A gateway alarm management method and system in a distributed network environment

By analyzing the historical alarm data of gateway devices, identifying false alarm periods and formulating processing strategies, the operation and maintenance management problems of multiple gateway device alarms in distributed networks are solved, and the efficiency and accuracy of alarm processing are improved.

CN120342842BActive Publication Date: 2025-09-16HANGZHOU GREEN OLIVE INTERNET OF THINGS TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510813298.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-09-16
Estimated Expiration
2045-06-18

AI Technical Summary

Technical Problem

In a distributed network environment, when multiple gateway devices issue alarms simultaneously, the efficiency of identifying and processing false alarm devices is low, making it difficult to generate differentiated alarm management and processing strategies, leading to difficulties in operation and maintenance management.

Method used

By analyzing the historical alarm data of gateway devices, the false alarm period and the false alarm impact period are determined. According to the interference level of the false alarm data and the similarity of the communication processing data, differentiated processing strategies are formulated to ignore or troubleshoot the false alarm devices.

Benefits of technology

It improves the recognition and processing efficiency of gateway device alarms, avoids the problem of untimely analysis and processing caused by false alarms, and improves the efficiency of operation and maintenance management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342842B_ABST
    Figure CN120342842B_ABST
Patent Text Reader

Abstract

The present invention provides a gateway alarm management method and system in a distributed network environment, belonging to the field of alarm management technology, and specifically comprising: taking a gateway device whose number of false alarms does not meet the requirements as a target gateway device, determining the processing strategy when an alarm occurs in different target gateway devices according to the similarity of communication processing data of different target gateway devices when false alarm data exists and the number of target gateway devices, taking a gateway device that adopts a preset processing strategy as a screening gateway device, and when the number of screening gateway devices does not meet the requirements, determining the processing strategy when an alarm occurs in the screening gateway device in different time periods according to the matching of historical communication data of false alarm matching intervals of different screening gateway devices in different time periods, thereby improving the efficiency of troubleshooting and processing of alarm signals in simultaneous alarm time periods.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of alarm management, and in particular relates to a gateway alarm management method and system in a distributed network environment. Background Art

[0002] In a distributed network environment, gateways are relatively dispersed. Therefore, once a gateway alarm occurs, especially when there are multiple gateway alarms, the operation and maintenance personnel will often be in a hurry and find it difficult to implement effective operation and maintenance management of the gateway equipment in a timely and effective manner.

[0003] Therefore, in order to solve the above technical solution, the existing technical solution is that the gateway device automatically sends alarm information to the terminal management platform, and the terminal management platform analyzes and compares the alarm information reported by each gateway device to determine the line fault of the gateway device. However, there are the following technical problems:

[0004] In a distributed network environment, if there are multiple gateway devices that issue alarms at the same time, there are also technical problems that make operation and maintenance management difficult. In particular, when there are false alarm devices, the identification and processing efficiency of the alarm gateway devices may be difficult to meet the requirements. Therefore, how to generate differentiated alarm management and processing strategies in different time periods based on the probability of false alarms of false alarm devices in different time periods and the distribution data, and improve the operation and maintenance efficiency of gateway devices has become a technical problem that needs to be solved urgently.

[0005] In order to solve the above technical problems, the present application provides a gateway alarm management method and system in a distributed network environment. Summary of the Invention

[0006] To achieve the purpose of the present invention, the present invention adopts the following technical solutions:

[0007] Specifically, this application provides a gateway alarm management method in a distributed network environment, specifically including:

[0008] S1 determines, based on historical alarm data of gateway devices in a distributed network environment, simultaneous alarm periods of gateway devices, and determines a false alarm impact period in the simultaneous alarm period based on the deviation of false alarm data of gateway devices in different simultaneous alarm periods from other simultaneous alarm periods;

[0009] S2 determines that the interference degree of the false alarm data does not meet the requirements based on the distribution data of the false alarm impact period on different dates and the alarm data of the gateway devices in different false alarm impact periods, and proceeds to the next step;

[0010] S3 takes the gateway devices whose false alarm times do not meet the requirements as target gateway devices, and determines the processing strategies for different target gateway devices when alarms occur based on the similarity of communication processing data of different target gateway devices when false alarm data exists and the number of target gateway devices;

[0011] S4 will use the target gateway device with a preset processing strategy as the screening gateway device. When the number of screening gateway devices does not meet the requirements, the processing strategy when the screening gateway device generates an alarm in different time periods is determined based on the matching of the false alarm matching intervals of different screening gateway devices with the historical communication data in different time periods.

