An alarm data correlation analysis method, system, device and medium

By performing multi-dimensional feature extraction, dynamic clustering compression, and graph structure association analysis on multi-source alarm data in communication networks, the problem of poor efficiency and effectiveness of alarm data association analysis in communication networks is solved, and more efficient fault location is achieved.

CN122120108APending Publication Date: 2026-05-29E SURFING IOT CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
E SURFING IOT CO LTD
Filing Date
2026-01-16
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively correlate alarm data in communication networks due to the complex and dynamic nature of the network environment, leading to difficulties in fault location and poor efficiency and effectiveness.

Method used

By extracting multidimensional features from multi-source alarm data, dynamically clustering and compressing the data, constructing alarm compression clusters, and performing graph structure correlation analysis, the alarm correlation analysis results are obtained.

Benefits of technology

It improves the efficiency and effectiveness of correlation analysis of alarm data, better adapts to the complex environment and rapid changes of communication networks, reduces the number of alarms, and improves processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122120108A_ABST
    Figure CN122120108A_ABST
Patent Text Reader

Abstract

The application discloses a kind of correlation analysis methods, systems, devices and media of alarm data, wherein the method obtains several multi-source alarm data;All the multi-source alarm data is extracted to multidimensional feature, and several multidimensional feature vectors are obtained;All the multidimensional feature vectors are dynamically clustered and compressed, and several alarm compression clusters are obtained;The alarm compression cluster includes several alarm cluster points, and the alarm compression cluster records the space-time distribution characteristics of all the alarm cluster points;All the alarm compression clusters are analyzed by graph structure correlation, and the alarm correlation analysis result of the multi-source alarm data is obtained.The method can effectively improve the correlation analysis efficiency and effect of alarm data.The application relates to the technical field of communication network operation and maintenance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication network operation and maintenance technology, and in particular to a method, system, device and medium for correlation analysis of alarm data. Background Technology

[0002] In large-scale communication networks, when network equipment or core links fail, a large number of related alarms are often generated in a short period of time, forming an alarm storm. Because alarm storms can easily overwhelm critical alarms, making fault location difficult, correlation analysis of alarm data has gradually become a key focus for relevant personnel.

[0003] Currently, related technologies typically rely on expert experience to write rules and filter and correlate alarms based on predefined rules to achieve correlation analysis of alarm data. However, due to the complex and dynamically changing network environment of communication networks, this method struggles to achieve effective correlation analysis of alarm data when new or complex faults occur in the communication network, resulting in poor efficiency and effectiveness of alarm correlation analysis.

[0004] Therefore, the problems existing in the current technology still need to be solved and optimized. Summary of the Invention

[0005] To address at least one of the aforementioned technical problems, this application provides a method, system, device, and medium for correlation analysis of alarm data, wherein the method can effectively improve the efficiency and effectiveness of correlation analysis of alarm data.

[0006] According to a first aspect of this application, a method for correlation analysis of alarm data is provided, including: Acquire several multi-source alarm data; Multidimensional feature extraction is performed on all the aforementioned multi-source alarm data to obtain several multidimensional feature vectors; Dynamic clustering and compression are performed on all the multidimensional feature vectors to obtain several alarm compression clusters; each alarm compression cluster includes several alarm cluster points, and each alarm compression cluster records the spatiotemporal distribution characteristics of all the alarm cluster points. A graph structure association analysis is performed on all the alarm compression clusters to obtain the alarm association analysis results of the multi-source alarm data.

[0007] In some embodiments, the step of extracting multidimensional features from all the multi-source alarm data to obtain several multidimensional feature vectors includes: Semantic feature extraction is performed on the multi-source alarm data to obtain a semantic feature vector; Spatiotemporal feature extraction is performed on the multi-source alarm data to obtain a spatiotemporal feature vector; Topological feature extraction is performed on the multi-source alarm data to obtain a topological feature vector; The multidimensional feature vector is obtained based on the semantic feature vector, the spatiotemporal feature vector, and the Susonghu topological feature vector.

[0008] In some embodiments, the dynamic clustering and compression of all the multidimensional feature vectors to obtain several alarm compression clusters includes: Obtain the adaptive neighborhood radius and neighborhood density threshold; Based on the spatiotemporal feature vectors in all the multidimensional feature vectors, obtain the clustering data points of each multidimensional feature vector in the clustering space; Based on the adaptive neighborhood radius and the neighborhood density threshold, alarm clustering is performed on all the clustered data points to obtain several alarm compression clusters.

