alarm impact period. When there are a large number of other simultaneous alarm periods with a false alarm similarity value greater than the preset similarity threshold, that is, when the quantity is within the preset quantity range, it can be determined that the simultaneous alarm period does not belong to the false alarm impact period. When the quantity is not within the preset quantity range, the false alarm impact value is determined again.

[0050] S13 determines the false alarm impact value of the simultaneous alarm period through the same number of false alarm devices of other simultaneous alarm periods and the false alarm devices of the simultaneous alarm devices, the number of false alarm occurrences of different false alarm devices in other simultaneous alarm periods, and the number of false alarm devices in the simultaneous alarm period, and determines whether the simultaneous alarm period is a false alarm impact period based on the false alarm impact value.

[0051] Specifically, the false alarm impact value of the simultaneous alarm period can be determined by inputting the input quantity composed of the same number of false alarm devices of other simultaneous alarm periods and the false alarm devices of the simultaneous alarm devices, the number of false alarm occurrences of different false alarm devices in other simultaneous alarm periods, and the number of false alarm devices in the simultaneous alarm period into a mathematical model based on the analytic hierarchy process.

[0052] At this time, it can be understood that in one of the embodiments, if the false alarm impact value is greater than the preset impact threshold, at this time, not only is the number of false alarm devices large and there is a deviation from the false alarm devices in other simultaneous alarm periods, so it can be determined that it belongs to the false alarm impact period.

[0053] S2, based on the distribution data of the false alarm impact periods on different dates, and combining the alarm data of the gateway devices in different false alarm impact periods, when it is determined that the interference degree of the false alarm data does not meet the requirements, proceed to the next step; Specifically, as Figure 3 shown, determining that the interference degree of the false alarm data does not meet the requirements specifically includes: According to the alarm data of the gateway devices in different false alarm impact periods, determine the number of gateway devices with alarms in different false alarm impact periods, and use it as the number of alarm devices, and use the false alarm impact period with the number of alarm devices greater than the alarm device quantity threshold as the analysis difficulty period; Based on the distribution data of the analysis difficulty periods on different dates, determine the dates with analysis difficulty periods, and use them as the false alarm dates; Determine whether the interference degree of the false alarm data meets the requirements based on the number of false alarm dates.

[0054] Further, when the number of false alarm dates is greater than the preset alarm date number threshold, it is determined that the interference degree of the false alarm data does not meet the requirements.

[0055] It can be understood that when the interference degree of the false alarm data meets the requirements, the gateway devices with the number of false alarms greater than the preset false alarm number threshold are ignored until the alarm duration is greater than the preset alarm duration, and then the fault troubleshooting of the alarm signal is carried out. For the alarm signals of the remaining gateway devices, the fault troubleshooting is carried out in real time.

[0056] S3 Obtain the similarity of the communication processing data when different target gateway devices have false alarm data, and combine the number of the target gateway devices to determine the processing strategy when different target gateway devices generate alarms.

[0057] Specifically, the target gateway device is a gateway device with the number of false alarms greater than the preset false alarm number threshold.

[0058] Further, the method for determining the processing strategy when the target gateway device generates an alarm is as follows: Determine the communication processing data volume in different false alarm time periods based on the false alarm time periods of different target gateway devices; According to the similarity of the communication processing data volume between different false alarm time periods, divide the false alarm time periods into different communication processing data volume intervals, and take the communication processing data volume interval with the most false alarm time periods as the false alarm matching interval; Determine the processing strategy when the target gateway device generates an alarm based on the proportion of the number of false alarm time periods in the false alarm matching interval in the number of false alarm time periods of the target gateway device and the number of gateway devices.

[0059] It should be noted that the false alarm time period is the time period when the target gateway device has false alarm data.

[0060] It can be understood that determining the processing strategy when the target gateway device generates an alarm based on the proportion of the number of false alarm time periods in the false alarm matching interval in the number of false alarm time periods of the target gateway device and the number of target gateway devices specifically includes: When the number of the target gateway devices is less than the preset device number threshold, ignore the alarms when different target gateway devices generate alarms until the alarm duration is greater than the preset alarm duration, and then carry out the fault troubleshooting. When the number of the target gateway devices is not less than a preset device number threshold, the proportion of the false alarm time periods in the false alarm matching interval in the number of false alarm time periods of the gateway devices is used as the false alarm signal matching value of the gateway devices, and a processing strategy when the gateway devices generate alarms is determined based on the false alarm signal matching value.