[0012] The beneficial effects of the present invention are:

[0013] Based on the similarity of communication processing data of different gateway devices when false alarm data exists and the number of gateway devices, the processing strategies of different gateway devices when alarms occur are determined, and the obvious degree of characteristics of communication traffic when false alarms occur is evaluated from the perspective of similarity of communication processing data. At the same time, combined with the number of gateway devices, the analysis and processing requirements of different gateway devices when alarms occur are evaluated from the perspective of the degree of deviation of false alarm communication traffic and the number of gateway devices, thereby ensuring the efficiency of analysis and processing of alarm signals.

[0014] According to the matching of false alarm matching intervals of different screening gateway devices with historical communication data in different time periods, the processing strategy when the screening gateway devices generate alarms in different time periods is determined, thereby avoiding the technical problem of untimely parsing and processing of the alarm data of the gateway devices when the number of screening gateway devices is large. By combining the matching of false alarm matching intervals with historical communication data, the screening of screening gateway devices with a high probability of generating false alarms at the same time is achieved, and the processing strategy is updated in a targeted manner, thereby improving the efficiency of identifying and processing alarm data.

[0015] A further technical solution is that the historical alarm data includes the historical alarm times of different gateway devices and the alarm time periods corresponding to the different historical alarm times.

[0016] A further technical solution is that the simultaneous alarm period is a period during which more than a target number of gateway devices simultaneously alarm.

[0017] A further technical solution is that the value of the target number is 3.

[0018] A further technical solution is that the false alarm data of the gateway device includes the number of gateway devices that falsely alarm in the simultaneous alarm period.

[0019] A further technical solution is that the method for determining the false alarm impact period in the simultaneous alarm period is:

[0020] Determining the gateway device that falsely alarmed during the simultaneous alarm period based on the false alarm data of the gateway device during the simultaneous alarm period, and using it as the false alarm device;

[0021] Determining, based on the deviation between the false alarm device and other simultaneous alarm periods, the number of false alarm devices in other simultaneous alarm periods that are identical to the false alarm devices of the simultaneous alarm device, and taking the maximum value of the number of identical false alarm devices in other simultaneous alarm periods as the maximum number of identical false alarm devices;

[0022] Whether the simultaneous alarm period is a false alarm impact period is determined by using the maximum value of the same number and the false alarm devices in the simultaneous alarm period.

[0023] A further technical solution is to determine whether the simultaneous alarm period is a false alarm impact period based on the maximum number of identical devices and the number of false alarm devices in the simultaneous alarm period, which specifically includes:

[0024] taking the difference between the number of false alarm devices in the simultaneous alarm period and the maximum number of the same number as the number difference;

[0025] When the quantity difference is greater than a preset difference threshold, the simultaneous alarm period is determined to be a false alarm influence period.

[0026] A further technical solution is that the method for determining the processing strategy when the gateway device generates an alarm is:

[0027] Determining the communication processing data volume in different false alarm periods based on the false alarm periods of different gateway devices;

[0028] According to the similarity of the communication processing data volume between different false alarm periods, the false alarm period is divided into different communication processing data volume intervals, and the communication processing data volume interval with the largest false alarm period is used as the false alarm matching interval;

[0029] A processing strategy when an alarm occurs in the gateway device is determined by the proportion of the false alarm time periods in the false alarm matching interval to the number of false alarm time periods of the gateway device and the number of gateway devices.

[0030] A further technical solution is to determine a processing strategy when an alarm occurs on the gateway device based on the proportion of the false alarm period in the false alarm matching interval to the number of false alarm periods on the gateway device and the number of gateway devices, specifically including:

[0031] When the number of gateway devices is less than the preset device number threshold, all alarms generated by different gateway devices are ignored until the alarm duration is longer than the preset alarm duration, and then troubleshooting is performed;

[0032] When the number of the gateway devices is not less than the preset device number threshold, the ratio of the false alarm time periods in the false alarm matching interval to the number of false alarm time periods of the gateway devices is used as the false alarm signal matching value of the gateway device, and the processing strategy of the gateway device when an alarm occurs is determined based on the false alarm signal matching value.

[0033] A further technical solution is to determine a processing strategy when the gateway device generates an alarm based on the false alarm signal matching value, specifically including:

[0034] When the false alarm signal matching value of the gateway device is greater than the preset matching threshold, determining whether to ignore the alarm by analyzing the communication processing data volume of the gateway device when the gateway device generates an alarm;

[0035] When the false alarm signal matching value of the gateway device is not greater than the preset matching threshold, the gateway device will be ignored when an alarm occurs, and troubleshooting will not be performed until the alarm duration is greater than the preset alarm duration.

[0036] A further technical solution is that the preset processing strategy is to determine whether neglect processing is required by analyzing the communication processing data volume of the gateway device when an alarm occurs in the gateway device.