[0009] In some embodiments, performing graph structure association analysis on all the alarm compression clusters to obtain the alarm association analysis results of the multi-source alarm data includes: An association graph is constructed for all the alarm compression clusters to obtain an alarm association graph corresponding to each alarm compression cluster; Perform graph analysis on all the alarm association graphs to obtain graph analysis data for each alarm association graph; Based on all the graph analysis data, the alarm correlation analysis results are obtained.

[0010] In some embodiments, the graph analysis data includes a plurality of node analysis data, and the step of performing graph analysis on all the alarm association graphs to obtain graph analysis data for each alarm association graph includes: Obtain a first node and a second node, wherein the first node is any one of the alarm nodes in the alarm association graph; and the second node is any one of the alarm nodes in the alarm association graph other than the first node. Based on the second node, a multidimensional correlation factor analysis is performed on the first node to obtain the temporal correlation data, topological connectivity data, and semantic similarity data between the first node and the second node. The node analysis data is obtained based on the time-related data, the topological connectivity data, and the semantic similarity data.

[0011] In some embodiments, the method further includes: Based on the alarm association diagram, several initial communities are obtained; Community optimization is performed on all the initial communities to obtain several independent communities; the independent communities are used to represent the community set of several alarm nodes in the alarm association graph; Based on all the independent communities, the graph analysis data of the alarm association graph is updated to obtain the updated graph analysis data.

[0012] In some embodiments, the method further includes: Perform node analysis on the alarm association graph to obtain the node importance of each alarm node in the alarm association graph; Root cause reasoning is performed on the node importance of all the alarm nodes to obtain root cause reasoning data; Based on the root cause reasoning data, the alarm correlation analysis results are updated to obtain the updated alarm correlation analysis results.

[0013] According to a second aspect of this application, a correlation analysis system for alarm data is provided, comprising: The first processing unit is used to acquire several multi-source alarm data. The second processing unit is used to extract multi-dimensional features from all the multi-source alarm data to obtain several multi-dimensional feature vectors. The third processing unit is used to dynamically cluster and compress all the multidimensional feature vectors to obtain several alarm compression clusters; the alarm compression cluster includes several alarm cluster points, and the alarm compression cluster records the spatiotemporal distribution characteristics of all the alarm cluster points. The fourth processing unit is used to perform graph structure association analysis on all the alarm compression clusters to obtain the alarm association analysis results of the multi-source alarm data.

[0014] According to a third aspect of this application, an electronic device is provided, comprising: At least one processor; At least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor performs the method as described above.

[0015] According to a fourth aspect of this application, a computer-readable storage medium is provided, wherein a processor-executable program is stored, the processor-executable program being used, when executed by the processor, to implement the method as described above.

[0016] According to a fifth aspect of this application, a computer program product is provided, comprising a computer program stored in a computer-readable storage medium, wherein a processor of an electronic device reads the computer program from the computer-readable storage medium and executes the computer program, causing the electronic device to perform the method described above.

[0017] The beneficial effects of the technical solutions provided in this application are: This application provides a method, system, device, and medium for correlation analysis of alarm data. The method acquires several multi-source alarm data sets; extracts multi-dimensional features from all the multi-source alarm data sets to obtain several multi-dimensional feature vectors; performs dynamic clustering and compression on all the multi-dimensional feature vectors to obtain several alarm compressed clusters; each alarm compressed cluster includes several alarm cluster points, and each alarm compressed cluster records the spatiotemporal distribution characteristics of all the alarm cluster points; and performs graph structure correlation analysis on all the alarm compressed clusters to obtain the alarm correlation analysis results of the multi-source alarm data. This method, by dynamically clustering and compressing multi-dimensional feature vectors and performing graph structure correlation analysis on the clustered alarm compressed clusters, can effectively improve the efficiency and effectiveness of alarm data correlation analysis. Attached Figure Description

[0018] Figure 1 A flowchart illustrating a correlation analysis method for alarm data provided in an embodiment of this application; Figure 2 A detailed flowchart of step S120 provided for an embodiment of this application; Figure 3 A detailed flowchart of step S130 provided for an embodiment of this application; Figure 4 A detailed flowchart of step S140 provided for an embodiment of this application; Figure 5 A detailed flowchart of step S420 provided for an embodiment of this application; Figure 6 A schematic diagram of a first optional process for an alarm data correlation analysis method provided in this application embodiment; Figure 7 A second optional flowchart of an alarm data correlation analysis method provided in this application embodiment is shown. Figure 8 A schematic diagram of the framework of an alarm data correlation analysis system provided in this application embodiment; Figure 9 This is a structural block diagram of a computer device provided in an embodiment of this application. Detailed Implementation

[0019] The present application will be further described below with reference to the accompanying drawings and specific embodiments. The described embodiments should not be considered as limitations on the present application, and all other embodiments obtained by those skilled in the art without inventive effort are within the scope of protection of the present application.

