IT service management system and method based on natural language and knowledge base

By using an IT service management system based on natural language and knowledge base, we have solved the pain points of traditional IT service management, such as high reliance on manual labor, slow response, opaque processes, and difficulty in quantifying quality. This has enabled the automation, predictability, and intelligence of IT service management, and improved SLA achievement rate and user satisfaction.

CN122437782APending Publication Date: 2026-07-21BEIJING MINGYIDA TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING MINGYIDA TECH CO LTD
Filing Date
2026-06-17
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Traditional IT service management systems face problems such as inefficiency of manual classification, knowledge base silos, passive SLA management, black-box processes, fragmented collaboration, and one-sided evaluation, resulting in delayed response, repetitive problems, unpredictable default risks, difficulty in identifying process bottlenecks, and homogenized user experience.

Method used

An IT service management system based on natural language and knowledge base is adopted, including a work order intelligent processing module, a knowledge graph linkage module, an SLA full lifecycle monitoring and default warning module, a process bottleneck identification and continuous optimization module, a multi-role visual collaboration module, and a service quality quantitative assessment and closed-loop management module. It combines multi-dimensional feature fusion, graph neural network, streaming computing, WebGL technology and differential privacy technology to achieve automated, predictive and intelligent management.

Benefits of technology

It improved the efficiency and accuracy of work order processing, enhanced the intelligence level of problem solving, achieved proactive prevention of SLA breaches, drove continuous process optimization, enabled efficient collaboration among multiple roles, built a closed loop for continuous improvement of service quality, provided a personalized and privacy-secure service experience, and significantly improved SLA achievement rate and user satisfaction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122437782A_ABST
    Figure CN122437782A_ABST
Patent Text Reader

Abstract

The application relates to the technical field of information technology service management, and provides an IT service management system and method based on natural language and a knowledge base, the IT service management system based on natural language and the knowledge base comprising: an intelligent work order processing module, which is used for extracting semantic features through a pre-trained language model, combining structured context information to perform multi-dimensional feature fusion, and outputting a work order classification result and a dynamic priority score; a knowledge graph linkage module, which is used for constructing an IT operation and maintenance field knowledge graph based on a graph database and performing causal reasoning recommendation; an SLA full life cycle monitoring and default warning module; a process bottleneck identification and continuous optimization module; a multi-role visual collaborative module; a service quality quantitative evaluation and closed-loop management module; and a user portrait personalized service module, which is used for constructing a user portrait system. In the technical scheme, automation, predictability and intelligence of IT service management are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information technology service management technology, and in particular to an IT service management system and method based on natural language and knowledge base. Background Technology

[0002] As enterprises undergo digital transformation, IT infrastructure becomes increasingly complex, posing significant challenges to traditional IT service management (ITSM) systems.

[0003] Manual classification is inefficient: The massive number of work orders rely on manual classification and grading, which is highly subjective and results in delayed response, causing high-priority faults to be delayed.

[0004] Knowledge silos: Historical work orders and solutions are scattered across different systems, lacking effective correlation retrieval, resulting in recurring problems and low resolution efficiency.

[0005] SLA management is passive: Service Level Agreement (SLA) monitoring mainly relies on manual inspections or simple timers, which cannot predict potential default risks and often only remedies are taken after a default has occurred.

[0006] Process black box: Managers have difficulty gaining real-time insight into bottlenecks in processes (such as approval backlogs and assignment errors) and lack data-driven continuous optimization methods.

[0007] Fragmented collaboration: The perspectives of users, front-line customer service, second-line engineers, and managers are fragmented, lacking a unified collaborative view, resulting in high communication costs.

[0008] The assessment is one-sided: service quality assessments rely heavily on post-event satisfaction surveys, lacking quantitative indicators and closed-loop improvement mechanisms across the entire process.

[0009] Homogeneous experience: Standardized service processes are applied to all users without taking into account differences in users' technical backgrounds and the urgency of their business. Summary of the Invention

[0010] This application provides an IT service management system and method based on natural language and knowledge base, which can realize the automation, predictability and intelligence of IT service management, and improve SLA achievement rate and user satisfaction.

[0011] Firstly, an IT service management system based on natural language processing and a knowledge base is provided, including:

[0012] The intelligent work order processing module is used to receive work order text data, extract semantic features through a pre-trained language model, perform multi-dimensional feature fusion by combining structured context information, and output work order classification results and dynamic priority scores.

[0013] The knowledge graph linkage module is used to build a knowledge graph for the IT operations and maintenance field based on a graph database. It calculates the vector similarity between the current work order and historical events through a graph neural network and performs causal reasoning and recommendation based on a path ranking algorithm.

[0014] The SLA full lifecycle monitoring and default early warning module is used to consume real-time work order status change data streams based on a streaming computing framework, predict the expected resolution time of work orders through regression models, and calculate the probability of SLA default risk through classification models to trigger tiered early warnings.

[0015] The process bottleneck identification and continuous optimization module is used to collect system event logs, reconstruct the actual business process model through process mining algorithms, identify deviation nodes by comparing with standard processes, and provide resource optimization suggestions through discrete event simulation.

[0016] The multi-role visual collaboration module is used to render multi-perspective service delivery views for users, engineers, and managers based on WebGL technology, and to achieve optimal matching of work orders and engineers based on combinatorial optimization algorithms.

[0017] The service quality quantitative assessment and closed-loop management module is used to define multi-dimensional service quality indicators, perform attribution analysis through interpretable machine learning models, and drive the automatic distribution and effect verification of improvement tasks.

[0018] The user profile personalization service module is used to build a user profile system that includes static and dynamic tags, protects privacy based on differential privacy technology, and dynamically adjusts service strategies according to the user's technical level and emotional state.

[0019] In the above technical solution, a work order intelligent processing module is set up to receive work order text data, extract semantic features through a pre-trained language model, perform multi-dimensional feature fusion by combining structured context information, and output work order classification results and dynamic priority scores; a knowledge graph linkage module is used to build a knowledge graph in the IT operations and maintenance field based on a graph database, calculate the vector similarity between the current work order and historical events through a graph neural network, and perform causal reasoning recommendation based on a path ranking algorithm; an SLA full lifecycle monitoring and default warning module is used to consume work order status change data streams in real time based on a streaming computing framework, predict the expected resolution time of work orders through a regression model, calculate the SLA default risk probability through a classification model, and trigger tiered warnings; a process bottleneck identification and continuous optimization module is used to collect system event logs and reconstruct actual business through process mining algorithms. The system includes a process model that compares to standard processes to identify deviation points and provides resource optimization suggestions through discrete event simulation; a multi-role visual collaboration module that uses WebGL technology to render multi-perspective service delivery views for users, engineers, and managers, and achieves optimal matching of work orders and engineers based on combinatorial optimization algorithms; a service quality quantitative assessment and closed-loop management module that defines multi-dimensional service quality indicators, performs attribution analysis through interpretable machine learning models, and drives the automatic distribution and effect verification of improvement tasks; and a user profile personalized service module that builds a user profile system including static and dynamic tags, protects privacy based on differential privacy technology, and dynamically adjusts service strategies according to users' technical skills and emotional states. This system achieves automation, predictability, and intelligence in IT service management, improving SLA achievement rates and user satisfaction.

[0020] In one specific implementation scheme, it also includes:

[0021] The anomaly detection and root cause localization module is used to detect log anomalies based on the sequence autoencoding model and infer the root cause of the fault by combining the dependency relationship between Bayesian network and configuration management database.

