A power distribution communication network fault locating method, device, equipment and medium
By identifying and analyzing alarm data streams, a time-series causal reasoning model is constructed to determine the root cause alarms in cascading faults, thereby improving the accuracy and efficiency of fault location in power distribution communication networks and solving the problem of alarm overwhelming in complex fault environments.
Patent Information
- Application Number
- CN202511270915.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-08
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2045-09-08
AI Technical Summary
Existing power distribution communication networks struggle to effectively cope with surges in alarm numbers and time-sequence disruptions under complex fault environments, resulting in root cause alarms being overwhelmed by a large amount of redundant information and a decrease in the accuracy of fault location.
By acquiring alarm data streams, identifying cascading fault clusters, constructing a time-series causal reasoning model, determining root cause alarms and secondary alarms, and combining alarm data characteristics with historical data matching reliability, fault location points are identified.
It improves the accuracy and efficiency of fault location, enables rapid identification of the root cause of the fault, and supports rapid fault recovery.
Smart Images

Figure CN120811877B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of fault location, in particular to a power distribution communication network fault location method, device, equipment and medium. BACKGROUND
[0002] The stable operation of communication networks is crucial to modern society, and this goal is achieved by efficient fault management technology, in which intelligent aggregation of alarm information and root cause analysis are the core means to ensure network reliability. With the continuous expansion of network size and the significant improvement of device interconnection, the chain reaction of faults is becoming more and more common, especially in alarm storms, and traditional methods are difficult to effectively cope with. In a complex fault environment, the existing fault location technology of power distribution communication networks is difficult to adapt to the dynamic environment of the surge in the number of alarms and the chaos of time sequence, resulting in the root alarm being overwhelmed by a large amount of redundant information, and the accuracy of fault location is greatly reduced. SUMMARY
[0003] To solve the above technical problems, the present application provides a power distribution communication network fault location method, device, equipment and medium, which effectively improves the efficiency and accuracy of fault location in a complex fault environment.
[0004] The embodiment of the present application provides a power distribution communication network fault location method, comprising:
[0005] Obtain the alarm data stream of the power distribution communication network, and identify the chain fault cluster based on the alarm data stream;
[0006] According to the chain fault cluster, a time sequence causal reasoning model is constructed to determine the root alarm and secondary alarm in the chain fault;
[0007] According to the alarm data corresponding to the root alarm, the fault location point candidate set is obtained by identifying the fault location point;
[0008] Based on the fault location point candidate set, according to the matching confidence of the alarm data and the historical alarm data corresponding to the location point, the final fault location point is determined.
[0009] As an improvement of the above scheme, the chain fault cluster is identified based on the alarm data stream, comprising:
[0010] Extract the alarm trigger record from the alarm data stream to obtain the alarm trigger sequence and the alarm trigger time;
[0011] According to the alarm trigger sequence and the alarm trigger time, the clustering algorithm is used to group the alarms to obtain the chain fault cluster and the independent fault cluster.
[0012] As an improvement of the above scheme, the step of constructing a time-causal reasoning model according to the cascading failure cluster, and determining the root alarm and the secondary alarm in the cascading failure, comprises:
[0013] calculating the conditional probability between the alarms for the cascading failure cluster;
[0014] adopting a Bayesian network to construct a time-causal reasoning model, taking the alarm type as a node, the conditional dependency relationship between the alarms as an edge, and the conditional probability between the alarms as an edge weight;
[0015] generating a causal relationship mapping table based on the time-causal reasoning model, and determining the root alarm and the secondary alarm in the cascading failure.
[0016] As an improvement of the above scheme, the step of identifying the fault location according to the alarm data corresponding to the root alarm to obtain a candidate set of fault positioning points comprises:
[0017] obtaining the alarm data according to a preset sliding window and an alarm detection frequency, and filtering the secondary alarms in the alarm data according to a preset alarm convergence rule to obtain the alarm data corresponding to the root alarm; the alarm convergence rule comprises but is not limited to a time window length of alarm detection, an association rule between different alarm types, and a time interval tolerance between alarms;
[0018] extracting the features of the alarm data corresponding to the root alarm to obtain the alarm type, the alarm parameter, and the network element device corresponding to each alarm;
[0019] adopting a Bayesian network algorithm to construct the probability dependency relationship between the alarm type, the alarm parameter, the network element device, and the potential fault location;
[0020] determining the association strength between the alarm type and the potential fault location, the first correlation between the alarm parameter and the potential fault location, and the second correlation between the network element device and the potential fault location according to the probability dependency relationship;
[0021] selecting a plurality of potential fault locations with the largest association strength between the alarm type and the potential fault location from the potential fault locations to obtain an initial set;
[0022] selecting the potential fault locations with the first correlation and the second correlation greater than a preset threshold from the initial set to obtain a candidate set of fault positioning points.