[0037] In a second aspect, the present invention provides a computer system comprising: a memory and a processor in communication connection, and a computer program stored in the memory and capable of running on the processor, wherein the processor executes the above-mentioned gateway alarm management method in a distributed network environment when running the computer program.

[0038] Other features and advantages will be described in the following description. The objectives and other advantages of the present invention are realized and obtained by the structures particularly pointed out in the description and drawings.

[0039] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] The above and other features and advantages of the present invention will become more apparent by describing in detail exemplary embodiments thereof with reference to the accompanying drawings.

[0041] Figure 1 It is a flow chart of a gateway alarm management method in a distributed network environment;

[0042] Figure 2 is a flow chart of a method for determining a false alarm impact period in a simultaneous alarm period;

[0043] Figure 3 It is a flow chart to determine whether the interference level of false alarm data does not meet the requirements;

[0044] Figure 4 is a flow chart of a method for determining a gateway device in a gateway device;

[0045] Figure 5 It is a framework diagram of a computer system. DETAILED DESCRIPTION

[0046] To help those skilled in the art better understand the technical solutions in this specification, the following will provide a clear and complete description of the technical solutions in the embodiments of this specification, in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of this specification, not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this specification without creative work should fall within the scope of protection of this specification.

[0047] In this application, by considering the similar situations of the communication processing data when false alarms occur in gateway devices and the number of gateway devices, the gateway devices with more obvious characteristics of the communication processing data when false alarms occur in the gateway devices are determined, and then differentiated alarm processing strategies are determined, thereby improving the processing efficiency of the alarm devices.

[0048] The false alarm impact period is a simultaneous alarm period in which the number of alarms of the gateway device is more than 3 and the gateway devices that generate false alarms are not the same as those in other simultaneous alarm periods.

[0049] A gateway device that issues a false alarm is a gateway device that does not have any abnormality but issues a false alarm due to a large amount of communication data, which causes a delay in communication data.

[0050] When there is a false alarm impact period on each date, it is determined that the interference level of the false alarm data does not meet the requirement.

[0051] The target gateway device is a gateway device whose number of false alarms is greater than a preset false alarm number threshold.

[0052] Determine the communication processing data volume in different false alarm periods based on the false alarm periods of different target gateway devices; divide the false alarm periods into different communication processing data volume intervals based on the similarity of the communication processing data volume between different false alarm periods; and use the communication processing data volume interval with the largest number of false alarm periods as the false alarm matching interval; when the number of target gateway devices is less than a preset device number threshold, ignore the alarms of different target gateway devices until the alarm duration exceeds the preset alarm duration, and then perform troubleshooting;

[0053] When the number of the target gateway devices is not less than the preset device number threshold, the ratio of the false alarm time periods in the false alarm matching interval to the number of false alarm time periods of the gateway devices is used as the false alarm signal matching value of the target gateway device, and the processing strategy when the target gateway device generates an alarm is determined based on the false alarm signal matching value.

[0054] , the preset processing strategy is to determine whether ignoring processing is required by analyzing the communication processing data volume of the target gateway device when an alarm occurs in the target gateway device.

[0055] When the number of screening gateway devices is greater than a preset screening gateway device number threshold, it is determined that the number of screening gateway devices does not meet the requirement.

[0056] The false alarm matching interval is the communication processing data volume interval with the largest false alarm period.

[0057] The historical moments when the historical communication data in the time period falls into the false alarm matching interval of the target alarm device are used as alarm risk moments, and the screening gateway devices whose number of alarm risk moments is greater than the risk moment number threshold are used as risk alarm devices.

[0058] When the number of risk alarm devices in a time period is not greater than a certain threshold, that is, less than 6, the preset processing strategy is used to troubleshoot all the screening alarm devices. When the number of risk alarm devices in the time period is large, that is, greater than 6, if the number of gateway devices with alarms is greater than the preset number of devices, the preset processing strategy is used to troubleshoot all the screening alarm devices. If the number of gateway devices with alarms is not greater than the preset number of devices, the alarm signals of the screening alarm devices whose false alarm signal matching values ​​are less than the matching preset value are troubleshooted in real time, and the others are troubleshooted using the preset processing strategy.

[0059] Example 1

[0060] like Figure 1 As shown, the present application provides a gateway alarm management method in a distributed network environment, specifically including:

[0061] S1 determines, based on historical alarm data of gateway devices in a distributed network environment, simultaneous alarm periods of gateway devices, and determines a false alarm impact period in the simultaneous alarm period based on the deviation of false alarm data of gateway devices in different simultaneous alarm periods from other simultaneous alarm periods;

[0062] Furthermore, the historical alarm data includes the historical alarm times of different gateway devices and the alarm time periods corresponding to the different historical alarm times.

[0063] Specifically, the simultaneous alarm period is a period during which more than a target number of gateway devices simultaneously alarm.

