Abnormality detection method and device, nonvolatile storage medium and electronic equipment

By adopting evaluation indicators within the time window and neural network prediction confidence interval analysis in the indoor distribution system, the problems of inaccurate detection and low efficiency in traditional anomaly detection methods are solved, and accurate and rapid identification and root cause analysis of cell anomalies are achieved.

CN120640342APending Publication Date: 2025-09-12CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511064706.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

In the existing technology, traditional anomaly detection methods use fixed alarm thresholds, resulting in inaccurate anomaly detection and low detection efficiency. In particular, it is difficult to detect hidden passive faults in indoor distributed systems, affecting network performance and user perception.

Method used

By determining the abnormal evaluation index in the time window to be detected based on the evaluation index in the first time window, combining the confidence interval analysis of short-term month-on-month and long-term neural network predictions, it is determined whether the cell is abnormal, and the root cause of the abnormality is determined through the correlation coefficient of the root cause index.

Benefits of technology

It enables the accurate and rapid discovery of cells with abnormal indoor distribution system indicators and the determination of the root causes of the abnormalities, thus improving the accuracy and efficiency of anomaly detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120640342A_ABST
    Figure CN120640342A_ABST
Patent Text Reader

Abstract

The invention discloses an anomaly detection method and device, a nonvolatile storage medium and electronic equipment. The method comprises the following steps: determining whether a second evaluation index in a to-be-detected time window is an abnormal evaluation index according to a first evaluation index in a first time window; under the condition that the second evaluation index is determined to be an abnormal evaluation index, predicting a confidence interval of the abnormal evaluation index according to a third evaluation index in a second time window; determining whether the cell corresponding to the abnormal evaluation index is abnormal or not according to whether the abnormal evaluation index is in a confidence interval or not; and under the condition that the cell is determined to be abnormal, abnormal root causes are determined according to correlation coefficients of the abnormal evaluation indexes and root cause indexes, and the root cause indexes are in one-to-one correspondence with root causes in a preset root cause set. According to the invention, the technical problems of inaccurate anomaly detection and low detection efficiency caused by the fact that a related anomaly detection technology adopts a fixed alarm threshold to carry out detection alarm are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of wireless communication technology, and more specifically, to an anomaly detection method, device, non-volatile storage medium, and electronic device. Background Art

[0002] With the rapid development of mobile wireless networks and the combined application of various wireless network technologies, network complexity is increasing, and network scale is expanding. This poses challenges for timely detection and root cause analysis of abnormal fluctuations in various indicators across mobile networks. There is an urgent need to find a method that can quickly and promptly detect abnormal fluctuations in indicators in indoor distributed systems and analyze and identify the root cause, thereby improving network performance and user experience.

[0003] Current technologies set fixed thresholds for various indicators. When an indicator falls below or rises above the threshold, it triggers an abnormal fluctuation and issues an alert. However, in real-world applications, absolute thresholds only provide a baseline. Except for certain critical scenarios, excessively high baselines can lead to false alarms, while excessively low baselines can miss many situations requiring early warning. This is particularly true for distributed indoor systems, which consist of multiple passive components (such as couplers, power splitters, feeders, and ceiling antennas) and signal source equipment (such as RRUs, dry-mounted amplifiers, and repeaters). The complexity of the system's passive connections increases the difficulty of monitoring. Traditional KPI monitoring struggles to effectively detect hidden, passive faults in distributed indoor systems. This traditional approach fails to effectively and promptly identify network issues, impacting network metrics and user experience.

[0004] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention

[0005] The embodiments of the present application provide an anomaly detection method, apparatus, non-volatile storage medium, and electronic device to at least solve the technical problems of inaccurate anomaly detection and low detection efficiency caused by the use of fixed alarm thresholds for detection and alarm in related anomaly detection technologies.

[0006] According to one aspect of an embodiment of the present application, a method for detecting an abnormality is provided, including: determining, based on a first evaluation indicator within a first time window, whether a second evaluation indicator within a time window to be detected is an abnormality evaluation indicator, wherein the abnormality evaluation indicator is a second evaluation indicator whose difference with the first evaluation indicator satisfies a preset rule, and a time interval corresponding to the first time window is before a time interval corresponding to the time window to be detected; when the second evaluation indicator is determined to be an abnormality evaluation indicator, predicting a confidence interval of the abnormality evaluation indicator based on a third evaluation indicator within the second time window, wherein the time interval corresponding to the second time window is before a time interval corresponding to the time window to be detected, the length of the second time window is longer than the first time window, and the third evaluation indicator and the abnormality evaluation indicator are evaluation indicators of the same type; determining, based on whether the abnormality evaluation indicator is within the confidence interval, whether a cell corresponding to the abnormality evaluation indicator is abnormal; when it is determined that the cell is abnormal, determining a root cause of the abnormality based on a correlation coefficient between the abnormality evaluation indicator and the root cause indicator, wherein the root cause indicator corresponds one-to-one to the root causes in a preset root cause set.

[0007] Optionally, the first time window includes a first preset number of first evaluation indicator value points, and the time window to be detected includes a second preset number of second evaluation indicator value points. Based on the first evaluation indicator in the first time window, determining whether the second evaluation indicator in the time window to be detected is an abnormal evaluation indicator includes: determining the difference between the value of the first evaluation indicator value point in the first time window and the value of each second evaluation indicator value point in the time window to be detected; counting the first number of times that the absolute value of the difference corresponding to the first evaluation indicator value point is greater than the first preset threshold; counting the second number of times that the first number is greater than the second preset threshold; and when the second number is greater than the third threshold, determining that the second evaluation indicator in the time window to be detected is an abnormal evaluation indicator.

[0008] Optionally, predicting the confidence interval of the abnormal evaluation index based on the third evaluation index within the second time window includes: constructing an evaluation index prediction model based on the numerical value of the third evaluation index within the second time window; determining the indicator prediction value of the second evaluation index at each value point in the time window to be detected based on the indicator prediction model; increasing the indicator prediction value corresponding to the value point by a preset upper limit value, which serves as the upper limit value of the confidence interval corresponding to the value point; and reducing the indicator prediction value corresponding to the value point by a preset lower limit value, which serves as the lower limit value of the confidence interval corresponding to the value point.

[0009] Optionally, determining whether the cell corresponding to the abnormality evaluation index is abnormal based on whether the abnormality evaluation index is in the confidence interval includes: counting the value of the abnormality evaluation index not being in the third number of the corresponding confidence interval; and determining that the cell is abnormal when the third number is greater than a fourth threshold.

[0010] Optionally, the type of abnormality evaluation indicator includes at least one of the following: key performance indicators and measurement report indicators. When determining that the cell is abnormal, determining the root cause of the abnormality based on the correlation coefficient between the abnormality evaluation indicator and the root cause indicator includes: determining a preset root cause set based on the type of the abnormality evaluation indicator, and arranging the root cause indicators in the preset root cause set according to a preset order; determining the correlation coefficient between the root cause indicator and the abnormality evaluation indicator in sequence according to the arrangement order of the root cause indicators; when the correlation coefficient meets the preset conditions, determining the root cause indicator corresponding to the correlation coefficient as the abnormal root cause indicator; and determining the root cause corresponding to the abnormal root cause indicator as the abnormal root cause.

[0011] Optionally, determining the root cause corresponding to the abnormal root cause indicator as the abnormal root cause includes: when the abnormal root cause indicator is the cell availability rate, determining that the abnormal root cause is a cell failure itself; when the abnormal root cause indicator is the sum of the traffic of other indoor cells with the same coverage, determining that the abnormal root cause is the diversion of indoor cells with the same coverage; when the abnormal root cause indicator is the sum of the traffic of macro station cells with the same coverage, determining that the abnormal root cause is a change in the business model.

[0012] Optionally, after determining the correlation coefficients between the root cause indicators and the abnormality assessment indicators in sequence according to the arrangement order of the root cause indicators, the method further includes: if there is no correlation coefficient that meets the preset conditions, determining the abnormal root cause as other reasons; if the abnormal root cause is other reasons, sending an abnormality detection report to the target object, wherein the abnormality detection report is used to prompt the target object to analyze the abnormal root cause, and the content of the abnormality detection report includes at least one of the following: the identification of the abnormal cell, the abnormality assessment indicator.

[0013] According to another aspect of an embodiment of the present application, an anomaly detection device is further provided, including: a first processing module, configured to determine, based on a first evaluation indicator within a first time window, whether a second evaluation indicator within a time window to be detected is an anomaly evaluation indicator, wherein the anomaly evaluation indicator is a second evaluation indicator whose difference with the first evaluation indicator satisfies a preset rule, and a time interval corresponding to the first time window is before a time interval corresponding to the time window to be detected; a second processing module, configured to, if the second evaluation indicator is determined to be an anomaly evaluation indicator, predict a confidence interval of the anomaly evaluation indicator based on a third evaluation indicator within the second time window, wherein the time interval corresponding to the second time window is before a time interval corresponding to the time window to be detected, the length of the second time window is longer than the first time window, and the third evaluation indicator and the anomaly evaluation indicator are of the same type; a third processing module, configured to determine, based on whether the anomaly evaluation indicator is within the confidence interval, whether a cell corresponding to the anomaly evaluation indicator is abnormal; and a fourth processing module, configured to, if the cell is determined to be abnormal, determine a root cause of the anomaly based on a correlation coefficient between the anomaly evaluation indicator and a root cause indicator, wherein the root cause indicator corresponds one-to-one to a root cause in a preset root cause set.

[0014] According to another aspect of an embodiment of the present application, a non-volatile storage medium is provided, in which a program is stored. When the program is running, a device where the non-volatile storage medium is located is controlled to execute an abnormality detection method.

[0015] According to another aspect of an embodiment of the present application, an electronic device is provided, including: a memory and a processor, wherein the processor is configured to run a program stored in the memory, wherein the abnormality detection method is executed when the program is run.

[0016] According to another aspect of an embodiment of the present application, a computer program product is further provided, including a computer program, which implements the anomaly detection method when executed by a processor.