[0020] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0021] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0022] Currently, related technologies typically rely on expert experience to write rules and filter and correlate alarms based on predefined rules to achieve correlation analysis of alarm data. However, due to the complex and dynamically changing network environment of communication networks, this method struggles to achieve effective correlation analysis of alarm data when new or complex faults occur in the communication network, resulting in poor efficiency and effectiveness of alarm correlation analysis.

[0023] It should be noted that the aforementioned related technologies are only used to assist in understanding the technical solutions of this application and do not mean that they belong to the publicly disclosed prior art.

[0024] In view of this, embodiments of this application provide a method, system, device, and medium for correlation analysis of alarm data. The method can automatically extract alarm features by extracting multi-dimensional features from multi-source alarm data, reducing reliance on manual rules and improving the efficiency of correlation analysis of alarm data.

[0025] Furthermore, this method dynamically clusters and compresses multidimensional feature vectors, automatically adjusting clusters based on the characteristics of alarm data. This means it can automatically adjust the association rules of alarm data, better adapting to the complex and rapidly changing network environment of communication networks, thus significantly improving the effectiveness of alarm data association analysis. Additionally, by dynamically clustering and compressing multidimensional feature vectors and then performing graph structure association analysis on the resulting compressed alarm clusters, this method effectively reduces the number of alarms, thereby improving the processing efficiency of alarm association analysis.

[0026] This application provides a method for correlation analysis of alarm data, which can be specifically described through the following embodiments. First, a method for correlation analysis of alarm data in this application is described.

[0027] The alarm data correlation analysis method provided in this application embodiment can be applied to communication network operation and maintenance application scenarios. In communication network operation and maintenance application scenarios, communication network operation and maintenance service providers can use the method provided in this application embodiment to perform correlation analysis on alarm data generated by various network devices in the communication network, which can effectively improve the efficiency and effectiveness of alarm data correlation analysis.

[0028] This application can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0029] Reference Figure 1 , Figure 1 This is a flowchart illustrating a correlation analysis method for alarm data provided in an embodiment of this application. The method includes, but is not limited to, steps S110 to S140: Step S110: Obtain several multi-source alarm data; In this embodiment, the multi-source alarm data can be the original alarm data generated by various network devices and servers in the communication network; or it can be the original alarm data after preprocessing. The preprocessing operation can be to standardize and clean the original alarm data, and extract key information such as timestamp, alarm type, alarm level, source device, and alarm description from the original alarm data.

[0030] Step S120: Perform multi-dimensional feature extraction on all the multi-source alarm data to obtain several multi-dimensional feature vectors; In this embodiment of the application, multi-dimensional features of each multi-source alarm data can be extracted to obtain a multi-dimensional feature vector corresponding to each multi-source alarm data.

[0031] Reference Figure 2 In some embodiments, step S120, which involves extracting multi-dimensional features from all the multi-source alarm data to obtain several multi-dimensional feature vectors, includes: Step S210: Extract semantic features from the multi-source alarm data to obtain a semantic feature vector; Step S220: Extract spatiotemporal features from the multi-source alarm data to obtain a spatiotemporal feature vector; Step S230: Extract topological features from the multi-source alarm data to obtain a topological feature vector; Step S240: Obtain the multidimensional feature vector based on the semantic feature vector, the spatiotemporal feature vector, and the topological feature vector.

[0032] In this embodiment of the application, text semantic analysis can be performed on multi-source alarm data based on a pre-trained BERT model to obtain the semantic feature vector of the multi-source alarm data; spatiotemporal feature extraction can be to extract the time features (such as alarm occurrence time, alarm duration, etc.) and spatial features (such as device location, rack location, etc.) of the multi-source alarm data and construct them into a spatiotemporal feature vector.