[0022] The cross-channel interaction and unified session management module is used to integrate multi-source access through channel adapters and maintain the session state machine to achieve smooth intent migration.

[0023] The data security and compliance audit module is used to implement dynamic access control based on the attribute access control model, encrypt and store sensitive data using national cryptographic algorithms, and generate compliance audit reports.

[0024] In one specific implementation scheme, the work order intelligent processing module includes:

[0025] The semantic feature extraction unit is used to convert the work order title and description text into a high-dimensional vector representation using a fine-tuned BERT model;

[0026] The entity recognition and intent analysis unit is used to identify key entities in text and determine user intent using the BiLSTM-CRF model.

[0027] The multi-dimensional feature fusion unit is used to concatenate the text feature vector with structured features including the submitter's job level, department, and number of affected users before inputting it into the fully connected layer;

[0028] The dynamic priority calculation unit is used to incorporate the time decay factor λ and the business impact factor β to calculate the priority score;

[0029] The confidence assessment and online incremental learning unit is used to output the Softmax classification probability. Work orders below the preset threshold are automatically transferred to the manual review queue, and the model parameters are updated daily based on few-shot learning technology.

[0030] In one specific implementation scheme, the knowledge graph linkage module includes:

[0031] The knowledge extraction and graph construction unit is used to extract fault phenomena, causes, solution entities and relationships from historical work orders using natural language processing technology, and to build a graph database.

[0032] The similarity matching and ranking unit is used to calculate the cosine similarity between the current work order vector and the solution vector in the knowledge graph, retrieve the Top-K similar cases, and combine the Learning to Rank model to re-rank the recommendation results based on the historical success rate, timeliness and applicable version of the solution.

[0033] The causal reasoning recommendation unit, used in knowledge graph-based path ranking algorithms, not only recommends solutions but also recommends upstream dependencies that may lead to the failure.

[0034] The feedback loop and unknown fault clustering unit is used to record the user's adoption of the recommended solution to correct the graph relationship weights, and to use the clustering algorithm to discover emerging fault trends for work orders with no matching results.

[0035] In one specific implementation scheme, the SLA full lifecycle monitoring and default early warning module includes:

[0036] Multi-level SLA parsing units are used to convert response time, resolution time, and availability metrics into computable rule engine scripts;

[0037] The real-time stream processing unit is used to consume the work order status change data stream in real time and calculate the current elapsed time using a streaming computing framework;

[0038] The remaining time prediction unit is used to train a gradient boosting regression model based on historical resolution time data to predict the estimated resolution time (ETA) of work orders.

[0039] The default risk scoring unit is used to build a logistic regression model to calculate the probability of a work order defaulting at a specific point in the future.

[0040] The dynamic early warning triggering unit is used to automatically upgrade the work order priority and push an alarm when the probability of default exceeds the first threshold, and to trigger the emergency resource allocation process when it exceeds the second threshold.

[0041] The exemption determination unit is used to automatically identify the downtime caused by user-side reasons and deduct it from the SLA timer.

[0042] In one specific implementation scheme, the process bottleneck identification and continuous optimization module includes:

[0043] The event log collection unit is used to collect all operation logs, including timestamps, operators, and state transitions.

[0044] The process discovery unit is used to automatically reconstruct the actual business process model from logs using the Alpha Miner or Heuristics Miner algorithm.

[0045] The compliance check unit is used to compare the actual process model with the preset standard process model to identify process deviations;

[0046] The bottleneck location unit is used to calculate the average dwell time and resource utilization of each active node and identify long-tail nodes;

[0047] The simulation optimization unit is used to simulate the changes in process efficiency after resource reallocation using discrete events and provide optimization suggestions.

[0048] The root cause analysis unit is used to correlate bottleneck data with organizational structure data to analyze whether the problem is caused by improper permission configuration or lack of skills.

[0049] In one specific implementation scheme, the multi-role visual collaboration module includes:

[0050] The user panoramic view unit is used to display the work order status, processing progress bar, and estimated completion time;

[0051] The engineer's workbench unit is used to aggregate to-do work orders, knowledge base recommendations, and related configuration item topology diagrams;

[0052] The manager's cockpit unit is used to provide a macro-level view of the SLA achievement rate heatmap, team load balancing chart, and fault type distribution tree diagram.

[0053] The intelligent routing unit automatically assigns the best engineer based on the skill graph and current load using a Hungarian algorithm;

[0054] The collaborative editing unit is used to resolve conflicts based on an operation conversion algorithm when multiple engineers are editing the same work order at the same time.

[0055] The voice interaction unit integrates automatic speech recognition technology, enabling engineers to input processing progress via voice and automatically convert it into a text log.

[0056] In one specific implementation scheme, the service quality quantitative assessment and closed-loop management module includes:

[0057] The multi-dimensional indicator definition unit is used to define hard indicators, including resolution time and first call resolution rate, and soft indicators, including customer satisfaction and communication quality.

[0058] The sentiment analysis unit is used to perform sentiment polarity analysis on user replies and evaluation texts to quantify user experience.

[0059] The attribution analysis unit is used to analyze the impact of each factor on satisfaction using the SHAP value interpretation model.

[0060] The automatic follow-up unit is used to automatically trigger outbound call robots or email questionnaires to collect feedback after the work order is closed;

[0061] Improve the task distribution unit to automatically generate improvement tasks for low-scoring items and assign them to the corresponding team leaders;

[0062] The closed-loop verification unit is used to automatically compare the changes in indicators before and after the improvement in the next assessment cycle to verify the improvement effect.

[0063] In one specific implementation scheme, the user profile personalization service module includes:

[0064] The tag system construction unit is used to build a user tag system that includes static tags such as department, position, and technical level, as well as dynamic tags such as commonly used software, historical failure rate, and preferred communication style.

[0065] The technical capability assessment unit is used to evaluate the technical level of users by analyzing the professionalism of the descriptions in the work orders they submit, and to determine the depth of their responses.

[0066] The personalized portal rendering unit is used to dynamically adjust the layout of the self-service portal based on the user profile and prioritize high-frequency requests.

[0067] The intelligent script adaptation unit is used to dynamically adjust the customer service robot's response scripts based on the user's emotional state and technical level.

[0068] The preventative care unit is used to proactively push care messages when abnormal logs are detected in key users or key business departments;

[0069] The privacy protection unit is used to perturb user profile data using differential privacy technology to prevent user identity re-identification.

[0070] Secondly, a method for intelligent IT operations and maintenance based on multidimensional observability and causal inference is provided, including the following steps:

[0071] The work order intelligent processing module receives work order text data, extracts semantic features through a pre-trained language model, and performs multi-dimensional feature fusion by combining structured context information to output work order classification results and dynamic priority scores.

[0072] The knowledge graph linkage module is used to construct a knowledge graph for the IT operations and maintenance domain based on a graph database. The vector similarity between the current work order and historical events is calculated through a graph neural network, and causal reasoning recommendation is performed based on a path ranking algorithm.

[0073] The SLA full lifecycle monitoring and default early warning module utilizes a streaming computing framework to consume real-time work order status change data streams. It predicts the expected resolution time of work orders through regression models and calculates the probability of SLA default risk through classification models, triggering tiered early warnings.

[0074] The system event logs are collected using the process bottleneck identification and continuous optimization module. The actual business process model is reconstructed through process mining algorithms. Deviation nodes are identified by comparing with standard processes. Resource optimization suggestions are given through discrete event simulation.

[0075] The multi-role visual collaboration module uses WebGL technology to render multi-perspective service delivery views for users, engineers, and managers, and uses a combinatorial optimization algorithm to achieve optimal matching of work orders and engineers.