[0023] As an improvement of the above scheme, the alarm detection frequency is dynamically adjusted according to the change trend of the alarm amount, and the specific steps of dynamic adjustment comprise:
[0024] The alarm quantity in a preset historical time is counted to obtain a statistical result, and an alarm quantity threshold is determined according to the statistical result; if the alarm quantity in a current window is greater than the alarm quantity threshold, it is determined that the current alarm quantity is surging;
[0025] When it is determined that the current alarm quantity is surging, the alarm detection frequency is adjusted according to the duration of the surging of the alarm quantity and the amplitude at which the alarm quantity exceeds the alarm quantity threshold; the alarm detection frequency is positively correlated with the duration and the amplitude.
[0026] As an improvement of the above scheme, the final fault locating point is determined based on the candidate set of fault locating points according to the matching confidence of the alarm data corresponding to the locating point and the historical alarm data, comprising:
[0027] The historical fault mode is extracted from the historical cascading failure cluster;
[0028] For each locating point in the candidate set of fault locating points, the fault mode is extracted from the cascading failure cluster corresponding to the locating point, the feature similarity of the alarm data corresponding to the fault mode and the historical fault mode is calculated, and the matching confidence of the locating point is obtained; wherein the features in the feature similarity include the time interval, frequency, sequence and device type of the alarm;
[0029] The locating points with the matching confidence greater than the preset confidence threshold are filtered out from the candidate set of fault locating points to obtain the final fault locating point.
[0030] The embodiment of the application also provides a power distribution communication network fault locating device, comprising:
[0031] A cascading failure module is configured to acquire alarm data flow of a power distribution communication network, and identify a cascading failure cluster based on the alarm data flow;
[0032] A root alarm module is configured to construct a time sequence causal reasoning model according to the cascading failure cluster, and determine a root alarm and a secondary alarm in the cascading failure;
[0033] A candidate fault point module is configured to identify a fault location according to alarm data corresponding to the root alarm to obtain a candidate set of fault locating points;
[0034] A fault point locating module is configured to determine a final fault locating point based on the candidate set of fault locating points according to the matching confidence of alarm data corresponding to the locating point and historical alarm data.
[0035] Further, the root alarm module is specifically configured to:
[0036] The conditional probability between alarms is calculated for the cascading failure cluster;
[0037] adopting a Bayesian network, taking an alarm type as a node, taking a conditional dependency relationship between alarms as an edge, and taking a conditional probability between the alarms as an edge weight to construct a time-series causal reasoning model;
[0038] generating a causal relationship mapping table based on the time-series causal reasoning model to determine a root alarm and a secondary alarm in a cascading failure.
[0039] The embodiment of the present application also provides a computer device, including a processor and a memory, the memory has a computer program stored therein, and the computer program is configured to be executed by the processor, and the processor implements the power distribution communication network fault positioning method according to any one of the above when executing the computer program.
[0040] The embodiment of the present application also provides a computer readable storage medium, the computer readable storage medium stores a computer program, wherein the computer readable storage medium controls a device where the computer readable storage medium is located to execute the power distribution communication network fault positioning method according to any one of the above when the computer program runs.
[0041] Compared with the prior art, the power distribution communication network fault positioning method, device, equipment and medium provided by the embodiment of the present application have the beneficial effects that: the cascading failure cluster is identified based on the alarm data stream, the time-series causal reasoning model is constructed according to the cascading failure cluster, the root alarm and the secondary alarm in the cascading failure are determined, the fault root cause can be quickly and accurately identified, and the accuracy and efficiency of the power distribution communication network fault positioning are improved; the fault location identification is performed according to the alarm data corresponding to the root alarm to obtain a candidate set of fault positioning points, the final fault positioning point is determined based on the candidate set of fault positioning points according to the matching confidence of the alarm data corresponding to the positioning point and the historical alarm data, and the efficiency and accuracy of the fault positioning are further improved, which provides support for rapid fault recovery. BRIEF DESCRIPTION OF DRAWINGS
[0042] Figure 1 is a flow schematic diagram of the power distribution communication network fault positioning method provided by the embodiment of the present application;
[0043] Figure 2 is a structural schematic diagram of the power distribution communication network fault positioning device provided by the embodiment of the present application;
[0044] Figure 3 is a structural schematic diagram of the computer device provided by the embodiment of the present application. DETAILED DESCRIPTION
[0045] With reference to the drawings of the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described, obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all the other embodiments obtained by those skilled in the art without creative work belong to the protection scope of the present application.
