Network hidden danger processing method and system
By configuring hidden danger models and static data rules, automatically monitoring and analyzing network hidden dangers, the problem of relying on manual analysis in the existing technology is solved, and the automation of network operation and maintenance and pre-hit hidden danger discovery is realized, and network stability and user experience are improved.
Patent Information
- Application Number
- CN202510582984.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-08-08
AI Technical Summary
The existing network operation and maintenance technology relies on manual analysis, and cannot achieve pre-analysis and automated processing, making it difficult to find potential hidden dangers, resulting in untimely handling of problems and affecting user perception.
Configure multiple hidden danger models of hidden danger types, and automatically monitor and analyze hidden danger characterization data through static data collection and analysis rules to achieve automatic hidden danger repair.
It realizes potential hidden dangers discovered in advance and automatically handles them, improves network stability and user experience, and reduces problem-solving cycles.
Smart Images

Figure CN120455238A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network operation and maintenance, and specifically to a method and system for handling network hidden dangers. Background Art
[0002] At present, the operation and maintenance work in the communication network is mainly based on the dispatch of work orders triggered by alarms and then manual backward analysis, supplemented by daily periodic inspections to ensure the normal operation of the network. The main body still relies on manual analysis to judge whether the operation status of the network is normal. The demand for manpower is large and highly dependent on the technical level and knowledge and experience of the operation and maintenance personnel. Therefore, the former usually takes operation and maintenance measures after a network failure occurs or the quality deterioration is serious. It is a post-analysis and processing method. Although the latter has a process detection of the real-time operation status of the network, it can discover some potential problems, such as The service protection path is missing or faulty, the fan unit has not been dusted for a long time, etc. However, these inspection items are currently fixed in the inspection system and rely on the experience summary of daily manual operation and maintenance. The detection of common operation and maintenance problems is implemented in the inspection system through hard coding. It is difficult to cope with the complexity and variability of problems that arise during network operation. Adding new inspection items or determining the rules for existing inspection items requires re-going through the system development and version release process. In addition, operation and maintenance disposal still relies heavily on manual processing, and the response and optimization implementation to quality degradation problems are delayed, which makes it difficult to meet the high-quality network operation and maintenance requirements of the 5G era.
[0003] With technological advancements, the convergence of IT (Information Technology) and CT (Communication Technology) technologies is deepening. Coupled with the rapid development of AI technologies such as machine learning and big data processing, this has brought new opportunities to network operations and maintenance (O&M). Network equipment manufacturers and operators have also proposed the concepts of intelligent O&M and self-intelligent networks, and have developed relevant enterprise and industry standards, providing technical guidance for intelligent O&M from the conceptual, implementation, testing, and deployment perspectives. These standards require O&M optimization to adapt to network changes in near-real time, or even in real time. This requires continuous monitoring of real-time network configuration, performance, and status changes before network issues occur. Intelligent O&M systems are required to enhance real-time network performance and status awareness, using automated analysis and optimization to minimize the negative impact of network issues on user perception. Appropriate optimization strategies, centered around proactive optimization and closed-loop adjustments, are being implemented to establish automated analysis and optimization methods for network vulnerabilities and performance degradation, gradually evolving towards integrated network intelligence.
[0004] Existing network management and operation and maintenance can only passively analyze and handle problems after they occur. The information sources and technical means of analyzing problems are relatively simple and relatively outdated, and largely rely on manual analysis and processing by operation and maintenance personnel. It is difficult to achieve pre-analysis, proactive prevention, and automatic disposal, and it is impossible to prevent problems before they occur and achieve stable, reliable, and high-quality operation of the network, thereby better serving customers.
[0005] 1. Existing network operation and maintenance technologies tend to use alarms or status or performance monitoring to identify network faults and problems. This is a post-analysis and passive handling method.
[0006] 2. Existing network operations and maintenance (O&M) processes manually analyze and troubleshoot problems by dispatching O&M personnel after receiving device or system alarms. The efficiency of troubleshooting relies heavily on the O&M personnel's skills and experience, making efficient, automated analysis and troubleshooting impossible.
[0007] 3. Limited by existing technical means, operations and maintenance personnel can only perform single-item analysis based on one or two types of data. They cannot simultaneously obtain multiple types of data for comprehensive and diversified analysis. This makes it difficult to discover the implicit correlations among different types of operations and maintenance data. The hidden dangers identified through analysis are relatively simple and few in number, and it is even difficult to identify potential risks and hidden dangers in the network system.
[0008] 4. After analyzing and discovering the causes of hidden dangers and failures, existing technologies and systems do not achieve automatic handling and repair, and rely heavily on manual repair and processing by operation and maintenance personnel, resulting in untimely problem handling and long cycles, which affects user perception. Summary of the Invention
[0009] The present application provides a network hidden danger handling method and system, which can solve the technical problems existing in the prior art, such as low automation and efficiency in hidden danger detection, analysis and identification, few and simple types of hidden dangers identified, inconvenience in adding methods for detecting, analyzing and identifying new hidden dangers or modifying the analysis and identification methods of existing hidden dangers, and low automation in hidden danger handling.