[0033] It is understandable that topological features can be based on multi-source alarm data to extract the topological features (such as network connection relationships and dependencies) of various hardware devices (such as network devices, servers, etc.) in the communication network; and then by integrating semantic feature vectors, spatiotemporal feature vectors and topological feature vectors, a multidimensional feature vector is obtained.

[0034] It is worth mentioning that there are already various ways to implement spatiotemporal feature extraction and topological feature extraction. For example, spatiotemporal feature extraction can be implemented based on a combination of convolutional neural networks (CNN) and long short-term memory networks (LSTM), while topological feature extraction can be implemented through graph convolutional networks (GCN) or graph attention networks (GAT), etc. This application will not elaborate further on these methods.

[0035] Step S130: Perform dynamic clustering compression on all the multidimensional feature vectors to obtain several alarm compression clusters; each alarm compression cluster includes several alarm cluster points, and each alarm compression cluster records the spatiotemporal distribution characteristics of all the alarm cluster points. In the embodiments of this application, all multidimensional feature vectors can be dynamically clustered and compressed to obtain several alarm compression clusters. Each alarm compression cluster records the spatiotemporal distribution characteristics of all alarm cluster points within the cluster.

[0036] Reference Figure 3 In some embodiments, step S130, dynamically clustering and compressing all the multidimensional feature vectors to obtain several alarm compression clusters, includes: Step S310: Obtain the adaptive neighborhood radius and neighborhood density threshold; Step S320: Based on the spatiotemporal feature vectors in all the multidimensional feature vectors, obtain the clustering data points of each multidimensional feature vector in the clustering space; Step S330: Based on the adaptive neighborhood radius and the neighborhood density threshold, perform alarm clustering on all the clustered data points to obtain several alarm compression clusters.

[0037] In this embodiment, the data point corresponding to each multidimensional feature vector in the clustering space can be determined based on the spatiotemporal feature vector in the multidimensional feature vector, and denoted as the cluster data point. The spatiotemporal feature vector is used to indicate the temporal and spatial characteristics of the corresponding multi-source alarm data. The adaptive neighborhood radius can be obtained by analyzing all multidimensional feature vectors in the clustering space using the local density estimation method. The neighborhood density threshold can be a predefined density threshold, which is used to indicate the minimum number of alarm cluster points in the cluster.

[0038] It is understandable that alarm clustering can be based on an adaptive neighborhood radius and a neighborhood density threshold, using a density clustering algorithm (such as the DBSCAN clustering algorithm) to compress all cluster data points in the clustering space to obtain several final clusters. Then, a compressed summary is generated for each cluster. This compressed summary includes the number statistics of each alarm cluster point in each cluster, key alarm representatives (i.e., alarm data corresponding to the cluster center), and the spatiotemporal distribution characteristics of the cluster. Specifically, the spatiotemporal distribution characteristics can be obtained by statistically analyzing the temporal and spatial characteristics of each alarm cluster point in the cluster.

[0039] Step S140: Perform graph structure association analysis on all the alarm compression clusters to obtain the alarm association analysis results of the multi-source alarm data.

[0040] In this embodiment of the application, graph structure association analysis can be performed on each alarm compression cluster to obtain alarm association analysis results corresponding to all multi-source alarm data.

[0041] Reference Figure 4 In some embodiments, step S140, performing graph structure association analysis on all the alarm compression clusters to obtain the alarm association analysis results of the multi-source alarm data, includes: Step S410: Construct an association graph for all the alarm compression clusters to obtain an alarm association graph corresponding to each alarm compression cluster; In this embodiment of the application, an alarm association graph corresponding to each alarm compression cluster can be constructed based on graph technology. Specifically, the alarm association graph can be represented as follows:

[0042] in, This is an alarm correlation diagram; This refers to an alarm node in the alarm association graph, which can specifically be an alarm cluster point in an alarm compression cluster. The associated edges in the alarm association graph are used to characterize the association relationship between alarm nodes. This association relationship can be determined by the aforementioned spatiotemporal distribution characteristics and / or topological characteristics. For example, the associated edges between each alarm node can be determined based on the network connection relationship in the topological characteristics.