[0046] Please refer to Figure 1 , Figure 1 is a flow diagram of a power distribution communication network fault locating method provided by an embodiment of the present application. The power distribution communication network fault locating method comprises:
[0047] S1: obtaining alarm data stream of a power distribution communication network, and identifying a cascading failure cluster based on the alarm data stream;
[0048] As one of the optional embodiments, the identifying a cascading failure cluster based on the alarm data stream comprises:
[0049] extracting alarm trigger records from the alarm data stream to obtain alarm trigger sequence and alarm trigger time;
[0050] According to the alarm trigger sequence and the alarm trigger time, a clustering algorithm is used to group alarms to obtain a cascading failure cluster and an independent failure cluster.
[0051] Specifically, in a power distribution network, real-time data collected from a substation is transmitted to a monitoring center through a communication network, wherein the data stream includes alarm signals such as overload alarm, short circuit alarm, etc. After obtaining a period of alarm data stream, alarm trigger records can be extracted from the alarm data stream to obtain alarm trigger sequence and alarm trigger time through the time stamp in the records. According to the alarm trigger sequence and the alarm trigger time, clustering grouping is performed according to alarm types and time intervals between alarms, and the alarms are divided into a cascading failure cluster and an independent failure cluster. The clustering algorithm can specifically use K-means or DBSCAN clustering algorithm.
[0052] The clustering process is determined according to the time interval between alarms and its change mode. Alarms with similar time sequence characteristics will be clustered into a cluster. These characteristics include consistency of time interval, stability of trigger sequence, similarity of fluctuation degree, and potential periodicity or trend characteristics. Specifically, if the average time interval between a group of alarms is relatively fixed and this pattern repeatedly occurs, it indicates that they belong to the same cascading failure event, for example, if "overload" always occurs within 5 seconds before "short circuit", it can be determined that the failure mode is "overload-short circuit", which is a cascading failure.
[0053] S2: constructing a time-causal reasoning model according to the cascading failure cluster to determine the root alarm and the secondary alarm in the cascading failure;
[0054] As one of the optional embodiments, the step of constructing a time-causal reasoning model according to the cascading failure cluster to determine the root alarm and the secondary alarm in the cascading failure includes:
[0055] calculating the conditional probability between the alarms for the cascading failure cluster;
[0056] adopting a Bayesian network to construct a time-causal reasoning model, taking the alarm type as a node, the conditional dependency relationship between the alarms as an edge, and the conditional probability between the alarms as an edge weight;
[0057] generating a causal relationship mapping table based on the time-causal reasoning model to determine the root alarm and the secondary alarm in the cascading failure.
[0058] Specifically, the cascading failure cluster includes several groups of cascading failures. In order to determine the root alarm and the secondary alarm in each cascading failure, a time-causal reasoning model is constructed according to the alarm data, the conditional dependency relationship between the alarms is analyzed, and the root alarm and the secondary alarm are identified.
[0059] The time-causal reasoning model is specifically constructed by using a Bayesian network. First, for the cascading failure cluster, the alarm data is divided into an ordered alarm sequence according to the alarm trigger sequence and the time interval. The joint probability of each pair of alarms A and B occurring simultaneously is calculated based on the alarm sequence. Then, the conditional probability of alarm B occurring under the condition that alarm A occurs is calculated based on the joint probability. The probability can be obtained by counting the number of occurrences of the alarm in the alarm sequence, and the conditional probability can be updated according to the update of the alarm data. Further, the Bayesian network is applied, and the calculated conditional probability is used as the edge weight to represent the dependency relationship between the alarm nodes in the Bayesian network, wherein each node represents an alarm type, and the edge represents the conditional dependency relationship between the alarms. With the continuous accumulation of new alarm data, the time-causal reasoning model is retrained and updated regularly to adapt to new failure modes and changing network environments. Illustratively, when alarm A has a high conditional probability with respect to alarm B, it means that under the condition that A occurs, B has a high probability of occurring, which indicates that A may be the root alarm of B.
[0060] Further, a causal relationship mapping table of the alarms can be generated according to the time-causal reasoning model, which quantifies the causal relationship strength between the alarms. By analyzing the causal relationship mapping table, the root alarm and the secondary alarm in the cascading failure can be determined, which is beneficial to locking the fault positioning point.