[0017] In an embodiment of the present application, a first evaluation indicator in a first time window is used to determine whether a second evaluation indicator in a time window to be detected is an abnormal evaluation indicator, wherein the abnormal evaluation indicator is a second evaluation indicator whose difference with the first evaluation indicator satisfies a preset rule, and the time interval corresponding to the first time window is before the time interval corresponding to the time window to be detected; when the second evaluation indicator is determined to be an abnormal evaluation indicator, a confidence interval of the abnormal evaluation indicator is predicted based on a third evaluation indicator in the second time window, wherein the time interval corresponding to the second time window is before the time interval corresponding to the time window to be detected, the length of the second time window is longer than the first time window, and the third evaluation indicator and the abnormal evaluation indicator are evaluation indicators of the same type. The abnormal evaluation index is used as the indicator; whether the cell corresponding to the abnormal evaluation index is abnormal is determined based on whether it is in the confidence interval; when the cell is determined to be abnormal, the root cause of the abnormality is determined based on the correlation coefficient between the abnormal evaluation index and the root cause index. The root cause index corresponds to the root cause in the preset root cause set one by one. The dynamic threshold index abnormality detection and vector product correlation analysis method combining short-term year-on-year comparison with long-term neural network prediction are used to accurately and quickly discover the cells with abnormal indicators of the indoor distribution system and determine the root cause of the abnormality, thereby achieving the technical effect of improving the accuracy and efficiency of abnormality detection, and further solving the technical problems of inaccurate abnormality detection and low detection efficiency caused by the use of fixed alarm thresholds for detection and alarm by related abnormality detection technologies. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0019] Figure 1 is a structural diagram of a computer terminal provided according to an embodiment of the present application;

[0020] Figure 2 1 is a flow chart of an anomaly detection method provided according to an embodiment of the present application;

[0021] Figure 3 This is a schematic diagram of a data acquisition and preprocessing process according to an embodiment of the present application;

[0022] Figure 4 This is a flowchart of a short-term month-on-month indicator anomaly detection method according to an embodiment of the present application;

[0023] Figure 5 2 is a schematic diagram of a short-term month-on-month indicator anomaly detection time window provided according to an embodiment of the present application;

[0024] Figure 6 2 is a schematic diagram of a short-term month-on-month indicator anomaly detection method according to an embodiment of the present application;

[0025] Figure 7 This is a flowchart of a long-term month-on-month indicator anomaly detection method according to an embodiment of the present application;

[0026] Figure 8 Schematic diagram of prediction results of an evaluation index prediction model provided according to an embodiment of the present application;

[0027] Figure 9 This is a schematic diagram of demarcating abnormal fluctuations of KPIs in a distributed indoor system according to an embodiment of the present application;

[0028] Figure 10 This is a schematic diagram of a correlation analysis between cell traffic drop and faults provided in an embodiment of the present application;

[0029] Figure 11 This is a schematic diagram of a correlation analysis between cell traffic drop and room-to-room traffic diversion with the same coverage, provided in an embodiment of the present application;

[0030] Figure 12 This is a schematic diagram of a correlation analysis between cell traffic decline and service model change provided in an embodiment of the present application;

[0031] Figure 13 This is a schematic diagram of a process for delimiting abnormal fluctuations in MR coverage of a room-distributed system according to an embodiment of the present application;

[0032] Figure 14 2 is a schematic diagram of a correlation analysis between cell MR coverage degradation and faults provided in an embodiment of the present application;

[0033] Figure 15 2 is a schematic diagram of a correlation analysis between a decrease in cell MR coverage and whether it is shared according to an embodiment of the present application;

[0034] Figure 16 2 is a schematic diagram of a correlation analysis between a decrease in cell MR coverage and a service model according to an embodiment of the present application;

[0035] Figure 17 This is a schematic diagram of the overall process of anomaly detection provided according to an embodiment of the present application;

[0036] Figure 18 It is a structural diagram of an anomaly detection device provided according to an embodiment of the present application. DETAILED DESCRIPTION

[0037] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.

[0038] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0039] In order to better understand the embodiments of the present application, the technical terms involved in the embodiments of the present application are explained as follows:

[0040] MR: It is a periodic measurement report reported by the terminal to the base station. The measurement report contains information such as the user's location, the actual wireless environment of the downlink measurement power, etc.

[0041] KPI: Key Performance Indicator.

[0042] At present, the relevant technology sets fixed thresholds for various indicators. When the indicators are lower than or higher than the thresholds, it triggers abnormal fluctuations of the indicators and issues an early warning. However, in actual business, the absolute threshold can only provide a "bottom line". Except for some very deterministic business scenarios, in other cases, too high a "bottom line" will lead to false alarms, and too low a "bottom line" may miss many situations that require early warning. This is especially true for indoor distributed systems composed of multiple passive components (such as couplers, power splitters, feeders, ceiling antennas, etc.) and signal source equipment (such as RRUs, dry placement, repeaters, etc.). The complexity of the system's passive connections increases the difficulty of monitoring. Traditional KPI indicator monitoring is difficult to effectively detect hidden and passive faults in indoor distributed systems. This traditional method cannot effectively and timely detect network problems, affecting network indicators and user perception. Specifically, the relevant technology has the following problems:

[0043] 1. The existing traditional indicator monitoring method sets a fixed threshold for anomaly detection, which is prone to misjudgment and missed judgment.

[0044] 2. Abnormal fluctuations in potential indicators that cannot be detected by existing traditional indicator monitoring methods.

[0045] 3. Existing traditional indicator monitoring methods are inefficient, resulting in low network optimization efficiency.

[0046] 4. When detecting abnormal fluctuations in indicators, existing technical algorithms only consider the unilateral reasons of the cell itself, but do not consider the linkage factors between the cell and the surrounding cells, which leads to misjudgment and incompleteness of the root cause analysis results.

[0047] In order to solve the above problems, relevant solutions are provided in the embodiments of the present application, which are described in detail below.

[0048] According to an embodiment of the present application, a method embodiment of an anomaly detection method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0049] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 FIG. 1 shows a hardware structure block diagram of a computer terminal for implementing an anomaly detection method. Figure 1As shown, the computer terminal 10 may include one or more (illustrated as 102a, 102b, ..., 102n in the figure) processors 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. It will be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 1 More or fewer components than shown, or with Figure 1 Different configurations shown.

[0050] It should be noted that the one or more processors 102 and / or other data processing circuits described above may generally be referred to herein as "data processing circuitry." The data processing circuitry may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuitry may be a single, independent processing module, or may be incorporated in whole or in part into any of the other components of the computer terminal 10. As described in the embodiments of the present application, the data processing circuitry serves as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).

[0051] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the abnormality detection method in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implementing the above-mentioned abnormality detection method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely located relative to the processor 102, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0052] The transmission device 106 is configured to receive or transmit data via a network. A specific example of the aforementioned network may include a wireless network provided by the communications provider of the computer terminal 10. In one embodiment, the transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, the transmission device 106 may be a radio frequency (RF) module, which is configured to communicate with the Internet wirelessly.

[0053] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the computer terminal 10 .

[0054] In the above operating environment, the embodiment of the present application provides an abnormality detection method, such as Figure 2 As shown, the method includes the following steps:

[0055] Step S202: Determine whether a second evaluation indicator in the time window to be detected is an abnormal evaluation indicator based on the first evaluation indicator in the first time window, wherein the abnormal evaluation indicator is a second evaluation indicator whose difference with the first evaluation indicator meets a preset rule, and the time interval corresponding to the first time window is before the time interval corresponding to the time window to be detected.

[0056] Optionally, before determining whether the second evaluation indicator within the time window to be detected is an abnormal evaluation indicator based on the first evaluation indicator within the first time window, the method further includes acquiring and preprocessing data (including the first evaluation indicator and the second evaluation indicator data). Specifically, network cell engineering parameters and KPI indicators (i.e., key performance indicators), MR coverage (i.e., measurement report indicators), and other indicator data are extracted from professional network management. The cell longitude and latitude in the engineering parameters are sorted, and missing, redundant, and inconsistent longitude and latitude at the same station are preprocessed. Then, the data is associated with the KPI indicators and MR coverage, and then cleaned and stored. Among them, the key fields of cell engineering parameters include but are not limited to base station identifier (enb), cell identifier (cellid), cell longitude (longitude), cell latitude (latitude), cell direction angle (azimuse), cell type (cover_type), etc. KPI indicators include traffic (pdcp), wireless connection success rate (wir_succconn_rate), ERAB drop rate (erab_abnormrel_rate), RRC connection reconstruction ratio (rrc_attconnreestab_rate), system handover success rate (sys_succout_rate), etc. MR coverage indicators include coverage rate (coverage_rate), weak coverage rate (weak_coverage_rate), weak coverage grid number (weak_coverage_grids), etc.

[0057] Optionally, Figure 3 A schematic diagram of a data acquisition and preprocessing process is shown in FIG. Figure 3 As shown, data acquisition and preprocessing include the following steps:

[0058] Step 301: Obtain cell engineering parameters: Obtain the existing network engineering parameter data from the engineering parameter network management, organize the cell longitude and latitude in the engineering parameters, and pre-process missing, redundant, and inconsistent longitude and latitude at the same station. Key fields of cell engineering parameters include but are not limited to base station identifier (enb), cell identifier (cellid), cell longitude (longitude), cell latitude (latitude), cell direction angle (azimuse), cell type (cover_type), etc., as shown below.

[0059]

[0060]

[0061] Step 302, obtaining KPI indicators: extracting KPI indicators from professional network management, where key fields of KPI indicators include but are not limited to date (p_day), base station identifier (enb), cell identifier (cellid), cell traffic (pdcp), cell availability rate (cell_available_rate), shared traffic (pdcp_share), wireless connection success rate (wir_succconn_rate), ERAB drop rate (erab_abnormrel_rate), RRC connection reestablishment ratio (rrc_attconnreestab_rate), intra-system handover success rate (sys_succout_rate), etc., as shown below:

[0062]

[0063] Step 303, obtaining MR coverage indicators: extracting MR coverage indicators from professional network management, where key fields of MR coverage indicators include but are not limited to date (p_day), base station identifier (enb), cell identifier (cellid), MR coverage ratio (rsrpgoodratio), number of weak coverage MRs (weakcover_mrcount), grid number (grid_count), number of MRs (rsrpcount), cell availability rate (cell_available_rate), shared traffic (pdcp_share), and other information. An example is as follows:

[0064]

[0065]

[0066] Step 304, association and integration: Based on the above cell working parameter data, the KPI indicators and MR coverage indicators are associated and integrated through the base station identifier (enb) and the cell identifier (cellid). The integrated KPI indicator key fields and MR coverage indicator key fields are as follows.