[0010] In a first aspect, an embodiment of the present application provides a method for handling network vulnerabilities, the method comprising:
[0011] Configuring multiple hidden danger models for hidden danger types, each hidden danger model including at least one hidden danger representation data associated with the hidden danger type, and static data collection rules and static data analysis rules for all hidden danger representation data; based on the association between the hidden danger representation data, the hidden danger models have an association relationship;
[0012] When abnormal hidden danger representation data is detected, all hidden danger models associated with it and with abnormal hidden danger representation data are queried, and corresponding hidden danger representation data are collected based on the hidden danger models obtained by the query to analyze the hidden danger objects and repair them. The hidden danger objects include the hidden danger types that have occurred.
[0013] In conjunction with the first aspect, in one embodiment, the method includes:
[0014] Network data is collected through preset cycles or preset trigger conditions, and hidden danger characterization data is extracted from the network data based on a preset data extraction method; the data extraction method includes one or any combination of deduplication, grouping, sorting and / or applying preset analysis rules for judgment.
[0015] In combination with the first aspect, in one embodiment, the hidden danger representation data includes configuration data and operation and maintenance data.
[0016] In conjunction with the first aspect, in one embodiment, the method includes:
[0017] Before configuring the hidden danger model, a rule editing and generation tool is used to edit and modify static rules based on domain knowledge and expert experience; the static rules include the static data collection rules and static data analysis rules;
[0018] The domain knowledge includes multiple major categories of custom configuration, multiple subcategories under each major category, multiple hidden danger representation data under each subcategory, and the hidden danger type corresponding to each hidden danger representation data; the multiple major categories include hardware category, forwarding category, protocol category, configuration category, and business category;
[0019] The expert experience includes the software and hardware component models and their source components to which each hidden danger representation data belongs in a custom configuration, the spatiotemporal attributes of the hidden danger representation data and its logical dependencies, the logical dependencies between the software and hardware component models, and the data collection method; the spatiotemporal attributes include the source components and timing information of the hidden danger representation data; the data collection method includes one or any combination of encoding method, data type conversion method, storage method, collection channel and / or collection frequency.
[0020] In combination with the first aspect, in one implementation, each software and hardware component model corresponds to a network node, which is a network element, a link between network elements, or a network management.
[0021] In combination with the first aspect, in one embodiment, the association relationship between the hidden danger models includes an association relationship between multiple hidden danger models based on the same hidden danger representation data, and an association relationship between multiple hidden danger models based on a logical dependency relationship between multiple hidden danger representation data.
[0022] In conjunction with the first aspect, in one embodiment, the static data analysis rule includes two parts: a condition and an action;
[0023] The condition part includes a logical judgment condition between the hidden danger characterization data and the hidden danger type;
[0024] The action part includes a hidden danger handling method according to the hidden danger type; the hidden danger handling method includes one or any combination of data reprocessing, data storage, data re-extraction and / or hidden danger repair.
[0025] In conjunction with the first aspect, in one embodiment, the hidden danger model obtained based on the query collects corresponding hidden danger representation data to analyze and obtain the hidden danger type, which specifically includes the following steps:
[0026] Obtaining the corresponding hidden danger representation data, static data collection rules, and static data analysis rules for each hidden danger model based on the hidden danger model obtained by the query;
[0027] Generate a detection object list and a detection item list based on the hidden danger representation data. The detection object list contains the network nodes corresponding to the software and hardware component models to which the hidden danger representation data belongs, and the detection item list contains the hidden danger detection items to which the hidden danger representation data belongs.
[0028] Dynamic data collection rules are obtained by combining static data collection rules, and dynamic data analysis rules are obtained by combining static data analysis rules;
[0029] The hidden danger representation data is collected using dynamic data collection rules, detection object lists, and detection item lists. The hidden danger representation data is analyzed using dynamic data analysis rules to obtain hidden danger objects and perform hidden danger repairs on them.
[0030] In a second aspect, an embodiment of the present application provides a network risk management system, the system comprising:
[0031] a configuration module configured to configure multiple hidden danger models for hidden danger types, each hidden danger model including at least one hidden danger representation data associated with the hidden danger type, and static data collection rules and static data analysis rules for all hidden danger representation data; based on the association between the hidden danger representation data, the hidden danger models are associated with each other;
[0032] The monitoring and processing module is used to query all the hidden danger models associated with it and having abnormal hidden danger representation data when abnormal hidden danger representation data is detected, and collect corresponding hidden danger representation data based on the hidden danger models obtained by the query, so as to analyze the hidden danger objects and repair the hidden dangers. The hidden danger objects include the hidden danger types of the hidden dangers that have occurred.
[0033] In conjunction with the second aspect, in one embodiment, the monitoring and processing module includes:
[0034] A first processing unit, which is used to obtain hidden danger representation data, static data collection rules, and static data analysis rules corresponding to each hidden danger model based on the hidden danger model obtained by the query;
[0035] A second processing unit is configured to generate a detection object list and a detection item list based on the hidden danger representation data, wherein the detection object list includes network nodes corresponding to the software and hardware component models to which the hidden danger representation data belongs, and the detection item list includes hidden danger detection items to which the hidden danger representation data belongs; a dynamic data collection rule is obtained by combining the static data collection rules, and a dynamic data analysis rule is obtained by combining the static data analysis rules;
[0036] The third processing unit collects hidden danger representation data using dynamic data collection rules, a detection object list, and a detection item list, and performs hidden danger analysis on the hidden danger representation data using dynamic data analysis rules to obtain hidden danger objects and perform hidden danger repair on them.