[0061] S3: performing fault location identification according to the alarm data corresponding to the root alarm to obtain a fault positioning point candidate set;
[0062] As one of the optional embodiments, the fault location identification according to the alarm data corresponding to the root alarm comprises:
[0063] The alarm data corresponding to the root alarm is obtained by acquiring alarm data according to a preset sliding window and alarm detection frequency, and filtering secondary alarms in the alarm data according to a preset alarm convergence rule; the alarm convergence rule includes but is not limited to a time window length of alarm detection, an association rule between different alarm types, and a time interval tolerance between alarms.
[0064] Features of the alarm data corresponding to the root alarm are extracted to obtain an alarm type, an alarm parameter, and a network element device corresponding to each alarm.
[0065] A Bayesian network algorithm is used to construct a probability dependency relationship between the alarm type, the alarm parameter, the network element device, and a potential fault location.
[0066] According to the probability dependency relationship, an association strength between the alarm type and the potential fault location, a first correlation between the alarm parameter and the potential fault location, and a second correlation between the network element device and the potential fault location are determined.
[0067] A number of potential fault locations with the largest association strength between the alarm type and the potential fault location are screened out to obtain an initial set.
[0068] Potential fault locations with the first correlation and the second correlation greater than a preset threshold are selected from the initial set to obtain a candidate set of fault locating points.
[0069] Specifically, real-time alarm data is obtained by using a sliding window at a certain detection frequency, and then secondary alarms are filtered according to a preset alarm convergence rule to obtain alarm data corresponding to a root cause alarm, wherein the alarm convergence rule is obtained according to the time sequence causal reasoning model constructed in step S2, and the secondary alarms and the root cause alarm in the alarm data can be determined according to the alarm convergence rule, and then the root cause alarm in the current alarm detection data is screened. Further, the features of the alarm data corresponding to the root cause alarm are extracted, including the alarm type, the alarm parameter and the network element device generating the alarm. For example, the alarm type of a certain alarm is "signal interruption", the alarm parameter is "signal strength 75 dBm", and the network element device is "base station A". According to the extracted alarm type, alarm parameter and network element device, a Bayesian network is used to construct the probability dependency relationship between these features and the potential fault location. For example, the probability dependency relationship shows that the "signal interruption" alarm has an 80% probability of being related to "hardware failure of base station A", and "signal strength lower than -70 dBm" has a 60% probability of pointing to "antenna problem". According to the probability dependency relationship, the potential relationship between the alarm type and the fault location can be determined.
[0070] Further, the correlation strength between the alarm type and the potential fault location is determined according to these probability dependency relationships, and a correlation strength ranking is obtained. The top several potential fault locations with the highest correlation strength are screened out according to the correlation strength ranking, and the potential fault locations with high correlation to the alarm parameter and the network element device are further screened out to obtain a fault location candidate set. The fault location candidate set can screen out fault locations with high priority, which is conducive to quickly focusing on the main problem source.
[0071] As one of the optional embodiments, the alarm detection frequency is dynamically adjusted according to the change trend of the alarm quantity, and the specific steps of dynamic adjustment include:
[0072] The alarm quantity in a preset historical time is counted to obtain a statistical result, and an alarm quantity threshold is determined according to the statistical result. If the alarm quantity in the current window is greater than the alarm quantity threshold, it is determined that the current alarm quantity has increased sharply.
[0073] When it is determined that the current alarm quantity has increased sharply, the alarm detection frequency is adjusted according to the duration of the alarm quantity increase and the amplitude of the alarm quantity exceeding the alarm quantity threshold. The alarm detection frequency is positively correlated with the duration and the amplitude.
[0074] Specifically, during the alarm detection process, the detection frequency is adjusted according to the change trend of the alarm quantity. For example, when the alarm quantity significantly increases within a continuous number of hours, the original detection frequency of once per hour is adjusted to detection once every 15 minutes to adapt to the change of the alarm quantity.
[0075] When analyzing the change trend of the alarm quantity, it is necessary to determine whether the current alarm quantity is in a surge state. Specifically, the mean value and the standard deviation of the alarm quantity are calculated through a sliding window to determine the boundary threshold of the alarm quantity surge (i.e., the alarm quantity threshold described above). Exemplarily, the boundary threshold can be obtained by calculating the sum of the mean value and 2 times the standard deviation. When the alarm quantity in the current window is greater than the set boundary threshold, it is determined that the current alarm quantity is surging. For example, the mean value is 100 times and the standard deviation is 20 times according to the alarm quantity statistics of the previous 7 days, and the boundary threshold is 140 times. If it is detected that the alarm quantity of the current window is greater than 140 times, it is considered that the current alarm quantity is surging. It should be noted that the alarm quantity threshold is determined by the alarm quantity in the preset historical time, and the threshold is dynamically adjusted with the data.
