Intelligent processing method and device for access network private line fault, medium and program product

By obtaining and aggregating the characteristic description information of alarm events, and using the fault classification model for prediction and adjustment, the problem of low fault handling efficiency of access network dedicated lines is solved, fast and accurate fault diagnosis and processing is achieved, and user experience is improved.

CN120358127APending Publication Date: 2025-07-22TENCENT DIGITAL TIANJIN
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410081000.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-19
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

In the prior art, the access network dedicated line fault processing efficiency is low, resulting in large labor costs for operation and maintenance and may miss alarms, affecting the user experience.

Method used

By obtaining the characteristic description information of the alarm event, using the trained fault classification model for prediction, and interactively displaying and adjusting the predicted fault type, and combining machine learning algorithms for automated analysis.

Benefits of technology

It realizes minute-level dedicated line access network fault diagnosis and positioning, improves diagnosis accuracy and processing efficiency, reduces operation and maintenance manpower, ensures timely notifications from customers, and improves user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358127A_ABST
    Figure CN120358127A_ABST
Patent Text Reader

Abstract

The invention provides an intelligent processing method for access network special line faults, an intelligent processing device for access network special line faults, an electronic device, a computer readable storage medium and a computer program product, and relates to the technical field of network faults. The method comprises the steps that feature description information corresponding to N alarm events is obtained, the feature description information of each alarm event is obtained by aggregating geographic information and time information, and N is a positive integer; processing the feature description information corresponding to the N alarm events through a trained fault classification model, and determining predicted fault types corresponding to the N alarm events according to the fault classification model; and displaying the predicted fault types corresponding to the N alarm events in an interactive manner so as to adjust the predicted fault types. According to the invention, the network fault processing efficiency of the access network can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the technical field of network faults, and in particular, to an intelligent processing method for access network dedicated line faults, an intelligent processing device for access network dedicated line faults, an electronic device, a computer-readable storage medium, and a computer program product. Background Art

[0002] With the continuous growth of the platform cloud dedicated line product business, the workload of product operation is also increasing. For example, the cloud dedicated line product generates about tens of thousands of alarm events per month on average. In the related art, most of the dedicated line alarm events are processed manually. However, there are many dedicated line alarm events, which not only consume the maintenance manpower for troubleshooting; on the other hand, it is possible to miss the processing of alarms, the service is not restored in time, and the customer is not notified in time. It can be seen that the related art has the problem of low efficiency in processing access network faults, which affects the user experience of using the dedicated line product service. Summary of the Invention

[0003] The present application provides an intelligent processing method for access network dedicated line faults, an intelligent processing device for access network dedicated line faults, an electronic device, a computer-readable storage medium, and a computer program product, which is beneficial to improving the efficiency of processing access network faults.

[0004] In a first aspect, the present application provides an intelligent processing method for access network dedicated line faults, the method including: obtaining the feature description information respectively corresponding to N alarm events, the feature description information of each of the above alarm events is obtained after aggregation according to geographical information and time information, and N is a positive integer; processing the feature description information respectively corresponding to the N alarm events through a trained fault classification model, and determining the predicted fault type respectively corresponding to the N alarm events according to the fault classification model; and displaying the predicted fault type respectively corresponding to the N alarm events in an interactive manner to adjust the predicted fault type.

[0005] In an exemplary embodiment, based on the above solution, the obtaining the feature description information respectively corresponding to N alarm events includes: obtaining the original description information, the original description information includes at least one of the following information: alarm device information, alarm type, alarm time; obtaining the service information associated with the original description information, the service information includes at least one of the following information: customer information, channel information, gateway information, dedicated line information; and determining the feature description information corresponding to the alarm event according to the original description information and its associated service information.

[0006] In an exemplary embodiment, based on the above solution, determining the feature description information corresponding to each of the N alarm events according to the above original description information and its associated service information includes: aggregating the original description information and its associated service information that belong to the target region and the target time period to obtain the feature description information about the i-th alarm event, where i is a positive integer less than or equal to N.

[0007] In an exemplary embodiment, based on the above solution, after determining the predicted fault types corresponding to each of the N alarm events according to the above fault classification model, the method further includes: displaying the predicted fault type corresponding to the i-th alarm event and the service information associated with the i-th alarm event, where i is a positive integer less than or equal to N.

[0008] In an exemplary embodiment, based on the above solution, obtaining the original description information includes: determining the associated devices of the target dedicated line channel according to the attributes of the target dedicated line channel, and performing a screening process on the associated devices of the target dedicated line channel to filter out interfering devices; and obtaining the original description information of the filtered associated devices within a preset time period.

[0009] In an exemplary embodiment, based on the above solution, determining the associated devices of the target dedicated line channel according to the attributes of the target dedicated line channel includes: determining the head node and the tail node of the target dedicated line channel according to the attributes of the target dedicated line channel to obtain the first-level associated devices. When the attribute of the target dedicated line channel is a cloud-side channel, the head node is an FCR device and the tail node is an access switch; determining the neighbor nodes corresponding to the first-level associated devices to obtain the second-level associated devices; and determining the neighbor nodes corresponding to the second-level associated devices until all nodes in the target dedicated line channel are traversed to obtain the associated devices of the target dedicated line channel.

[0010] In an exemplary embodiment, based on the above solution, after displaying the predicted fault types corresponding to each of the N alarm events in an interactive manner to adjust the predicted fault types, the method further includes: receiving the adjustment information of the predicted fault type of the j-th alarm event to obtain the actual fault type of the j-th alarm event, where j is a positive integer less than or equal to N.

[0011] In an exemplary embodiment, based on the above solution, the method further includes: adjusting the model parameters of the fault classification model through the feature description information of the j-th alarm event and the actual fault type.

[0012] In an exemplary embodiment, based on the above solution, the above method further includes: updating or adding feature description information about the alarm event; updating or adding classification labels for the alarm event; and adjusting model parameters of the above fault classification model by at least one of the updated feature description information and the updated classification labels.

[0013] In an exemplary embodiment, based on the above solution, the feature description information of each of the above alarm events includes at least one of the following information: alarm time, recovery time, region, number of channels, channel type, number of alarms, alarm type, number of access points, number of access switches, number of access ports, number of customer-side devices, peak utilization rate of channel bandwidth, average utilization rate of channel bandwidth, number of physical dedicated lines, number of customers, number of associated switch alarms, type of associated switch alarms, type of associated switch devices, number of FCR clusters, number of NGW clusters, channel jitter ratio of the same gateway, channel jitter ratio of the same dedicated line, BGP Down information, BFD Down information, number of FCR exception logs, IPSLADown information, difference between the received optical power of the port and the average value, difference between the transmitted optical power of the port and the average value, channel ping detection, number of alarms in a past preset duration, whether the channel traffic drops to zero, whether the dedicated line traffic drops to zero, whether the gateway traffic drops to zero, channel opening time, and cluster detection data.

[0014] In an exemplary embodiment, based on the above solution, the above predicted fault types include a first type and a second type; wherein, the above first type represents a customer-side fault, including any one of the following subclasses: single-channel fault, single dedicated line fault, line or equipment fault, dedicated line port fault, customer fault drill, and excessive channel utilization; the above second type represents a cloud-side fault, including any one of the following subclasses: internal network jitter, FCR device exception, NGW device exception, and access switch exception.

[0015] In a second aspect, the present application provides an intelligent processing device for access network dedicated line faults, and the device includes: an acquisition module, a prediction module, and a display module;

[0016] Wherein, the above acquisition module is used to acquire the feature description information respectively corresponding to N alarm events, and the feature description information of each of the above alarm events is obtained by aggregating according to geographical information and time information, and N is a positive integer; the above prediction module is used to process the feature description information respectively corresponding to the N alarm events through a trained fault classification model, and determine the predicted fault types respectively corresponding to the N alarm events according to the above fault classification model; and the above display module is used to display the predicted fault types respectively corresponding to the N alarm events in an interactive manner to adjust the above predicted fault types.