[0037] The beneficial effects of the technical solutions provided in the embodiments of the present application include:
[0038] When business scenarios change and existing hidden danger analysis rules have defects and need to be modified, or when new hidden danger types need to be analyzed, existing technologies and products need to modify equipment and network management codes, and need to go through the version compilation, construction and release process again, resulting in a long problem location and solution cycle and poor customer experience. The present invention only needs to first determine the hidden danger model to which the monitored abnormal hidden danger characterization data belongs, and then find models that are all in the abnormal hidden danger characterization data from other models associated with the hidden danger model. Based on the static rule combination of all these hidden danger models with abnormal hidden danger characterization data, new dynamic rules are obtained. The new dynamic rules can support the analysis and identification of new hidden danger types or the iterative upgrade of existing rules, eliminating the system modification and online cycle, and solving the current problem of long problem location and solution cycles and poor customer experience.
[0039] The present invention can periodically and comprehensively analyze various process data generated during the operation of network equipment and systems, so as to discover potential hidden dangers of equipment and networks before failures occur, and notify operation and maintenance personnel to take measures in advance, so as to achieve pre-analysis and prevent problems before they occur.
[0040] Existing technical means rely on operation and maintenance personnel to simply perform a single analysis based on one or two types of data, and are unable to simultaneously obtain multiple different types of data for comprehensive and diversified fusion analysis. The present invention can simultaneously collect and comprehensively analyze various process data generated during the operation of equipment and systems, thereby avoiding the disadvantage of inaccurate analysis results caused by insufficient information when analyzing a single information.
[0041] Existing network operation and maintenance manually analyzes, processes, locates problems, and troubleshoots by assigning tasks to operation and maintenance personnel after receiving alarms from equipment or systems. The efficiency of troubleshooting is heavily dependent on the ability and experience of the operation and maintenance personnel, and automated analysis and troubleshooting are not possible. The present invention uses the action mechanism of hidden danger analysis rules combined with the workflow mechanism to automatically handle discovered hidden dangers, achieve early warning and automatic troubleshooting, thereby ensuring the long-term stable and effective operation of equipment and networks, and enhancing customers' perception and trust in the product. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 This is a flow chart of an embodiment of a method for handling network hidden dangers of the present application;
[0043] Figure 2 This is a schematic diagram of the specific process of step S3 of this application;
[0044] Figure 3 This is a functional module diagram of an embodiment of the network hidden danger handling system of the present application;
[0045] Figure 4 This is a schematic diagram of the specific functional modules of the monitoring and processing module of this application. DETAILED DESCRIPTION
[0046] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0047] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.
[0048] In a first aspect, an embodiment of the present application provides a method for handling network hidden dangers.
[0049] In one embodiment, referring to Figure 1 , Figure 1 This is a flow chart of an embodiment of the network hidden danger handling method of this application. Figure 1 As shown in the figure, the methods for handling network risks include:
[0050] Step S1: Configure multiple hidden danger models for each hidden danger type. Each hidden danger model includes at least one hidden danger representation data associated with the hidden danger type, as well as static data collection rules and static data analysis rules for all hidden danger representation data. Based on the associations between the hidden danger representation data, the hidden danger models are associated with each other.
[0051] Step S2: When abnormal hidden danger representation data is detected, all hidden danger models associated with it and having abnormal hidden danger representation data are collected, and corresponding hidden danger representation data are collected based on the hidden danger models obtained by query, so as to analyze the hidden danger objects and perform hidden danger repair on them. The hidden danger objects include the hidden danger types of the hidden dangers that have occurred.
[0052] In this embodiment, when the business scenario changes and causes defects in the existing hidden danger analysis rules to need to be modified, or when there are new hidden danger types that need to be analyzed, the existing technology and products need to modify the equipment and network management code, and the version compilation, construction and release process needs to be re-performed, the problem location and solution cycle is long, and the customer experience is poor. The present invention only needs to first determine the hidden danger model to which the monitored abnormal hidden danger representation data belongs, and then find the models that are all in the abnormal hidden danger representation data from other models associated with the hidden danger model. Based on the static rule combination of all these hidden danger models with abnormal hidden danger representation data, new dynamic rules are obtained. The new dynamic rules can support the analysis and identification of new hidden danger types or the iterative upgrade of existing rules, eliminating the system modification and online cycle, and solving the current problem of long problem location and solution cycles and poor customer experience. Among them, the hidden danger object is the management data model of the hidden danger analysis results, and its attributes include data information such as the hidden danger type, hidden danger name, source component, generation time, hidden danger status, disposal action, and clearing time of the hidden danger that has occurred.
[0053] Existing technical means rely on operation and maintenance personnel to simply perform a single analysis based on one or two types of data, and are unable to simultaneously obtain multiple different types of data for comprehensive and diversified fusion analysis. The present invention can simultaneously collect and comprehensively analyze various process data generated during the operation of equipment and systems, thereby avoiding the disadvantage of inaccurate analysis results caused by insufficient information when analyzing a single information.
[0054] Existing network operation and maintenance manually analyzes, processes, locates problems, and troubleshoots by assigning tasks to operation and maintenance personnel after receiving alarms from equipment or systems. The efficiency of troubleshooting is heavily dependent on the ability and experience of the operation and maintenance personnel, and automated analysis and troubleshooting are not possible. The present invention uses the action mechanism of hidden danger analysis rules combined with a preset workflow mechanism to automatically handle discovered hidden dangers, achieve early warning and automatic troubleshooting, thereby ensuring the long-term stable and effective operation of equipment and networks, and enhancing customers' perception and trust in the product.