[0076] The service quality quantitative assessment and closed-loop management module defines multi-dimensional service quality indicators, performs attribution analysis through interpretable machine learning models, and drives the automatic distribution and effect verification of improvement tasks.

[0077] The user profile personalization service module is used to build a user profile system that includes static and dynamic tags. Privacy is protected based on differential privacy technology, and service strategies are dynamically adjusted according to the user's technical level and emotional state.

[0078] In the above technical solution, a work order intelligent processing module is set up to receive work order text data, extract semantic features through a pre-trained language model, perform multi-dimensional feature fusion by combining structured context information, and output work order classification results and dynamic priority scores; a knowledge graph linkage module is used to build a knowledge graph in the IT operations and maintenance field based on a graph database, calculate the vector similarity between the current work order and historical events through a graph neural network, and perform causal reasoning recommendation based on a path ranking algorithm; an SLA full lifecycle monitoring and default warning module is used to consume work order status change data streams in real time based on a streaming computing framework, predict the expected resolution time of work orders through a regression model, calculate the SLA default risk probability through a classification model, and trigger tiered warnings; a process bottleneck identification and continuous optimization module is used to collect system event logs and reconstruct actual business through process mining algorithms. The system includes a process model that compares to standard processes to identify deviation points and provides resource optimization suggestions through discrete event simulation; a multi-role visual collaboration module that uses WebGL technology to render multi-perspective service delivery views for users, engineers, and managers, and achieves optimal matching of work orders and engineers based on combinatorial optimization algorithms; a service quality quantitative assessment and closed-loop management module that defines multi-dimensional service quality indicators, performs attribution analysis through interpretable machine learning models, and drives the automatic distribution and effect verification of improvement tasks; and a user profile personalized service module that builds a user profile system including static and dynamic tags, protects privacy based on differential privacy technology, and dynamically adjusts service strategies according to users' technical skills and emotional states. This system achieves automation, predictability, and intelligence in IT service management, improving SLA achievement rates and user satisfaction. Attached Figure Description

[0079] Figure 1 A structural block diagram of an IT service management system based on natural language and knowledge base provided for embodiments of this application;

[0080] Figure 2 A flowchart illustrating the IT service management method based on natural language and knowledge base provided in this application embodiment. Detailed Implementation

[0081] The present application will now be described in further detail with reference to the accompanying drawings and embodiments. Through these descriptions, the features and advantages of the present application will become clearer and more apparent.

[0082] The term “exemplary” as used herein means “serving as an example, embodiment, or illustration.” Any embodiment illustrated herein as “exemplary” is not necessarily to be construed as superior to or better than other embodiments. Although various aspects of embodiments are shown in the accompanying drawings, the drawings are not necessarily drawn to scale unless specifically indicated otherwise.

[0083] Furthermore, the technical features involved in the different embodiments of this application described below can be combined with each other as long as they do not conflict with each other. The following detailed description, in conjunction with specific accompanying drawings, illustrates the embodiments.

[0084] exist Figure 1 This application provides an IT service management system based on natural language processing and a knowledge base, comprising:

[0085] The intelligent work order processing module is used to receive work order text data, extract semantic features through a pre-trained language model, perform multi-dimensional feature fusion by combining structured context information, and output work order classification results and dynamic priority scores.

[0086] The knowledge graph linkage module is used to build a knowledge graph for the IT operations and maintenance field based on a graph database. It calculates the vector similarity between the current work order and historical events through a graph neural network and performs causal reasoning and recommendation based on a path ranking algorithm.

[0087] The SLA full lifecycle monitoring and default early warning module is used to consume real-time work order status change data streams based on a streaming computing framework, predict the expected resolution time of work orders through regression models, and calculate the probability of SLA default risk through classification models to trigger tiered early warnings.

[0088] The process bottleneck identification and continuous optimization module is used to collect system event logs, reconstruct the actual business process model through process mining algorithms, identify deviation nodes by comparing with standard processes, and provide resource optimization suggestions through discrete event simulation.

[0089] The multi-role visual collaboration module is used to render multi-perspective service delivery views for users, engineers, and managers based on WebGL technology, and to achieve optimal matching of work orders and engineers based on combinatorial optimization algorithms.

[0090] The service quality quantitative assessment and closed-loop management module is used to define multi-dimensional service quality indicators, perform attribution analysis through interpretable machine learning models, and drive the automatic distribution and effect verification of improvement tasks.

[0091] The user profile personalization service module is used to build a user profile system that includes static and dynamic tags, protects privacy based on differential privacy technology, and dynamically adjusts service strategies according to the user's technical level and emotional state.

[0092] In the above technical solution, a work order intelligent processing module is set up to receive work order text data, extract semantic features through a pre-trained language model, perform multi-dimensional feature fusion by combining structured context information, and output work order classification results and dynamic priority scores; a knowledge graph linkage module is used to build a knowledge graph in the IT operations and maintenance field based on a graph database, calculate the vector similarity between the current work order and historical events through a graph neural network, and perform causal reasoning recommendation based on a path ranking algorithm; an SLA full lifecycle monitoring and default warning module is used to consume work order status change data streams in real time based on a streaming computing framework, predict the expected resolution time of work orders through a regression model, calculate the SLA default risk probability through a classification model, and trigger tiered warnings; a process bottleneck identification and continuous optimization module is used to collect system event logs and reconstruct actual business through process mining algorithms. The system includes a process model that compares to standard processes to identify deviation points and provides resource optimization suggestions through discrete event simulation; a multi-role visual collaboration module that uses WebGL technology to render multi-perspective service delivery views for users, engineers, and managers, and achieves optimal matching of work orders and engineers based on combinatorial optimization algorithms; a service quality quantitative assessment and closed-loop management module that defines multi-dimensional service quality indicators, performs attribution analysis through interpretable machine learning models, and drives the automatic distribution and effect verification of improvement tasks; and a user profile personalized service module that builds a user profile system including static and dynamic tags, protects privacy based on differential privacy technology, and dynamically adjusts service strategies according to users' technical skills and emotional states. This system achieves automation, predictability, and intelligence in IT service management, improving SLA achievement rates and user satisfaction.

[0093] Specifically, the beneficial effects include:

[0094] 1. Significantly improves the efficiency and accuracy of work order processing. By fusing multi-dimensional features of pre-trained language models and structured contextual information, the system can automatically complete the semantic understanding and accurate classification of work orders. Combined with dynamic priority scoring, it achieves intelligent order allocation, effectively reducing manual interpretation time, lowering the misclassification rate, and significantly shortening the average response time of work orders.

[0095] 2. Enhance the intelligence of problem-solving. The knowledge graph linkage module uses graph neural networks to calculate the vector similarity between work orders and historical events, and performs causal reasoning recommendations through path ranking algorithms. This enables engineers to quickly obtain historical solutions to similar problems, reducing the cost of repeatedly troubleshooting faults and improving the first-time resolution rate.

[0096] 3. Proactively prevent SLA defaults. The SLA lifecycle monitoring module is based on real-time consumption work order status data streams using streaming computing. It predicts the expected resolution time through regression models and calculates the probability of default risk using classification models, triggering tiered early warnings. This transforms passive response into proactive intervention, effectively improving SLA achievement rates.

[0097] 4. Driving continuous process optimization. The process bottleneck identification module uses process mining algorithms to reconstruct actual business processes and compare them with standard processes to accurately locate deviation nodes. Then, through discrete event simulation, it provides resource optimization suggestions to help managers make scientific decisions, eliminate process bottlenecks, and improve overall operational efficiency.