[0061] It should be further noted that determining the processing strategy when the target gateway devices generate alarms based on the false alarm signal matching value specifically includes: When the false alarm signal matching value of the target gateway devices is greater than a preset matching threshold, when the target gateway devices generate alarms, determine whether neglect processing is required by analyzing the communication processing data volume of the gateway devices; When the false alarm signal matching value of the target gateway devices is not greater than the preset matching threshold, perform neglect processing until the alarm duration is greater than the preset alarm duration, and then perform fault troubleshooting processing on the alarm signal.

[0062] In another possible embodiment, the method for determining the processing strategy when the target gateway devices generate alarms is as follows: S31 Obtain the number of the target gateway devices, and determine the communication processing data volume in different false alarm time periods based on the false alarm time periods of different target gateway devices; It should be noted that before proceeding to the next step, it is necessary to determine whether the number of target gateway devices meets the requirements. Specifically, when the number of target gateway devices is less than the preset device number threshold, since the number of target gateway devices is small at this time, neglect processing is performed when different target gateway devices generate alarms until the alarm duration is greater than the preset alarm duration, and then fault troubleshooting processing is performed, which will not have a great impact on the reliability of the overall fault signal troubleshooting.

[0063] Only when the number of target gateway devices is not less than the preset device number threshold, the number of target gateway devices is large at this time, so it is necessary to perform the specificity of the signal characteristics when different target gateway devices generate false alarms, and determine the differential processing strategy when alarms are generated.

[0064] S32 According to the similarity of the communication processing data volume between different false alarm time periods, divide the false alarm time periods into different communication processing data volume intervals, take the communication processing data volume interval with the most false alarm time periods as the false alarm matching interval, and determine the false alarm signal matching value of the target gateway devices according to the proportion of the false alarm time periods in the false alarm matching interval in the number of false alarm time periods of the target gateway devices; It can be understood that in the above steps, it is necessary to determine whether the false alarm signal matching value of the target gateway device meets the requirements. Specifically, when the false alarm signal matching value of the target gateway device is relatively large, that is, greater than the preset threshold, since the characteristics of its false alarm are obvious, it is possible to directly determine whether to perform an ignoring process by analyzing the communication processing data volume of the target gateway device when the target gateway device issues an alarm. Specifically, when the communication processing data volume falls within the communication processing data interval with the largest amount during the false alarm period, an ignoring process is performed on it.

[0065] In addition, it should be noted that when the false alarm signal matching value is relatively small, that is, less than the fixed threshold, since the characteristics of its false alarm are not obvious, an ignoring process is performed until the alarm duration is greater than the preset alarm duration, and then a fault troubleshooting process for the alarm signal is carried out.

[0066] Only when the false alarm signal matching value is neither relatively small nor relatively large, that is, within a certain range, will it proceed to the next step.

[0067] S33 determines the sorting result of the false alarm signal matching value of the target gateway device among different target gateway devices through the false alarm signal matching values of different target gateway devices, and combines the number of the target gateway devices and the false alarm signal matching values of the target gateway devices to determine the recognition matching value of the false alarm signal of the target gateway device, and determines the processing strategy when the target gateway device issues an alarm based on the recognition matching value.

[0068] In addition, it should be noted that when the sorting result of the false alarm signal matching value among the target gateway devices is before the target position, that is, within 5, it is determined that the processing strategy when the target gateway device issues an alarm is to determine whether to perform an ignoring process by analyzing the communication processing data volume of the gateway device when the target gateway device issues an alarm. Specifically, when the communication processing data volume is within the false alarm matching interval, the alarm signal is directly ignored until the alarm duration is greater than the preset alarm duration, and then a fault troubleshooting process is carried out. In other cases, a troubleshooting process for the alarm signal is directly carried out.

[0069] In addition, if the sorting result is not before the target position, it is also necessary to further determine the recognition matching value of the false alarm signal of the target gateway device. Specifically, it is determined according to the output result of an expert scoring model with the sorting result of the false alarm signal matching value of the target gateway device among the target gateway devices, the number of the target gateway devices, and the false alarm signal matching value of the target gateway device as input quantities.

[0070] Specifically, if the recognized matching value is above 0.6, then it is determined that the processing strategy when the target gateway device issues an alarm is to determine whether to perform an ignoring process by analyzing the communication processing data volume of the gateway device when the target gateway device issues an alarm. When it is 0.6 or below 0.6, an ignoring process is performed until the alarm duration is greater than the preset alarm duration, and then a fault troubleshooting process for the alarm signal is carried out.