[0076] Further, according to the duration and amplitude of the alarm quantity surge, the detection frequency is dynamically updated. The longer the duration, the higher the detection frequency, and the greater the amplitude of the alarm quantity surge, the higher the detection frequency. For example, if the alarm quantity exceeds 140 times for 3 hours in a row, the detection frequency is adjusted from once per hour to once every 15 minutes, so as to respond to the abnormality more timely and improve the sensitivity of the system. Similarly, when the alarm quantity decreases, the detection frequency is correspondingly reduced.
[0077] In an optional embodiment, the alarm distribution characteristics are analyzed according to the alarm data to obtain the alarm concentration degree, and then the detection frequency of a device whose alarm concentration degree is greater than a preset threshold is improved, so as to concentrate the computing resources on the key devices, thereby improving the efficiency and avoiding resource waste.
[0078] S4: determining a final fault locating point based on the candidate set of fault locating points according to the matching confidence of the alarm data corresponding to the locating point and the historical alarm data.
[0079] As one of the optional embodiments, the determination of the final fault locating point based on the candidate set of fault locating points according to the matching confidence of the alarm data corresponding to the locating point and the historical alarm data includes:
[0080] The historical fault mode is extracted from the historical cascading failure cluster;
[0081] For each locating point in the candidate set of fault locating points, the fault mode is extracted from the cascading failure cluster corresponding to the locating point, the feature similarity of the alarm data corresponding to the fault mode and the historical fault mode is calculated, and the matching confidence of the locating point is obtained. The features in the feature similarity include the time interval, frequency, sequence and device type of the alarm;
[0082] The locating points with the matching confidence greater than a preset confidence threshold are filtered out from the candidate set of fault locating points to obtain the final fault locating point.
[0083] Specifically, for a candidate set of fault locating points, a fault mode is extracted from alarm data corresponding to each fault locating point, a matching confidence is obtained by matching the fault mode corresponding to the current alarm with the fault mode corresponding to the historical alarm, and a final fault locating point is obtained by selecting a fault locating point with a high matching confidence, thereby effectively improving the accuracy of fault locating. The matching confidence is obtained by calculating the feature similarity of the alarm data, that is, by calculating the similarity of the alarm time interval, frequency, sequence and device type of the current alarm and the historical alarm.
[0084] The extraction process of the fault mode includes: extracting feature data such as the time interval, frequency, sequence and device type of the alarm from the alarm data, and preliminarily screening the feature data according to a preset rule or threshold to remove noise and irrelevant alarm information; then, a similarity measurement standard is defined according to the alarm feature data, and a suitable clustering algorithm is selected to classify alarms with similar features into a class; for each clustering result, the time sequence characteristics, common occurrence frequency and their mutual relationship of the alarms therein are analyzed to obtain the fault mode of the alarms in this class, for example, the alarms in a certain cluster result are always accompanied by a specific type of device problem or a certain specific behavior mode.
[0085] The embodiment of the present application can quickly and accurately identify the root cause of the fault by identifying the cascading failure cluster based on the alarm data stream and determining the root alarm and the secondary alarm in the cascading failure according to the cascading failure cluster, thereby improving the accuracy and efficiency of fault locating of the power distribution communication network; the efficiency and accuracy of fault locating are further improved by identifying the candidate set of fault locating points according to the alarm data corresponding to the root alarm, and determining the final fault locating point based on the candidate set of fault locating points and the matching confidence of the alarm data corresponding to the locating point and the historical alarm data, thereby providing support for rapid fault recovery.
[0086] Correspondingly, the present application also provides a power distribution communication network fault locating device capable of realizing all processes of the power distribution communication network fault locating method in the above-mentioned embodiments.
[0087] Please refer to Figure 2 , Figure 2 is a structural schematic diagram of a power distribution communication network fault locating device provided by the embodiment of the present application. The power distribution communication network fault locating device comprises:
[0088] The cascading failure module 201 is configured to obtain an alarm data stream of the power distribution communication network, and identify a cascading failure cluster based on the alarm data stream;
[0089] The root alarm module 202 is configured to construct a time-causal reasoning model according to the cascading failure cluster, and determine a root alarm and a secondary alarm in the cascading failure.
[0090] The candidate fault point module 203 is configured to perform fault location identification on alarm data corresponding to the root alarm, and obtain a candidate set of fault positioning points.