[0043] Step S420: Perform graph analysis on all the alarm association graphs to obtain graph analysis data for each alarm association graph; Reference Figure 5 Furthermore, the graph analysis data includes analysis data for several nodes. Step S420 involves performing graph analysis on all the alarm association graphs to obtain graph analysis data for each alarm association graph, including: Step S510: Obtain the first node and the second node. The first node is any one of the alarm nodes in the alarm association graph. The second node is any one of the alarm nodes in the alarm association graph other than the first node. Step S520: Based on the second node, perform multidimensional correlation factor analysis on the first node to obtain time correlation data, topological connectivity data and semantic similarity data between the first node and the second node; Step S530: Obtain the node analysis data based on the time-related data, the topological connectivity data, and the semantic similarity data.

[0044] In this embodiment of the application, for any alarm association graph, node analysis data between each alarm node in the alarm association graph can be obtained, and all node analysis data can be integrated to obtain graph analysis data of the alarm association graph.

[0045] It is understandable that, for any alarm node (i.e., the first node) and its second node in the alarm correlation graph, multidimensional correlation factor analysis can analyze three factors between the first and second nodes: temporal proximity, topological connectivity, and semantic similarity, to obtain temporal correlation data, topological connectivity data, and semantic similarity data, respectively. Temporal proximity can be determined based on the temporal features corresponding to the first node and the temporal features corresponding to the second node. This temporal proximity (i.e., temporal correlation data) can be expressed as:

[0046] in, For time-related data; if For the alarm occurrence time corresponding to the first node, then The alarm occurrence time corresponding to the second node; or, if For the alarm duration corresponding to the first node, then The alarm duration corresponding to the second node.

[0047] Topology connectivity data can be obtained based on the topological characteristics of the first node and / or the second node. For example, if there is a network connection or dependency relationship between the first node and the second node, the specific value of the topology connectivity data can be a non-zero constant; or, if there is no network connection or dependency relationship between the first node and the second node, the specific value of the topology connectivity data can be zero.

[0048] It is worth mentioning that semantic similarity data can be used to calculate the semantic similarity between the semantic feature vector corresponding to the first node and the semantic feature vector corresponding to the second node. Specifically, this can be obtained based on calculation methods such as cosine similarity and Euclidean distance, which will not be elaborated upon here. Node analysis data is used to indicate the association strength between the first and second nodes, and this node analysis data can be represented as:

[0049] in, The data analyzed for the nodes can specifically be the node analysis data between the first node i and the second node j. This is topological connectivity data; Data with semantic similarity; , and These are weighting coefficients, and their specific values ​​can be 0.4, 0.4, and 0.2, respectively.

[0050] Step S430: Based on all the graph analysis data, obtain the alarm correlation analysis results.

[0051] In this embodiment of the application, graph analysis data of each alarm association graph can be obtained separately, and alarm association analysis results of all multi-source alarm data can be obtained by integrating the graph analysis data of all alarm association graphs.

[0052] Reference Figure 6 In some embodiments, the method further includes: Step S610: Obtain several initial communities based on the alarm association diagram; Step S620: Perform community optimization on all the initial communities to obtain several independent communities; the independent communities are used to represent the community set of several alarm nodes in the alarm association graph; Step S630: Update the graph analysis data of the alarm association graph based on all the independent communities to obtain the updated graph analysis data.

[0053] In this embodiment, each alarm node in the alarm association graph can be defined as an initial community. Community optimization can be performed iteratively on all initial communities based on a community discovery algorithm (such as the Louvain algorithm) to obtain several independent communities. Each independent community includes several alarm nodes in the alarm association graph, and there is a strong correlation between each alarm node in the independent community. Step S630 can be to add the community set of several alarm nodes recorded in each independent community to the graph analysis data of the alarm association graph to obtain updated graph analysis data, and display the alarm association analysis results containing the updated graph analysis data through a visualization interface.

[0054] Reference Figure 7 In some embodiments, the method further includes: Step S710: Perform node analysis on the alarm association graph to obtain the node importance of each alarm node in the alarm association graph; Step S720: Perform root cause reasoning on the node importance of all the alarm nodes to obtain root cause reasoning data; Step S730: Update the alarm correlation analysis results based on the root cause inference data to obtain the updated alarm correlation analysis results.

[0055] In the embodiments of this application, for any alarm association graph, node analysis can be based on the PageRank algorithm to calculate the importance of each alarm node in the alarm association graph to obtain the node importance of each alarm node; root cause reasoning can be based on the root cause reasoning algorithm, combining the topological features and node importance of each alarm node to identify the most likely root cause alarm to obtain root cause reasoning data.