[0098] 5. Enable efficient collaboration among multiple roles. Based on WebGL technology, multi-view visualization rendering and combined optimization algorithms ensure optimal matching of work orders and engineers, allowing different roles to obtain what they need, ensuring transparent and symmetrical information, reducing communication costs, and improving service delivery quality.

[0099] 6. Build a closed loop for continuous service quality improvement. Through interpretable machine learning models, conduct multi-dimensional attribution analysis to make improvement tasks traceable and verifiable, forming a complete closed loop of "evaluation-analysis-improvement-verification" to continuously improve service quality.

[0100] 7. Provide a personalized and privacy-secure service experience. The user profiling module, combined with differential privacy technology, dynamically adjusts service strategies based on the user's technical skills and emotional state while protecting user privacy, significantly improving user satisfaction and service warmth.

[0101] In summary, this invention systematically solves the pain points of traditional IT service management, such as high reliance on manual labor, slow response, opaque processes, and difficulty in quantifying quality, and comprehensively improves the intelligence level and user satisfaction of IT service management.

[0102] In one specific implementation scheme, it also includes:

[0103] The anomaly detection and root cause localization module is used to detect log anomalies based on the sequence autoencoding model and infer the root cause of the fault by combining the dependency relationship between Bayesian network and configuration management database.

[0104] The cross-channel interaction and unified session management module is used to integrate multi-source access through channel adapters and maintain the session state machine to achieve smooth intent migration.

[0105] The data security and compliance audit module is used to implement dynamic access control based on the attribute access control model, encrypt and store sensitive data using national cryptographic algorithms, and generate compliance audit reports.

[0106] In one specific implementation scheme, the work order intelligent processing module includes:

[0107] The semantic feature extraction unit is used to convert the work order title and description text into a high-dimensional vector representation using a fine-tuned BERT model;

[0108] The entity recognition and intent analysis unit is used to identify key entities in text and determine user intent using the BiLSTM-CRF model.

[0109] The multi-dimensional feature fusion unit is used to concatenate the text feature vector with structured features including the submitter's job level, department, and number of affected users before inputting it into the fully connected layer;

[0110] The dynamic priority calculation unit is used to incorporate the time decay factor λ and the business impact factor β to calculate the priority score;

[0111] The confidence assessment and online incremental learning unit is used to output the Softmax classification probability. Work orders below the preset threshold are automatically transferred to the manual review queue, and the model parameters are updated daily based on few-shot learning technology.

[0112] In one specific implementation scheme, the knowledge graph linkage module includes:

[0113] The knowledge extraction and graph construction unit is used to extract fault phenomena, causes, solution entities and relationships from historical work orders using natural language processing technology, and to build a graph database.

[0114] The similarity matching and ranking unit is used to calculate the cosine similarity between the current work order vector and the solution vector in the knowledge graph, retrieve the Top-K similar cases, and combine the Learning to Rank model to re-rank the recommendation results based on the historical success rate, timeliness and applicable version of the solution.

[0115] The causal reasoning recommendation unit, used in knowledge graph-based path ranking algorithms, not only recommends solutions but also recommends upstream dependencies that may lead to the failure.

[0116] The feedback loop and unknown fault clustering unit is used to record the user's adoption of the recommended solution to correct the graph relationship weights, and to use the clustering algorithm to discover emerging fault trends for work orders with no matching results.

[0117] In one specific implementation scheme, the SLA full lifecycle monitoring and default early warning module includes:

[0118] Multi-level SLA parsing units are used to convert response time, resolution time, and availability metrics into computable rule engine scripts;

[0119] The real-time stream processing unit is used to consume the work order status change data stream in real time and calculate the current elapsed time using a streaming computing framework;

[0120] The remaining time prediction unit is used to train a gradient boosting regression model based on historical resolution time data to predict the estimated resolution time (ETA) of work orders.

[0121] The default risk scoring unit is used to build a logistic regression model to calculate the probability of a work order defaulting at a specific point in the future.

[0122] The dynamic early warning triggering unit is used to automatically upgrade the work order priority and push an alarm when the probability of default exceeds the first threshold, and to trigger the emergency resource allocation process when it exceeds the second threshold.

[0123] The exemption determination unit is used to automatically identify the downtime caused by user-side reasons and deduct it from the SLA timer.

[0124] In one specific implementation scheme, the process bottleneck identification and continuous optimization module includes:

[0125] The event log collection unit is used to collect all operation logs, including timestamps, operators, and state transitions.

[0126] The process discovery unit is used to automatically reconstruct the actual business process model from logs using the Alpha Miner or Heuristics Miner algorithm.

[0127] The compliance check unit is used to compare the actual process model with the preset standard process model to identify process deviations;

[0128] The bottleneck location unit is used to calculate the average dwell time and resource utilization of each active node and identify long-tail nodes;

[0129] The simulation optimization unit is used to simulate the changes in process efficiency after resource reallocation using discrete events and provide optimization suggestions.

[0130] The root cause analysis unit is used to correlate bottleneck data with organizational structure data to analyze whether the problem is caused by improper permission configuration or lack of skills.

[0131] In one specific implementation scheme, the multi-role visual collaboration module includes:

[0132] The user panoramic view unit is used to display the work order status, processing progress bar, and estimated completion time;

[0133] The engineer's workbench unit is used to aggregate to-do work orders, knowledge base recommendations, and related configuration item topology diagrams;

[0134] The manager's cockpit unit is used to provide a macro-level view of the SLA achievement rate heatmap, team load balancing chart, and fault type distribution tree diagram.

[0135] The intelligent routing unit automatically assigns the best engineer based on the skill graph and current load using a Hungarian algorithm;

[0136] The collaborative editing unit is used to resolve conflicts based on an operation conversion algorithm when multiple engineers are editing the same work order at the same time.

[0137] The voice interaction unit integrates automatic speech recognition technology, enabling engineers to input processing progress via voice and automatically convert it into a text log.

[0138] In one specific implementation scheme, the service quality quantitative assessment and closed-loop management module includes:

[0139] The multi-dimensional indicator definition unit is used to define hard indicators, including resolution time and first call resolution rate, and soft indicators, including customer satisfaction and communication quality.

[0140] The sentiment analysis unit is used to perform sentiment polarity analysis on user replies and evaluation texts to quantify user experience.

[0141] The attribution analysis unit is used to analyze the impact of each factor on satisfaction using the SHAP value interpretation model.

[0142] The automatic follow-up unit is used to automatically trigger outbound call robots or email questionnaires to collect feedback after the work order is closed;

[0143] Improve the task distribution unit to automatically generate improvement tasks for low-scoring items and assign them to the corresponding team leaders;

[0144] The closed-loop verification unit is used to automatically compare the changes in indicators before and after the improvement in the next assessment cycle to verify the improvement effect.

[0145] In one specific implementation scheme, the user profile personalization service module includes:

[0146] The tag system construction unit is used to build a user tag system that includes static tags such as department, position, and technical level, as well as dynamic tags such as commonly used software, historical failure rate, and preferred communication style.

[0147] The technical capability assessment unit is used to evaluate the technical level of users by analyzing the professionalism of the descriptions in the work orders they submit, and to determine the depth of their responses.

[0148] The personalized portal rendering unit is used to dynamically adjust the layout of the self-service portal based on the user profile and prioritize high-frequency requests.

[0149] The intelligent script adaptation unit is used to dynamically adjust the customer service robot's response scripts based on the user's emotional state and technical level.