[0067] The key fields of the integrated KPI indicators are as follows:

[0068]

[0069] The key fields of the integrated MR coverage indicators are as follows:

[0070]

[0071]

[0072] As an optional implementation, the first time window includes a first preset number of first evaluation indicator value points, and the time window to be detected includes a second preset number of second evaluation indicator value points. Based on the first evaluation indicator in the first time window, determining whether the second evaluation indicator in the time window to be detected is an abnormal evaluation indicator includes: determining the difference between the value of the first evaluation indicator value point in the first time window and the value of each second evaluation indicator value point in the time window to be detected; counting the first number of times that the absolute value of the difference corresponding to the first evaluation indicator value point is greater than a first preset threshold; counting the second number of times that the first number is greater than the second preset threshold; and when the second number is greater than a third threshold, determining that the second evaluation indicator in the time window to be detected is an abnormal evaluation indicator.

[0073] Optionally, after obtaining the indicator data and preprocessing the indicator data, a preliminary judgment of abnormal fluctuations of rapid indicators is made based on the preprocessed integrated KPI indicators and MR coverage indicators, and a short-term month-on-month indicator anomaly detection algorithm is used to quickly and preliminarily judge whether there is abnormal fluctuation in the indoor cell indicators (i.e., determine whether there are abnormal evaluation indicators). Specifically, the obtained indicators are divided into reference indicators (i.e., first evaluation indicators) within the time window T1 (i.e., the first time window) and indicators to be evaluated (i.e., second evaluation indicators) within the time window T2 (i.e., the time window to be detected). Based on this, the indicators to be evaluated within the time window T2 are cyclically calculated. and the reference index within time window T1 The absolute value of the difference kpi′ ij (i.e., determine the absolute value of the difference between the value of the first evaluation indicator value point in the first time window and the value of each second evaluation indicator value point in the time window to be detected), and then compare it with the dynamic threshold value kpi calculated by the reference indicator in the time window T1) thr (first preset threshold) is compared, if kpi′ ij Greater than KPI thr , then the counter kpi cnt Add 1, after each round of calculation is completed, if kpi cnt (ie the first number) is greater than the threshold number thr (i.e., the second preset threshold), indicating that the corresponding indicator has moved once, then T cnt Add 1. The indicator to be evaluated within the time window T2 and the reference index within time window T1 After the loop is completed, if T cnt The value (i.e. the second number) is greater than the preset time threshold T thr (ie, the third preset threshold), it means that the indicator to be evaluated within the time window T2 has experienced abnormal fluctuations (ie, it is an abnormal evaluation indicator).

[0074] Among them, T1 refers to the cycle length of the reference indicator data, and the cycle in this algorithm is measured in days; T2 refers to the cycle length of the indicator data to be evaluated, and the cycle in this algorithm is measured in days; Refers to an indicator in the reference indicator data within the time window T1; Refers to an indicator in the indicator data to be evaluated within the time window T2, and The same indicator; KPI' ij means and Absolute value of the difference; KPI thr Refers to the dynamic threshold value calculated from the reference indicator data within the time window T1; KPI cnt Refers to comparing KPIs in each cycle ij and KPIs thr Time counter; number thr Refers to comparing KPIs in each cycle ij Greater than KPI thr The minimum threshold value of the number of times; T cnt Refers to the number of abnormal fluctuations of the corresponding indicator to be evaluated within the time window T2; T thr This refers to the minimum number of abnormal fluctuations in the corresponding indicator to be evaluated within time window T2. The value of i ranges from 1 to the length of time window T2, and the value of j ranges from 1 to the length of time window T1.

[0075] Optionally, Figure 4 A schematic diagram of the process of detecting abnormality of short-term month-on-month indicators is shown in FIG. Figure 4 As shown in the figure, taking the KPI indicator as an example (the short-term month-on-month indicator anomaly detection process of the MR indicator is similar to that of the KPI indicator and is not repeated here), the short-term month-on-month indicator anomaly detection includes the following steps:

[0076] Step 401, divide the KPI indicators into reference indicators (first evaluation indicators) and indicators to be evaluated (second evaluation indicators) according to the time window: Based on the KPI indicators integrated in step 304, divide the KPI indicators into reference indicators in time window T1 and indicators to be evaluated in time window T2 from the time dimension, such as Figure 5 As shown, the blue time interval corresponds to the first time window, and the red time interval corresponds to the time window to be detected. Based on the reference index in the time window T1 at the cell level, the abnormal fluctuation dynamic threshold KPI is calculated through step 402. thr (First preset threshold), then calculate the absolute value kpi′ of the difference between the indicator to be evaluated in the time window T2 and the reference indicator in the time window T1 according to the time granularity ij and compared with the dynamic threshold.

[0077] Step 402, calculate the abnormal fluctuation dynamic threshold of the indicator based on the reference indicator (first preset threshold): the cell dynamic threshold kpi calculated based on the reference indicator within the time window T1 in step 401 thr First, take the cell as the granularity to obtain the maximum value of the reference indicator kpi for each cell in the time window T1 max , minimum KPI min , average KPI avg Then take the maximum value of the difference between the maximum value and the average value and the difference between the average value and the minimum value and multiply it by the dynamic threshold coefficient kpi μ This coefficient can flexibly adjust the dynamic threshold KPI thr Size, KPI μ It is a floating point number with a value greater than 0. Theoretically, there is no upper limit. The formula is as follows:

[0078] KPIs thr =KPI μ *max(kpi max -kpi avg , KPI avg -kpi min )

[0079] Step 403: Based on the reference index in time window T1 and the index to be evaluated in time window T2 in step 401, the absolute value kpi′ of the difference between the index to be evaluated in time window T2 and the reference index in time window T1 is calculated cyclically with the cell as the granularity. ij , and then compared with the cell dynamic threshold KPI obtained in step 10202 thr Compare, if KPI′ ij Greater than KPI thr , then the counter kpi cnt Add 1, after each round of calculation is completed, if kpi cnt Greater than or equal to the threshold number thr , indicating that the corresponding indicator has experienced an abnormal change, then T cnt Add 1, and the calculation formula is as follows:

[0080]

[0081] Assume that the time windows T1 and T2 are both 7 (i.e., the first time window includes 7 (the first preset number) first evaluation index value points, and the time window to be detected includes 7 (the second preset number) second evaluation index value points), number thr is 3, T thr If it is 3, the generated KPI′ ij The matrix is ​​as follows:

[0082]

[0083] Each row vector in the above matrix corresponds to a cycle, and the row vector in the matrix is ​​used as a unit to determine whether it is greater than the dynamic threshold kpi thr If it is greater than the dynamic threshold kpi thr , then KPI cnt Add 1, otherwise remain unchanged, KPI cnt The initial value of each row vector in the matrix is ​​0. Figure 6 A schematic diagram of short-term month-on-month indicator anomaly detection is shown, Figure 6 As shown in the first row vector kpi′ 12 , kpi′ 14 , kpi′ 15 , kpi′ 16 Greater than the dynamic threshold KPI thr , then KPI cnt 4. Based on the assumption number thr is 3, so KPI cnt Greater than or equal to number thr , so T cnt Add 1. kpi′ in the second row vector 22 , kpi′ 24 , kpi′ 25 , kpi′ 26 Greater than the dynamic threshold KPI thr , then KPI cnt is 4. cnt Add 1 to the result of the first row vector, and T cnt is 2, and so on, the third row vector, the fourth row vector, and the seventh row vector all meet the KPI cnt Greater than or equal to number thr Therefore, after traversing all row vectors, we get T cnt The value is 5, and then with the assumption that T thr For comparison with 3, it is found that T cnt Greater than T thr , it is considered that the KPI indicator corresponding to the cell has experienced abnormal fluctuations. cnt The initial value of each indicator for each cell is 0, and the maximum value is the time window T2.

[0084] Step S204: When it is determined that the second evaluation indicator is an abnormality evaluation indicator, a confidence interval of the abnormality evaluation indicator is predicted based on the third evaluation indicator within the second time window, wherein the time interval corresponding to the second time window is before the time interval corresponding to the time window to be detected, the length of the second time window is longer than the first time window, and the third evaluation indicator and the abnormality evaluation indicator are the same type of evaluation indicators.

[0085] As an optional implementation, predicting the confidence interval of the abnormal evaluation index based on the third evaluation index within the second time window includes: constructing an evaluation index prediction model based on the numerical value of the third evaluation index within the second time window; determining the indicator prediction value of the second evaluation index at each value point in the time window to be detected based on the indicator prediction model; increasing the indicator prediction value corresponding to the value point by a preset upper limit value, which serves as the upper limit value of the confidence interval corresponding to the value point; and reducing the indicator prediction value corresponding to the value point by a preset lower limit value, which serves as the lower limit value of the confidence interval corresponding to the value point.

[0086] Optionally, after detecting abnormal indicators using the short-term year-over-year comparison method, further confirmation can be made using the long-term year-over-year comparison method. This method is a relatively simple method for detecting recent abnormal fluctuations in indicators, offering fast computational speed and good generalization. However, it cannot track indicators over the long term. Specifically, if the reference value window completely changes to abnormal fluctuations over time, it will no longer be able to monitor whether the indicator is experiencing abnormal fluctuations. However, if the reference value window is fixed and not updated for an extended period, normal traffic model changes may be misidentified as abnormal data. Therefore, it is necessary to consider the overall data trends over a longer period of time. As a supplement to absolute value warnings, relative value warnings can determine whether current fluctuations are abnormal based on historical indicators and fluctuations, enabling timely detection and warning of potential network issues. Long-term year-over-year comparisons typically use a curve to fit the trend. If new data disrupts this trend, causing the curve to become less smooth, an anomaly has occurred at that point.

[0087] Optionally, based on the cells detected with abnormal fluctuations in indicators (i.e., cells with abnormal evaluation indicators), a time series model algorithm based on a neural network is used for fitting and prediction, and it is determined whether the actual data is within the confidence interval. If not, and the number of times it is not within the confidence interval (i.e., the third number) is greater than the minimum number of abnormal fluctuations thr long (i.e., the fourth threshold), the indicator is ultimately judged to be fluctuating abnormally. The neural network-based time series model algorithm not only has good interpretability but also has better predictive performance than Prophet.