[0091] The fault point positioning module 204 is configured to determine a final fault positioning point based on the candidate set of fault positioning points, and according to matching confidence of alarm data corresponding to a positioning point and historical alarm data.
[0092] Preferably, the cascading failure module 201 is specifically configured to:
[0093] extract alarm trigger records from the alarm data stream to obtain an alarm trigger sequence and an alarm trigger time;
[0094] group alarms by using a clustering algorithm according to the alarm trigger sequence and the alarm trigger time, to obtain a cascading failure cluster and an independent failure cluster.
[0095] Preferably, the root alarm module 202 is specifically configured to:
[0096] calculate a conditional probability between alarms for the cascading failure cluster;
[0097] construct a time-causal reasoning model by using a Bayesian network, taking alarm types as nodes, taking conditional dependency relationships between alarms as edges, and taking the conditional probability between the alarms as edge weights;
[0098] generate a causal relationship mapping table based on the time-causal reasoning model, and determine a root alarm and a secondary alarm in the cascading failure.
[0099] Preferably, the candidate fault point module 203 is specifically configured to:
[0100] obtain alarm data according to a preset sliding window and an alarm detection frequency, and filter secondary alarms in the alarm data according to a preset alarm convergence rule to obtain alarm data corresponding to the root alarm; the alarm convergence rule includes but is not limited to a time window length of alarm detection, an association rule between different alarm types, and a time interval tolerance between alarms;
[0101] extract features of the alarm data corresponding to the root alarm to obtain an alarm type, an alarm parameter, and a network element device corresponding to each alarm;
[0102] construct a probabilistic dependency relationship between the alarm type, the alarm parameter, the network element device, and a potential fault location by using a Bayesian network algorithm;
[0103] According to the probability dependency relationship, determine an association strength between the alarm type and the potential fault location, a first correlation between the alarm parameter and the potential fault location, and a second correlation between the network element device and the potential fault location;
[0104] Select a number of potential fault locations with the maximum association strength between the alarm type and the potential fault location to obtain an initial set;
[0105] Select the potential fault locations with the first correlation and the second correlation greater than a preset threshold from the initial set to obtain a candidate set of fault locating points.
[0106] Preferably, the alarm detection frequency is dynamically adjusted according to the change trend of the alarm amount, wherein the specific steps of dynamic adjustment include:
[0107] Statistically obtain the alarm amount in a preset historical time to obtain a statistical result, and determine an alarm amount threshold according to the statistical result; if the alarm amount in a current window is greater than the alarm amount threshold, it is determined that the current alarm amount is surging;
[0108] When it is determined that the current alarm amount is surging, the alarm detection frequency is adjusted according to the duration of the alarm amount surge and the amplitude at which the alarm amount exceeds the alarm amount threshold; the alarm detection frequency is positively correlated with the duration and the amplitude.
[0109] Preferably, the fault point locating module 204 is specifically configured to:
[0110] Extract a historical fault mode from a historical cascading failure cluster;
[0111] For each locating point in the candidate set of fault locating points, extract a fault mode from a cascading failure cluster corresponding to the locating point, calculate a feature similarity of alarm data corresponding to the fault mode and the historical fault mode, and obtain a matching confidence of the locating point; wherein the features in the feature similarity include time intervals, frequencies, sequences and device types of alarms;
[0112] Select the locating points with the matching confidence greater than a preset confidence threshold from the candidate set of fault locating points to obtain a final fault locating point.
[0113] In specific implementation, the working principle, control flow and technical effects of the power distribution communication network fault locating device provided by the embodiments of the present application are the same as those of the power distribution communication network fault locating method in the above embodiments, and thus will not be described herein.
[0114] Referring to Figure 3 , Figure 3is a structural block diagram of a computer device provided by an embodiment of the present application, and the computer device comprises a processor 301, a memory 302, and a computer program stored in the memory 302 and capable of running on the processor 301. The processor 301 implements the steps in the power distribution communication network fault locating method embodiment when executing the computer program. Alternatively, the processor 301 implements the functions of each module / unit in each device embodiment when executing the computer program.
[0115] For example, the computer program can be divided into one or more modules / units, which are stored in the memory 302 and executed by the processor 301 to complete the present application. The one or more modules / units can be a series of computer program instruction segments capable of completing a specific function, which are used to describe the execution process of the computer program in the computer device.
[0116] The computer device can include, but is not limited to, the processor 301 and the memory 302. Those skilled in the art can understand that the schematic diagram is only an example of the computer device and does not limit the computer device, which can include more or fewer components than the diagram, or combine certain components, or different components, for example, the computer device can also include an input / output device, a network access device, a bus, etc.