[0150] The preventative care unit is used to proactively push care messages when abnormal logs are detected in key users or key business departments;

[0151] The privacy protection unit is used to perturb user profile data using differential privacy technology to prevent user identity re-identification.

[0152] In one specific implementation scheme, the IT service management system based on natural language and knowledge base achieves intelligent management of the entire process from work order creation to archiving by constructing a multimodal deep learning model, a dynamic knowledge graph, a real-time stream computing engine, and a visualization graph, including:

[0153] 1. Automatic work order classification and dynamic priority determination module based on multimodal deep learning

[0154] This module utilizes BERT (Bidirectional Encoder Representations from Transformers) and its variants, combined with user context information, to achieve accurate work order classification and real-time priority adjustment. It includes:

[0155] Unit 1.1 Semantic Feature Extraction Unit: Using a fine-tuned BERT model, the work order title and description text are transformed into high-dimensional vector representations.

[0156] Unit 1.2 Entity Recognition and Intent Analysis Unit: Use the BiLSTM-CRF model to identify key entities in the text (such as server IP, error code, application name) and determine the user's intent (reporting fault, seeking advice, requesting).

[0157] Unit 1.3 Multi-dimensional Feature Fusion Unit: Concatenates text features with structured features (submitter's job title, department, number of affected users) and inputs them into a fully connected layer.

[0158] Unit 1.4 Dynamic Priority Algorithm: Introducing a time decay factor and a business impact factor, a priority calculation formula is constructed: Priority=f(Impact,Urgency,Timedecay). For example, work orders approaching their SLA deadlines automatically have their weight increased.

[0159] Specifically, by introducing a time decay factor λ and a business impact factor β, the priority score is calculated according to the following formula:

[0160] ;

[0161] Where α is the weighting coefficient, β is the business impact factor, λ is the time decay coefficient, and t is the work order survival time;

[0162] Unit 1.5 Confidence Assessment Unit: Outputs the Softmax probability value of the classification result. Work orders with a probability value lower than the threshold (e.g., 0.8) are automatically transferred to the manual review queue.

[0163] Unit 1.6 Online Incremental Learning Unit: Based on the results of manual correction, the model parameters are updated daily using few-shot learning technology to adapt to new business terms.

[0164] 2. Knowledge Graph-Based Historical Event Linkage and Intelligent Recommendation Module

[0165] This module constructs a knowledge graph in the IT operations and maintenance field, enabling related recommendations based on a "one case, one graph" approach. It includes:

[0166] Unit 2.1 Knowledge Extraction and Graph Construction: Using NLP technology, entities (fault phenomena, causes, and solutions) and relationships are extracted from historical work orders to construct the Neo4j graph database.

[0167] Unit 2.2 Similarity Matching Algorithm: Calculate the cosine similarity between the current work order vector and the solution vector in the knowledge base, and retrieve Top-K similar cases.

[0168] Unit 2.3 Causal Reasoning Recommendation Unit: Path Ranking Algorithm based on knowledge graph, which not only recommends solutions, but also recommends upstream dependencies that may lead to the failure.

[0169] Unit 2.4 Solution Ranking Model: By combining the historical success rate, timeliness, and applicable version of the solution, a Learning to Rank model is trained to re-rank the recommendation results.

[0170] Unit 2.5 Feedback Loop Unit: Records the user's adoption of the recommendation scheme, which is used to adjust the weight of the relationship in the knowledge graph.

[0171] Unit 2.6 Unknown Fault Clustering Unit: For work orders with no matching results, cluster analysis is performed using K-Means or DBSCAN algorithms to discover emerging fault trends.

[0172] 3. SLA Full Lifecycle Monitoring and Default Early Warning Module

[0173] This module, based on a streaming computing framework, enables millisecond-level monitoring and predictive alerts for Service Level Abilities (SLAs). It includes:

[0174] Unit 3.1 Multi-level SLA parsing unit: Supports parsing SLAs (response time, resolution time, availability metrics) in different dimensions and converting them into computable rule engine scripts.

[0175] Unit 3.2 Real-time Stream Processing Unit: Adopts the Apache Flink framework to consume work order status change data streams in real time and calculate the current time elapsed.

[0176] Unit 3.3 Remaining Time Prediction Algorithm: Based on historical resolution time data, an XGBoost regression model is trained to predict the estimated time to resolution (ETA) of the current work order.

[0177] Unit 3.4 Default Risk Scoring Model: Construct a Logistic Regression model to calculate the probability P(SLA_Breach) of a work order defaulting at a specific point in the future.

[0178] Specifically, the formula is:

[0179] ;

[0180] Among them, xi includes the current time consumption percentage, historical resolution volatility, and engineer workload index.

[0181] Unit 3.5 Dynamic Early Warning Trigger Unit: When P>0.7, automatically upgrade the work order priority and push an alarm to the supervisor; when P>0.9, trigger the emergency resource allocation process.

[0182] Unit 3.6 Exemption Decision Unit: Automatically identifies downtime caused by user-side reasons (such as failure to provide logs) and deducts it from the SLA timer.

[0183] 4. IT Service Process Bottleneck Identification and Continuous Optimization Module

[0184] This module uses process mining technology to visually identify inefficient steps in a process. It includes:

[0185] Unit 4.1 Event Log Collection Unit: Collects all operation logs (Event Logs) in the ITSM system, including timestamps, operators, and state transitions.

[0186] Unit 4.2 Process Discovery Algorithm: The Alpha Miner or Heuristics Miner algorithm is used to automatically reconstruct the actual business process model (Petri net) from the logs.

[0187] Unit 4.3 Compliance Check Unit: Compare the actual process model with the preset standard process model (BPMN) to identify deviations (Deviation Detection).

[0188] Unit 4.4 Bottleneck Localization Algorithm: Calculate the average dwell time and resource utilization of each active node to identify "long tail" nodes.

[0189] Unit 4.5 Simulation Optimization Suggestion Unit: Use Discrete Event Simulation (DES) to simulate the effect of resource reallocation and provide optimization suggestions (such as increasing a certain group of manpower).

[0190] Unit 4.6 Root Cause Analysis Unit: Correlate bottleneck data with organizational structure data to analyze whether the problem is caused by improper permission configuration or lack of skills.

[0191] 5. Service delivery visualization and collaboration module for multiple roles

[0192] This module provides a WebGL-based 3D visualization dashboard for various roles. It includes:

[0193] Unit 5.1 User Panorama View: Displays the status of user-submitted work orders, processing progress bar, and estimated completion time, and supports real-time IM chat embedding.

[0194] Unit 5.2 Engineer's Workbench: Aggregates to-do work orders, knowledge base recommendations, and associates CI (configuration item) topology diagrams to reduce context switching.

[0195] Unit 5.3 Manager's Dashboard: A macro view of the SLA achievement rate heatmap, team load balancing chart, and fault type distribution tree diagram.

[0196] Unit 5.4 Intelligent Routing and Collaboration Unit: Based on the skill map and current load, the optimal engineer is automatically assigned using the Hungarian Algorithm.

[0197] Unit 5.5 Conflict Detection Unit: When two engineers are editing the same work order at the same time, the OT algorithm is used to resolve collaborative editing conflicts.

[0198] Unit 5.6 Voice Interaction Unit: Integrates ASR (Automatic Speech Recognition) technology, allowing engineers to input processing progress via voice, which is automatically converted into a text log.

[0199] 6. Service quality quantitative assessment and improvement closed-loop management module

[0200] This module establishes a multi-dimensional service quality evaluation system. This includes:

[0201] Unit 6.1 Multi-dimensional indicator definition unit: Define hard indicators (resolvement time, first call resolution rate) and soft indicators (customer satisfaction, communication quality).