[0088] The neural network-based time series model algorithm is a decomposable time series model. Compared to Prophet, its core concept is its modular composability. The model consists of multiple modules, each contributing an additional component to the forecast. All modules can be configured individually and combined to form a model. If all modules are disabled, only a static offset parameter is installed as the trend component. By default, only the trend and seasonality modules are activated. For example, the trend module can be used to build a linear or combined multiple linear trend models by setting change points. Seasonality is modeled using Fourier terms, thus addressing the various seasonality characteristics of high-frequency data. Autoregression is addressed using an implementation of AR-Net, an auto-regressive feed-forward neural network for time series. Lagged regressors are also modeled using a separate feed-forward neural network. Future regressors and special events are included as covariates in the model.

[0089] The neural network-based time series model algorithm consists of multiple modules, and the formula is as follows.

[0090]

[0091] in:

[0092] T(t) = trend at time t

[0093] S(t) = seasonal effect at time t

[0094] E(t) = event and holiday effects at time t

[0095] F(t) = the regression effect of a known future exogenous variable at time t

[0096] A(t) = autoregressive effect at time t based on past observations

[0097] L(t)=the regression effect of the lagged observation of the exogenous variable at time t

[0098] Optionally, Figure 7 A schematic diagram of a long-term month-on-month anomaly detection process is shown in FIG. Figure 7 As shown in the figure, long-term month-on-month anomaly detection is based on the cells and related indicators (abnormal evaluation indicators) with abnormal fluctuations in short-term indicators. It performs fitting prediction based on the time series model algorithm of the neural network and judges whether the actual data is within the confidence interval. If not, and it is greater than the minimum abnormal fluctuation number thr long, it is determined as the final abnormal indicator fluctuation cell (i.e., cell abnormality). Otherwise, the cell detected with abnormal short-term month-on-month indicator fluctuation will not be determined as the final abnormal indicator fluctuation cell. Specifically, the process includes the following steps:

[0099] Step 701, Model Selection: The goal of long-term month-on-month abnormal indicator detection is to use a trend fitting method to quickly and accurately fit the trends of cell indicators, thereby accurately determining whether there are abnormal fluctuations in cell indicators. Fitting methods include LSTM, ARIMA, SARIMA, and Prophet. However, these model algorithms are highly sensitive to data and parameter settings. For example, a slight difference in parameter settings may result in significant deviations in the prediction results. After comprehensive comparison, this example uses a time series model algorithm based on a neural network.

[0100] Step 702, build the model: The neural network-based time series model has good interpretability. Its core concept is its modular composability. The model consists of multiple modules, each of which contributes an additional component to the forecast. All module components can be individually configured and combined to form the model. If all modules are turned off, only a static offset parameter is installed as the trend component. By default, only the trend and seasonality modules are activated. Therefore, its forecasting performance is better than the Prophet model algorithm. The algorithm expression of the neural network-based time series model is as follows:

[0101]

[0102] in:

[0103] T(t) = trend at time t

[0104] S(t) = seasonal effect at time t

[0105] E(t) = event and holiday effects at time t

[0106] F(t) = the regression effect of a known future exogenous variable at time t

[0107] A(t) = autoregressive effect at time t based on past observations

[0108] L(t)=the regression effect of the lagged observation of the exogenous variable at time t

[0109] After initializing the algorithm model, the cell index (i.e., the third evaluation index) within the time window T3 (i.e., the second time window) is modeled and optimized (i.e., an evaluation index prediction model is constructed), and the corresponding index at each time granularity within the time window T2 is accurately predicted (i.e., the index prediction value of the second evaluation index at each value point in the time window to be detected) and the confidence interval are determined. If the cell index fluctuation within the time window T2 exceeds the corresponding confidence interval and is greater than the minimum abnormal fluctuation number thr long , then the cell is determined to be a cell with abnormal fluctuation of the final indicator. The time window T3 includes and is longer than the time window T1. The time series model and parameters based on the neural network in this example are as follows:

[0110] model=NeuralProphet(growth="linear",changepoints_range=0.8,

[0111] trend_reg=0, trend_reg_threshold=False,

[0112] yearly_seasonality="auto",weekly_seasonality="auto",

[0113] daily_seasonality="auto",seasonality_mode="additive",

[0114] loss_func="Huber",normalize="auto")

[0115] The parameter growth indicates the prediction method. In this example, linear is used; changepoints_range indicates that there is no inflection point in the training data after the set ratio. In this example, the value is set to 0.8; trend_reg indicates the trend regularization term. In this example, it is set to 0; trend_reg_threshold indicates whether the trend is allowed to change without regularization. In this example, it is set to False; yearly_seasonality determines whether to automatically detect the seasonal component of the annual cycle. In this example, it is set to auto; weekly_seasonality determines whether to automatically detect the seasonal component of the weekly cycle. In this example, it is set to auto; daily_seasonality determines whether to automatically detect the seasonal component of the daily cycle. In this example, it is set to auto; seasonality_mode specifies how the seasonal component is combined with the trend component and other components, whether to use additive or multiplicative methods. In this example, additive methods are used; loss_func indicates the loss function used to measure the difference between the model prediction value and the true value. In this example, it is set to Huber; normalize controls the normalization method of the input time series data. In this example, it is set to auto.

[0116] Step 703: Predict the cell indicators and confidence intervals within the time window T2: The model established in step 702 is used to predict the cell indicators within the time window T2, thereby obtaining the predicted values ​​and confidence intervals. The prediction function is:

[0117] forecast=model.predict(future)

[0118] Among them, future is the time series of cell indicators within the time window T2, and forecast contains the forecast results (i.e. the predicted values ​​of indicators). Figure 8 The prediction results of an evaluation index prediction model are shown, such as Figure 8 As shown in the figure, the green point is the predicted result value (i.e., the indicator predicted value), the yellow point (obtained by increasing the indicator predicted value corresponding to the value point by the preset upper limit value) and the red point (obtained by reducing the indicator predicted value corresponding to the value point by the preset lower limit value) are the upper and lower limits of the confidence interval respectively.

[0119] Step S206 : Determine whether the cell corresponding to the abnormality assessment indicator is abnormal based on whether the abnormality assessment indicator is within the confidence interval.

[0120] As an optional implementation, determining whether the cell corresponding to the abnormality evaluation index is abnormal based on whether the abnormality evaluation index is in the confidence interval includes: the value of the statistical abnormality evaluation index is not in the third number of the corresponding confidence interval; when the third number is greater than the fourth threshold, determining that the cell is abnormal.

[0121] Alternatively, as Figure 7 As shown, step 704 is used to determine whether there is abnormal fluctuation of long-term indicators in the cell: based on the predicted value and confidence interval of the cell indicator within the time window T2 range obtained in step 703, combined with the actual value of the cell indicator within the time window T2 range, the number of time granularities cnt whose actual value is outside the confidence interval range is determined. long (third number), if cnt long Greater than or equal to the preset threshold thr long (the fourth threshold), it is finally determined that the corresponding indicator of the cell has abnormal fluctuation phenomenon (determining that the cell is abnormal). Figure 8 As shown in the figure, the indicators corresponding to the dates marked 1 to 7 are all outside the confidence interval, cnt long is 7, which is greater than the preset threshold thr long , indicating that there are abnormal fluctuations in the corresponding indicators of this community.

[0122] Step S208 : When it is determined that the cell is abnormal, the root cause of the abnormality is determined based on the correlation coefficient between the abnormality assessment index and the root cause index, wherein the root cause index corresponds one-to-one to the root causes in the preset root cause set.

[0123] As an optional implementation, the type of abnormality assessment indicator includes at least one of the following: key performance indicators and measurement report indicators. When determining that the cell is abnormal, determining the root cause of the abnormality based on the correlation coefficient between the abnormality assessment indicator and the root cause indicator includes: determining a preset root cause set based on the type of the abnormality assessment indicator, and arranging the root cause indicators in the preset root cause set according to a preset order; determining the correlation coefficient between the root cause indicator and the abnormality assessment indicator in sequence according to the arrangement order of the root cause indicators; when the correlation coefficient meets the preset conditions, determining the root cause indicator corresponding to the correlation coefficient as the abnormal root cause indicator; and determining the root cause corresponding to the abnormal root cause indicator as the abnormal root cause.

[0124] Optionally, when the abnormal evaluation indicator is a key performance indicator (KPI), the demarcation of abnormal fluctuations in the indoor distributed system KPI includes dividing the indicator data into Class I and Class II indicators through correlation processing of the KPI indicator and industrial parameter data. The Class I indicator is the abnormal fluctuation indicator to be analyzed (i.e., the preset root cause determination indicator), and the Class II indicator is the root cause indicator. The correlation between the Class I and Class II indicators is calculated by vector product, and based on the strength of the correlation, the strongly correlated Class II indicator is used as the root cause of the abnormal fluctuation of the Class I indicator. By correlating with industrial parameter data, the indicator changes of surrounding indoor distributed and macro cell sites can be combined for linkage analysis, solving the problem of only considering the cell's own unilateral causes in the existing technology, thereby avoiding misjudgment of the cause analysis results. Key KPI indicator fields include but are not limited to date (p_day), base station identifier (enb), cell identifier (cellid), cell traffic (pdcp), cell availability rate (cell_available_rate), shared traffic (pdcp_share), wireless connection success rate (wir_succconn_rate), ERAB drop rate (erab_abnormrel_rate), RRC connection reestablishment ratio (rrc_attconnreestab_rate), intra-system handover success rate (sys_succout_rate), etc. Key cell engineering parameter fields include but are not limited to base station identifier (enb), cell identifier (cellid), cell longitude (longitude), cell latitude (latitude), cell direction angle (azimuse), cell type (cover_type), etc.

[0125] Optionally, when the abnormal evaluation indicator is a measurement report indicator (MR indicator), the abnormal fluctuation of the MR coverage of the indoor distributed system is delimited. Based on the MR coverage indicator, the indicator data is divided into a first-class indicator and a second-class indicator. The first-class indicator is the abnormal fluctuation indicator to be analyzed, and the second-class indicator is the root cause indicator. The correlation between the first-class indicator and the second-class indicator is calculated by vector product. According to the strength of the correlation, the strongly correlated second-class indicator is used as the root cause of the abnormal fluctuation of the first-class indicator. The key fields of the MR coverage indicator include but are not limited to date (p_day), base station identifier (enb), cell identifier (cellid), MR coverage ratio (rsrpgoodratio), weak coverage MR number (weakcover_mrcount), grid number (grid_count), MR number (rsrpcount), cell availability rate (cell_available_rate), shared traffic (pdcp_share), etc.