[0055] Furthermore, in one embodiment, the method includes:
[0056] Network data is collected based on a preset period or trigger condition, and hidden danger characterization data is extracted from the network data based on a preset data extraction method. The above data extraction method includes one or any combination of deduplication, grouping, sorting, and / or applying preset analysis rules for identification.
[0057] The above-mentioned hidden danger characterization data includes configuration data and operation and maintenance data.
[0058] In this embodiment, when a certain type of hidden danger occurs, it may manifest as a certain performance degradation or exceeding the limit, or trigger a certain type of alarm, or the status, configuration or protocol data may be abnormal, or these data items may exist at the same time. At the same time, the system log of the device or system may also record the relevant register or memory parameter values when the hidden danger occurs. These data are all hidden danger representation data generated when the hidden danger occurs.
[0059] Task settings drive the periodic or on-demand collection of various alarms, performance, events, status, logs, various protocol packets, configuration data and operation and maintenance data generated during the operation of network devices and systems. This configuration and operation and maintenance data is network data, also known as process data.
[0060] By periodically and comprehensively analyzing various process data generated during the operation of network equipment and systems, the present invention can discover potential hidden dangers in equipment and networks before a failure occurs, and notify operation and maintenance personnel to take measures in advance, thereby achieving pre-analysis and prevention.
[0061] Furthermore, in one embodiment, the method includes:
[0062] Before configuring the hidden danger model, use the rule editing and generation tool to edit and modify static rules based on domain knowledge and expert experience. The above static rules include the above static data collection rules and static data analysis rules.
[0063] This domain knowledge includes multiple categories of custom configuration, multiple subcategories within each category, multiple hidden danger representation data within each subcategory, and the hidden danger type corresponding to each hidden danger representation data. These multiple categories include hardware, forwarding, protocol, configuration, and business.
[0064] This expert experience includes the custom-configured software and hardware component models to which each hidden danger representation data belongs, their source components, the temporal and spatial attributes of the hidden danger representation data and their logical dependencies, the logical dependencies between the software and hardware component models, and data collection methods. The temporal and spatial attributes include the source components and timing information of the hidden danger representation data. The data collection methods include one or any combination of encoding methods, data type conversion methods, storage methods, collection channels, and / or collection frequencies.
[0065] In this embodiment, static rules are composed of domain knowledge and expert experience, which together form the domain knowledge base (Domain Knowledge Base) of the communication network. The present invention provides a rule editing and generation tool for creating, editing, and modifying static rules. The rule editing and generation tool is a knowledge editing tool provided by the present invention. This tool can be used to create, generate, and edit the relevant content of static rules, namely, domain knowledge and knowledge formed by abstracting, summarizing, and summarizing expert experience.
[0066] Domain knowledge is divided into five major categories: hardware, forwarding, protocol, configuration, and business. Each major category is further subdivided to form subcategories in the subdivided fields. For example, the hardware field is divided into subdivided fields such as the whole machine, single disk, port, chip, bus, clock, and logic. In each subdivided field, multiple hidden danger detection items and corresponding hidden danger types are set. At the same time, the configuration data and operation and maintenance data generated during the operation of the communication network are defined as hidden danger representation data in the domain knowledge base. At the same time, the encoding method, data type conversion method, storage method, acquisition channel, acquisition frequency and other data collection methods of these hidden danger representation data are defined. In addition, the hardware and software component models related to the communication network, the relationship between the hardware and software component models and the hidden danger representation data, and the dependency relationship between the hardware and software component models are defined to form expert experience knowledge.
[0067] The software and hardware component model definition includes component definitions at multiple levels, including the OS layer, forwarding layer, driver layer, system support layer, hardware abstraction layer, business layer, control layer, management layer, and control layer. It also defines the associated dependencies between components, and defines the association between these components and the representation data through hidden danger location source information.
[0068] The hidden danger location source information includes three fields: object type, rate level, and WS-KEY. The object type indicates the type of the component object where the hidden danger is located. The rate level indicates the level at which the corresponding component object is located. The WS-KEY field further defines three fields: reason-id, slot-id, and kpi-index. The reason-id field indicates the code of the hardware and software component where the hidden danger is located. The slot-id field indicates the slot number of the single disk to which the hardware and software component where the hidden danger is located belongs. The kpi-index field indicates the serial number of the hardware and software component where the hidden danger is located.
[0069] The hidden danger types in each field are associated with the hidden danger representation data items based on expert experience to form a one-to-one or one-to-many association relationship.
[0070] By establishing an association between hidden danger types and hidden danger analysis and identification rules, the pre-processing process of each hidden danger representation data associated with the hidden danger type is defined, such as performing deduplication, grouping, sorting, applying analysis rules for judgment, etc., to generate a processing workflow corresponding to the hidden danger type.
[0071] A hidden danger model is constructed, which corresponds to a hidden danger type and includes data collection rules and hidden danger analysis and identification rules for the hidden danger type.
[0072] Furthermore, in one embodiment, each software and hardware component model corresponds to a network node, which is a network element, a link between network elements, or a network management.
[0073] In this embodiment, logical dependencies exist between different network nodes. For example, if a downstream network element fails, the failure may be caused by an upstream network element, which may also be at fault. When one or more hidden danger representation data corresponding to a specific type of failure in a downstream network element exhibit an anomaly, it is determined that other hidden danger models (or hidden danger types) associated with the hidden danger model (or hidden danger type) to which the abnormal hidden danger representation data belongs may also exhibit an anomaly. From these potentially abnormal hidden danger models, models with similarly abnormal hidden danger representation data are screened. By combining the static rules of these models, relatively dynamic data collection and hidden danger analysis rules can be obtained.