[0064] Furthermore, the target number is set to 3.

[0065] It should be noted that the false alarm data of the gateway device includes the number of gateway devices that falsely alarm during the simultaneous alarm period.

[0066] Specifically, such as Figure 2 As shown, the method for determining the false alarm impact period in the simultaneous alarm period is:

[0067] Determining the gateway device that falsely alarmed during the simultaneous alarm period based on the false alarm data of the gateway device during the simultaneous alarm period, and using it as the false alarm device;

[0068] Determining, based on the deviation between the false alarm device and other simultaneous alarm periods, the number of false alarm devices in other simultaneous alarm periods that are identical to the false alarm devices of the simultaneous alarm device, and taking the maximum value of the number of identical false alarm devices in other simultaneous alarm periods as the maximum number of identical false alarm devices;

[0069] Whether the simultaneous alarm period is a false alarm impact period is determined by using the maximum value of the same number and the false alarm devices in the simultaneous alarm period.

[0070] Further, determining whether the simultaneous alarm period is a false alarm impact period based on the maximum number of identical devices and the false alarm devices in the simultaneous alarm period specifically includes:

[0071] taking the difference between the number of false alarm devices in the simultaneous alarm period and the maximum number of the same number as the number difference;

[0072] When the quantity difference is greater than a preset difference threshold, the simultaneous alarm period is determined to be a false alarm influence period.

[0073] It can be understood that when there is no false alarm impact period, the gateway devices whose false alarm times are greater than the preset false alarm threshold will be ignored until the alarm duration is greater than the preset alarm duration, and then the alarm signal troubleshooting will be performed. The alarm signals of the remaining gateway devices will be troubleshooted in real time.

[0074] In another possible embodiment, a method for determining the false alarm impact period in the simultaneous alarm period is:

[0075] Determining the gateway device that falsely alarmed during the simultaneous alarm period based on the false alarm data of the gateway device during the simultaneous alarm period, and using it as the false alarm device;

[0076] According to the deviation between the false alarm device and other simultaneous alarm periods, determining the number of false alarm devices in other simultaneous alarm periods that are identical to the false alarm devices of the simultaneous alarm device, and taking it as the number of identical false alarms;

[0077] The false alarm similarity value of other simultaneous alarm periods is determined by the ratio of the same number of false alarms in other simultaneous alarm periods to the number of false alarm devices in the simultaneous alarm period, and whether the simultaneous alarm period is a false alarm impact period is determined based on the false alarm similarity value of other simultaneous alarm periods.

[0078] It should be noted that, when the number of other simultaneous alarm periods with a false alarm similarity value greater than a preset similarity threshold is less than a preset alarm period number threshold, it is determined that the simultaneous alarm period belongs to a false alarm influence period.

[0079] In another possible embodiment, a method for determining the false alarm impact period in the simultaneous alarm period is:

[0080] S11 determines the gateway device that falsely alarmed in the simultaneous alarm period based on the false alarm data of the gateway device in the simultaneous alarm period, and uses it as the false alarm device, and determines the number of false alarms of different false alarm devices in other simultaneous alarm periods;

[0081] It should be noted that before proceeding to the next step, it is necessary to further determine whether there are false alarm devices in the simultaneous alarm period, whether the number of false alarm devices and the proportion of false alarm devices do not meet the requirements, and whether the number of false alarms in other simultaneous alarm periods is relatively small, that is, the number of false alarm devices less than the number threshold does not meet the requirements, and whether the specific determination of passing the threshold meets the requirements.

[0082] It is understandable that if there is no false alarm device in the simultaneous alarm period, it can be directly determined that the simultaneous alarm period does not belong to the false alarm period. However, if there is only false alarm device, it is necessary to determine whether the number of false alarm devices and the proportion of false alarm devices do not meet the requirements.

[0083] When the number of false alarm devices and the number of gateway devices that alarm during the simultaneous alarm period are both too high, that is, they do not meet the requirements, then due to the large number of false alarm devices, it can be determined that the simultaneous alarm period belongs to the false alarm response period.

[0084] In addition, when the number of false alarm devices is small, the number of false alarms in other simultaneous alarm time periods is relatively small, that is, the number of false alarm devices less than the number threshold does not meet the requirements, that is, when the number is greater than a certain threshold, then due to the large degree of deviation from the false alarm devices in other simultaneous alarm time periods, it can be determined that the simultaneous alarm time period belongs to the false alarm period, and in other cases, the number of false alarm devices in other simultaneous alarm time periods is the same as that of the false alarm devices of the simultaneous alarm device.