[0117] The processor 301 can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The processor 301 is the control center of the computer device, which connects each part of the computer device through various interfaces and lines.
[0118] The memory 302 can be used to store the computer programs and / or modules, and the processor 301 realizes various functions of the computer device by running or executing the computer programs and / or modules stored in the memory 302, and calling the data stored in the memory 302. The memory 302 can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application program required by a function (such as a sound playing function, an image playing function, etc.), and the like; and the data storage area can store data created according to the use of the mobile phone (such as audio data, a phone book, etc.), and the like. In addition, the memory 302 can include a high-speed random access memory, and can also include a nonvolatile memory, for example, a hard disk, a memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state memory devices.
[0119] The modules / units integrated in the computer device, if realized in the form of software function units and sold or used as independent products, can be stored in a computer readable storage medium. Based on this understanding, all or part of the processes in the above-mentioned embodiment methods can also be completed by a computer program instructing related hardware, and the computer program can be stored in a computer readable storage medium. The computer program can realize the steps of the above-mentioned various method embodiments when executed by the processor 301. The computer program includes computer program code, which can be in the form of source code, object code, an executable file, or some intermediate form, etc. The computer readable medium can include any entity or device capable of carrying the computer program code, a recording medium, a U disk, a mobile hard disk, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc.
[0120] The embodiment of the present application also provides a computer readable storage medium, which includes a stored computer program, wherein when the computer program runs, the device where the computer readable storage medium is located executes the power distribution communication network fault locating method provided in any one of the above-mentioned embodiments.
[0121] The embodiment of the present application provides a power distribution communication network fault positioning method, device, equipment and medium, which has the beneficial effects that: the cascading failure cluster is identified based on the alarm data flow, and the root alarm and the secondary alarm in the cascading failure are determined according to the time sequence causal reasoning model constructed according to the cascading failure cluster, so that the fault root cause can be quickly and accurately identified, and the accuracy and efficiency of the power distribution communication network fault positioning are improved; the fault location identification is performed according to the alarm data corresponding to the root alarm to obtain a candidate set of fault positioning points, and then the final fault positioning point is determined according to the matching confidence of the alarm data and the historical alarm data corresponding to the positioning point based on the candidate set of fault positioning points, so that the efficiency and accuracy of the fault positioning are further improved, and support is provided for rapid fault recovery.
[0122] The above is the preferred embodiment of the present application. It should be noted that for those skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, which are also considered within the scope of protection of the present application.
Claims
1. A power distribution communication network fault location method, characterized by, The method comprises the following steps: obtain alarm data stream of power distribution communication network, and identify cascading failure cluster based on the alarm data stream; construct time sequence causal reasoning model according to the cascading failure cluster, and determine root cause alarm and secondary alarm in cascading failure; identify fault location according to alarm data corresponding to the root cause alarm, and obtain candidate set of fault positioning points; determine final fault positioning point based on the candidate set of fault positioning points and matching confidence of alarm data and historical alarm data corresponding to positioning point; wherein, the step of identifying fault location according to alarm data corresponding to the root cause alarm to obtain candidate set of fault positioning points comprises: obtain alarm data according to preset sliding window and alarm detection frequency, and filter secondary alarm in the alarm data according to preset alarm convergence rule to obtain alarm data corresponding to root cause alarm; the alarm convergence rule includes but is not limited to time window length of alarm detection, correlation rule between different alarm types and time interval tolerance between alarms; extract features of alarm data corresponding to the root cause alarm to obtain alarm type, alarm parameter and network element device corresponding to each alarm; use Bayesian network algorithm to construct probability dependency relationship between the alarm type, the alarm parameter, the network element device and potential fault location; determine correlation strength between the alarm type and potential fault location, first correlation between the alarm parameter and potential fault location, and second correlation between the network element device and potential fault location according to the probability dependency relationship; select several potential fault locations with the largest correlation strength between the alarm type and potential fault location from the initial set to obtain initial set; select potential fault locations with the first correlation and the second correlation greater than preset threshold from the initial set to obtain candidate set of fault positioning points.
2. The power distribution communications network fault location method of claim 1, wherein, The step of identifying cascading failure cluster based on the alarm data stream comprises: extract alarm trigger record from the alarm data stream to obtain alarm trigger sequence and alarm trigger time; group alarms by using clustering algorithm according to the alarm trigger sequence and the alarm trigger time to obtain cascading failure cluster and independent failure cluster.