[0017] In an exemplary embodiment, based on the above solution, the obtaining module includes: a first obtaining unit, a second obtaining unit, and an association unit. Among them, the first obtaining unit is configured to: obtain original description information, where the original description information includes at least one of the following information: alarm device information, alarm type, alarm time; the second obtaining unit is configured to: obtain service information associated with the original description information, where the service information includes at least one of the following information: customer information, channel information, gateway information, dedicated line information; and, the association unit is configured to: determine the characteristic description information corresponding to the alarm event according to the original description information and its associated service information.

[0018] In an exemplary embodiment, based on the above solution, the obtaining module further includes: an aggregation unit. Among them, the aggregation unit is configured to: perform an aggregation process on the original description information and its associated service information that belong to the target region and the target time period, to obtain the characteristic description information about the i-th alarm event, where i is a positive integer less than or equal to N.

[0019] In an exemplary embodiment, based on the above solution, the intelligent processing device for access network dedicated line faults further includes: a second display module; among them, after the prediction module determines the predicted fault types corresponding to the N alarm events according to the fault classification model, the second display module is configured to: display the predicted fault type corresponding to the i-th alarm event and the service information associated with the i-th alarm event, where i is a positive integer less than or equal to N.

[0020] In an exemplary embodiment, based on the above solution, the first obtaining unit includes: a determination subunit and an obtaining subunit; among them, the determination subunit is configured to: determine the associated devices of the target dedicated line channel according to the attributes of the target dedicated line channel, and perform a screening process on the associated devices of the target dedicated line channel to filter out interfering devices; and, the obtaining subunit is configured to: obtain the original description information of the filtered associated devices within a preset time period.

[0021] In an exemplary embodiment, based on the above solution, the determination subunit is configured to: determine the head node and the tail node of the target dedicated line channel according to the attributes of the target dedicated line channel, to obtain first-level associated devices. When the attribute of the target dedicated line channel is a cloud-side channel, the head node is an FCR device and the tail node is an access switch; determine the neighbor nodes corresponding to the first-level associated devices to obtain second-level associated devices; and determine the neighbor nodes corresponding to the second-level associated devices until all nodes in the target dedicated line channel are traversed, to obtain the associated devices of the target dedicated line channel.

[0022] In an exemplary embodiment, based on the above solution, the intelligent processing device for access network dedicated line faults further includes: a receiving module; wherein, after the first display module displays the predicted fault types corresponding to the N alarm events in an interactive manner to adjust the predicted fault types, the receiving module is configured to: receive the adjustment information of the predicted fault type of the j-th alarm event to obtain the actual fault type of the j-th alarm event, where j is a positive integer less than or equal to N.

[0023] In an exemplary embodiment, based on the above solution, the intelligent processing device for access network dedicated line faults further includes: an adjustment module; the adjustment module is configured to: adjust the model parameters of the fault classification model through the feature description information of the j-th alarm event and the actual fault type.

[0024] In an exemplary embodiment, based on the above solution, the intelligent processing device for access network dedicated line faults further includes: an update module; the update module is configured to: update or add the feature description information about the alarm event; the update module is further configured to: update or add the classification label about the alarm event; the adjustment module is configured to: adjust the model parameters of the fault classification model through at least one of the updated feature description information and the updated classification label.

[0025] In an exemplary embodiment, based on the above solution, the feature description information of each of the alarm events includes at least one of the following information: alarm time, recovery time, region, number of channels, channel type, number of alarms, alarm type, number of access points, number of access switches, number of access ports, number of customer-side devices, peak utilization rate of channel bandwidth, average utilization rate of channel bandwidth, number of physical dedicated lines, number of customers, number of associated switch alarms, type of associated switch alarms, type of associated switch devices, number of FCR clusters, number of NGW clusters, channel jitter ratio of the same gateway, channel jitter ratio of the same dedicated line, BGP Down information, BFD Down information, number of FCR exception logs, IPSLA Down information, difference between the average received optical power of the port and the average value, difference between the average transmitted optical power of the port and the average value, channel ping detection, number of alarms in the past preset duration, whether the channel traffic drops to zero, whether the dedicated line traffic drops to zero, whether the gateway traffic drops to zero, channel opening time, and cluster detection data.

[0026] In an exemplary embodiment, based on the above solution, the predicted fault types include a first type and a second type; wherein, the first type represents a customer-side fault, including any one of the following sub-types: single-channel fault, single dedicated line fault, line or equipment fault, dedicated line port fault, customer fault drill, excessive channel utilization; the second type represents a cloud-side fault, including any one of the following sub-types: internal network jitter, FCR device anomaly, NGW device anomaly, access switch anomaly.

[0027] In a third aspect, an electronic device is provided, including a processor and a memory; the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory to execute the methods in the first aspect and its various implementation manners.

[0028] In a fourth aspect, a chip is provided for implementing the methods in any one of the first aspect or its various implementation manners. Specifically, the chip includes: a processor for calling and running a computer program from a memory, so that a device installed with the chip executes the methods in the first aspect and its various implementation manners.

[0029] In a fifth aspect, a computer-readable storage medium is provided for storing a computer program, and the computer program causes a computer to execute the methods in the first aspect and its various implementation manners.

[0030] In a sixth aspect, a computer program product is provided, including computer program instructions, and the computer program instructions cause a computer to execute the methods in the first aspect and its various implementation manners.

[0031] In a seventh aspect, a computer program is provided, which when running on a computer, causes the computer to execute the methods in the first aspect and its various implementation manners.

[0032] In summary, in the solution provided by the embodiments of the present application, the feature description information corresponding to N alarm events is obtained, where the feature description information of each alarm event is obtained after aggregation according to geographical information and time information. Through the aggregation process, a large number of information can be integrated, which is beneficial to improving the information processing efficiency. Further, the feature description information corresponding to the above N alarm events is processed by the trained fault classification model, and the predicted fault types corresponding to the N alarm events are determined according to the fault classification model. By diagnosing and analyzing a large number of alarm events based on the machine learning model, the fault diagnosis efficiency can be effectively improved. The predicted fault types corresponding to the N alarm events are displayed in an interactive manner, so that in the case where the prediction result of the model is deviated, the predicted fault type can be conveniently adjusted, so that on the basis of improving the fault diagnosis efficiency, the individual deviated diagnosis results are corrected, effectively ensuring the diagnostic accuracy of the access network dedicated line fault, and further being beneficial to improving the fault handling efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] In order to more clearly illustrate the technical solutions in the embodiments of the present invention of this application, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention of this application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0034] Figure 1 FIG. is a schematic diagram of a dedicated line channel applicable to the embodiments of the present application;

[0035] Figure 2 FIG. is a schematic flowchart of an intelligent processing system for access network dedicated line faults provided by the embodiments of the present application;

[0036] Figure 3 FIG. is a schematic flowchart of an intelligent processing method for access network dedicated line faults provided by the embodiments of the present application;

[0037] Figure 4 FIG. is a schematic flowchart of a method for determining feature description information provided by the embodiments of the present application;

[0038] Figure 5 FIG. is a schematic diagram of screening associated devices in a target dedicated line channel provided by the embodiments of the present application;

[0039] Figure 6 FIG. is a schematic flowchart of an intelligent processing method for access network dedicated line faults provided by the embodiments of the present application;

[0040] Figure 7Schematic flowchart of a method for determining a fault classification model provided by an embodiment of the present application;

[0041] Figure 8 Schematic diagram applicable to prediction by the KNN algorithm in an embodiment of the present application;

[0042] Figure 9 Schematic diagram applicable to prediction by the decision tree algorithm in an embodiment of the present application;

[0043] Figure 10 Schematic structural diagram of an intelligent processing device for access network dedicated line faults provided by an embodiment of the present application;

[0044] Figure 11 Schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0045] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.

[0046] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In the embodiments of the present invention and the present application, "B corresponding to A" means that B is associated with A. In one implementation, B can be determined according to A. However, it should also be understood that determining B according to A does not mean determining B only according to A, but B can also be determined according to A and / or other information. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or server including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices. In the description of the present application, unless otherwise specified, "a plurality of" means two or more than two.