[0126] Optionally, determining the root cause corresponding to the abnormal root cause indicator as the abnormal root cause includes: when the abnormal root cause indicator is the cell availability rate, determining that the abnormal root cause is a cell failure itself; when the abnormal root cause indicator is the sum of the traffic of other indoor cells with the same coverage, determining that the abnormal root cause is the diversion of indoor cells with the same coverage; when the abnormal root cause indicator is the sum of the traffic of macro station cells with the same coverage, determining that the abnormal root cause is a change in the business model.

[0127] Optionally, Figure 9 The process of defining abnormal fluctuations of KPI in the indoor distribution system is shown as follows: Figure 9 As shown, based on the cells that have abnormal KPI fluctuations that are finally determined, the KPI indicators of the cells with abnormal fluctuations and the industrial parameter data are correlated and processed, and the indicator data are divided into one type of indicators and two types of indicators, where the one type of indicators are the abnormal fluctuation indicators to be analyzed, and the second type of indicators are the root cause indicators. The correlation between the one type of indicators and the second type of indicators is calculated by vector product. According to the strength of the correlation, the strongly correlated second type of indicators are used as the root cause of the abnormal fluctuation of the one type of indicators. By associating with the industrial parameter data, the indicator changes of the surrounding indoor and macro cells can be combined for linkage analysis to solve the problem of only considering the unilateral reasons of the cell itself in the existing technology, thereby avoiding misjudgment of the cause analysis results. Before the root cause analysis, the two types of indicators are prioritized according to the degree of influence on the network performance in the existing network, and then the correlation analysis is performed in turn. For example, the highest priority is the fault type, the next is the diversion type, and the next is the business model change type. To briefly explain the process, the decline in the traffic volume (i.e., the abnormal evaluation index) of the indoor system cell is taken as an example. The process includes the following steps:

[0128] Step 901, index classification: Based on the final determined abnormal fluctuation of traffic flow, the subsystem cell index and the working parameter information are calculated to calculate the distance from the cell to the thr dis1 The sum of the traffic of the same coverage indoor cells in the range at the corresponding time granularity (the same coverage indoor split flow, that is, the sum of the traffic of other indoor cells with the same coverage), and the sum of the cell traffic of the same coverage macro cell at the corresponding time granularity (that is, the sum of the traffic of the same coverage macro cell). The same coverage macro cell is thr dis2 The macro base station is within the range, and the indoor cell is within the range of ±60 degrees of the macro base station antenna direction angle. n The key fields of a macro cell are as follows:

[0129]

[0130] Step 902, fault analysis: Based on the indicators related to the abnormal decrease and fluctuation of the indoor distributed system cell traffic obtained in step 901, first analyze the correlation coefficient r between the first-class indicator cell traffic and the fault class in the second-class indicator by vector product method. If the correlation coefficient is greater than or equal to the preset threshold β1, it can be determined that the abnormal fluctuation of the cell traffic decrease is mainly caused by the cell's own fault. If the correlation coefficient is less than the preset threshold β1, jump to step 10403 for further analysis and demarcation of the cause. Among them, the cell fault class indicator can be directly reflected by the cell availability. The vector product function formula for calculating the correlation coefficient by vector product method is as follows:

[0131]

[0132] Where r represents the correlation coefficient, and the coefficient range is between -1 and 1. Negative numbers represent negative correlation, positive numbers represent positive correlation, and 0 represents no correlation. n represents the number of samples involved in the correlation coefficient calculation, i represents the i-th sample involved in the correlation coefficient calculation, and x represents the number of samples involved in the correlation coefficient calculation. i 、y i Respectively represent the values ​​of the i-th x and y samples involved in the calculation of the correlation coefficient, Respectively represent the sample means of x and y involved in the calculation of the correlation coefficient.

[0133] Based on the above vector product function, the correlation coefficient r can be obtained by assigning the cell traffic (pdcp) (abnormal evaluation index) and the cell availability rate (root cause index) (cell_available_rate) to x and y respectively. In order to clearly compare the correlation, this example lists the correlation coefficients between the traffic and cell availability of two indoor cells, such as Figure 10 As shown, the scatter distribution of the traffic volume (PDCP) of the cell (base station ID: 68236, cell ID: 2) and the cell availability rate (cell_available_rate), a fault indicator, is represented by dots, and the correlation coefficient with the cell availability rate (cell_available_rate), a fault indicator, is represented by a solid line. The correlation coefficient is 0.02, which is less than the preset threshold β1, indicating a low correlation. The traffic volume (PDCP) of the cell (base station ID: 69068, cell ID: 59) and the cell availability rate (cell_available_rate), a fault indicator, are represented by triangles, and the correlation coefficient with the cell availability rate (cell_available_rate), a fault indicator, is represented by a dashed line. The correlation coefficient is 0.86, which is greater than the preset threshold β1, indicating a high correlation. Therefore, it is determined that the abnormal decrease and fluctuation in traffic volume in this cell is caused by a fault in the cell itself (i.e., if the correlation coefficient meets the preset conditions, the root cause indicator corresponding to the correlation coefficient is determined to be an abnormal root cause indicator).

[0134] It should be noted that the size of the correlation coefficient is not equal to Figure 10 The slope of the solid or dashed line. The slope can only reflect whether it is a positive correlation or a negative correlation. When the correlation is positive, the slope is greater than 0, and when the correlation is negative, the slope is less than 0.

[0135] Step 903: Analysis of Traffic Diversion within the Same Coverage Room: Based on the analysis in step 902 and after eliminating the causes of fault indicators, a correlation analysis is performed on the traffic diversion within the same coverage room. This analysis also uses the vector product function from step 10402 to calculate the correlation between the cell traffic and the sum of the traffic of other cells within the same coverage. If the correlation coefficient r is less than or equal to the preset threshold β2, it can be determined that the abnormal fluctuation in the cell traffic decrease is primarily due to traffic diversion from other cells within the same coverage. If the correlation coefficient r is greater than the preset threshold β2, the process proceeds to step 10404 for further analysis and demarcation of the cause.

[0136] Based on the vector product function in step 902, the indoor cell traffic (pdcp) and the traffic sum of other indoor cells with the same coverage at the corresponding time granularity (pdcp_mic) are assigned to the values ​​x and y respectively to obtain the correlation coefficient r. In order to clearly compare the magnitude of the correlation, this example lists the correlation coefficients between the traffic of two indoor cells and the traffic sum of other indoor cells with the same coverage at the corresponding time granularity, as shown in the figure below: Figure 11 As shown in the figure, the scatter distribution of the traffic (pdcp) of the cell (base station ID: 65401, cell ID: 51) and the traffic sum (pdcp_mic) at the corresponding time granularity of the same indoor cell is represented by dots, and the correlation coefficient with the traffic sum (pdcp_mic) at the corresponding time granularity of other indoor cells with the same coverage is represented by a solid line. The correlation coefficient is -0.11, which is greater than the preset threshold β2 and indicates a low correlation. The traffic (pdcp) of the cell (base station ID: 802983, cell ID: 53) and the traffic sum (pdcp_mic) at the corresponding time granularity of the same indoor cell are represented by triangles, and the correlation coefficient with the traffic sum (pdcp_mic) at the corresponding time granularity of other indoor cells with the same coverage is represented by a dotted line. The correlation coefficient is -0.92, which is less than the preset threshold β2 and indicates a high correlation. Therefore, it is determined that the abnormal traffic decrease and fluctuation in this cell is caused by traffic diversion from the same indoor cell with the same coverage.

[0137] Step 904, business model analysis: Based on the analysis of steps 902 and 903, after eliminating the causes of fault-related indicators and indoor distribution diversion indicators with the same coverage, a correlation analysis is performed on the cell business model. During the analysis, the vector product function in step 10402 is also used to calculate the correlation between the cell traffic (pdcp) and the traffic sum (pdcp_mac) of the corresponding time granularity of the macro cell with the same coverage. If the correlation coefficient r is greater than or equal to the preset threshold β3, it can be determined that the main cause of the abnormal fluctuation in the indoor cell traffic is due to changes in the business model. If the correlation coefficient r is less than the preset threshold β3, it is classified as other reasons, or transferred to the relevant optimization personnel for manual analysis and judgment.

[0138] Based on the vector product function in step 902, the indoor cell traffic (pdcp) and the traffic sum (pdcp_mac) of the same coverage macro cell meeting the above conditions at the corresponding time granularity are assigned to the values ​​x and y respectively to obtain the correlation coefficient r. In order to clearly compare the magnitude of the correlation, this example lists the correlation coefficients between the traffic (pdcp) of two indoor cells and the traffic sum (pdcp_mac) of the same coverage macro cell meeting the above conditions at the corresponding time granularity, as shown in FIG. Figure 12 As shown in the figure, the scatter distribution of the traffic (pdcp) of the cell (base station ID: 92016, cell ID: 1) and the traffic sum (pdcp_mac) of the corresponding time granularity of the same macro cell are represented by dots, and the correlation coefficient with the traffic sum (pdcp_mac) of the corresponding time granularity of the same macro cell is represented by a solid line. The correlation coefficient is 0.29, which is less than the preset threshold β3, indicating a low correlation. The scatter distribution of the traffic (pdcp) of the cell (base station ID: 90065, cell ID: 4) and the traffic sum (pdcp_mac) of the corresponding time granularity of the same macro cell are represented by triangles, and the correlation coefficient with the traffic sum (pdcp_mac) of the corresponding time granularity of the same macro cell is represented by a dotted line. The correlation coefficient is 0.89, which is greater than or equal to the preset threshold β3, indicating a high correlation. Therefore, it is determined that the abnormal traffic decrease and fluctuation in this cell is caused by changes in the service model.