3. The power distribution communications network fault location method of claim 1, wherein, The step of constructing time sequence causal reasoning model according to the cascading failure cluster to determine root cause alarm and secondary alarm in cascading failure comprises: calculate conditional probability between alarms for the cascading failure cluster; use Bayesian network to construct time sequence causal reasoning model, taking alarm type as node, conditional dependency relationship between alarms as edge, and conditional probability between alarms as edge weight; generate causal relationship mapping table based on the time sequence causal reasoning model to determine root cause alarm and secondary alarm in cascading failure.
4. The power distribution communications network fault location method of claim 1, wherein, The alarm detection frequency is dynamically adjusted according to the change trend of alarm quantity, and the specific steps of dynamic adjustment comprise: statistically obtain alarm quantity in preset historical time to obtain statistical result, and determine alarm quantity threshold according to the statistical result; if alarm quantity in current window is greater than the alarm quantity threshold, it is determined that current alarm quantity is increasing rapidly; When it is determined that the current alarm quantity surges, the alarm detection frequency is adjusted according to the duration of the alarm quantity surge and the amplitude at which the alarm quantity exceeds the alarm quantity threshold; the alarm detection frequency is positively correlated with the duration and the amplitude.
5. The power distribution communications network fault location method of claim 1, wherein, The final fault locating point is determined according to matching confidence of alarm data corresponding to the locating point and historical alarm data based on the candidate set of fault locating points. A historical fault mode is extracted from a historical cascading failure cluster; For each locating point in the candidate set of fault locating points, a fault mode is extracted from a cascading failure cluster corresponding to the locating point, a feature similarity of alarm data corresponding to the fault mode and the historical fault mode is calculated, and a matching confidence of the locating point is obtained; wherein the features in the feature similarity include time interval, frequency, sequence and device type of the alarm; Locating points with matching confidence greater than a preset confidence threshold are filtered from the candidate set of fault locating points, and a final fault locating point is obtained.
6. A power distribution communication network fault location apparatus, characterized by, It comprises: A cascading failure module is configured to obtain alarm data flow of a power distribution communication network and identify a cascading failure cluster based on the alarm data flow; A root cause alarm module is configured to construct a time sequence causal reasoning model according to the cascading failure cluster and determine a root cause alarm and a secondary alarm in the cascading failure; A candidate fault point module is configured to identify a fault location based on alarm data corresponding to the root cause alarm and obtain a candidate set of fault locating points; A fault point locating module is configured to determine a final fault locating point based on matching confidence of alarm data corresponding to the locating point and historical alarm data based on the candidate set of fault locating points; The candidate set of fault locating points is obtained by identifying a fault location based on alarm data corresponding to the root cause alarm, and comprises: Alarm data is obtained according to a preset sliding window and alarm detection frequency, and secondary alarms in the alarm data are filtered according to a preset alarm convergence rule to obtain alarm data corresponding to the root cause alarm; the alarm convergence rule includes but is not limited to time window length of alarm detection, association rule between different alarm types, and time interval tolerance between alarms; Features of the alarm data corresponding to the root cause alarm are extracted to obtain alarm type, alarm parameter and network element device corresponding to each alarm; A Bayesian network algorithm is used to construct a probability dependency relationship between the alarm type, the alarm parameter, the network element device and the potential fault location; According to the probability dependency relationship, the association strength between the alarm type and the potential fault location, the first correlation between the alarm parameter and the potential fault location, and the second correlation between the network element device and the potential fault location are determined; A number of potential fault locations with the largest association strength between the alarm type and the potential fault location are selected to obtain an initial set; Potential fault locations with the first correlation and the second correlation greater than a preset threshold are selected from the initial set to obtain a candidate set of fault locating points.
7. The power distribution communications network fault location apparatus of claim 6, wherein, The root cause alarm module is specifically configured to: For the cascading failure cluster, the conditional probability between alarms is calculated; A Bayesian network is adopted to construct a time-series causal reasoning model, with alarm types as nodes, conditional dependency relationships between alarms as edges, and conditional probabilities between the alarms as edge weights; A causal relationship mapping table is generated based on the time-series causal reasoning model to determine a root alarm and secondary alarms in a cascading failure.
8. A computer device, comprising: The power distribution communication network fault locating method comprises a processor and a memory, the memory stores a computer program, and the computer program is configured to be executed by the processor, and the processor executes the computer program to realize the power distribution communication network fault locating method according to any one of claims 1 to 5.
9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and a device where the computer readable storage medium is located executes the computer program to realize the power distribution communication network fault locating method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Server fault root cause analysis method and device, electronic equipment and storage medium
CN120276907A
Multi-protocol transmission text data monitoring and warning method and system
CN120321267A