[0047] In the embodiments of the present application, the term "module" or "unit" refers to a computer program with a predetermined function or a part of a computer program, which works together with other related parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as a processing circuit or a memory), or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of an overall module or unit that includes the function of that module or unit.

[0048] Artificial Intelligence (AI) is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use knowledge to obtain the best results. In other words, artificial intelligence is a comprehensive technology in computer science that attempts to understand the essence of intelligence and produce a new intelligent machine that can respond in a way similar to human intelligence. Artificial intelligence also studies the design principles and implementation methods of various intelligent machines to enable the machines to have the functions of perception, reasoning, and decision-making.

[0049] Artificial intelligence technology is an interdisciplinary subject that involves a wide range of fields, including both hardware-level technologies and software-level technologies. The basic technologies of artificial intelligence generally include sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technology, pre-trained model technology, operation / interaction systems, mechatronics, etc. Among them, the pre-trained model, also known as the large model or the foundation model, can be widely applied to downstream tasks in various directions of artificial intelligence after fine-tuning. The software technologies of artificial intelligence mainly include several major directions such as computer vision technology, speech processing technology, natural language processing technology, and machine learning / deep learning.

[0050] Machine Learning (ML) is an interdisciplinary subject that involves multiple disciplines such as probability theory, statistics, approximation theory, convex analysis, and algorithm complexity theory. It specifically studies how computers simulate or implement human learning behaviors to acquire new knowledge or skills and reorganize the existing knowledge structure to continuously improve their own performance. Machine learning is the core of artificial intelligence and the fundamental way to make computers intelligent, and its applications cover all fields of artificial intelligence. Machine learning and deep learning usually include technologies such as artificial neural networks, belief networks, reinforcement learning, transfer learning, inductive learning, and rote learning. The pre-trained model is the latest development result of deep learning, which integrates the above technologies.

[0051] With the research and progress of artificial intelligence technology, artificial intelligence technology has been studied and applied in multiple fields, such as common smart homes, smart wearable devices, virtual assistants, smart speakers, smart marketing, driverless, autonomous driving, drones, digital twins, virtual humans, robots, artificial intelligence-generated content (AIGC), conversational interaction, intelligent healthcare, intelligent customer service, game AI, etc. It is believed that with the development of technology, artificial intelligence technology will be applied in more fields and play an increasingly important role.

[0052] The solution provided by the embodiments of this application relates to technologies such as machine learning in artificial intelligence. The technical solutions of the embodiments of this application will be described in detail through some embodiments below. These embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.

[0053] Figure 1 It is a schematic diagram of a dedicated line channel applicable to the embodiments of this application. Figure 1 It shows the neighbor relationship of establishing a dedicated line channel between the pavement instance device (such as, Fast Cloud Router (FCR)) in the platform cloud intranet and the customer's Internet Data Center (IDC). Refer to Figure 1 , the dedicated line channel includes the following nodes: IDC, the access switch in the platform cloud intranet, the forwarding instance device (such as, Next Generation Gateway (NGW)), and FCR. The dedicated line channel also includes the lines between nodes, including the operator line S1 connecting IDC and the access switch in the platform cloud intranet, the line S2 between the access switch and NGW, and the line S3 between NGW and FCR. Among them, the access switch can be a High Speed Access (HSA), Intermediate Speed Access (MSA), or Low Speed Access (LSA).

[0054] Refer to Figure 1 , the forwarding instance device is connected to the Virtual Private Cloud (VPC). The VPC is used to provide cloud services for users, such as the cloud dedicated line product of the platform.

[0055] Exemplarily, most (e.g., more than 90%) of the alarm times are triggered by neighbor jitter of the dedicated line channel. Specifically, it can be alarms caused by anomalies in links, ports, or nodes on the network path from the FCR to the customer IDC. Exemplary alarm types include: Border Gateway Protocol (BGP) down alarm of the FCR, Bidirectional Forwarding Detection (BFD) session DOWN alarm of the FCR, IP Service-Level Agreement (SLA) session DOWN alarm of the FCR, etc. Exemplarily, the device for generating the alarm can be the FCR.

[0056] In the related art, the original alarm information of the dedicated line channel has the following characteristics:

[0057] Large quantity of original alarm messages: 10,000 - 20,000 alarms per month, and with the growth of business, the quantity of the original alarm information is continuously increasing;

[0058] Simple content of the original alarm messages: For example, it only contains brief information such as device name, IP, alarm type, time, neighbor IP, Virtual Cloud Router (VCR) ID, etc.; business information such as customers, channels, gateways, dedicated lines, etc. is missing;

[0059] The original alarm information is scattered and disorderly: There may be 1 - 100 alarms within one minute. In many cases, the overall situation of the alarm information cannot be understood from a single alarm message.

[0060] In the related art, during the process of manually resolving the alarm information of the dedicated line channel, the operation and maintenance personnel need to jump back and forth between systems such as the network collection system (Monitor Platform, MP) of the platform to query relevant business information, and manually summarize information such as the affected channels and customer lists of each alarm message. However, there is a large amount of dedicated line alarm information, which not only consumes the operation and maintenance manpower for troubleshooting; on the other hand, it may miss handling alarms, the service is not restored in time, and the customer is not notified in time. It can be seen that the related art has the problem of low efficiency in handling access network network faults, which affects the user experience of using the dedicated line product service.

[0061] The embodiments of the present application can solve the technical problems existing in the related art. By accumulating a large number of in-network alarm cases and combining mature machine learning algorithms, the embodiments of the present application provide an automated analysis solution for access network dedicated line faults based on machine learning. Through a large number of in-network operation practices, the fault type is predicted through a machine learning model, and the fault diagnosis and location of the dedicated line access network can be achieved at the minute level (e.g., within 1 minute). Through this automated analysis solution for access network dedicated line faults based on machine learning, alarm information can be processed automatically, effectively ensuring the diagnostic accuracy rate of access network dedicated line faults, ensuring that customers are notified in a timely manner, and being beneficial to improving the customer's cloud access experience. At the same time, it can also save operation and maintenance manpower.

[0062] In an exemplary embodiment, Figure 2 is a schematic flowchart of an intelligent processing system 200 for access network dedicated line faults provided by an embodiment of the present application. Refer to Figure 2 , the system 200 includes: an alarm inspection module 210, an alarm event database 220, an alarm diagnosis module 230, a classification diagnosis report 240, and a real-time alarm dashboard 250.

[0063] Among them, the alarm inspection module 210 is used to collect offline data, and store the collected labeled historical alarm events (including the feature description information of the alarm events and their fault classifications) in the alarm event database 220. The data in the alarm event database 220 is used to train the fault classification model. The alarm inspection module 210 is also used to collect online data, preprocess the collected online data to obtain the feature description information corresponding to each alarm event, and then use the feature description information corresponding to an alarm event as a set to input into the alarm diagnosis module 230 (the trained fault classification model) to predict the fault type of the input alarm event through the fault analysis model. Furthermore, a fault solution can be provided according to the predicted fault type.

[0064] Figure 3 is a schematic flowchart of an intelligent processing method P300 for access network dedicated line faults provided by an embodiment of the present application. Refer to Figure 3 , the method P300 includes: S310 - S330.

[0065] In S310, obtain the feature description information corresponding to N alarm events respectively, and the feature description information of each alarm event is obtained by aggregating according to geographical information and time information.

[0066] Among them, N represents the number of alarm events to be diagnosed. Exemplarily, the embodiments of the present application can diagnose N alarm events in parallel, thereby improving the processing efficiency of alarm events. Even if multiple alarm events occur in a short period of time, the diagnosis will be achieved in a short period of time.

[0067] Among them, the feature description information corresponding to each of the above warning events is obtained according to the original warning information.

[0068] Exemplarily, the above original warning information is the alarm information sent by a warning device such as an FCR, which is used to describe the characteristics of the warning event. As mentioned above, the original warning information has problems such as simple and unrich content, large quantity and scattered messiness. In view of the above problems existing in the original warning information, the embodiments of the present application perform a preprocessing operation on the original warning information, that is, the feature description information corresponding to a warning event is obtained after preprocessing the original warning information.