[0085] S12: determining the number of false alarm devices in other simultaneous alarm periods that is the same as the number of false alarm devices of the simultaneous alarm device according to the deviation between the false alarm device and other simultaneous alarm periods;

[0086] It can be understood that, in the above step S12, it is necessary to further determine the number of false alarm devices in other simultaneous alarm time periods that is the same as the number of false alarm devices of the said simultaneous alarm device, and use it as the same number of false alarms. When the same number of false alarms in different other simultaneous alarm time periods is relatively small, that is, less than a certain threshold, then due to the large degree of deviation from the false alarm devices in other simultaneous alarm time periods, it can be determined that the simultaneous alarm period belongs to the false alarm influence period.

[0087] In other cases, the false alarm similarity value of other simultaneous alarm periods is determined by the ratio of the same number of false alarms in other simultaneous alarm periods to the number of false alarm devices in the simultaneous alarm period. Specifically, if the number of other simultaneous alarm periods with false alarm similarity values ​​greater than the preset similarity threshold is less than the preset alarm period number threshold, it is determined that the simultaneous alarm period belongs to the false alarm impact period. When there are a large number of other simultaneous alarm periods with false alarm similarity values ​​greater than the preset similarity threshold, that is, the number is within the preset number range, it can be determined that the simultaneous alarm period does not belong to the false alarm impact period. When the number is no longer within the preset number range, the false alarm impact value is determined.

[0088] S13 determines the false alarm impact value of the simultaneous alarm period by the same number of false alarm devices in other simultaneous alarm periods as the false alarm devices of the simultaneous alarm device, the number of false alarms of different false alarm devices in other simultaneous alarm periods, and the number of false alarm devices in the simultaneous alarm period, and determines whether the simultaneous alarm period is a false alarm impact period based on the false alarm impact value.

[0089] The false alarm impact value of a specific simultaneous alarm period can be determined by inputting the input quantity into a mathematical model based on the hierarchical analysis method based on the same number of false alarm devices in other simultaneous alarm periods as the false alarm devices of the simultaneous alarm device, the number of false alarms of different false alarm devices in other simultaneous alarm periods, and the number of false alarm devices in the simultaneous alarm period.

[0090] It can be understood at this time that in one of the embodiments, if the false alarm impact value is greater than the preset impact threshold, not only is the number of false alarm devices large, but there is also a deviation from the false alarm devices in other simultaneous alarm periods, so it can be determined that it belongs to the false alarm impact period.

[0091] S2 is based on the distribution data of the false alarm impact period on different dates, and combines the alarm data of the gateway device in different false alarm impact periods to determine that the interference level of the false alarm data does not meet the requirements, and then proceeds to the next step;

[0092] Specifically, such as Figure 3 As shown, it is determined that the interference level of the false alarm data does not meet the requirements, specifically including:

[0093] According to the alarm data of the gateway devices in different false alarm impact periods, the number of gateway devices with alarms in different false alarm impact periods is determined, and the number is used as the number of alarm devices, and the false alarm impact period in which the number of alarm devices is greater than the alarm device number threshold is used as the analysis difficulty period;

[0094] Based on the distribution data of the analysis difficulty period on different dates, the date on which the analysis difficulty period occurs is determined, and the false alarm date is determined;

[0095] Whether the interference level of the false alarm data meets the requirement is determined by the number of the false alarm dates.

[0096] Further, when the number of the false alarm dates is greater than a preset threshold value of the number of alarm dates, it is determined that the interference level of the false alarm data does not meet the requirement.

[0097] It can be understood that when the interference level of the false alarm data meets the requirements, the gateway devices whose false alarm times are greater than the preset false alarm times threshold will be ignored until the alarm duration is greater than the preset alarm duration, and then the alarm signal will be troubleshooted. The alarm signals of the remaining gateway devices will be troubleshooted in real time.

[0098] S3 obtains similar situations of communication processing data of different target gateway devices when false alarm data exists, and determines processing strategies when alarms occur in different target gateway devices in combination with the number of the target gateway devices.

[0099] Specifically, the target gateway device is a gateway device whose number of false alarms is greater than a preset false alarm number threshold.

[0100] Furthermore, the method for determining the processing strategy when the target gateway device generates an alarm is:

[0101] Determining communication processing data volumes in different false alarm periods based on false alarm periods of different target gateway devices;

[0102] According to the similarity of the communication processing data volume between different false alarm periods, the false alarm period is divided into different communication processing data volume intervals, and the communication processing data volume interval with the largest false alarm period is used as the false alarm matching interval;

[0103] A processing strategy when an alarm occurs on the target gateway device is determined by the proportion of the false alarm time periods in the false alarm matching interval to the number of false alarm time periods on the target gateway device and the number of gateway devices.

[0104] It should be noted that the false alarm period is a period during which the target gateway device has false alarm data.