[0139] Optionally, Figure 13 The process of demarcating abnormal fluctuations in MR coverage of the room distribution system is shown in FIG. Figure 13As shown, based on the cells that are finally determined to have abnormal fluctuations in MR coverage indicators, the MR coverage indicators of the cells with abnormal fluctuations in MR coverage indicators are divided into one type of indicators and two types of indicators, wherein the one type of indicators are the abnormal fluctuation indicators (abnormal evaluation indicators) to be analyzed, and the two types of indicators are the root cause indicators. The correlation between the one type of indicators and the two types of indicators is calculated by the vector product function in step 902. According to the strength of the correlation, the strongly correlated two types of indicators are used as the root cause of the abnormal fluctuation of the one type of indicators. Before the root cause analysis, the two types of indicators are prioritized according to their impact on the network performance in the existing network (that is, the root cause indicators in the preset root cause set are arranged according to the preset order), and then the correlation analysis and judgment are performed in turn. For example, the highest priority is the fault class, followed by the whether to share class, and then the business model change class, etc. In order to briefly explain the process, the decline in MR coverage (abnormal evaluation index) of the indoor distributed system cell is taken as an example. The process specifically includes the following steps:

[0140] Step 1301, Fault Analysis: Based on the integrated first-category indicator, cell MR coverage ratio (rsrpgoodratio), and second-category indicator, cell availability ratio (cell_available_rate), the correlation coefficient r is calculated using the cross product function in step 902. If the absolute value of the correlation coefficient r is greater than or equal to the preset threshold β4, it can be determined that the abnormal fluctuation in the cell MR coverage ratio is primarily due to a cell fault. If the absolute value of the correlation coefficient r is less than the preset threshold β4, the process proceeds to step 1302 for further analysis and cause determination. Cell fault indicators can be directly reflected by the cell availability ratio.

[0141] Based on the vector product function in step 902, the correlation coefficient r can be obtained by assigning the cell MR coverage ratio (rsrpgoodratio) and the cell availability rate (cell_available_rate) to x and y respectively. In order to clearly compare the correlation, the correlation coefficients between the MR coverage ratio (rsrpgoodratio) and the cell availability rate (cell_available_rate) of two indoor cells are listed in this example, as shown in FIG. Figure 14As shown in the figure, the scatter distribution of the MR coverage ratio (rsrpgoodratio) and the cell availability rate (cell_available_rate) for the cell (base station ID: 66215, cell ID: 51) is represented by dots, and the correlation coefficient with the fault indicator cell availability rate (cell_available_rate) is represented by a solid line. The absolute value of the correlation coefficient r is 0.22, which is less than the preset threshold β4, indicating a low correlation. The scatter distribution of the MR coverage ratio (rsrpgoodratio) and the cell availability rate (cell_available_rate) for the cell (base station ID: 83754, cell ID: 56) is represented by triangles, and the correlation coefficient with the fault indicator cell availability rate (cell_available_rate) is represented by a dotted line. The absolute value of the correlation coefficient r is 0.95, which is greater than or equal to the preset threshold β4, indicating a high correlation. Therefore, it is determined that the abnormal decline and fluctuation of the MR coverage ratio in this cell is due to a fault in the cell itself.

[0142] Step 1302, sharing analysis: Based on the analysis of step 1301, after eliminating the causes of the fault indicators, a correlation analysis is performed on whether the cell is shared. During the analysis, the vector product function of step 902 is also used to calculate the correlation between the MR coverage rate (rsrpgoodratio) and whether the cell is shared (is_share). If the absolute value of the correlation coefficient r is greater than or equal to the preset threshold β5, it can be determined that the abnormal fluctuation of the cell MR coverage rate is mainly due to sharing. If the absolute value of the correlation coefficient r is less than the preset threshold β5, jump to step 1303 for further analysis and demarcation of the cause. Whether it is shared (is_share) is determined by the shared traffic (pdcp_share). If the shared traffic is greater than 0, whether it is shared (is_share) is set to 1, otherwise it is set to 0.

[0143] Based on the vector product function in step 1302, the correlation coefficient r can be obtained by assigning the MR coverage ratio (rsrpgoodratio) and whether it is shared (is_share) to the values ​​x and y respectively. In order to clearly compare the correlation, the correlation coefficients between the MR coverage ratio (rsrpgoodratio) and whether it is shared (is_share) of three indoor cells are listed in this example, as shown in FIG. Figure 15As shown in the figure, the scatter distribution of the MR coverage rate (rsrpgoodratio) and whether it is shared (is_share) in the cell (base station ID: 63352, cell ID: 50) is represented by dots, and the correlation coefficient with whether it is shared (is_share) is represented by a solid line. The absolute value of the correlation coefficient is 0, which is less than the preset threshold β5, indicating a low correlation. The scatter distribution of the MR coverage rate (rsrpgoodratio) and whether it is shared (is_share) in the cell (base station ID: 806744, cell ID: 57) is represented by triangles, and the correlation coefficient with whether it is shared (is_share) is represented by a long dashed line. The absolute value of the correlation coefficient is 0.92, which is greater than the preset threshold β5 and indicates a high correlation. Therefore, it is determined that the abnormal decline and fluctuation in the MR coverage rate of this cell is caused by the diversion of cells with the same coverage. The scatter distribution of the MR coverage rate (rsrpgoodratio) and whether it is shared (is_share) of the cell (base station ID: 825346, cell ID: 51) is represented by squares, and the correlation coefficient with whether it is shared (is_share) is represented by a short dashed line. The absolute value of the correlation coefficient is 0.86, which is greater than the preset threshold β5. The correlation is large. Therefore, it is determined that the abnormal decline and fluctuation of the MR coverage rate of the cell is caused by the diversion of cells with the same coverage room.

[0144] Step 1303, business model analysis: Based on the analysis of steps 1301 and 1302, after eliminating the fault indicators and whether the reasons are shared, a correlation analysis is performed on the cell business model. During the analysis, the vector product function in step 902 is also used to calculate the correlation between the MR coverage rate (rsrpgoodratio) and the corresponding time granularity traffic sum (pdcp_mac) of the macro cell with the same coverage as described in step 901. If the correlation coefficient r is less than or equal to the preset threshold β6, it can be determined that the abnormal fluctuation of the cell MR coverage rate is mainly due to changes in the business model. If the correlation coefficient r is greater than the preset threshold β6, it is classified as other reasons or transferred to relevant optimization personnel for manual analysis and judgment.

[0145] Based on the vector product function in step 902, the MR coverage ratio (rsrpgoodratio) and the corresponding time granularity traffic sum (pdcp_mac) of the same coverage macro cell are assigned to x and y respectively to obtain the correlation coefficient r. In order to clearly compare the correlation, this example lists the correlation coefficients between the MR coverage ratio (rsrpgoodratio) of two indoor cells and the corresponding time granularity traffic sum (pdcp_mac) of the same coverage macro cell, as shown in Figure 1. Figure 16As shown in the figure, the scatter distribution of the MR coverage rate (rsrpgoodratio) of the cell (base station ID: 862541, cell ID: 51) and the corresponding time-granularity traffic sum (pdcp_mac) of the same macro cell is represented by dots, and the correlation coefficient with the corresponding time-granularity traffic sum (pdcp_mac) of the same macro cell is represented by a solid line. The correlation coefficient is -0.07, which is greater than the preset threshold β6 and has a low correlation. The scatter distribution of the MR coverage rate (rsrpgoodratio) of the cell (base station ID: 89967, cell ID: 56) and the corresponding time-granularity traffic sum (pdcp_mac) of the same macro cell is represented by triangles, and the correlation coefficient with the corresponding time-granularity traffic sum (pdcp_mac) of the same macro cell is represented by a dotted line. The correlation coefficient is -0.72, which is less than the preset threshold β6 and has a high negative correlation. Therefore, it is determined that the abnormal decline and fluctuation of the MR coverage rate of this cell is due to changes in the service model.

[0146] Optionally, after determining the correlation coefficients between the root cause indicators and the abnormality assessment indicators in sequence according to the arrangement order of the root cause indicators, the method further includes: if there is no correlation coefficient that meets the preset conditions, determining the abnormal root cause as other reasons; if the abnormal root cause is other reasons, sending an abnormality detection report to the target object, wherein the abnormality detection report is used to prompt the target object to analyze the abnormal root cause, and the content of the abnormality detection report includes at least one of the following: the identification of the abnormal cell, the abnormality assessment indicator.

[0147] Optional, Figure 17 An overall flow chart of anomaly detection is shown in FIG. Figure 17 As shown, the method includes the following steps:

[0148] Step 1701, Data Acquisition and Preprocessing Module: Extract KPIs, engineering parameters, and MR coverage metrics from professional network management. First, organize the cell longitudes and latitudes in the engineering parameters, pre-processing for missing, redundant, or inconsistent longitudes and latitudes at the same station. Then, correlate them with KPIs and MR coverage.

[0149] Step 1702, short-term index abnormality detection module: This algorithm can quickly and preliminarily determine whether there are abnormal fluctuations in the indoor cell KPI index and MR coverage index. The algorithm divides the indoor system KPI index or MR coverage index into reference index data within the time window T1 and the index to be evaluated within the time window T2, such as Figure 7 As shown in the example. Based on this, the indicators to be evaluated within the time window T2 are calculated cyclically and the reference index within time window T1 The absolute value of the difference kpi′ ijThen the dynamic threshold KPI is calculated with the reference index in the time window T1 thr Compare, if kpi′ ij Greater than KPI thr , then the counter kpi cnt Add 1, after each round of calculation is completed, if kpi cnt Greater than the threshold number thr , indicating that the corresponding indicator has moved once, then T cnt Add 1. The indicator to be evaluated within the time window T2 and the reference index within time window T1 After the loop is completed, if T cnt The value is greater than the preset time threshold T thr , it means that the indicator to be evaluated in the time window T2 has experienced abnormal fluctuations, such as Figure 8 As shown in the figure, when i is equal to 1, 2, 3, 4, and 7, the 5-day indicators corresponding to each have a fluctuation range of 4 days greater than the dynamic threshold value KPI thr , indicating that abnormal fluctuations have occurred in the community.

[0150] Among them, T1 refers to the cycle length of the reference indicator (KPI indicator or MR coverage indicator), and the cycle in this algorithm is measured in days; T2 refers to the cycle length of the indicator to be evaluated (KPI indicator or MR coverage indicator), and the cycle in this algorithm is measured in days; It refers to the value of a certain indicator among the reference indicators within the time window T1; It refers to the value of a certain indicator in the time window T2, and The same indicator; KPI' ij means and Absolute value of the difference; KPI thr Refers to the dynamic threshold value calculated from the reference indicator data within the time window T1; KPI cnt Refers to comparing KPIs in each cycle ij and KPIs thr Time counter; number thr Refers to comparing KPIs in each cycle ij Greater than KPI thr The minimum threshold value of the number of times; T cnt Refers to the number of abnormal fluctuations of the corresponding indicator to be evaluated within the time window T2; T thr Refers to the minimum number of abnormal fluctuations of the corresponding indicator to be evaluated within the time window T2.