[0069] Exemplarily, the above preprocessing operation may include the following two aspects of operations. On the one hand, it is to perform an association processing operation on the original warning information and relevant service information; on the other hand, perform an aggregation processing operation on the feature description information. Through the above two aspects of operations, the feature description information corresponding to a warning event can be obtained, that is, the input information of the model is obtained. It should be noted that the above preprocessing operation may only include the association processing operation, may also only include the aggregation processing operation, or may include both the association operation and the aggregation processing operation. How to preprocess the original warning information can be flexibly determined according to actual needs, and the embodiments of the present application do not limit this.

[0070] The following combines Figure 4 to describe the association processing operation in detail:

[0071] In an exemplary embodiment, Figure 4 is a schematic flowchart of a method P400 for determining feature description information provided by an embodiment of the present application. It can be understood that the method P400 can be used for determining the feature description information in the training samples, and can also be used for determining the to-be-predicted / to-be-diagnosed feature description information collected online (such as the feature description information in S210). Refer to Figure 4 , this method P400 includes: S410 - S430.

[0072] In S410, obtain the original description information, where the original description information includes at least one of the following information: warning device information, warning type, and warning time.

[0073] The warning patrol inspection module 310 queries the original warning information from the network collection system of the platform. The content of the original warning information is relatively simple, for example, it only includes brief information such as device name, IP, warning type, time, neighbor IP, VCR ID, etc. This original warning information lacks relevant service information, such as customer information, channel information, gateway information, dedicated line information, etc.

[0074] In an exemplary embodiment, when the alarm inspection module 310 queries the original alarm information from the network collection system of the platform, a full-volume query method may be adopted. When there is a problem of low efficiency in using the full-volume query, the range of the queried original alarm information may be optimized to eliminate the interfering original alarm information.

[0075] S410-1. According to the attributes of the target dedicated line channel, determine the associated devices of the target dedicated line channel, and perform screening processing on the associated devices of the target dedicated line channel to screen out interfering devices. That is, determine the devices with low relevance to the target dedicated line channel as interfering devices.

[0076] Regarding the specific implementation manner of the above S410-1, it may include the following steps:

[0077] S1. According to the attributes of the above target dedicated line channel, determine the head node and the tail node of the target dedicated line channel to obtain the first-level associated devices.

[0078] Exemplarily, when the attribute of the above target dedicated line channel is a cloud-side channel, the head node is the FCR device, and the tail node is the access switch. Exemplarily, when the attribute of the above target dedicated line channel is a customer-side channel, the device before the access switch and the tail node are the user terminals.

[0079] Exemplarily, referring to Figure 5 , when the attribute of dedicated line channel 1 is a cloud-side channel, the head node is the FCR device, and the tail node is the access switch XSA, and the FCR device and XSA are determined as the first-level associated devices of dedicated line channel 1.

[0080] S2. Determine the neighbor nodes corresponding to the first-level associated devices respectively to obtain the second-level associated devices. S3. Determine the neighbor nodes corresponding to the second-level associated devices respectively until all the nodes in the target dedicated line channel are traversed to obtain the associated devices of the target dedicated line channel.

[0081] Exemplarily, by querying the neighbor device list of the channel head and tail node devices, the second-level associated devices can be determined. Exemplarily, referring to Figure 1 , the first-level associated devices of dedicated line channel 1 are the FCR device and XSA, and the neighbor nodes of the FCR device and XSA are the same, both being the forwarding example device NGW. Then all the associated devices of dedicated line channel 1 are determined.

[0082] S4. Perform screening processing on the associated devices of the target dedicated line channel to screen out interfering devices

[0083] Exemplarily, since the isolated ports generally have no traffic or very little traffic, the devices with isolated ports can be excluded from the above-mentioned associated devices. Exemplarily, device types that the target dedicated line channel cannot pass through are also excluded, such as out-of-band management switches, etc.

[0084] Exemplarily, referring to Figure 5 , through the determination and exclusion process of the above-mentioned associated devices, device 51 can be excluded, and the remaining associated devices with dedicated line channel 1 include device 52, FCR device, and XSA. The embodiment of the present application screens out irrelevant devices spatially, reduces the devices that may generate interference information, and is beneficial to accurately determining the query range of the original warning information.

[0085] S410-2, obtain the original description information of the associated devices of the target dedicated line channel after screening processing within a preset time period.

[0086] Exemplarily, query the original warning information of the above devices within 1 minute of the channel alarm.

[0087] In an exemplary embodiment, the original description information of the associated devices after screening processing within a preset time period can also be screened to exclude alarm types that cannot affect the target dedicated line channel. For example, neighbor route exceeds high water level alarm, fan alarm, etc. Thus, the query range of the original alarm information is further narrowed.

[0088] In the solution provided by S410, the associated devices of the target dedicated line channel can be determined, that is, the original alarm information generated by non-associated devices is not considered, so as to achieve the first range reduction spatially. Interference devices can also be removed from the associated devices, that is, the original alarm information generated by interference devices is not considered, so as to achieve the second range reduction spatially. For the associated devices after screening out interference devices, only the original alarm information generated within a preset duration is considered, so as to achieve the third range reduction temporally. Further, alarm types that cannot affect the target dedicated line channel can also be screened according to the types of the above original alarm information, so as to achieve the fourth range reduction from the perspective of alarm types. By accurately narrowing the query range, it is beneficial to improve the query efficiency.

[0089] In S420, obtain the service information associated with the original description information, where the service information includes at least one of the following information: customer information, channel information, gateway information, dedicated line information.

[0090] After the alarm inspection module 310 queries the original alarm information from the network collection system of the platform, it also obtains the service information associated with the original description information, where the service information includes at least one of the following information: customer information, channel information, gateway information, dedicated line information.

[0091] In S430, based on the original description information and its associated service information, the feature description information is determined.

[0092] The alarm inspection module 310 associates the above-mentioned original alarm information with its surrounding service information, so as to output relatively rich feature description information. Further, the alarm inspection module 310 enters the recorded case library of the marked historical alarm events, and the unmarked real-time alarm events can be directly used as the input of the alarm diagnosis module 320, or can be used as the input of the alarm diagnosis module 320 after aggregation processing.

[0093] Through the solution provided by method P400, by associating the original alarm information with its related service information, the problem of the simple content of the original alarm information can be solved, so as to predict faults by enriching the description features of alarm events, which is beneficial to ensuring the accuracy of fault diagnosis.

[0094] Next, an embodiment of the aggregation operation is introduced:

[0095] In one implementation, the alarm inspection module 310 is further configured to aggregate the originally collected alarm information by region and minute granularity to obtain alarm events.

[0096] In one implementation, the alarm inspection module 310 is further configured to aggregate the information after the above-mentioned association processing by region and minute granularity to obtain alarm events.

[0097] In an exemplary embodiment, the feature description information corresponding to each alarm event is obtained by aggregating by region and minute granularity. Exemplarily, the original description information belonging to the target region and the target time period and its associated service information are aggregated to obtain the feature description information about the i-th alarm event. For example, the alarm event after aggregation processing can be expressed as: "At 15:03:00 on August 28, 2023, 10 dedicated line channel alarm messages appeared in Beijing (which can be the original alarm information or the alarm information after association operation processing)". In this application, the aggregation processing is not real-time aggregation processing.

[0098] Through the above aggregation processing, multiple alarm messages (which can be the original alarm information or the alarm information after association operation processing) can be aggregated into the feature description information about different alarm events, and then the multiple feature description information related to the alarm events is used as a set for unified analysis and diagnosis. For example, even if there may be 1 to 100 alarm messages (which can be the original alarm information) within one minute, through the above aggregation processing, the overall situation of the entire alarm event can be understood, so as to solve the problem of the scattered and messy original alarm information in the related art.

[0099] After the alarm inspection module 310 performs the above preprocessing operations on the online collected data, the feature description information corresponding to the i-th alarm event can be obtained. Exemplarily, the above feature description information in the embodiments of the present application can refer to Table 1.