[0105] It can be understood that the processing strategy when an alarm occurs in the target gateway device is determined by the proportion of the false alarm period in the false alarm matching interval to the number of false alarm periods of the target gateway device and the number of target gateway devices, specifically including:

[0106] When the number of target gateway devices is less than the preset device number threshold, all alarms generated by different target gateway devices are ignored until the alarm duration is longer than the preset alarm duration, and then troubleshooting is performed;

[0107] When the number of the target gateway devices is not less than the preset device number threshold, the ratio of the false alarm time periods in the false alarm matching interval to the number of false alarm time periods of the gateway devices is used as the false alarm signal matching value of the gateway device, and the processing strategy of the gateway device when an alarm occurs is determined based on the false alarm signal matching value.

[0108] It should be further explained that determining a processing strategy when an alarm occurs on the target gateway device based on the false alarm signal matching value specifically includes:

[0109] When the false alarm signal matching value of the target gateway device is greater than the preset matching threshold, determining whether to ignore the target gateway device by analyzing the communication processing data volume of the gateway device when the target gateway device generates an alarm;

[0110] When the false alarm signal matching value of the target gateway device is not greater than the preset matching threshold, it is ignored until the alarm duration is greater than the preset alarm duration and then the alarm signal fault troubleshooting is performed.

[0111] In another possible embodiment, a method for determining a processing strategy when an alarm occurs in the target gateway device is:

[0112] S31 obtains the number of target gateway devices, and determines the communication processing data volume in different false alarm periods based on the false alarm periods of different target gateway devices;

[0113] It should be noted that before proceeding to the next step, it is necessary to determine whether the number of target gateway devices meets the requirements. Specifically, when the number of target gateway devices is less than the preset device number threshold, since the number of target gateway devices at this time is relatively small, the alarms generated by different target gateway devices are ignored. Fault troubleshooting is not performed until the alarm duration is greater than the preset alarm duration, which will not have a major impact on the overall reliability of fault signal troubleshooting.

[0114] However, only when the number of target gateway devices is not less than the preset device number threshold, the number of target gateway devices is too large. Therefore, it is necessary to analyze the specificity of the signal characteristics when false alarms occur in different target gateway devices and determine differentiated processing strategies when alarms occur.

[0115] S32 divides the false alarm period into different communication processing data volume intervals according to the similarity of the communication processing data volume between different false alarm periods, takes the communication processing data volume interval with the largest number of false alarm periods as the false alarm matching interval, and determines the false alarm signal matching value of the target gateway device according to the proportion of the false alarm periods in the false alarm matching interval to the number of false alarm periods of the target gateway device;

[0116] It can be understood that in the above steps, it is necessary to determine whether the false alarm signal matching value of the target gateway device meets the requirements. Specifically, when the false alarm signal matching value of the target gateway device is too large, that is, greater than the preset threshold, then due to the obvious characteristics when the false alarm occurs, it can be directly determined by analyzing the communication processing data volume of the target gateway device when the alarm occurs, to determine whether it needs to be ignored. When the specific communication processing data volume falls within the communication processing data interval with the most false alarm period, it is ignored.

[0117] It should also be noted that when the false alarm signal matching value is relatively small, that is, less than a fixed threshold, it will be ignored because the characteristics of the false alarm are not obvious. The alarm signal troubleshooting will not be carried out until the alarm duration is greater than the preset alarm duration.

[0118] Only when the false alarm signal matching value is neither too small nor too large, that is, within a certain range, will the process proceed to the next step.

[0119] S33 determines the sorting result of the false alarm signal matching value of the target gateway device in the target gateway device through the false alarm signal matching value of different target gateway devices, and determines the identification matching value of the false alarm signal of the target gateway device in combination with the number of the target gateway devices and the false alarm signal matching value of the target gateway device, and determines the processing strategy when the target gateway device generates an alarm based on the identification matching value.

[0120] It should also be noted that when the sorting result of the false alarm signal matching value in the target gateway device is before the target position, that is, within 5, the processing strategy when the target gateway device generates an alarm is to analyze the communication processing data volume of the gateway device when the target gateway device generates an alarm to determine whether it needs to be ignored. Specifically, when the communication processing data volume is within the false alarm matching interval, the alarm signal is directly ignored until the alarm duration is greater than the preset alarm duration, and then troubleshooting is performed. In other cases, the alarm signal is directly troubleshooted.

[0121] In addition, if the sorting result is not before the target position, it is necessary to further determine the recognition matching value of the false alarm signal of the target gateway device, which is specifically determined based on the output result of the expert scoring model with the false alarm signal matching value of the target gateway device in the sorting result of the target gateway device, the number of the target gateway devices, and the false alarm signal matching value of the target gateway device as input.