[0074] The data collection rule is to define the collection parameters of hidden danger representation data, that is, operation and maintenance data. The data collection rules corresponding to the hidden danger type include the collection data list and the collection frequency, etc. When generating dynamic data collection rules, the domain knowledge base is queried to obtain the hidden danger representation data list associated with the hidden danger model in the knowledge base. Based on the obtained list information, the operation and maintenance data list to be collected is generated, and then the collection frequency, processing method and other information corresponding to the hidden danger representation data in the knowledge base are obtained. The returned information is filled into the collection frequency and processing method and other parameters of the hidden danger collection rules.
[0075] Furthermore, in one embodiment, the association relationship between the hidden danger models includes an association relationship between multiple hidden danger models based on the same hidden danger representation data, and an association relationship between multiple hidden danger models based on logical dependencies between multiple hidden danger representation data.
[0076] In this embodiment, there is an association relationship between the hidden danger models with the same hidden danger representation data, and there is a logical dependency relationship between the subordinate hidden danger representation data. For example, if one hidden danger representation data is abnormal, the other hidden danger representation data will also be abnormal, and there is an association relationship between the above-mentioned hidden danger models of these two hidden danger representation data.
[0077] Furthermore, in one embodiment, the static data analysis rule includes two parts: a condition and an action.
[0078] The above-mentioned condition part includes the logical judgment conditions between the hidden danger characterization data and the hidden danger type.
[0079] The above-mentioned action part includes a hidden danger handling method according to the hidden danger type. The above-mentioned hidden danger handling method includes one or any combination of data reprocessing, data storage, data re-extraction and / or hidden danger repair.
[0080] In this embodiment, the hidden danger analysis and identification rules are also dynamically generated by querying the hidden danger model information in the knowledge base, and include two parts: condition and action.
[0081] Rule conditions serve as the basis for analyzing the existence of a particular type of hazard. They can be categorized as single conditions or combined conditions. When generating the hazard model, the knowledge base previously determined the relationship between hazard types and representation data, and also recorded the spatiotemporal and logical dependency properties of the representation data. Spatiotemporal properties refer to the source components and timing information of the representation data. Logical dependency properties determine whether the representation data satisfies the logical judgment conditions for hazard generation. These could be a True / False logical value indicating whether the corresponding representation data item appears, a threshold indicating whether the corresponding representation data item has exceeded a limit, a mathematical formula calculating the trend of the corresponding representation data item, or a combination of several attributes. The system generates hazard analysis and identification rules based on this information. If the hazard model is associated with only one type of representation data, the generated analysis and identification rule is a single condition. If the hazard model is associated with multiple types of representation data, the generated analysis and identification rule is a combined condition. Based on the spatiotemporal and logical dependency properties of the different representation data in the model, the system generates different types of combined conditions: atomic, mutually exclusive, and compound.
[0082] When the presence of a hidden danger can be determined as only the satisfaction of any one of the multiple characterization data associated with the hidden danger, a mutually exclusive combination condition is automatically generated.
[0083] Multiple characterization data associated with the hidden danger must be met at the same time to determine the existence of the hidden danger, and the atomic combination conditions will be automatically generated.
[0084] In addition to the above two conditions, other situations, including those where the logical relationship between data needs to be calculated through a certain mathematical formula to determine whether the hidden danger exists, will generate a composite combination condition, and the mathematical formula is obtained through the static rules in the aforementioned knowledge base.
[0085] When a certain type of hidden danger occurs, it may manifest as a certain performance degradation or exceeding the limit, or trigger a certain type of alarm, or the status, configuration or protocol data may be abnormal, or the aforementioned data items may exist at the same time. At the same time, the system log of the device or system may also record the relevant register or memory parameter values when the hidden danger occurs. These data are all representation data generated when the hidden danger occurs. The knowledge base module associates this hidden danger type with these corresponding representation data according to the domain association dependency information in the aforementioned static rules, and records the specific data values or data attributes such as the type, location information, generation time, occurrence frequency, duration, change trend, etc. of these representation data to form the analysis and judgment condition items of the hidden danger model.
[0086] By traversing the aforementioned integrated original operation and maintenance data, according to the aforementioned analysis and identification rules, the data are checked and judged in the order of single rule conditions, mutually exclusive combination conditions, atomic combination conditions, and compound combination conditions to determine whether they meet the conditions for the existence of a certain type of hidden danger, and then determine whether the equipment or system has corresponding hidden dangers.
[0087] The action definition of the hidden danger analysis and identification rule is a series of operations performed by the rule engine when the condition is true, including further processing of the representation data, such as re-filtering, grouping, sorting, calculating according to mathematical formulas, generating new hidden danger data, or saving new hidden danger data or processed hidden danger representation data into the database. It can also be issuing corresponding commands to the equipment or system to test or obtain data for further analysis, or other necessary diagnostic operation and maintenance or repair actions.
[0088] The rule engine executes corresponding processing operations based on these rule definitions. In addition to analyzing and identifying potential risks, the system also supports automatic remediation of potential risks. This automatic remediation is achieved through a workflow mechanism. Each processing step in the workflow is defined by an action in the rule, which is then parsed and triggered by the rule engine.