[0151] Step 1703, long-term month-on-month index anomaly detection module: Based on the cells and related indicators with short-term index abnormal fluctuations obtained in module 102, a time series model algorithm based on a neural network is used for fitting and prediction, and it is determined whether the actual index data is within the confidence interval. If not, and the number of abnormal fluctuations is greater than the minimum number of thr long , it will be determined as the final abnormal indicator fluctuation cell. Otherwise, the cell where the short-term abnormal indicator fluctuation is detected will not be determined as the final abnormal indicator fluctuation cell.

[0152] Step 1704, the indoor distributed system KPI abnormal fluctuation demarcation module: Based on the cells with abnormal KPI fluctuations finally determined by module 103, the KPI indicators and working parameter data of the cells with abnormal KPI fluctuations are correlated and processed. The indicator data is divided into Class I indicators and Class II indicators. Class I indicators are the abnormal fluctuation indicators to be analyzed, and Class II indicators are the root cause indicators. The correlation between Class I indicators and Class II indicators is calculated using a vector product method. Based on the strength of the correlation, the strongly correlated Class II indicators are identified as the root cause of the abnormal fluctuation of Class I indicators. Before root cause analysis, the Class II indicators are prioritized according to their impact on network performance in the live network. Correlation analysis is then performed in order. For example, the highest priority is the fault category, followed by the diversion category, and then the service model change category.

[0153] Step 1705, the indoor distributed system MR coverage abnormal fluctuation demarcation module: Based on the cells with abnormal MR coverage fluctuations finally determined by module 103, the MR coverage indicators of the cells with abnormal MR coverage fluctuations are divided into Class I indicators and Class II indicators. Class I indicators are the abnormal fluctuation indicators to be analyzed, and Class II indicators are the root cause indicators. The correlation between Class I and Class II indicators is calculated using a vector product method. Based on the strength of the correlation, the strongly correlated Class II indicators are identified as the root cause of the abnormal fluctuation of Class I indicators. Before root cause analysis, the Class II indicators are prioritized according to their impact on network performance in the live network, and then correlation analysis is performed in order. For example, the highest priority is the fault category, followed by the sharing category, and then the service model change category.

[0154] Through the above steps, based on network working parameters and KPI indicators, MR coverage and other indicator data, through short-term month-on-month indicator anomaly detection, long-term month-on-month indicator anomaly detection, vector product correlation coefficient algorithm, etc., it is possible to quickly, accurately and timely detect abnormal fluctuations in indoor distributed system indicators and locate the causes. It also solves the problems of misjudgment and missed judgment and the inability to timely discover potential abnormal fluctuations in indicators in traditional indicator monitoring. At the same time, it solves the problem that the existing technology only considers the unilateral reasons of the cell itself, thereby solving the misjudgment and incompleteness of the cause analysis results. It improves the stability of indoor distributed system indicators and user perception. The algorithm can be widely applied to mobile networks of various standards.

[0155] Based on the method embodiment of the present application, abnormal fluctuations in indicators of all indoor cells in the existing network were classified and demarcated. A total of 1,867 indoor cells were found to have abnormal fluctuations in indicators. Through correlation analysis between abnormal evaluation indicators and root cause indicators, 721 cells were identified as the root causes of abnormal fluctuations in indicators, saving 38.62% of the traditional manual analysis workload and significantly improving network optimization efficiency.

[0156]

[0157]

[0158] The advantages of the method embodiment of the present application are:

[0159] 1. Solve the problems of misjudgment and missed judgment caused by setting fixed thresholds in existing traditional indicator monitoring methods.

[0160] 2. Solve the problem of abnormal fluctuations in potential indicators that cannot be detected by existing traditional indicator monitoring methods.

[0161] 3. Solve the low efficiency problem of existing traditional indicator monitoring methods and improve network optimization efficiency.

[0162] 4. Solve the problem that the existing technical algorithm only considers the unilateral reasons of the detection cell itself when detecting abnormal fluctuations of indicators, which leads to misjudgment and incompleteness of the root cause analysis results.

[0163] 5. The algorithm of the method embodiment of the present application features low algorithmic complexity, fast operation speed, high accuracy, low cost, and high practicality. Based on network parameters, KPI indicators, MR coverage, and other indicator data, it uses short-term and long-term indicator anomaly detection, and a vector product correlation coefficient algorithm to quickly, accurately, and timely detect abnormal fluctuations in indoor distributed system indicators and identify the causes, thereby improving the stability of indoor distributed system indicators and user perception. This algorithm is widely applicable to mobile networks of various standards. The short-term indicator anomaly detection algorithm can quickly and preliminarily determine whether there are abnormal fluctuations in indoor distributed cell indicators, thereby improving the detection efficiency of indoor distributed system cells. The long-term indicator anomaly detection algorithm uses a modular, freely combinable neural network time series model algorithm to perform secondary analysis and confirmation based on the preliminary judgment results of the short-term indicator anomaly detection, thereby reducing the impact of time changes on cell wireless network performance and improving the accuracy of detecting abnormal indicator fluctuations. The vector product correlation coefficient algorithm can quickly calculate the correlation between the first and second category indicators, thereby obtaining the root cause of the abnormal indicator fluctuations and improving the efficiency of cause identification.

[0164] 6. Good applicability. The method embodiment of the present application only needs to combine the above data and call the relevant algorithm module through the program to quickly and accurately monitor the abnormal fluctuations of the indoor distribution system indicators and determine the causes, which can be better used in actual work.

[0165] The present invention provides an abnormality detection device. Figure 18 is a structural diagram of the device, such as Figure 18 As shown, the device includes: a first processing module 180, configured to determine, based on a first evaluation indicator within a first time window, whether a second evaluation indicator within a time window to be detected is an abnormal evaluation indicator, wherein the abnormal evaluation indicator is a second evaluation indicator whose difference with the first evaluation indicator satisfies a preset rule, and the time interval corresponding to the first time window is before the time interval corresponding to the time window to be detected; a second processing module 182, configured to, if the second evaluation indicator is determined to be an abnormal evaluation indicator, predict a confidence interval of the abnormal evaluation indicator based on a third evaluation indicator within the second time window, wherein the time interval corresponding to the second time window is before the time interval corresponding to the time window to be detected, the length of the second time window is longer than the first time window, and the third evaluation indicator and the abnormal evaluation indicator are of the same type; a third processing module 184, configured to determine, based on whether the abnormal evaluation indicator is within the confidence interval, whether a cell corresponding to the abnormal evaluation indicator is abnormal; and a fourth processing module 186, configured to, if the cell is determined to be abnormal, determine a root cause of the abnormality based on a correlation coefficient between the abnormal evaluation indicator and a root cause indicator, wherein the root cause indicator has a one-to-one correspondence with a root cause in a preset root cause set.

[0166] In some embodiments of the present application, the first time window includes a first preset number of first evaluation indicator value points, and the time window to be detected includes a second preset number of second evaluation indicator value points. The first processing module 180 determines whether the second evaluation indicator in the time window to be detected is an abnormal evaluation indicator based on the first evaluation indicator in the first time window, including: determining the difference between the value of the first evaluation indicator value point in the first time window and the value of each second evaluation indicator value point in the time window to be detected; counting the first number of times that the absolute value of the difference corresponding to the first evaluation indicator value point is greater than the first preset threshold; counting the second number of times that the first number is greater than the second preset threshold; and when the second number is greater than the third threshold, determining that the second evaluation indicator in the time window to be detected is an abnormal evaluation indicator.

[0167] In some embodiments of the present application, the second processing module 182 predicts the confidence interval of the abnormal evaluation index based on the third evaluation index in the second time window, including: constructing an evaluation index prediction model based on the numerical value of the third evaluation index in the second time window; determining the indicator prediction value of the second evaluation index at each value point in the time window to be detected based on the indicator prediction model; increasing the indicator prediction value corresponding to the value point by a preset upper limit value, as the upper limit value of the confidence interval corresponding to the value point; reducing the indicator prediction value corresponding to the value point by a preset lower limit value, as the lower limit value of the confidence interval corresponding to the value point.

[0168] In some embodiments of the present application, the third processing module 184 determines whether the cell corresponding to the abnormality assessment indicator is abnormal based on whether the abnormality assessment indicator is in the confidence interval, including: the value of the statistical abnormality assessment indicator is not in the third number of the corresponding confidence interval; when the third number is greater than the fourth threshold, determining that the cell is abnormal.

[0169] In some embodiments of the present application, the type of abnormality assessment indicator includes at least one of the following: key performance indicators and measurement report indicators. When determining that a cell is abnormal, the fourth processing module 186 determines the root cause of the abnormality based on the correlation coefficient between the abnormality assessment indicator and the root cause indicator, including: determining a preset root cause set based on the type of the abnormality assessment indicator, and arranging the root cause indicators in the preset root cause set according to a preset order; determining the correlation coefficient between the root cause indicator and the abnormality assessment indicator in sequence according to the arrangement order of the root cause indicators; when the correlation coefficient meets a preset condition, determining the root cause indicator corresponding to the correlation coefficient as the abnormal root cause indicator; and determining the root cause corresponding to the abnormal root cause indicator as the abnormal root cause.

[0170] In some embodiments of the present application, the fourth processing module 186 determines the root cause corresponding to the abnormal root cause indicator as the abnormal root cause, including: when the abnormal root cause indicator is the cell availability rate, determining that the abnormal root cause is a cell failure itself; when the abnormal root cause indicator is the sum of the traffic of other indoor cells with the same coverage, determining that the abnormal root cause is the diversion of indoor cells with the same coverage; when the abnormal root cause indicator is the sum of the traffic of macro cells with the same coverage, determining that the abnormal root cause is a change in the business model.

[0171] In some embodiments of the present application, after determining the correlation coefficients between the root cause indicators and the abnormality assessment indicators in sequence according to the arrangement order of the root cause indicators, the fourth processing module 186 is also used to: if there is no correlation coefficient that meets the preset conditions, determine the root cause of the abnormality as other reasons; if the root cause of the abnormality is other reasons, send an abnormality detection report to the target object, wherein the abnormality detection report is used to prompt the target object to analyze the root cause of the abnormality, and the content of the abnormality detection report includes at least one of the following: the identification of the abnormal cell, the abnormality assessment indicator.