[0071] S4 uses the target gateway device adopting the preset processing strategy as the screened gateway device. When the number of screened gateway devices does not meet the requirements, according to the matching situation of the historical communication data of different screened gateway devices in the false alarm matching interval at different time periods, the processing strategy when the screened gateway device issues an alarm at different time periods is determined.

[0072] Specifically, the preset processing strategy is to determine whether to perform an ignoring process by analyzing the communication processing data volume of the target gateway device when the target gateway device issues an alarm.

[0073] Furthermore, when the number of screened gateway devices is greater than the preset screened gateway device quantity threshold, it is determined that the number of screened gateway devices does not meet the requirements.

[0074] It can be understood that when the number of screened gateway devices meets the requirements, then in different time periods, it is determined whether to perform an ignoring process by analyzing the communication processing data volume of the gateway device. Specifically, when the communication processing data volume falls within the false alarm matching interval of the screened gateway device, an ignoring process is performed.

[0075] It should be noted that the false alarm matching interval is the communication processing data volume interval with the most false alarm time periods.

[0076] Specifically, the method for determining the processing strategy when the screened gateway device issues an alarm is as follows: Based on the matching situation of the historical communication data of the false alarm matching interval of the screened gateway device in the time period, determine the historical moment when the historical communication data in the time period falls into the false alarm matching interval, and use it as the alarm risk moment; Determine the risk alarm devices in the screened gateway device according to the number of alarm risk moments; Through the number of risk alarm devices in the time period, determine the processing strategy when different screened gateway devices issue alarms in the time period.

[0077] It can be understood that the risk alarm device is the screened gateway device with a relatively large number of alarm risk moments. Specifically, the screened gateway device with the number of alarm risk moments greater than the risk moment quantity threshold is used as the risk alarm device.

[0078] In addition, it should be noted that the processing strategy when different screening gateway devices issue alarms during the period is determined according to the number of risk alarm devices in the period, specifically including: When the number of risk alarm devices in the period is small, that is, not greater than a certain threshold, a preset processing strategy is adopted for all screening alarm devices to conduct fault troubleshooting; When the number of risk alarm devices in the period is large, that is, greater than a certain threshold, and at this time if the number of gateway devices with alarms is greater than the preset device number, a preset processing strategy is adopted for all screening alarm devices to conduct fault troubleshooting; In a possible embodiment, if the number of gateway devices with alarms is not greater than the preset device number, the alarm quantity threshold corresponding to different gateway devices is determined according to the false alarm signal matching value of different gateway devices, where the alarm quantity threshold and the false alarm signal matching value are determined according to a preset corresponding relationship. The larger the false alarm signal matching value, the smaller the alarm quantity threshold. When the number of gateway devices with alarms is greater than the alarm quantity threshold corresponding to the gateway device, a preset processing strategy is adopted for the screening alarm devices to conduct fault troubleshooting. When the number of gateway devices with alarms is not greater than the alarm quantity threshold corresponding to the gateway device, the alarm signals of the screening gateway devices are troubleshot in real time.

[0079] In another embodiment, if the number of gateway devices with alarms is not greater than the preset device number, the alarm signals of the screening alarm devices with false alarm signal matching values less than the matching preset value are troubleshot in real time, and the others adopt a preset processing strategy for fault troubleshooting.

[0080] Embodiment 2 In a second aspect, as Figure 5 shown, the present invention provides a computer system, including: a memory and a processor connected by communication, and a computer program stored on the memory and capable of running on the processor. When the processor runs the computer program, it executes the above-mentioned gateway alarm management method in a distributed network environment.

[0081] Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other, and the key points of each embodiment are the differences from other embodiments. In particular, for the embodiments of the device, equipment, and non-volatile computer storage medium, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiments.

[0082] The above description has been made of specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the acts or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order shown or sequential order to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0083] The foregoing is only one or more embodiments of this specification and is not intended to limit this specification. For those skilled in the art, various modifications and variations can be made to one or more embodiments of this specification. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of one or more embodiments of this specification shall be included within the scope of the claims of this specification.

Claims

1. A method for gateway alarm management in a distributed network environment, characterized in that, Specifically include: Based on the historical alarm data of gateway devices in a distributed network environment, determine the simultaneous alarm periods of the gateway devices. Based on the deviation of the false alarm data of the gateway devices in different simultaneous alarm periods from that of other simultaneous alarm periods, determine the false alarm impact periods in the simultaneous alarm periods; When it is determined that the interference degree of the false alarm data does not meet the requirements based on the distribution data of the false alarm impact periods on different dates and the alarm data of the gateway devices in different false alarm impact periods, proceed to the next step; Take the gateway devices with the number of false alarms not meeting the requirements as target gateway devices. Based on the similarity of the communication processing data when there is false alarm data for different target gateway devices and the number of target gateway devices, determine the processing strategies when different target gateway devices generate alarms; Take the gateway devices adopting the preset processing strategy as screened gateway devices. When the number of screened gateway devices does not meet the requirements, based on the matching situation of the historical communication data of the false alarm matching intervals of different screened gateway devices in different periods, determine the processing strategies when the screened gateway devices generate alarms in different periods.