[0056] Understandably, updating the results can involve adding root cause inference data to the alarm correlation analysis results to obtain updated alarm correlation analysis results, and then displaying the updated alarm correlation analysis results through a visualization interface.

[0057] Figure 8 A system block diagram of an alarm data correlation analysis system provided in this application embodiment includes: The first processing unit 801 is used to acquire several multi-source alarm data; The second processing unit 802 is used to perform multi-dimensional feature extraction on all the multi-source alarm data to obtain several multi-dimensional feature vectors. The third processing unit 803 is used to perform dynamic clustering and compression on all the multidimensional feature vectors to obtain several alarm compression clusters; the alarm compression cluster includes several alarm cluster points, and the alarm compression cluster records the spatiotemporal distribution characteristics of all the alarm cluster points. The fourth processing unit 804 is used to perform graph structure association analysis on all the alarm compression clusters to obtain the alarm association analysis results of the multi-source alarm data.

[0058] It is worth mentioning that the content of the above method embodiments is applicable to this system embodiment. The specific functions implemented in this system embodiment are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those achieved in the above method embodiments.

[0059] Figure 9 A schematic diagram of the structure of a computer device provided in this application embodiment includes: At least one processor 980; At least one memory 920 is used to store at least one program; When the at least one program is executed by the at least one processor 980, the at least one processor 980 performs the method as described in the foregoing embodiments.

[0060] This application also provides a computer-readable storage medium storing a processor-executable program, which, when executed by the processor 980, is used to implement the methods described in the foregoing embodiments.

[0061] Specifically, computer equipment can be either a user terminal or a server.

[0062] This application uses a computer device as a user terminal as an example, as detailed below: like Figure 9 As shown, the computer device 900 may include an RF (Radio Frequency) circuit 910, a memory 920 including one or more computer-readable storage media, an input unit 930, a display unit 940, a sensor 950, an audio circuit 960, a WiFi module 970, a processor 980 including one or more processing cores, and a power supply 990, among other components. Those skilled in the art will understand that... Figure 9 The device structure shown does not constitute a limitation on the electronic device and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0063] The RF circuit 910 can be used for receiving and transmitting signals during information transmission or calls. Specifically, it receives downlink information from the base station and hands it over to one or more processors 980 for processing; additionally, it transmits uplink data to the base station. Typically, the RF circuit 910 includes, but is not limited to, an antenna, at least one amplifier, a tuner, one or more oscillators, a Subscriber Identity Module (SIM) card, a transceiver, a coupler, an LNA (Low Noise Amplifier), a duplexer, etc. Furthermore, the RF circuit 910 can also communicate wirelessly with networks and other devices. Wireless communication can use any communication standard or protocol, including but not limited to GSM (Global System for Mobile communication), GPRS (General Packet Radio Service), CDMA (Code Division Multiple Access), WCDMA (Wideband Code Division Multiple Access), LTE (Long Term Evolution), email, SMS (Short Messaging Service), etc.

[0064] The memory 920 can be used to store software programs and modules. The processor 980 executes various functional applications and data processing by running the software programs and modules stored in the memory 920. The memory 920 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, application programs required for at least one function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the computer device 900 (such as audio data, telephone directory, etc.). In addition, the memory 920 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. Accordingly, the memory 920 may also include a memory controller to provide access to the memory 920 by the processor 980 and the input unit 930. Although Figure 9 The RF circuit 910 is shown, but it is understood that it is not a necessary component of the computer device 900 and can be omitted as needed without changing the nature of the invention.

[0065] The input unit 930 can be used to receive input digital or character information, and to generate keyboard, mouse, joystick, optical, or trackball signal inputs related to user settings and function control. Specifically, the input unit 930 may include a touch-sensitive surface 932 and other input devices 931. The touch-sensitive surface 932, also known as a touch display screen or touchpad, can collect touch operations performed by the user on or near it (such as operations performed by the user using a finger, stylus, or any suitable object or accessory on or near the touch-sensitive surface 932), and drive the corresponding connection device according to a pre-set program. Optionally, the touch-sensitive surface 932 may include two parts: a touch detection device and a touch controller. The touch detection device detects the user's touch position and the signal generated by the touch operation, and transmits the signal to the touch controller; the touch controller receives touch information from the touch detection device, converts it into touch point coordinates, sends it to the processor 980, and can receive and execute commands from the processor 980. In addition, the touch-sensitive surface 932 can be implemented using various types such as resistive, capacitive, infrared, and surface acoustic wave. In addition to the touch-sensitive surface 932, the input unit 930 may also include other input devices 931. Specifically, other input devices 931 may include, but are not limited to, one or more of the following: physical keyboard, function keys (such as volume control buttons, power buttons, etc.), trackball, mouse, joystick, etc.