[0202] Unit 6.2 Sentiment Analysis Unit: Perform sentiment polarity analysis (Positive / Negative) on user responses and evaluation texts to quantify user experience.

[0203] Unit 6.3 Attribution Analysis Algorithm: Using SHAP (SHapley Additive exPlanations) values ​​to interpret the model and analyze which factors have the greatest impact on satisfaction.

[0204] Unit 6.4 Automated Follow-up Robot: After a work order is closed, an outbound call robot or email questionnaire is automatically triggered to collect feedback.

[0205] Unit 6.5 Improved Task Distribution Unit: For low-scoring items, automatically generate improvement tasks and assign them to the corresponding team leaders.

[0206] Unit 6.6 Closed-Loop Verification Unit: In the next assessment cycle, automatically compare the changes in indicators before and after the improvement to verify the improvement effect.

[0207] 7. Personalized service experience optimization module based on user profiles

[0208] This module builds a 360-degree user profile to provide differentiated services. It includes:

[0209] Unit 7.1 Tag System Construction Unit: Static tags (department, position, technical level) + Dynamic tags (commonly used software, historical failure rate, preferred communication style).

[0210] Unit 7.2 Technical Capability Assessment Model: By analyzing the professionalism of the work order descriptions submitted by users, the technical level is assessed, and the depth of the response content is determined.

[0211] Unit 7.3 Personalized Portal Rendering: Dynamically adjust the layout of the self-service portal based on user profiles, prioritizing high-frequency needs.

[0212] Unit 7.4 Intelligent Script Adaptation: Dynamically adjust the customer service robot's response script based on the user's emotional state (anger / calm) and technical level.

[0213] Unit 7.5 Preventive Care Unit: When abnormal logs are detected in VIP users or key business departments, proactive care messages are pushed without requiring users to report the problem.

[0214] Unit 7.6 Privacy Protection Unit: Differential privacy technology is used to process user profile data to ensure compliance.

[0215] 8. Anomaly Detection and Root Cause Localization Assistance Module

[0216] This module performs intelligent analysis of system logs and monitoring data. This includes:

[0217] Unit 8.1 Log Pattern Recognition: Use the LSTM-Autoencoder model to learn normal log patterns and detect abnormal log sequences.

[0218] Unit 8.2 Anomaly Detection: Based on STL (Seasonal-Trend decomposition) time series decomposition, detect sudden changes in indicators such as CPU and memory.

[0219] Unit 8.3 Topology Association Analysis: Combining the dependencies of CMDB (Configuration Management Database), inferring the root cause device of the fault through Bayesian network.

[0220] Unit 8.4 Alarm Convergence Algorithm: Merge and deduplicate a large number of repeated alarms within a short period of time to extract the core alarm information.

[0221] Unit 8.5 Fault Propagation Chain Construction: Visualizing the propagation path of faults from applications to middleware and then to infrastructure.

[0222] Unit 8.6 Automated Repair Recommendations: For known fault patterns, directly call the predefined automated script (Runbook) for repair.

[0223] 9. Cross-channel interaction and unified session management module

[0224] This module integrates multiple channels including email, ChatOps, and mobile. It includes:

[0225] Unit 9.1 Channel Adapter: Unified encapsulation of API interfaces such as Email, Slack, DingTalk, and WeChat Work.

[0226] Unit 9.2 Session State Machine: Maintains the multi-turn dialogue context of the user and prevents the user from repeatedly entering information.

[0227] Unit 9.3 Smooth Intent Transfer: When a user is switched from a robot to a human, contextual information is automatically carried, eliminating the need for a human to ask again.

[0228] Unit 9.4 Rich Media Support: Supports users to upload screenshots, videos, and log files, and performs OCR recognition and content parsing.

[0229] Unit 9.5 Intelligent form filling: Automatically extract key information from the dialogue to generate standardized work orders for user confirmation.

[0230] Unit 9.6 Channel Preference Learning: Learn the feedback channels most frequently used by users and prioritize those channels when notifications are needed.

[0231] 10. Data Security and Compliance Audit Module

[0232] This module ensures the system operates safely and compliantly. It includes:

[0233] Unit 10.1 Sensitive Information De-identification: Real-time detection of ID card number, mobile phone number, and password in work orders, and masking processing.

[0234] Unit 10.2 Dynamic Access Control: Based on the ABAC (Attribute-Based Access Control) model, data access permissions are dynamically granted according to user attributes.

[0235] Unit 10.3 Operation Tracking: Records all data addition, deletion, modification and query operations in an immutable manner, generating audit trails.

[0236] Unit 10.4 Data Encryption Storage: Use national cryptographic algorithms to encrypt and store sensitive fields (such as server passwords).

[0237] Unit 10.5 Compliance Report Generation: Automatically generates compliance report documents that comply with standards such as ISO 20000 and GDPR.

[0238] Unit 10.6 Threat Awareness: Monitor abnormal batch data export behavior and block potential internal data leakage risks in real time.

[0239] In a specific feasible implementation, the process of work order classification and prioritization includes:

[0240] Suppose a user submits a work order stating: "The master-slave synchronization delay in the production environment order database exceeds 300 seconds, causing transaction failures and impacting revenue."

[0241] 1. Preprocessing: The system removes stop words and performs word segmentation.

[0242] 2. Vectorization: The BERT model encodes the sentence as a 768-dimensional vector Vtext.

[0243] 3. Feature Fusion: The system retrieves user attributes: This user belongs to the "Finance Department," has a job title of "Director," and is estimated to affect 500 users. A structured vector Vstruct is generated.

[0244] 4. Classification Calculation: Calculation of Fully Connected Layers The Softmax output classification probabilities are: ["Database failure": 0.95, "Network failure": 0.03, ...]. The classification is determined as "Database failure".

[0245] 5. Priority Calculation:

[0246] Impact: High (impacts revenue).

[0247] Urgency: High (transaction failed).

[0248] Timedecay: If the current time is 17:30 (before the end of the workday), the weight increases.

[0249] The final decision was P1 (highest priority).

[0250] In a specific feasible implementation, the SLA default warning process includes:

[0251] For the above P1 work order, the system is set to resolve within 2 hours.

[0252] 1. Real-time stream processing: Flink monitors the status of work orders and records the start time as T0.

[0253] 2. ETA Prediction: The model predicts the end time Tpred = T0 + 90min based on the historical average time to resolve faults (MTTR) of 90 minutes.

[0254] 3. Risk Assessment: The current time Tnow has 30 minutes remaining until the deadline Tdeadline.

[0255] 4. Warning Trigger: The system calculates that the probability of resolving the issue within the remaining 30 minutes is only 20% (i.e., a default probability of 80%). The system will automatically execute:

[0256] Send an alarm SMS to the duty manager.

[0257] Pin the work order to the top of the engineer's workbench.

[0258] Unlock the backup expert resource pool.

[0259] In a specific implementable solution, the knowledge base recommendation process includes:

[0260] 1. Vector Retrieval: The system calculates the similarity between the current work order vector and all solution vectors related to "database master-slave synchronization" in the knowledge base.

[0261] 2. Knowledge Graph Reasoning: The knowledge graph shows that "master-slave synchronization delay" is usually related to "excessive disk I / O", "Binlog write blocking", and "network packet loss".

[0262] 3. Scheme Ranking: The system recommends three schemes:

[0263] Option A: Check disk space (historical success rate 99%).

[0264] Option B: Restart the synchronization thread (historical success rate 85%).