[0100] Table 1

[0101]

[0102]

[0103] It can be understood that the feature description information in the embodiments of the present application is not limited to the content shown in Table 1. It can also be other relevant feature description information about the alarm event, and the embodiments of the present application do not limit this.

[0104] Refer to Figure 3 , the alarm inspection module 210 takes the feature description information about an alarm event obtained after pre-operation processing as a set and inputs it into the alarm diagnosis module 230 (the trained fault classification model) to predict the fault type of the input alarm event through the fault analysis model. Furthermore, a fault solution can be provided according to the predicted fault type.

[0105] In S320, the feature description information corresponding to the N alarm events is processed by the trained fault classification model, and the predicted fault types corresponding to the N alarm events are determined according to the fault classification model.

[0106] Exemplarily, after the feature description information of an alarm event is input into the above trained fault classification model, after being analyzed and processed by the model, the predicted fault type output by the model can refer to Table 2.

[0107] Table 2

[0108]

[0109]

[0110] Referring to Table 2, the predicted fault types can be divided into 2 major categories, namely the cloud side or the customer side, and are further divided into 10 sub-categories as shown in Table 2. It can be understood that the predicted fault types are not limited to the types shown in Table 2, and can also be other fault types of the dedicated line channel, which can be continuously added or adjusted during the subsequent model optimization process. The embodiments of the present application do not limit the predicted fault types.

[0111] In S330, the predicted fault types corresponding to the N alarm events are displayed in an interactive manner to adjust the predicted fault types.

[0112] In an exemplary embodiment, refer to Figure 2, the output of the alarm diagnosis module 230 can be a classified diagnosis report 240 presented interactively. This module can adopt a templatized message function to provide rich message interaction capabilities, thus facilitating the annotation of the classified diagnosis report. Exemplarily, when the predicted fault type of alarm event A is determined according to the model output, targeted solutions, causes of faults, measures to avoid faults, etc. can be provided based on the characteristics of alarm event A. Then, based on the above-mentioned interactive capabilities, detailed information such as the solutions, causes of faults, and measures to avoid faults for high-level event A can be added, which is beneficial to improving the resolution efficiency of alarm events or reducing the occurrence frequency of alarm events. Another exemplarily, when it is determined that the predicted fault type of a certain alarm event by the model is inaccurate or needs to be adjusted, the actual fault type after correction can be provided based on the above-mentioned interactive capabilities, which is beneficial to ensuring the accuracy of fault diagnosis. In this embodiment, the classified diagnosis report 240 can implement group push of templatized messages, enabling operation and maintenance personnel to view faults in a timely and convenient manner, which is conducive to quickly determining fault solutions. For example, the closed-loop feedback of alarm events can be completed within 1 minute and notified to relevant personnel.

[0113] In an exemplary embodiment, when the alarm inspection module 210 performs a preprocessing operation and specifically performs an association operation process, refer to Figure 2 , the output of the alarm diagnosis module 230 can also be displayed on the real-time alarm dashboard 250.

[0114] In an exemplary embodiment, Figure 6 is a schematic flowchart of an intelligent processing method P600 for access network dedicated line faults provided by an embodiment of the present application. Refer to Figure 6 , the method P600 includes: S610 - S660.

[0115] Among them, the method P600 is implemented based on P300, and the specific implementation manners of S610 - S630 are the same as those of S310 - S330 and will not be elaborated here.

[0116] Refer to Figure 6 , after executing S620, S660 is also executed: displaying the predicted fault type corresponding to the i-th alarm event and the service information related to the i-th alarm event. Exemplarily, the predicted fault type or actual fault type corresponding to each alarm event and the service information associated with the alarm event are displayed through the real-time alarm dashboard 250. As mentioned above, the service information includes at least one of the following information: customer information, channel information, gateway information, dedicated line information. Exemplarily, the above real-time alarm dashboard 250 can be implemented based on the Grafana system, which integrates real-time service data of multiple systems, making the visualization of alarm events more intuitive and facilitating the timely resolution of faults.

[0117] Continue to refer to Figure 6 , after executing S630, S640 and S650 are also executed. In S640, adjustment information for the predicted fault type of the j-th alarm event is received to obtain the actual fault type of the j-th alarm event, where j is a positive integer less than or equal to N. In S650, the model parameters of the fault classification model are adjusted by the feature description information of the j-th alarm event and the actual fault type.

[0118] Due to machine learning model prediction errors, or real-time adjustments based on the causes of faults, etc., the predicted fault type may be inaccurate, or there may be a need to further adjust the predicted fault type. Then, based on the interactive function of the classification diagnosis report 240, the predicted fault type can be adjusted to the actual fault type. Further, the model parameters of the fault classification model can also be adjusted by the feature description information of the j-th alarm event and the actual fault type, so as to improve the prediction ability of the fault classification model and enhance the prediction accuracy of the fault classification model.

[0119] Refer to Figure 2 , where the alarm event database 220 is continuously updated, including the labeled historical alarm events collected offline by the alarm inspection module 210, and may also include the alarm events predicted by the model output by the alarm diagnosis module 230 (including prediction labels), and may also include the alarm events adjusted by the user to the actual fault type, as well as the alarm events manually labeled by the user. It should be noted that for the alarm events whose predicted fault types need to be adjusted, they need to be deleted from the alarm event database to avoid the influence of samples with inaccurate labels on the model prediction ability. Among them, the alarm events stored in the alarm event database 220 are used to train or adjust the fault classification model.

[0120] The following will introduce in detail an embodiment for training a machine learning model to determine a fault classification module. Exemplarily, Figure 7 is a schematic flowchart of a method P700 for determining a fault classification model provided by an embodiment of the present application.

[0121] In an exemplary embodiment, a full-scale data set is obtained from the alarm event database 220 as a sample, for example, including 8,499 alarm events, and each alarm event is labeled with a classification label for each alarm event manually or automatically. Exemplarily, 70% of the full-scale data set is randomly selected as the training data set.

[0122] In an exemplary embodiment, the machine learning classification algorithm adopted in the embodiments of the present application may be: the K Nearest Neighbors (KNN) algorithm. The KNN algorithm finds the nearest K neighbors by measuring the distance between the new data point and the known data points, and then predicts the class of the new data point based on the classes of these neighbors. Exemplarily, referring to Figure 8 , when K is set to 5, the 5 known-type data points closest to the data point to be measured are obtained. The 5 known-type data points are respectively one of the plus sign type, one of the circle symbol type, and three of the triangle symbol type. Then, the classification of the data point to be measured is determined according to the classification with the largest quantity, that is, the classification of the data point to be measured is the triangle symbol.

[0123] In an exemplary embodiment, the machine learning classification algorithm adopted in the embodiments of the present application may be: the decision tree classification algorithm. The decision tree classification algorithm forms a tree structure by learning decision rules from data features to achieve the classification of new data. Exemplarily, referring to Figure 9 , it is determined whether it is a fault of the access switch port. If so, the fault type is determined to be a dedicated line port fault; if not, the fault type cannot be directly determined and further judgment is required: whether it is a fault of the cloud-side intranet device port. If so, the fault type is determined to be a cloud-side intranet device port fault; if not, the fault type cannot be directly determined and further judgment is required: whether the channel utilization rate is too high. If so, the fault type is determined to be too high channel utilization rate; if not, the fault type cannot be directly determined and a further judgment process is required.

[0124] In an exemplary embodiment, the machine learning classification algorithm adopted in the embodiments of the present application may be: the random forest algorithm. The random forest algorithm classifies by combining multiple decision tree models. Each decision tree is trained based on a randomly selected subset of features and a randomly selected subset of samples, and finally the classification is performed by voting or averaging the prediction results.

[0125] In an exemplary embodiment, the machine learning classification algorithm adopted in the embodiments of the present application may be other classification algorithms, such as the logistic regression algorithm, the support vector machine algorithm, etc. The embodiments of the present application do not limit this.

[0126] In an exemplary embodiment, the above classification algorithm is trained with the above training dataset. Exemplarily, the embodiments of the present application have respectively trained the KNN algorithm model, the decision tree algorithm model, and the random forest algorithm model with the above training samples.