[0066] Display unit 940 can be used to display information input by the user or information provided to the user, as well as various graphical user interfaces of computer device 900. These graphical user interfaces can be composed of graphics, text, icons, video, and any combination thereof. Display unit 940 may include display panel 941, optionally configured as LCD (Liquid Crystal Display), OLED (Organic Light-Emitting Diode), etc. Further, touch-sensitive surface 932 may cover display panel 941. When touch-sensitive surface 932 detects a touch operation on or near it, it transmits the information to processor 980 to determine the type of touch event. Subsequently, processor 980 provides corresponding visual output on display panel 941 according to the type of touch event. Although in Figure 9 In this embodiment, the touch-sensitive surface 932 and the display panel 941 are implemented as two separate components to realize input and output functions. However, in some embodiments, the touch-sensitive surface 932 and the display panel 941 can be integrated to realize input and output functions.

[0067] The computer device 900 may also include at least one sensor 950, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor. The ambient light sensor can adjust the brightness of the display panel 941 according to the ambient light level, and the proximity sensor can turn off the display panel 941 and / or backlight when the computer device 900 is moved to the ear. As a type of motion sensor, a gravity acceleration sensor can detect the magnitude of acceleration in various directions (generally three axes). When stationary, it can detect the magnitude and direction of gravity and can be used for applications that recognize the phone's posture (such as landscape / portrait switching, related games, magnetometer posture calibration), vibration recognition-related functions (such as pedometers, taps), etc. Other sensors that the computer device 900 may also be equipped with, such as gyroscopes, barometers, hygrometers, thermometers, and infrared sensors, will not be described in detail here.

[0068] Audio circuitry 960, speaker 961, and microphone 962 provide an audio interface between the user and computer device 900. Audio circuitry 960 converts received audio data into electrical signals, which are then transmitted to speaker 961, where they are converted into sound signals for output. Conversely, microphone 962 converts collected sound signals into electrical signals, which are received by audio circuitry 960, converted back into audio data, and then processed by processor 980 before being transmitted via RF circuitry 910 to another control device, or output to memory 920 for further processing. Audio circuitry 960 may also include an earphone jack to facilitate communication between peripheral headphones and computer device 900.

[0069] Computer device 900 can transmit information with the wireless transmission module set up on the battle equipment via WiFi module 970.

[0070] The processor 980 is the control center of the computer device 900. It connects various parts of the control device via various interfaces and lines. By running or executing software programs and / or modules stored in the memory 920, and by calling data stored in the memory 920, it performs various functions of the computer device 900 and processes data, thereby providing overall monitoring of the control device. Optionally, the processor 980 may include one or more processing cores; optionally, the processor 980 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the aforementioned modem processor may also not be integrated into the processor 980.

[0071] The computer device 900 also includes a power supply 990 (such as a battery) that supplies power to various components. Preferably, the power supply can be logically connected to the processor 980 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system. The power supply 990 may also include one or more DC or AC power supplies, recharging systems, power fault detection circuits, power converters or inverters, power status indicators, and other arbitrary components.

[0072] Although not shown, the computer device 900 may also include a camera, Bluetooth module, etc., which will not be described in detail here.

[0073] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to perform the methods described in the foregoing embodiments.

[0074] This application also discloses a computer program product or computer program, which includes computer instructions stored in the aforementioned computer-readable storage medium; the processor of the aforementioned electronic device can read the computer instructions from the aforementioned computer-readable storage medium, and the processor executes the computer instructions, causing the electronic device to perform the aforementioned method embodiment.

[0075] It is understood that the content of the above method embodiments is applicable to this computer program product or computer program embodiment. The specific functions implemented by this computer program product or computer program embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0076] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented, for example, in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatuses.

[0077] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0078] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between apparatuses or units through some interfaces, and may be electrical, mechanical, or other forms.

[0079] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0080] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0081] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0082] The step numbers in the above method embodiments are set only for ease of explanation and do not limit the order of the steps. The execution order of each step in the embodiments can be adaptively adjusted according to the understanding of those skilled in the art.