[0265] Option C: Roll back large transactions (historical success rate 70%).

[0266] 4. Presentation: The system prioritizes displaying the operation steps of Solution A, along with links to relevant configuration items (CI).

[0267] exist Figure 2 This application provides an IT intelligent operation and maintenance method based on multidimensional observability and causal inference, including the following steps:

[0268] The work order intelligent processing module receives work order text data, extracts semantic features through a pre-trained language model, and performs multi-dimensional feature fusion by combining structured context information to output work order classification results and dynamic priority scores.

[0269] The knowledge graph linkage module is used to construct a knowledge graph for the IT operations and maintenance domain based on a graph database. The vector similarity between the current work order and historical events is calculated through a graph neural network, and causal reasoning recommendation is performed based on a path ranking algorithm.

[0270] The SLA full lifecycle monitoring and default early warning module utilizes a streaming computing framework to consume real-time work order status change data streams. It predicts the expected resolution time of work orders through regression models and calculates the probability of SLA default risk through classification models, triggering tiered early warnings.

[0271] The system event logs are collected using the process bottleneck identification and continuous optimization module. The actual business process model is reconstructed through process mining algorithms. Deviation nodes are identified by comparing with standard processes. Resource optimization suggestions are given through discrete event simulation.

[0272] The multi-role visual collaboration module uses WebGL technology to render multi-perspective service delivery views for users, engineers, and managers, and uses a combinatorial optimization algorithm to achieve optimal matching of work orders and engineers.

[0273] The service quality quantitative assessment and closed-loop management module defines multi-dimensional service quality indicators, performs attribution analysis through interpretable machine learning models, and drives the automatic distribution and effect verification of improvement tasks.

[0274] The user profile personalization service module is used to build a user profile system that includes static and dynamic tags. Privacy is protected based on differential privacy technology, and service strategies are dynamically adjusted according to the user's technical level and emotional state.

[0275] In the above technical solution, a work order intelligent processing module is set up to receive work order text data, extract semantic features through a pre-trained language model, perform multi-dimensional feature fusion by combining structured context information, and output work order classification results and dynamic priority scores; a knowledge graph linkage module is used to build a knowledge graph in the IT operations and maintenance field based on a graph database, calculate the vector similarity between the current work order and historical events through a graph neural network, and perform causal reasoning recommendation based on a path ranking algorithm; an SLA full lifecycle monitoring and default warning module is used to consume work order status change data streams in real time based on a streaming computing framework, predict the expected resolution time of work orders through a regression model, calculate the SLA default risk probability through a classification model, and trigger tiered warnings; a process bottleneck identification and continuous optimization module is used to collect system event logs and reconstruct actual business through process mining algorithms. The system includes a process model that compares to standard processes to identify deviation points and provides resource optimization suggestions through discrete event simulation; a multi-role visual collaboration module that uses WebGL technology to render multi-perspective service delivery views for users, engineers, and managers, and achieves optimal matching of work orders and engineers based on combinatorial optimization algorithms; a service quality quantitative assessment and closed-loop management module that defines multi-dimensional service quality indicators, performs attribution analysis through interpretable machine learning models, and drives the automatic distribution and effect verification of improvement tasks; and a user profile personalized service module that builds a user profile system including static and dynamic tags, protects privacy based on differential privacy technology, and dynamically adjusts service strategies according to users' technical skills and emotional states. This system achieves automation, predictability, and intelligence in IT service management, improving SLA achievement rates and user satisfaction.

[0276] In one specific implementation scheme, the IT intelligent operation and maintenance method based on multidimensional observability and causal inference includes the following steps:

[0277] S1: Obtain work order data, perform semantic analysis using a pre-trained language model, and perform entity extraction and intent recognition using a sequence labeling model;

[0278] S2: The text features are fused with the structured context features, input into the classification model to output the work order category, and the dynamic priority score is calculated based on the priority formula that includes the time decay factor and the business impact factor.

[0279] S3: Perform similarity matching between the current work order vector and the historical solution vector in the knowledge graph, perform causal reasoning recommendation based on the path ranking algorithm, and re-rank the recommendation results using the ranking model;

[0280] S4: Based on the streaming computing framework, monitor the status of work orders in real time, use regression models to predict the expected resolution time, use classification models to calculate the probability of SLA default risk, and trigger graded warnings when the threshold is exceeded.

[0281] S5: Collect system event logs, use process mining algorithms to reconstruct actual business processes, identify bottleneck nodes by comparing with standard processes, and provide optimization suggestions through discrete event simulation;

[0282] S6: Define multi-dimensional service quality indicators, use interpretable models for attribution analysis, automatically distribute improvement tasks, and verify the improvement effects in the next cycle;

[0283] S7: Build a user profile system, protect privacy based on differential privacy technology, and dynamically adjust service strategies according to users' technical skills and emotional state.

[0284] In step S2, when the Softmax probability output by the classification model is lower than the preset confidence threshold, the work order is automatically transferred to the manual review queue, and the model parameters are incrementally updated based on the manual review results using small sample learning technology to adapt to new business terms.

[0285] Those skilled in the art will know that this application can be implemented as a system, method, or computer program product.

[0286] Therefore, this disclosure can be implemented in the following forms: it can be entirely hardware, entirely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software, generally referred to herein as a "circuit," "module," or "system." Furthermore, in some embodiments, this application can also be implemented as a computer program product in one or more computer-readable media, the computer-readable media containing computer-readable program code.

[0287] Any combination of one or more computer-readable media may be used. A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus, or device.

[0288] Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of this application. Based on this, various substitutions and improvements can be made to this application, all of which fall within the protection scope of this application.

Claims

1. An IT service management system based on natural language processing and a knowledge base, characterized in that, include: The intelligent work order processing module is used to receive work order text data, extract semantic features through a pre-trained language model, perform multi-dimensional feature fusion by combining structured context information, and output work order classification results and dynamic priority scores. The knowledge graph linkage module is used to build a knowledge graph for the IT operations and maintenance field based on a graph database. It calculates the vector similarity between the current work order and historical events through a graph neural network and performs causal reasoning and recommendation based on a path ranking algorithm. The SLA full lifecycle monitoring and default early warning module is used to consume real-time work order status change data streams based on a streaming computing framework, predict the expected resolution time of work orders through regression models, and calculate the probability of SLA default risk through classification models to trigger tiered early warnings. The process bottleneck identification and continuous optimization module is used to collect system event logs, reconstruct the actual business process model through process mining algorithms, identify deviation nodes by comparing with standard processes, and provide resource optimization suggestions through discrete event simulation. The multi-role visual collaboration module is used to render multi-perspective service delivery views for users, engineers, and managers based on WebGL technology, and to achieve optimal matching of work orders and engineers based on combinatorial optimization algorithms. The service quality quantitative assessment and closed-loop management module is used to define multi-dimensional service quality indicators, perform attribution analysis through interpretable machine learning models, and drive the automatic distribution and effect verification of improvement tasks. The user profile personalization service module is used to build a user profile system that includes static and dynamic tags, protects privacy based on differential privacy technology, and dynamically adjusts service strategies according to the user's technical level and emotional state.

2. The IT service management system based on natural language and knowledge base according to claim 1, characterized in that, Also includes: The anomaly detection and root cause localization module is used to detect log anomalies based on the sequence autoencoding model and infer the root cause of the fault by combining the dependency relationship between Bayesian network and configuration management database. The cross-channel interaction and unified session management module is used to integrate multi-source access through channel adapters and maintain the session state machine to achieve smooth intent migration. The data security and compliance audit module is used to implement dynamic access control based on the attribute access control model, encrypt and store sensitive data using national cryptographic algorithms, and generate compliance audit reports.