2. The gateway alarm management method in a distributed network environment according to claim 1, characterized in that, The historical alarm data includes the historical alarm times of different gateway devices and the alarm periods corresponding to different historical alarm times.

3. The gateway alarm management method in a distributed network environment according to claim 1, wherein, The simultaneous alarm period is a period when there are more than a target number of gateway devices generating alarms simultaneously.

4. The gateway alarm management method in a distributed network environment according to claim 1, characterized in that The false alarm data of the gateway devices includes the number of gateway devices with false alarms in the simultaneous alarm periods.

5. The method for gateway alarm management in a distributed network environment according to claim 1, wherein The method for determining the false alarm impact periods in the simultaneous alarm periods is as follows: Based on the false alarm data of the gateway devices in the simultaneous alarm periods, determine the gateway devices with false alarms in the simultaneous alarm periods and take them as false alarm devices; Based on the deviation of the false alarm devices from other simultaneous alarm periods, determine the same number of false alarm devices in other simultaneous alarm periods as those of the false alarm devices in the simultaneous alarm periods. Take the maximum value of the same number of false alarm devices in other simultaneous alarm periods as the maximum value of the same number; Based on the maximum value of the same number and the false alarm devices in the simultaneous alarm periods, determine whether the simultaneous alarm period is a false alarm impact period.

6. The method for gateway alarm management in a distributed network environment according to claim 5, wherein, Based on the maximum value of the same number and the false alarm devices in the simultaneous alarm periods, determine whether the simultaneous alarm period is a false alarm impact period, specifically including: Take the difference between the number of false alarm devices in the simultaneous alarm period and the maximum value of the same number as the number difference; When the number difference is greater than the preset difference threshold, determine that the simultaneous alarm period is a false alarm impact period.

7. The method for gateway alarm management in a distributed network environment according to claim 1, characterized in that When there is no false alarm impact period, ignore the gateway devices with the number of false alarms greater than the preset false alarm number threshold until the alarm duration is greater than the preset alarm duration, and then conduct a fault investigation and treatment of the alarm signal. Conduct a real-time fault investigation and treatment of the alarm signals of the remaining gateway devices.

8. The method for gateway alarm management in a distributed network environment according to claim 1, characterized in that, The method for determining the processing strategies when the gateway devices generate alarms is as follows: Based on the false alarm periods of different gateway devices, determine the amount of communication processing data in different false alarm periods; According to the similarity of the communication processing data volume between different false alarm periods, the false alarm periods are divided into different communication processing data volume intervals, and the communication processing data volume interval with the most false alarm periods is used as the false alarm matching interval; Based on the proportion of the number of false alarm periods in the false alarm matching interval to the number of false alarm periods of the gateway device, and the number of gateway devices, determine the processing strategy when the gateway device generates an alarm.

9. The method for gateway alarm management in a distributed network environment according to claim 8, wherein, Based on the proportion of the number of false alarm periods in the false alarm matching interval to the number of false alarm periods of the gateway device, and the number of gateway devices, determine the processing strategy when the gateway device generates an alarm, which specifically includes: When the number of gateway devices is less than the preset device number threshold, ignore the alarms generated by different gateway devices until the alarm duration is greater than the preset alarm duration, and then perform fault troubleshooting; When the number of gateway devices is not less than the preset device number threshold, use the proportion of the number of false alarm periods in the false alarm matching interval to the number of false alarm periods of the gateway device as the false alarm signal matching value of the gateway device, and determine the processing strategy when the gateway device generates an alarm based on the false alarm signal matching value.

10. A computer system, comprising: A memory and a processor for communication connection, and a computer program stored on the memory and capable of running on the processor, wherein the processor executes the computer program to perform the method for managing gateway alarms in a distributed network environment according to any one of claims 1-9.

Citation Information

Patent Citations

  • Alarm suppression method and device, equipment and storage medium

    CN113886197A

  • Operation and maintenance management platform monitoring alarm system and method based on big data

    CN116401131A

  • Target tracking device erroneous alarm analysis method, analyzer and analysis program

    JP2014169942A