[0089] In a specific embodiment, taking the power supply hazard analysis in the hardware field as an example, the power supply hazard detection items are divided into rack power supply and partition power supply. The corresponding rack power supply hazard type is power supply undervoltage, and the corresponding partition power supply hazard type is insufficient power supply protection. Rack power supply requires continuous monitoring and judgment of the rack power supply voltage reported by the power module. In addition to monitoring the working status of the power module, partition power supply also needs to monitor that the number of power supply disks in normal operation must not be less than the set threshold.
[0090] The knowledge base module treats power modules as component entity objects, and rack power supply voltage, operating status, and number of power modules as attributes of the power modules. At the same time, detection rules are set based on expert experience. For example, if the rack power supply voltage shows a continuous downward trend for three consecutive 15-minute periods, it is determined that there is a hidden danger of power undervoltage. For zoned power supply, the number of normally operating power modules is set based on the power supply module requirements of different equipment types. If the number is less than the threshold value, it is determined that there is a hidden danger of insufficient power protection.
[0091] Fault detection involves power module performance and status data. The knowledge base associates fault types with corresponding O&M data. For example, undervoltage faults are associated with rack power supply voltage performance data, and insufficient power protection faults are associated with power supply status data. Based on expert experience, the coding, collection method, storage mode, and processing methods of this O&M data are entered into the knowledge base. For example, for rack power supply voltage performance, the data is encoded natively, and 15 minutes of performance data is collected and cached for before-and-after comparisons.
[0092] Furthermore, in one embodiment, referring to Figure 2 The hidden danger model obtained based on the query collects corresponding hidden danger characterization data to analyze and obtain the hidden danger type, which specifically includes the following steps:
[0093] Step S31: based on the hidden danger models obtained through the query, obtain the hidden danger representation data, static data collection rules, and static data analysis rules corresponding to each hidden danger model.
[0094] Step S32: Generate a detection object list and a detection item list based on the hidden danger representation data. The detection object list includes network nodes corresponding to the software and hardware component models to which the hidden danger representation data belongs, and the detection item list includes hidden danger detection items to which the hidden danger representation data belongs.
[0095] Step S33: obtain dynamic data collection rules based on the combination of static data collection rules, and obtain dynamic data analysis rules based on the combination of static data analysis rules.
[0096] Step S34: collect hidden danger characterization data using dynamic data collection rules, the detection object list, and the detection item list, and analyze the hidden danger characterization data using dynamic data analysis rules to obtain hidden danger objects and perform hidden danger repair on them.
[0097] In this embodiment, when performing hidden danger repair, a condition evaluation is first performed in the order of single rule conditions, mutually exclusive combination conditions, atomic combination conditions, and compound combination conditions based on the analysis and identification rules to determine whether these hidden danger representation data meet the conditions for the existence of a certain type of hidden danger, and then determine the network element equipment and system components with hidden dangers. At the same time, a hidden danger object is generated based on the evaluation results, and the operation and maintenance data of the hidden danger is evaluated and associated with the hidden danger object as hidden danger representation data, and is simultaneously saved in the database.
[0098] Hidden danger objects are used to manage the results of hidden danger analysis for network elements, devices, and systems, as well as for subsequent handling operations. In addition to basic attributes such as hidden danger name, type, severity, generation time, and clearing time, their attribute fields also include location source information, whether it affects business, and status. The location source information field records the network element, system component, or business item where the hidden danger was detected. Whether it affects business is used to record whether the hidden danger is associated with business. The status field records the state transition definition of the hidden danger after it has been handled during its life cycle. The status fields and their meanings are shown in Table 1 below:
[0099] Table 1 Status fields and their meanings
[0100]
[0101]
[0102] Hidden dangers can be divided into three levels based on their impact on the normal operation of the network and equipment: severe, general, and warning.
[0103] Severe level: Severe level hazards will affect the normal operation of the network and services, and may cause severe packet loss or bit error rate exceeding the threshold, or service failure after deployment or service interruption after switchover. Further, it may cause network or service failure, resulting in serious damage or even interruption of services.
[0104] General level: General level vulnerabilities have a lower impact on the network and services than severe level vulnerabilities. For example, if a parameter value (such as CBS) differs from the expected value, it may cause packet loss in scenarios with sudden high traffic or affect the smooth deployment of new services.
[0105] Warning level: Warning-level vulnerabilities have the lowest impact on the network and services. Generally, they do not affect the normal operation of the network and services. In special scenarios, they may cause packet loss in related services or affect cross-vendor connectivity.
[0106] For different severity levels, each hidden danger definition has corresponding optimization suggestions. The hidden danger analysis module will display the optimization suggestions and provide a processing entry for the operating user to handle the hidden danger. The hidden danger handling actions are divided into three types:
[0107] Ignore: Ignore means temporarily not taking any corresponding action on the hidden danger. You can ignore the hidden dangers of general level and warning level. At this time, the hidden danger status changes from initial state to ignored. Ignore is not allowed for hidden dangers of serious level.
[0108] Unignore: Undo the action for a hidden danger that has been ignored, and the hidden danger status will return to the initial state from ignored. Unignore is not supported for hidden dangers that have been entered into the history library and are in the ignored state.