[0127] In an exemplary embodiment, the trained fault classification model can be measured using a test data set. Exemplarily, 30% of the remaining samples in the full data set after random sampling are determined as the training data set. Further, the performance of the fault classification model is evaluated using the above training data set. Exemplarily, the test metric in the embodiments of the present application is accuracy. Specifically, accuracy refers to the ratio of the number of correctly classified samples to the total number of samples. That is: (TP + TN) / (ALL). Where TP refers to the positive samples retrieved, which are actually positive samples; TN refers to the positive samples not retrieved, which are actually negative samples; and ALL refers to all test samples.

[0128] In the above embodiment, the KNN algorithm model, decision tree algorithm model, and random forest algorithm model are respectively trained using the above training samples, and the test results are as follows: the overall accuracy of the KNN algorithm model is 98.63%, the overall accuracy of the decision tree algorithm model is 99.02%, and the overall accuracy of the random forest algorithm model is 99.29%. Among them, the accuracy of the fault classification model obtained by training the random forest algorithm model is the highest and can be used for fault diagnosis of alarm events.

[0129] To further improve the diagnostic accuracy of the model for alarm events, the model parameters can also be tuned regularly or irregularly.

[0130] In an exemplary embodiment, on the one hand, the feature description information about the alarm event can be updated or increased, and on the other hand, the classification label about the alarm event can also be updated or increased. The model parameters of the fault classification model are adjusted using at least one of the updated feature description information and the updated classification label to optimize the prediction performance of the model in real time.

[0131] Optimization embodiment 1 of the fault classification model: By deploying a Virtual Private Network (VPN) instance for each service to be isolated on a Multi-VPN-Instance Customer Edge (MCE) device. Different VPN users deploy independent routing protocols to communicate with the MCE device. The MCE extends the functions of the Provider Edge (PE) device at the edge of the service provider network to the CE device. Each interface of the MCE and the interfaces of the PE accessing the multi-instance CE are bound with corresponding VPN instances, and an independent routing forwarding table is created and maintained for each VPN, thus establishing an independent channel for the VPN user and achieving service isolation for different users.

[0132] In the feature description field of the related technology, the feature field related to FCR MCE is not included, resulting in the inability to accurately diagnose the channel alarm event caused by the FCR device MCE exception. In the embodiments of the present application, the feature field related to FCR MCE and the corresponding label "Abnormal FCR device on the cloud side" or "Abnormal FCR device MCE on the cloud side" will be added. That is, the feature description information of the alarm event is the feature field related to FCR MCE, and the corresponding label is: Abnormal FCR device on the cloud side, and the fault classification model is trained to optimize the model parameters. Thereby enriching the training samples of the model and further improving the model prediction accuracy. Exemplarily, before the above optimization, the predicted fault type of the fault classification model for the related alarm event may be "Single-channel debugging on the customer side". After the above optimization, the predicted fault type of the fault classification model for the related alarm event is "Fault of FCR device on the cloud side".

[0133] Optimization embodiment 2 of the fault classification model: The target platform may conduct dedicated line fault drills in the customer's user data center IDC (i.e., the customer side). The characteristics of its alarm event are: only affecting the target platform, multiple physical dedicated lines and neighbors on the cloud side are interrupted simultaneously, and there are no other alarms on the cloud side. In the predicted fault classification / label of the related technology, the customer-side customer fault drill is not included. In this case, the present application embodiment adds the classification label "Customer-side customer fault drill". That is, the feature description information of the alarm event is: only affecting the target platform, multiple physical dedicated lines and neighbors on the cloud side are interrupted simultaneously, and there are no other alarms on the cloud side, and the corresponding label is: Customer-side customer fault drill, and the fault classification model is trained to optimize the model parameters. Exemplarily, before the above optimization, the predicted fault type of the fault classification model for the related alarm event may be "Multiple dedicated line faults on the customer side". After the above optimization, the predicted fault type of the fault classification model for the related alarm event is "Customer-side customer fault drill".

[0134] Optimization Example 3 for the Fault Classification Model: When it is determined that the predicted fault type x1 of the fault classification model for a certain alarm event B is inaccurate or needs adjustment, the corrected actual fault type x2 can be provided based on the interactive ability of the classification diagnosis report 240. In this case, the classification label of the alarm event B in the embodiment of the present application is updated from x1 to the actual fault type x2. That is, the sample of "the feature description information of the alarm event B and the predicted fault type x1" is screened out from the sample set, or the sample is directly updated to "the feature description information of the alarm event B and the predicted fault type x2"; and the fault classification model is trained with the updated sample "the feature description information of the alarm event B and the corresponding label actual fault type x2" to optimize the model parameters. Exemplarily, before the aforementioned optimization, the predicted fault type of the fault classification model for the alarm event B may be x1;. After the above optimization, the predicted fault type of the fault classification model for the alarm event B is x2.

[0135] It can be understood that the embodiments for optimizing the fault classification model are not limited to the above embodiments, and other ways for improving the model diagnosis accuracy rate may also be used, and the embodiments of the present application do not limit this.

[0136] In an exemplary embodiment, after determining the fault type of the alarm event through the fault classification model, it can also be divided into different levels according to the customer level, business volume, and influence range, etc. Exemplarily, the first-level fault type: a channel with a traffic exceeding 1 Mbps, affecting 2 or more dedicated lines of a single customer; the second-level fault type: a channel with a traffic exceeding 100 Mbos, affecting more than 3 customers.

[0137] Furthermore, according to the fault level, the handling measures for the fault are determined to actively handle alarm events of each level in a timely manner. For example, the handling method for the alarm event of the first-level fault type can be upgraded to a telephone alarm to attract the attention of relevant personnel in a timely manner. For example, the handling method for the alarm event of the second-level fault type can be to push the alarm event and its fault type through group messages. For example, the handling method for the alarm events of the first-level fault type and the second-level fault type can be to push the fault message to relevant customers to ensure that the customers are notified in a timely manner.

[0138] In the solution provided by the embodiments of the present application, characteristic description information corresponding to N alarm events is obtained. Among them, the characteristic description information of each alarm event is obtained after aggregation according to geographical information and time information. Through the aggregation process, a large number of information can be integrated, which can specifically solve the problem of scattered and disordered alarm information (characteristic description information) in the related art, and is beneficial to improving the information processing efficiency. Further, the characteristic description information corresponding to the above N alarm events is processed by a trained fault classification model, and the predicted fault types corresponding to the above N alarm events are determined according to the fault classification model. By diagnosing and analyzing a large number of alarm events based on the machine learning model, the fault diagnosis efficiency can be effectively improved. The predicted fault types corresponding to the above N alarm events are displayed in an interactive manner, so that when it is determined that there is a deviation in the prediction result of the model, the predicted fault type can be conveniently adjusted. Thus, on the basis of improving the fault diagnosis efficiency, individual diagnosis results with deviations are corrected, effectively ensuring the diagnostic accuracy of the access network dedicated line fault, and also being beneficial to improving the solution efficiency of alarm events and reducing the occurrence frequency of alarm events.

[0139] As described above in conjunction with Figures 2 to 9 , the embodiments of the method for processing access network channel faults of the present application have been described in detail. Below in conjunction with Figure 10 , the embodiments of the intelligent processing device for access network dedicated line faults of the present application will be described in detail.

[0140] Figure 10 FIG. is a schematic structural diagram of an intelligent processing device 1000 for access network dedicated line faults provided by the embodiments of the present application. Referring to Figure 10 , the intelligent processing device 1000 for access network dedicated line faults includes: an acquisition module 1010, a prediction module 1020, and a display module 1030;

[0141] Among them, the above acquisition module 1010 is used to obtain the characteristic description information corresponding to N alarm events. The characteristic description information of each of the above alarm events is obtained after aggregation according to geographical information and time information, and N is a positive integer; the above prediction module 1020 is used to process the characteristic description information corresponding to the above N alarm events by a trained fault classification model, and determine the predicted fault types corresponding to the above N alarm events according to the above fault classification model; and, the above first display module 1030 is used to display the predicted fault types corresponding to the above N alarm events in an interactive manner to adjust the above predicted fault types.