[0083] The above is a detailed description of the preferred embodiments of this application, but this application is not limited to the embodiments described. Those skilled in the art can make various equivalent modifications or substitutions without departing from the spirit of this application, and these equivalent modifications or substitutions are all included within the scope defined by the claims of this application.

Claims

1. A method for correlation analysis of alarm data, characterized in that, include: Acquire several multi-source alarm data; Multidimensional feature extraction is performed on all the aforementioned multi-source alarm data to obtain several multidimensional feature vectors; Dynamic clustering and compression are performed on all the multidimensional feature vectors to obtain several alarm compression clusters; each alarm compression cluster includes several alarm cluster points, and each alarm compression cluster records the spatiotemporal distribution characteristics of all the alarm cluster points. A graph structure association analysis is performed on all the alarm compression clusters to obtain the alarm association analysis results of the multi-source alarm data.

2. The method according to claim 1, characterized in that, The step of performing multi-dimensional feature extraction on all the multi-source alarm data yields several multi-dimensional feature vectors, including: Semantic feature extraction is performed on the multi-source alarm data to obtain a semantic feature vector; Spatiotemporal feature extraction is performed on the multi-source alarm data to obtain a spatiotemporal feature vector; Topological feature extraction is performed on the multi-source alarm data to obtain a topological feature vector; The multidimensional feature vector is obtained based on the semantic feature vector, the spatiotemporal feature vector, and the topological feature vector.

3. The method according to claim 1, characterized in that, The dynamic clustering and compression of all the multidimensional feature vectors yields several alarm compression clusters, including: Obtain the adaptive neighborhood radius and neighborhood density threshold; Based on the spatiotemporal feature vectors in all the multidimensional feature vectors, obtain the clustering data points of each multidimensional feature vector in the clustering space; Based on the adaptive neighborhood radius and the neighborhood density threshold, alarm clustering is performed on all the clustered data points to obtain several alarm compression clusters.

4. The method according to claim 1, characterized in that, The graph structure association analysis of all the alarm compression clusters is performed to obtain the alarm association analysis results of the multi-source alarm data, including: An association graph is constructed for all the alarm compression clusters to obtain an alarm association graph corresponding to each alarm compression cluster; Perform graph analysis on all the alarm association graphs to obtain graph analysis data for each alarm association graph; Based on all the graph analysis data, the alarm correlation analysis results are obtained.

5. The method according to claim 4, characterized in that, The graph analysis data includes several node analysis data. The graph analysis of all the alarm association graphs, to obtain the graph analysis data for each alarm association graph, includes: Obtain a first node and a second node, wherein the first node is any one of the alarm nodes in the alarm association graph; and the second node is any one of the alarm nodes in the alarm association graph other than the first node. Based on the second node, a multidimensional correlation factor analysis is performed on the first node to obtain the temporal correlation data, topological connectivity data, and semantic similarity data between the first node and the second node. The node analysis data is obtained based on the time-related data, the topological connectivity data, and the semantic similarity data.

6. The method according to claim 4 or 5, characterized in that, The method further includes: Based on the alarm association diagram, several initial communities are obtained; Community optimization is performed on all the initial communities to obtain several independent communities; the independent communities are used to represent the community set of several alarm nodes in the alarm association graph; Based on all the independent communities, the graph analysis data of the alarm association graph is updated to obtain the updated graph analysis data.

7. The method according to claim 4, characterized in that, The method further includes: Perform node analysis on the alarm association graph to obtain the node importance of each alarm node in the alarm association graph; Root cause reasoning is performed on the node importance of all the alarm nodes to obtain root cause reasoning data; Based on the root cause reasoning data, the alarm correlation analysis results are updated to obtain the updated alarm correlation analysis results.

8. A correlation analysis system for alarm data, characterized in that, include: The first processing unit is used to acquire several multi-source alarm data. The second processing unit is used to extract multi-dimensional features from all the multi-source alarm data to obtain several multi-dimensional feature vectors. The third processing unit is used to dynamically cluster and compress all the multidimensional feature vectors to obtain several alarm compression clusters; the alarm compression cluster includes several alarm cluster points, and the alarm compression cluster records the spatiotemporal distribution characteristics of all the alarm cluster points. The fourth processing unit is used to perform graph structure association analysis on all the alarm compression clusters to obtain the alarm association analysis results of the multi-source alarm data.

9. An electronic device, characterized in that, include: At least one processor; At least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor performs the method as described in any one of claims 1-7.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-7.