[0109] Clear: Make maintenance adjustments or modifications to the root cause of the hidden danger based on the corresponding optimization recommendations. This will clear the root cause. The hidden danger's status will then change from Initial or Ignored to Cleared. Cleared hidden dangers are then transferred to the historical hidden danger database. Severe hidden dangers can only be cleared. General and Warning hidden dangers can be ignored or cleared.
[0110] In addition to providing several hidden danger handling functions that rely on human participation, the system also provides automatic hidden danger handling and repair functions.
[0111] By modifying the action attribute settings in the hidden danger analysis rule in the rule editing and generation tool, a corresponding hidden danger disposal workflow is generated and parsed and executed by the rule engine.
[0112] The action attribute of the hidden danger analysis and identification rule sets the instruction sequence that the rule engine can execute when the rule condition is evaluated to true. It can be re-filtering, grouping, sorting, and calculating according to mathematical formulas of the hidden danger representation data, or generating new hidden danger object data, or saving new hidden danger data or processed hidden danger representation data into the database. It also supports issuing corresponding diagnostic commands to the equipment or system to test or obtain data for further analysis, and can also be other necessary diagnostic operation and maintenance or repair actions.
[0113] The system encapsulates commonly used operation and maintenance diagnostic commands such as ping, tracert, netstat, and some configuration-related command lines such as IP address settings and routing configurations to form a tool component set and provide an interface for external calls. At the same time, the commonly used basic configurations and business configurations are split into small-granularity configuration templates according to the smallest functional units. The device is diagnosed and the configuration is modified by calling the corresponding interfaces of these diagnostic commands or configuration commands in the rule action settings. When it comes to repairing more complex business configurations, the above configuration template is called and the parameter information obtained during the hidden danger analysis process is used to improve the relevant parameter values in the configuration template to form a new correct configuration. Then, the configuration interface of the tool is called to add the correct configuration to the corresponding configuration of the network element with the hidden danger to complete the repair of the hidden danger.
[0114] In a second aspect, an embodiment of the present application also provides a network risk management system.
[0115] In one embodiment, referring to Figure 3 , Figure 3 This is a functional module diagram of an embodiment of the network hidden danger processing system of this application. Figure 3 As shown in FIG, the network hidden danger handling system includes:
[0116] Configuration module 1 is used to configure multiple hidden danger models for various hidden danger types. Each hidden danger model includes at least one hidden danger representation data associated with the hidden danger type, as well as static data collection rules and static data analysis rules for all hidden danger representation data. Based on the associations between the hidden danger representation data, the hidden danger models are associated with each other.
[0117] Monitoring and processing module 2 is used to query all the hidden danger models associated with it and having abnormal hidden danger representation data when abnormal hidden danger representation data is detected, and collect corresponding hidden danger representation data based on the hidden danger models obtained by the query, so as to analyze the hidden danger objects and repair the hidden dangers. The hidden danger objects include the hidden danger types of the hidden dangers that have occurred.
[0118] Furthermore, in one embodiment, referring to Figure 4 , the monitoring and processing module 2 includes:
[0119] The first processing unit 21 is configured to obtain the hidden danger representation data, static data collection rules, and static data analysis rules corresponding to each hidden danger model based on the hidden danger model obtained by query.
[0120] The second processing unit 22 is configured to generate a detection object list and a detection item list based on the hidden danger representation data. The detection object list includes network nodes corresponding to the software and hardware component models to which the hidden danger representation data belongs, and the detection item list includes hidden danger detection items to which the hidden danger representation data belongs. Dynamic data collection rules are generated by combining static data collection rules, and dynamic data analysis rules are generated by combining static data analysis rules.
[0121] The third processing unit 23 collects hidden danger representation data using dynamic data collection rules, a detection object list, and a detection item list, and performs hidden danger analysis on the hidden danger representation data using dynamic data analysis rules to obtain hidden danger objects and perform hidden danger repair on the hidden danger objects.
[0122] Among them, the functional implementation of each module in the above-mentioned network hidden danger processing system corresponds to each step in the above-mentioned network hidden danger processing method embodiment, and its functions and implementation processes are not repeated here one by one.
[0123] It should be noted that the serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0124] The terms "including" and "having" and any variations thereof in the specification and claims of this application and the above-mentioned drawings are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally includes steps or units that are not listed, or optionally includes other steps or units inherent to these processes, methods, products or devices. The terms "first", "second" and "third" are used to distinguish different objects, etc., and do not represent a sequence, nor do they limit the "first", "second" and "third" to different types.
[0125] In the description of the embodiments of this application, the words "exemplary," "for example," or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary," "for example," or "for example" in the embodiments of this application should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary," "for example," or "for example" is intended to present the relevant concepts in a concrete manner.
[0126] In the description of the embodiments of the present application, unless otherwise specified, “ / ” means or, for example, A / B can mean A or B; “and / or” in the text is merely a description of the association relationship of associated objects, indicating that three relationships may exist, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present application, “multiple” refers to two or more than two.
[0127] In some processes described in the embodiments of the present application, multiple operations or steps are included that appear in a specific order. However, it should be understood that these operations or steps may not be performed in the order in which they appear in the embodiments of the present application or may be performed in parallel. The sequence numbers of the operations are only used to distinguish between different operations, and the sequence numbers themselves do not represent any order of execution. In addition, these processes may include more or fewer operations, and these operations or steps may be performed in sequence or in parallel, and these operations or steps may be combined.
[0128] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, of course, it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes a number of instructions for enabling a terminal device to execute the methods described in each embodiment of the present application.