3. The IT service management system based on natural language and knowledge base according to claim 2, characterized in that, The intelligent work order processing module includes: The semantic feature extraction unit is used to convert the work order title and description text into a high-dimensional vector representation using a fine-tuned BERT model; The entity recognition and intent analysis unit is used to identify key entities in text and determine user intent using the BiLSTM-CRF model. The multi-dimensional feature fusion unit is used to concatenate the text feature vector with structured features including the submitter's job level, department, and number of affected users before inputting it into the fully connected layer; The dynamic priority calculation unit is used to incorporate the time decay factor λ and the business impact factor β to calculate the priority score; The confidence assessment and online incremental learning unit is used to output the Softmax classification probability. Work orders below the preset threshold are automatically transferred to the manual review queue, and the model parameters are updated daily based on few-shot learning technology.

4. The IT service management system based on natural language and knowledge base according to claim 3, characterized in that, The knowledge graph linkage module includes: The knowledge extraction and graph construction unit is used to extract fault phenomena, causes, solution entities and relationships from historical work orders using natural language processing technology, and to build a graph database. The similarity matching and ranking unit is used to calculate the cosine similarity between the current work order vector and the solution vector in the knowledge graph, retrieve the Top-K similar cases, and combine the Learning to Rank model to re-rank the recommendation results based on the historical success rate, timeliness and applicable version of the solution. The causal reasoning recommendation unit, used in knowledge graph-based path ranking algorithms, not only recommends solutions but also recommends upstream dependencies that may lead to the failure. The feedback loop and unknown fault clustering unit is used to record the user's adoption of the recommended solution to correct the graph relationship weights, and to use the clustering algorithm to discover emerging fault trends for work orders with no matching results.

5. The IT service management system based on natural language and knowledge base according to claim 4, characterized in that, The SLA full lifecycle monitoring and default early warning module includes: Multi-level SLA parsing units are used to convert response time, resolution time, and availability metrics into computable rule engine scripts; The real-time stream processing unit is used to consume the work order status change data stream in real time and calculate the current elapsed time using a streaming computing framework; The remaining time prediction unit is used to train a gradient boosting regression model based on historical resolution time data to predict the estimated resolution time (ETA) of work orders. The default risk scoring unit is used to build a logistic regression model to calculate the probability of a work order defaulting at a specific point in the future. The dynamic early warning triggering unit is used to automatically upgrade the work order priority and push an alarm when the probability of default exceeds the first threshold, and to trigger the emergency resource allocation process when it exceeds the second threshold. The exemption determination unit is used to automatically identify the downtime caused by user-side reasons and deduct it from the SLA timer.

6. The IT service management system based on natural language and knowledge base according to claim 5, characterized in that, The process bottleneck identification and continuous optimization module includes: The event log collection unit is used to collect all operation logs, including timestamps, operators, and state transitions. The process discovery unit is used to automatically reconstruct the actual business process model from logs using the Alpha Miner or Heuristics Miner algorithm. The compliance check unit is used to compare the actual process model with the preset standard process model to identify process deviations; The bottleneck location unit is used to calculate the average dwell time and resource utilization of each active node and identify long-tail nodes; The simulation optimization unit is used to simulate the changes in process efficiency after resource reallocation using discrete events and provide optimization suggestions. The root cause analysis unit is used to correlate bottleneck data with organizational structure data to analyze whether the problem is caused by improper permission configuration or lack of skills.

7. The IT service management system based on natural language and knowledge base according to claim 6, characterized in that, The multi-role visual collaboration module includes: The user panoramic view unit is used to display the work order status, processing progress bar, and estimated completion time; The engineer's workbench unit is used to aggregate to-do work orders, knowledge base recommendations, and related configuration item topology diagrams; The manager's cockpit unit is used to provide a macro-level view of the SLA achievement rate heatmap, team load balancing chart, and fault type distribution tree diagram. The intelligent routing unit automatically assigns the best engineer based on the skill graph and current load using a Hungarian algorithm; The collaborative editing unit is used to resolve conflicts based on an operation conversion algorithm when multiple engineers are editing the same work order at the same time. The voice interaction unit integrates automatic speech recognition technology, enabling engineers to input processing progress via voice and automatically convert it into a text log.

8. The IT service management system based on natural language and knowledge base according to claim 7, characterized in that, The service quality quantitative assessment and closed-loop management module includes: The multi-dimensional indicator definition unit is used to define hard indicators, including resolution time and first call resolution rate, and soft indicators, including customer satisfaction and communication quality. The sentiment analysis unit is used to perform sentiment polarity analysis on user replies and evaluation texts to quantify user experience. The attribution analysis unit is used to analyze the impact of each factor on satisfaction using the SHAP value interpretation model. The automatic follow-up unit is used to automatically trigger outbound call robots or email questionnaires to collect feedback after the work order is closed; Improve the task distribution unit to automatically generate improvement tasks for low-scoring items and assign them to the corresponding team leaders; The closed-loop verification unit is used to automatically compare the changes in indicators before and after the improvement in the next assessment cycle to verify the improvement effect.

9. The IT service management system based on natural language and knowledge base according to claim 8, characterized in that, The user profile personalization service module includes: The tag system construction unit is used to build a user tag system that includes static tags such as department, position, and technical level, as well as dynamic tags such as commonly used software, historical failure rate, and preferred communication style. The technical capability assessment unit is used to evaluate the technical level of users by analyzing the professionalism of the descriptions in the work orders they submit, and to determine the depth of their responses. The personalized portal rendering unit is used to dynamically adjust the layout of the self-service portal based on the user profile and prioritize high-frequency requests. The intelligent script adaptation unit is used to dynamically adjust the customer service robot's response scripts based on the user's emotional state and technical level. The preventative care unit is used to proactively push care messages when abnormal logs are detected in key users or key business departments; The privacy protection unit is used to perturb user profile data using differential privacy technology to prevent user identity re-identification.

10. An IT intelligent operation and maintenance method based on multidimensional observability and causal inference, characterized in that, Includes the following steps: The work order intelligent processing module receives work order text data, extracts semantic features through a pre-trained language model, and performs multi-dimensional feature fusion by combining structured context information to output work order classification results and dynamic priority scores. The knowledge graph linkage module is used to construct a knowledge graph for the IT operations and maintenance domain based on a graph database. The vector similarity between the current work order and historical events is calculated through a graph neural network, and causal reasoning recommendation is performed based on a path ranking algorithm. The SLA full lifecycle monitoring and default early warning module utilizes a streaming computing framework to consume real-time work order status change data streams. It predicts the expected resolution time of work orders through regression models and calculates the probability of SLA default risk through classification models, triggering tiered early warnings. The system event logs are collected using the process bottleneck identification and continuous optimization module. The actual business process model is reconstructed through process mining algorithms. Deviation nodes are identified by comparing with standard processes. Resource optimization suggestions are given through discrete event simulation. The multi-role visual collaboration module uses WebGL technology to render multi-perspective service delivery views for users, engineers, and managers, and uses a combinatorial optimization algorithm to achieve optimal matching of work orders and engineers. The service quality quantitative assessment and closed-loop management module defines multi-dimensional service quality indicators, performs attribution analysis through interpretable machine learning models, and drives the automatic distribution and effect verification of improvement tasks. The user profile personalization service module is used to build a user profile system that includes static and dynamic tags. Privacy is protected based on differential privacy technology, and service strategies are dynamically adjusted according to the user's technical level and emotional state.