[0122] Specifically, if the identification matching value is above 0.6, the processing strategy when the target gateway device generates an alarm is to determine whether to ignore the processing by analyzing the communication processing data volume of the gateway device when the target gateway device generates an alarm. When it is 0.6 or below 0.6, ignore the processing until the alarm duration is greater than the preset alarm duration, and then perform troubleshooting of the alarm signal.

[0123] S4 will use the target gateway device with a preset processing strategy as the screening gateway device. When the number of screening gateway devices does not meet the requirements, the processing strategy when the screening gateway device generates an alarm in different time periods is determined based on the matching of the false alarm matching intervals of different screening gateway devices with the historical communication data in different time periods.

[0124] Specifically, the preset processing strategy is to determine whether to perform ignore processing by analyzing the communication processing data volume of the target gateway device when an alarm occurs in the target gateway device.

[0125] Further, when the number of screening gateway devices is greater than a preset screening gateway device number threshold, it is determined that the number of screening gateway devices does not meet the requirement.

[0126] It can be understood that when the number of screening gateway devices meets the requirements, the communication processing data volume of the gateway device is analyzed in different time periods to determine whether ignore processing is required. Specifically, when the communication processing data volume falls within the false alarm matching interval of the screening gateway device, ignore processing is performed.

[0127] It should be noted that the false alarm matching interval is the communication processing data volume interval with the largest number of false alarm periods.

[0128] Specifically, the method for determining the processing strategy when the screening gateway device generates an alarm is:

[0129] Based on the matching condition of the false alarm matching interval of the screening gateway device with the historical communication data in the time period, determining the historical moment when the historical communication data in the time period falls into the false alarm matching interval, and using it as the alarm risk moment;

[0130] Determining a risk alarm device in the screening gateway device according to the number of the alarm risk moments;

[0131] The processing strategies when different screening gateway devices generate alarms in the period are determined according to the number of risk alarm devices in the period.

[0132] It can be understood that the risk warning device is a screening gateway device that warns a large number of risk moments. Specifically, the screening gateway device that warns a large number of risk moments is used as the risk warning device.

[0133] It should also be noted that, based on the number of risk alarm devices in the time period, the processing strategies when different screening gateway devices generate alarms in the time period are determined, specifically including:

[0134] When the number of risk alarm devices in the time period is small, that is, not greater than a certain threshold, all the screened alarm devices are subjected to troubleshooting using a preset processing strategy;

[0135] When the number of risk alarm devices in the time period is large, that is, greater than a certain threshold, if the number of gateway devices with alarms is greater than the preset number of devices, all filtered alarm devices are troubleshooted using the preset processing strategy;

[0136] In a possible embodiment, if the number of gateway devices with alarms is not greater than the preset number of devices, the alarm quantity thresholds corresponding to different gateway devices are determined based on the false alarm signal matching values ​​of different gateway devices, wherein the alarm quantity threshold and the false alarm signal matching value are determined based on a preset corresponding relationship, wherein the larger the false alarm signal matching value, the smaller the alarm quantity threshold. When the number of gateway devices with alarms is greater than the alarm quantity threshold corresponding to the gateway device, the preset processing strategy is used to perform troubleshooting on the screened alarm device. When the number of gateway devices with alarms is not greater than the alarm quantity threshold corresponding to the gateway device, the alarm signal of the screened gateway device is troubleshooted in real time.

[0137] In another embodiment, if the number of gateway devices with alarms is not greater than the preset number of devices, the alarm signals of the screened alarm devices whose false alarm signal matching values ​​are less than the matching preset value will be troubleshooted in real time, and the others will be troubleshooted using the preset processing strategy.

[0138] Example 2

[0139] Second, as Figure 5 As shown, the present invention provides a computer system, comprising: a memory and a processor in communication connection, and a computer program stored in the memory and capable of running on the processor, wherein the processor executes the above-mentioned gateway alarm management method in a distributed network environment when running the computer program.

[0140] The various embodiments in this specification are described in a progressive manner. Similar portions between the various embodiments can be referenced to each other, and each embodiment focuses on the differences from the other embodiments. In particular, the device, apparatus, and non-volatile computer storage medium embodiments are generally similar to the method embodiments, so their descriptions are relatively simplified. For relevant details, refer to the descriptions of the method embodiments.

[0141] The foregoing description of this specification describes specific embodiments. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0142] The foregoing description is merely one or more embodiments of this specification and is not intended to limit this specification. It will be apparent to those skilled in the art that various modifications and variations may be made to one or more embodiments of this specification. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of one or more embodiments of this specification are intended to be within the scope of the claims of this specification.