[0129] The above are only preferred embodiments of the present application and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.
Claims
1. A method for handling network hidden dangers, characterized in that: The method comprises: Configuring multiple hidden danger models for hidden danger types, each hidden danger model including at least one hidden danger representation data associated with the hidden danger type, and static data collection rules and static data analysis rules for all hidden danger representation data; based on the association between the hidden danger representation data, the hidden danger models have an association relationship; When abnormal hidden danger representation data is detected, all hidden danger models associated with it and with abnormal hidden danger representation data are queried, and corresponding hidden danger representation data are collected based on the hidden danger models obtained by the query to analyze the hidden danger objects and repair them. The hidden danger objects include the hidden danger types that have occurred.
2. The method for handling network hidden dangers according to claim 1, wherein: The method comprises: Network data is collected through preset cycles or preset trigger conditions, and hidden danger characterization data is extracted from the network data based on a preset data extraction method; the data extraction method includes one or any combination of deduplication, grouping, sorting and / or applying preset analysis rules for judgment.
3. The method for handling network hidden dangers according to claim 1, wherein: The hidden danger characterization data includes configuration data and operation and maintenance data.
4. The method for handling network hidden dangers according to claim 1, wherein: The method comprises: Before configuring the hidden danger model, a rule editing and generation tool is used to edit and modify static rules based on domain knowledge and expert experience; the static rules include the static data collection rules and static data analysis rules; The domain knowledge includes multiple major categories of custom configuration, multiple subcategories under each major category, multiple hidden danger representation data under each subcategory, and the hidden danger type corresponding to each hidden danger representation data; the multiple major categories include hardware category, forwarding category, protocol category, configuration category, and business category; The expert experience includes the software and hardware component models and their source components to which each hidden danger representation data belongs in a custom configuration, the spatiotemporal attributes of the hidden danger representation data and their logical dependencies, the logical dependencies between the software and hardware component models, and the data collection method; the spatiotemporal attributes include the source components and timing information of the hidden danger representation data; the data collection method includes one or any combination of encoding method, data type conversion method, storage method, collection channel and / or collection frequency.
5. The method for handling network hidden dangers according to claim 4, wherein: Each software and hardware component model corresponds to a network node, which is a network element, a link between network elements, or a network management.
6. The method for handling network hidden dangers according to claim 4, wherein: The association relationship between the hidden danger models includes an association relationship between multiple hidden danger models based on the same hidden danger representation data, and an association relationship between multiple hidden danger models based on a logical dependency relationship between multiple hidden danger representation data.
7. The method for handling network hidden dangers according to claim 1, wherein: The static data analysis rules include two parts: conditions and actions; The condition part includes a logical judgment condition between the hidden danger characterization data and the hidden danger type; The action part includes a hidden danger handling method according to the hidden danger type; the hidden danger handling method includes one or any combination of data reprocessing, data storage, data re-extraction and / or hidden danger repair.
8. The method for handling network hidden dangers according to claim 1, wherein: The hidden danger model obtained based on the query collects corresponding hidden danger characterization data to analyze and obtain the hidden danger type, which specifically includes the following steps: Obtaining the corresponding hidden danger representation data, static data collection rules, and static data analysis rules for each hidden danger model based on the hidden danger model obtained by the query; Generate a detection object list and a detection item list based on the hidden danger representation data. The detection object list contains the network nodes corresponding to the software and hardware component models to which the hidden danger representation data belongs, and the detection item list contains the hidden danger detection items to which the hidden danger representation data belongs. Dynamic data collection rules are obtained by combining static data collection rules, and dynamic data analysis rules are obtained by combining static data analysis rules; The hidden danger representation data is collected using dynamic data collection rules, detection object lists, and detection item lists. The hidden danger representation data is analyzed using dynamic data analysis rules to obtain hidden danger objects and perform hidden danger repairs on them.
9. A network hidden danger processing system, characterized in that: The system comprises: a configuration module configured to configure multiple hidden danger models for each hidden danger type, each hidden danger model including at least one hidden danger representation data associated with the hidden danger type, and static data collection rules and static data analysis rules for all hidden danger representation data; based on the association between the hidden danger representation data, the hidden danger models are associated with each other; The monitoring and processing module is used to query all the hidden danger models associated with it and having abnormal hidden danger representation data when abnormal hidden danger representation data is detected, and collect corresponding hidden danger representation data based on the hidden danger models obtained by the query, so as to analyze the hidden danger objects and repair the hidden dangers. The hidden danger objects include the hidden danger types of the hidden dangers that have occurred.
10. The network hidden danger handling system according to claim 9, characterized in that: The monitoring and processing module includes: A first processing unit, which is used to obtain hidden danger representation data, static data collection rules, and static data analysis rules corresponding to each hidden danger model based on the hidden danger model obtained by the query; A second processing unit is configured to generate a detection object list and a detection item list based on the hidden danger representation data, wherein the detection object list includes network nodes corresponding to the software and hardware component models to which the hidden danger representation data belongs, and the detection item list includes hidden danger detection items to which the hidden danger representation data belongs; a dynamic data collection rule is obtained by combining the static data collection rules, and a dynamic data analysis rule is obtained by combining the static data analysis rules; The third processing unit collects hidden danger representation data using dynamic data collection rules, a detection object list, and a detection item list, and performs hidden danger analysis on the hidden danger representation data using dynamic data analysis rules to obtain hidden danger objects and perform hidden danger repair on them.