[0142] In an exemplary embodiment, based on the above solution, the above acquisition module 1010 includes: a first acquisition unit, a second acquisition unit, and an association unit.

[0143] Among them, the first obtaining unit is used to: obtain the original description information, and the original description information includes at least one of the following information: alarm device information, alarm type, alarm time; the second obtaining unit is used to: obtain the service information associated with the original description information, and the service information includes at least one of the following information: customer information, channel information, gateway information, dedicated line information; and, the association unit is used to: determine the characteristic description information corresponding to the alarm event according to the original description information and its associated service information.

[0144] In an exemplary embodiment, based on the above solution, the obtaining module 1010 further includes: an aggregation unit.

[0145] Among them, the aggregation unit is used to: perform aggregation processing on the original description information belonging to the target region and the target time period and its associated service information to obtain the characteristic description information about the i-th alarm event, where i is a positive integer less than or equal to N.

[0146] In an exemplary embodiment, based on the above solution, the intelligent processing device 1000 for access network dedicated line faults further includes: a second display module;

[0147] Among them, after the prediction module 1020 determines the predicted fault types corresponding to the N alarm events according to the fault classification model, the second display module is used to: display the predicted fault type corresponding to the i-th alarm event and the service information associated with the i-th alarm event, where i is a positive integer less than or equal to N.

[0148] In an exemplary embodiment, based on the above solution, the first obtaining unit includes: a determination subunit and an obtaining subunit;

[0149] Among them, the determination subunit is used to: determine the associated devices of the target dedicated line channel according to the attributes of the target dedicated line channel, and perform screening processing on the associated devices of the target dedicated line channel to filter out interfering devices; and the obtaining subunit is used to: obtain the original description information of the filtered associated devices within a preset time period.

[0150] In an exemplary embodiment, based on the above solution, the above-mentioned determination subunit is configured to: determine the head node and the tail node of the above-mentioned target dedicated line channel according to the attributes of the above-mentioned target dedicated line channel, so as to obtain first-level associated devices. Wherein, when the attribute of the above-mentioned target dedicated line channel is a cloud-side channel, the above-mentioned head node is an FCR device, and the above-mentioned tail node is an access switch; determine the neighbor nodes respectively corresponding to the above-mentioned first-level associated devices to obtain second-level associated devices; and determine the neighbor nodes respectively corresponding to the above-mentioned second-level associated devices until all nodes in the above-mentioned target dedicated line channel are traversed to obtain the associated devices of the above-mentioned target dedicated line channel.

[0151] In an exemplary embodiment, based on the above solution, the intelligent processing device 1000 for access network dedicated line faults further includes: a receiving module;

[0152] Wherein, after the above-mentioned first display module 1030 displays the predicted fault types respectively corresponding to the above-mentioned N alarm events in an interactive manner to adjust the above-mentioned predicted fault types, the above-mentioned receiving module is configured to: receive the adjustment information of the predicted fault type of the j-th alarm event to obtain the actual fault type of the j-th alarm event, where j is a positive integer less than or equal to N.

[0153] In an exemplary embodiment, based on the above solution, the intelligent processing device 1000 for access network dedicated line faults further includes: an adjustment module;

[0154] The above-mentioned adjustment module is configured to: adjust the model parameters of the above-mentioned fault classification model through the feature description information of the above-mentioned j-th alarm event and the above-mentioned actual fault type.

[0155] In an exemplary embodiment, based on the above solution, the intelligent processing device 1000 for access network dedicated line faults further includes: an update module;

[0156] The above-mentioned update module is configured to: update or add feature description information about alarm events; the above-mentioned update module is further configured to: update or add classification labels about alarm events; the above-mentioned adjustment module is configured to: adjust the model parameters of the above-mentioned fault classification model through at least one of the updated feature description information and the updated classification labels.

[0157] In an exemplary embodiment, based on the above solution, the feature description information of each of the above alarm events includes at least one of the following information: alarm time, recovery time, region, number of channels, channel type, number of alarms, alarm type, number of access points, number of access switches, number of access ports, number of customer-side devices, peak utilization rate of channel bandwidth, average utilization rate of channel bandwidth, number of physical dedicated lines, number of customers, number of associated switch alarms, type of associated switch alarms, type of associated switch devices, number of FCR clusters, number of NGW clusters, channel jitter ratio of the same gateway, channel jitter ratio of the same dedicated line, BGP Down information, BFD Down information, number of FCR exception logs, IPSLADown information, difference between the optical receiving power of the port and the average value, difference between the optical transmitting power of the port and the average value, channel ping detection, number of alarms in a past preset duration, whether the channel traffic drops to zero, whether the dedicated line traffic drops to zero, whether the gateway traffic drops to zero, channel opening time, and cluster detection data.

[0158] In an exemplary embodiment, based on the above solution, the above predicted fault types include a first type and a second type; wherein, the first type represents a customer-side fault, including any one of the following subclasses: single-channel fault, single dedicated-line fault, line or device fault, dedicated-line port fault, customer fault drill, and excessive channel utilization; the second type represents a cloud-side fault, including any one of the following subclasses: internal network jitter, FCR device exception, NGW device exception, and access switch exception.

[0159] In the solution provided by the embodiment of the present application, the feature description information corresponding to N alarm events is obtained, wherein the feature description information of each of the alarm events is obtained after being aggregated according to geographical information and time information. Through the aggregation process, a large number of information can be integrated, which can specifically solve the problem of scattered and disorderly alarm information (feature description information) in the related art and is beneficial to improving the information processing efficiency. Further, the feature description information corresponding to the N alarm events is processed by a trained fault classification model, and the predicted fault types corresponding to the N alarm events are determined according to the fault classification model. By diagnosing and analyzing a large number of alarm events based on the machine learning model, the fault diagnosis efficiency can be effectively improved. The predicted fault types corresponding to the N alarm events are displayed in an interactive manner, so that in the case where the prediction result of the model is deviated, the predicted fault type can be conveniently adjusted, thereby correcting individual deviated diagnosis results on the basis of improving the fault diagnosis efficiency, effectively ensuring the diagnostic accuracy of the dedicated line fault in the access network, and also being beneficial to improving the solution efficiency of alarm events and reducing the occurrence frequency of alarm events.

[0160] It should be understood that the embodiments of the intelligent processing device for access network dedicated line faults correspond to the embodiments of the intelligent processing method for access network dedicated line faults. Similar descriptions can refer to the embodiments of the intelligent processing method for access network dedicated line faults. To avoid repetition, they will not be elaborated here. Specifically, Figure 10 The illustrated intelligent processing device for access network dedicated line faults can execute the embodiments of the above-mentioned intelligent processing method for access network dedicated line faults, and the foregoing and other operations and / or functions of each module in the device respectively implement the embodiments of the intelligent processing method for access network dedicated line faults. For the sake of brevity, they will not be elaborated here.

[0161] In the foregoing, the device of the embodiments of the present application has been described from the perspective of functional modules. It should be understood that the functional modules can be implemented in the form of hardware, can also be implemented by instructions in the form of software, and can also be implemented by a combination of hardware and software modules. Specifically, each step of the method embodiments in the present application can be completed by the integrated logic circuit in the hardware of the processor and / or instructions in the form of software. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by a combination of the hardware and software modules in the decoding processor. Optionally, the software module can be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps in the above method embodiments.

[0162] Figure 11 is a schematic block diagram of the electronic device 1100 provided by the embodiments of the present application. Figure 11 The electronic device 1100 can be used to execute the above-mentioned intelligent processing method for access network dedicated line faults, and the electronic device 1100 can be an intelligent processing device for access network dedicated line faults.

[0163] As Figure 11 shown, the electronic device 1100 may include:

[0164] A memory 1110 and a processor 1120. The memory 1110 is used to store a computer program 1130 and transmit the computer program 1130 to the processor 1120. In other words, the processor 1120 can call and run the computer program 1130 from the memory 1110 to implement the method in the embodiments of the present application.