[0172] It should be noted that the various modules in the above-mentioned abnormality detection device can be program modules (for example, a set of program instructions that implement a certain specific function) or hardware modules. For the latter, it can be expressed in the following forms, but is not limited to this: the expression form of each of the above-mentioned modules is a processor, or the functions of each of the above-mentioned modules are implemented by a processor.

[0173] An embodiment of the present application provides a non-volatile storage medium having a program stored therein, wherein when the program is executed, a device containing the non-volatile storage medium is controlled to execute the following anomaly detection method: determining, based on a first evaluation indicator within a first time window, whether a second evaluation indicator within a time window to be detected is an anomaly evaluation indicator, wherein the anomaly evaluation indicator is a second evaluation indicator whose difference with the first evaluation indicator satisfies a preset rule, and a time interval corresponding to the first time window is before a time interval corresponding to the time window to be detected; if the second evaluation indicator is determined to be an anomaly evaluation indicator, predicting a confidence interval of the anomaly evaluation indicator based on a third evaluation indicator within the second time window, wherein the time interval corresponding to the second time window is before a time interval corresponding to the time window to be detected, the length of the second time window is longer than the first time window, and the third evaluation indicator and the anomaly evaluation indicator are of the same type; determining, based on whether the anomaly evaluation indicator is within the confidence interval, whether a cell corresponding to the anomaly evaluation indicator is abnormal; and if the cell is determined to be abnormal, determining a root cause of the anomaly based on a correlation coefficient between the anomaly evaluation indicator and a root cause indicator, wherein the root cause indicator has a one-to-one correspondence with a root cause in a preset root cause set.

[0174] An embodiment of the present application provides an electronic device, comprising: a memory and a processor, the processor being configured to run a program stored in the memory, wherein the program executes the following anomaly detection method when running: determining, based on a first evaluation indicator within a first time window, whether a second evaluation indicator within a time window to be detected is an anomaly evaluation indicator, wherein the anomaly evaluation indicator is a second evaluation indicator whose difference with the first evaluation indicator satisfies a preset rule, and a time interval corresponding to the first time window is before a time interval corresponding to the time window to be detected; if the second evaluation indicator is determined to be an anomaly evaluation indicator, predicting a confidence interval of the anomaly evaluation indicator based on a third evaluation indicator within the second time window, wherein the time interval corresponding to the second time window is before a time interval corresponding to the time window to be detected, the length of the second time window is longer than the first time window, and the third evaluation indicator and the anomaly evaluation indicator are of the same type; determining, based on whether the anomaly evaluation indicator is within the confidence interval, whether a cell corresponding to the anomaly evaluation indicator is abnormal; and if the cell is determined to be abnormal, determining a root cause of the anomaly based on a correlation coefficient between the anomaly evaluation indicator and a root cause indicator, wherein the root cause indicator has a one-to-one correspondence with a root cause in a preset root cause set.

[0175] An embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the following anomaly detection method: determining, based on a first evaluation indicator within a first time window, whether a second evaluation indicator within a time window to be detected is an anomaly evaluation indicator, wherein the anomaly evaluation indicator is a second evaluation indicator whose difference with the first evaluation indicator satisfies a preset rule, and a time interval corresponding to the first time window is before a time interval corresponding to the time window to be detected; if the second evaluation indicator is determined to be an anomaly evaluation indicator, predicting a confidence interval of the anomaly evaluation indicator based on a third evaluation indicator within the second time window, wherein the time interval corresponding to the second time window is before a time interval corresponding to the time window to be detected, the length of the second time window is longer than the first time window, and the third evaluation indicator and the anomaly evaluation indicator are of the same type; determining, based on whether the anomaly evaluation indicator is within the confidence interval, whether a cell corresponding to the anomaly evaluation indicator is abnormal; if the cell is determined to be abnormal, determining a root cause of the anomaly based on a correlation coefficient between the anomaly evaluation indicator and a root cause indicator, wherein the root cause indicator has a one-to-one correspondence with a root cause in a preset root cause set.

[0176] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.

[0177] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0178] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0179] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0180] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the relevant technology or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0181] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A method for detecting anomalies, characterized in that: include: Determining, based on a first evaluation indicator within a first time window, whether a second evaluation indicator within a time window to be detected is an abnormality evaluation indicator, wherein the abnormality evaluation indicator is the second evaluation indicator whose difference with the first evaluation indicator satisfies a preset rule, and a time interval corresponding to the first time window is before a time interval corresponding to the time window to be detected; When it is determined that the second evaluation indicator is an abnormality evaluation indicator, predicting a confidence interval of the abnormality evaluation indicator based on a third evaluation indicator within a second time window, wherein a time interval corresponding to the second time window is before a time interval corresponding to the time window to be detected, a length of the second time window is longer than that of the first time window, and the third evaluation indicator and the abnormality evaluation indicator are evaluation indicators of the same type; Determining whether a cell corresponding to the abnormality assessment indicator is abnormal based on whether the abnormality assessment indicator is within the confidence interval; When the cell is determined to be abnormal, a root cause of the abnormality is determined according to a correlation coefficient between the abnormality assessment index and a root cause index, wherein the root cause index corresponds one-to-one to a root cause in a preset root cause set.

2. The anomaly detection method according to claim 1, wherein: The first time window includes a first preset number of first evaluation indicator value points, the time window to be detected includes a second preset number of second evaluation indicator value points, and determining whether the second evaluation indicator in the time window to be detected is an abnormal evaluation indicator based on the first evaluation indicator in the first time window includes: Determine the difference between the value of the first evaluation index value point in the first time window and the value of each second evaluation index value point in the time window to be detected; Counting a first number of times that the absolute value of the difference corresponding to the first evaluation indicator value point is greater than a first preset threshold; Counting a second number of times that the first number is greater than a second preset threshold; When the second number of times is greater than a third threshold, the second evaluation indicator within the time window to be detected is determined to be the abnormality evaluation indicator.

3. The anomaly detection method according to claim 1, wherein: Predicting the confidence interval of the abnormality evaluation indicator based on the third evaluation indicator in the second time window includes: Constructing an evaluation index prediction model according to the value of the third evaluation index within the second time window; Determining the indicator prediction value of the second evaluation indicator at each value point in the time window to be detected according to the indicator prediction model; The predicted value of the indicator corresponding to the value point is increased by the preset upper limit value as the upper limit value of the confidence interval corresponding to the value point The indicator prediction value corresponding to the value point is reduced by a preset lower limit value as the lower limit value of the confidence interval corresponding to the value point.

4. The anomaly detection method according to claim 1, wherein: Determining whether the cell corresponding to the abnormality assessment indicator is abnormal according to whether the abnormality assessment indicator is within the confidence interval includes: Count the third times that the value of the abnormality assessment indicator is not within the corresponding confidence interval; When the third number is greater than a fourth threshold, it is determined that the cell is abnormal.

5. The anomaly detection method according to claim 1, wherein: The type of the abnormality assessment indicator includes at least one of the following: a key performance indicator and a measurement report indicator; when the cell is determined to be abnormal, determining the abnormality root cause based on the correlation coefficient between the abnormality assessment indicator and the root cause indicator includes: Determining a preset root cause set according to the type of the abnormality assessment indicator, wherein the root cause indicators in the preset root cause set are arranged according to a preset order; Determining the correlation coefficients between the root cause indicators and the abnormality assessment indicators in sequence according to the arrangement order of the root cause indicators; When the correlation coefficient meets a preset condition, determining the root cause indicator corresponding to the correlation coefficient as an abnormal root cause indicator; The root cause corresponding to the abnormal root cause indicator is determined as the abnormal root cause.

6. The anomaly detection method according to claim 5, characterized in that: Determining the root cause corresponding to the abnormal root cause indicator as the abnormal root cause includes: When the abnormal root cause indicator is the cell availability rate, determining that the abnormal root cause is a cell fault; When the abnormal root cause indicator is the sum of the traffic of other indoor cells with the same coverage, determining that the abnormal root cause is the traffic diversion of indoor cells with the same coverage; When the abnormal root cause indicator is the sum of traffic of the macro cell with the same coverage, it is determined that the abnormal root cause is a change in the service model.

7. The anomaly detection method according to claim 5, characterized in that: After determining the correlation coefficients between the root cause indicators and the abnormality assessment indicators in sequence according to the arrangement order of the root cause indicators, the method further includes: If the correlation coefficient does not satisfy the preset condition, determining the abnormal root cause as other reasons; In the case where the abnormality root cause is other reasons, an abnormality detection report is sent to the target object, wherein the abnormality detection report is used to prompt the target object to analyze the abnormality root cause, and the content of the abnormality detection report includes at least one of the following: the identifier of the abnormal cell, and the abnormality evaluation index.

8. An abnormality detection device, characterized in that: include: A first processing module is configured to determine, based on a first evaluation indicator within a first time window, whether a second evaluation indicator within a time window to be detected is an abnormal evaluation indicator, wherein the abnormal evaluation indicator is the second evaluation indicator whose difference with the first evaluation indicator satisfies a preset rule, and a time interval corresponding to the first time window is before a time interval corresponding to the time window to be detected; a second processing module, configured to, when determining that the second evaluation indicator is an abnormality evaluation indicator, predict a confidence interval of the abnormality evaluation indicator based on a third evaluation indicator within a second time window, wherein a time interval corresponding to the second time window is before a time interval corresponding to the time window to be detected, a length of the second time window is longer than that of the first time window, and the third evaluation indicator and the abnormality evaluation indicator are of the same type of evaluation indicators; A third processing module is configured to determine whether the cell corresponding to the abnormality assessment indicator is abnormal based on whether the abnormality assessment indicator is within the confidence interval; The fourth processing module is configured to determine the root cause of the abnormality according to the correlation coefficient between the abnormality assessment index and the root cause index when the cell is determined to be abnormal, wherein the root cause index corresponds one-to-one to the root cause in the preset root cause set.

9. A non-volatile storage medium, characterized in that: The non-volatile storage medium stores a program, wherein when the program is running, the device where the non-volatile storage medium is located is controlled to execute the abnormality detection method according to any one of claims 1 to 7.

10. An electronic device, characterized in that: include: A memory and a processor, wherein the processor is configured to run a program stored in the memory, wherein the abnormality detection method according to any one of claims 1 to 7 is executed when the program is run.

11. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the abnormality detection method according to any one of claims 1 to 7 is implemented.