Claims

1. A gateway alarm management method in a distributed network environment, characterized in that: Specifically include: Determine, based on historical alarm data of gateway devices in a distributed network environment, a simultaneous alarm period of the gateway devices, and determine, based on the deviation of false alarm data of the gateway devices in the simultaneous alarm period and other simultaneous alarm periods, a false alarm impact period in the simultaneous alarm period; When it is determined that the interference degree of the false alarm data does not meet the requirements based on the distribution data of the false alarm impact period on different dates and the alarm data of the gateway devices in different false alarm impact periods, the next step is entered; The gateway devices whose false alarm counts do not meet the requirements are used as target gateway devices. Based on the similarity of communication processing data of different target gateway devices when false alarm data exists and the number of target gateway devices, the processing strategies when different target gateway devices generate alarms are determined; The gateway devices that adopt the preset processing strategy are used as screening gateway devices. When the number of screening gateway devices does not meet the requirement, the processing strategy when the screening gateway devices generate alarms in different time periods is determined based on the matching of the false alarm matching intervals of different screening gateway devices with the historical communication data in different time periods. The simultaneous alarm period is a period during which more than a target number of gateway devices simultaneously alarm; The method for determining the false alarm impact period in the simultaneous alarm period is: Determining the gateway device that falsely alarmed during the simultaneous alarm period based on the false alarm data of the gateway device during the simultaneous alarm period, and using it as the false alarm device; Determining, based on the deviation between the false alarm device and other simultaneous alarm periods, the number of false alarm devices in other simultaneous alarm periods that are identical to the false alarm device in the simultaneous alarm period, and taking the maximum value of the number of identical false alarm devices in other simultaneous alarm periods as the maximum number of identical devices; Determining whether the simultaneous alarm period is a false alarm impact period based on the maximum number of identical devices and the number of false alarm devices in the simultaneous alarm period; Determining whether the simultaneous alarm period is a false alarm impact period based on the maximum number of identical devices and the number of false alarm devices in the simultaneous alarm period specifically includes: taking the difference between the number of false alarm devices in the simultaneous alarm period and the maximum number of the same number as the number difference; When the quantity difference is greater than a preset difference threshold, the simultaneous alarm period is determined to be a false alarm influence period.

2. The gateway alarm management method in a distributed network environment according to claim 1, characterized in that: The historical alarm data includes the historical alarm times of different gateway devices and the alarm time periods corresponding to the different historical alarm times.

3. The gateway alarm management method in a distributed network environment according to claim 1, characterized in that: The simultaneous alarm period is a period during which more than a target number of gateway devices simultaneously alarm.

4. The gateway alarm management method in a distributed network environment according to claim 1, characterized in that: The false alarm data of the gateway device includes the number of gateway devices that falsely alarm during the simultaneous alarm period.

5. The gateway alarm management method in a distributed network environment according to claim 1, characterized in that: When there is no false alarm impact period, the gateway devices whose false alarm times are greater than the preset false alarm threshold will be ignored until the alarm duration is greater than the preset alarm duration, and then the alarm signal troubleshooting will be carried out. The alarm signals of the remaining gateway devices will be troubleshooted in real time.

6. The gateway alarm management method in a distributed network environment according to claim 1, characterized in that: The method for determining the processing strategy when the gateway device generates an alarm is: Determining the communication processing data volume in different false alarm periods based on the false alarm periods of different gateway devices; According to the similarity of the communication processing data volume between different false alarm periods, the false alarm period is divided into different communication processing data volume intervals, and the communication processing data volume interval with the largest false alarm period is used as the false alarm matching interval; A processing strategy when an alarm occurs in the gateway device is determined by the proportion of the false alarm time periods in the false alarm matching interval to the number of false alarm time periods of the gateway device and the number of gateway devices.

7. The gateway alarm management method in a distributed network environment according to claim 6, characterized in that: Determining a processing strategy when an alarm occurs on the gateway device based on the proportion of the false alarm period in the false alarm matching interval to the number of false alarm periods on the gateway device and the number of gateway devices, specifically including: When the number of gateway devices is less than the preset device number threshold, all alarms generated by different gateway devices are ignored until the alarm duration is longer than the preset alarm duration, and then troubleshooting is performed; When the number of the gateway devices is not less than the preset device number threshold, the ratio of the false alarm time periods in the false alarm matching interval to the number of false alarm time periods of the gateway devices is used as the false alarm signal matching value of the gateway device, and the processing strategy of the gateway device when an alarm occurs is determined based on the false alarm signal matching value.

8. A computer system comprising: A memory and a processor in communication connection, and a computer program stored in the memory and capable of running on the processor, characterized in that when the processor runs the computer program, it executes a gateway alarm management method in a distributed network environment as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Operation and maintenance management platform monitoring alarm system and method based on big data

    CN116401131A

  • Target tracking device erroneous alarm analysis method, analyzer and analysis program

    JP2014169942A