[0165] For example, the processor 1120 can be used to execute the steps in the above method according to the instructions in the computer program 1130.

[0166] In some embodiments of the present application, the processor 1120 may include but is not limited to:

[0167] General-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and the like.

[0168] In some embodiments of the present application, the memory 1110 includes, but is not limited to:

[0169] Volatile memory and / or non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous DRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synch link DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0170] In some embodiments of the present application, the computer program 1130 may be divided into one or more modules, and the one or more modules are stored in the memory 1110 and executed by the processor 1120 to complete the intelligent processing method for access network dedicated line faults provided by the present application. The one or more modules may be a series of computer program instruction segments capable of performing specific functions, and the instruction segments are used to describe the execution process of the computer program 1130 in the electronic device.

[0171] Such as Figure 11As shown, the electronic device 1100 may further include:

[0172] A transceiver 1140, which may be connected to the processor 1120 or the memory 1110.

[0173] Among them, the processor 1120 can control the transceiver 1140 to communicate with other devices. Specifically, it can send information or data to other devices, or receive information or data sent by other devices. The transceiver 1140 may include a transmitter and a receiver. The transceiver 1140 may further include an antenna, and the number of antennas may be one or more.

[0174] It should be understood that each component in the electronic device 1130 is connected through a bus system. Among them, the bus system includes not only a data bus, but also a power bus, a control bus, and a status signal bus.

[0175] According to one aspect of the present application, there is provided a computer storage medium, on which a computer program is stored. When the computer program is executed by the computer, the computer can execute the method of the above method embodiment. Or, the embodiment of the present application further provides a computer program product including instructions. When the instructions are executed by the computer, the computer executes the method of the above method embodiment.

[0176] According to another aspect of the present application, there is provided a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the method of the above method embodiment.

[0177] In other words, when implemented using software, it can be implemented in the form of a computer program product in whole or in part. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a digital video disc (DVD)), or a semiconductor medium (such as a solid state disk (SSD)), etc.

[0178] Those of ordinary skill in the art will appreciate that the modules and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0179] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division. In actual implementation, there can be other division methods. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of devices or modules can be in an electrical, mechanical, or other form.

[0180] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. For example, in each embodiment of the present application, each functional module can be integrated into one processing module, or each module can exist physically alone, or two or more modules can be integrated into one module.

[0181] The above content is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. An intelligent processing method for dedicated line faults in an access network, characterized in that, The method includes: Obtaining the feature description information corresponding to N alarm events respectively, where the feature description information of each alarm event is obtained after aggregation according to geographical information and time information, and N is a positive integer; Processing the feature description information corresponding to the N alarm events respectively through a trained fault classification model, and determining the predicted fault types corresponding to the N alarm events according to the fault classification model; Displaying the predicted fault types corresponding to the N alarm events respectively in an interactive manner to adjust the predicted fault types.

2. The method according to claim 1, wherein The obtaining of the feature description information corresponding to the N alarm events respectively includes: Obtaining the original description information, where the original description information includes at least one of the following information: alarm device information, alarm type, alarm time; Obtaining the service information associated with the original description information, where the service information includes at least one of the following information: customer information, channel information, gateway information, dedicated line information; Determining the feature description information corresponding to the alarm event according to the original description information and its associated service information.

3. The method according to claim 2, wherein The determining of the feature description information corresponding to the N alarm events respectively according to the original description information and its associated service information includes: Performing an aggregation process on the original description information and its associated service information that belong to the target region and the target time period to obtain the feature description information about the i-th alarm event, where i is a positive integer less than or equal to N.

4. The method according to claim 2, wherein After determining the predicted fault types corresponding to the N alarm events respectively according to the fault classification model, the method includes: Displaying the predicted fault type corresponding to the i-th alarm event and the service information associated with the i-th alarm event, where i is a positive integer less than or equal to N.

5. The method according to claim 2, wherein The obtaining of the original description information includes: Determining the associated devices of the target dedicated line channel according to the attributes of the target dedicated line channel, and performing a screening process on the associated devices of the target dedicated line channel to filter out interfering devices; Obtaining the original description information of the screened associated devices within a preset time period.

6. The method according to claim 5, characterized in that, The determining of the associated devices of the target dedicated line channel according to the attributes of the target dedicated line channel includes: Determining the head node and the tail node of the target dedicated line channel according to the attributes of the target dedicated line channel to obtain the first-level associated devices, where when the attribute of the target dedicated line channel is a cloud-side channel, the head node is an FCR device and the tail node is an access switch; Determining the neighbor nodes corresponding to the first-level associated devices to obtain the second-level associated devices; Determining the neighbor nodes corresponding to the second-level associated devices until all nodes in the target dedicated line channel are traversed to obtain the associated devices of the target dedicated line channel.

7. The method according to any one of claims 1 to 6, characterized in that After displaying the predicted fault types corresponding to the N alarm events respectively in an interactive manner to adjust the predicted fault types, the method includes: Receiving the adjustment information of the predicted fault type of the j-th alarm event to obtain the actual fault type of the j-th alarm event, where j is a positive integer less than or equal to N.

8. The method according to claim 7, characterized in that, The method further includes: Adjust the model parameters of the fault classification model according to the feature description information of the j-th alarm event and the actual fault type.

9. The method according to any one of claims 1 to 6, characterized in that The method further includes: Updating or adding the feature description information about the alarm event; Updating or adding the classification labels about the alarm event; Adjust the model parameters of the fault classification model by at least one of the updated feature description information and the updated classification labels.

10. The method according to any one of claims 1 to 6, characterized in that, The feature description information of each alarm event includes at least one of the following information: alarm time, recovery time, region, number of channels, channel type, number of alarms, alarm type, number of access points, number of access switches, number of access ports, number of customer-side devices, peak utilization rate of channel bandwidth, average utilization rate of channel bandwidth, number of physical dedicated lines, number of customers, number of associated switch alarms, type of associated switch alarms, type of associated switch devices, number of FCR clusters, number of NGW clusters, channel jitter ratio of the same gateway, channel jitter ratio of the same dedicated line, BGP Down information, BFD Down information, number of FCR exception logs, IPSLADown information, difference between the received optical power of the port and the average value, difference between the transmitted optical power of the port and the average value, channel ping detection, number of alarms in a past preset duration, whether the channel traffic drops to zero, whether the dedicated line traffic drops to zero, whether the gateway traffic drops to zero, channel opening time, and cluster detection data.

11. The method according to any one of claims 1 to 6, characterized in that, The predicted fault types include the first type and the second type; Among them, the first type represents customer-side faults, including any one of the following subclasses: single-channel fault, single dedicated line fault, line or equipment fault, dedicated line port fault, customer fault drill, and excessive channel utilization; The second type represents cloud-side faults, including any one of the following subclasses: internal network jitter, FCR device exception, NGW device exception, and access switch exception.

12. An intelligent processing device for access network dedicated line faults, characterized in that, The device includes: An acquisition module, configured to acquire the feature description information respectively corresponding to N alarm events, where the feature description information of each alarm event is obtained by aggregating according to geographical information and time information, and N is a positive integer; A prediction module, configured to process the feature description information respectively corresponding to the N alarm events through a trained fault classification model, and determine the predicted fault types respectively corresponding to the N alarm events according to the fault classification model; A first display module, configured to display the predicted fault types respectively corresponding to the N alarm events in an interactive manner to adjust the predicted fault types.

13. An electronic device, characterized in that, Includes a processor and a memory; The memory is used to store a computer program; The processor is configured to execute the computer program to implement the method according to any one of claims 1 to 11 above.

14. A computer-readable storage medium, characterized in that, For storing a computer program; The computer program causes the computer to execute the method according to any one of claims 1 to 11 above.

15. A computer program, characterized in that, When it runs on a computer, it causes the computer to execute the method according to any one of claims 1 to 11 above.

16. A computer program product, characterized in that, including computer program instructions that cause a computer to perform the method according to any one of claims 1 to 11 as described above.