Network anomaly positioning method, device and equipment and readable storage medium

By segmenting the network service flow transmission link and using a prediction model to analyze transmission characteristic values, combined with network self-labeling to generate training samples, the problems of low efficiency and insufficient accuracy in network anomaly localization are solved, and fast and accurate network anomaly localization is achieved.

CN122476012APending Publication Date: 2026-07-28HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2025-01-27
Publication Date
2026-07-28

AI Technical Summary

Technical Problem

Existing technologies for locating network anomalies are inefficient, produce inaccurate results, and are costly in terms of manpower, making it difficult to quickly and accurately pinpoint the location of network anomalies.

Method used

By segmenting the service flow transmission link, obtaining the transmission characteristic value of each segment, and using a prediction model to analyze these characteristic values ​​to determine whether the network is abnormal, and combining the network self-labeling method to generate training samples, the precise location of network anomalies can be achieved.

Benefits of technology

It enables rapid and accurate location of network anomalies, improving the efficiency and accuracy of network anomaly localization while reducing the cost and manpower required for training models.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122476012A_ABST
    Figure CN122476012A_ABST
Patent Text Reader

Abstract

The application provides a network anomaly positioning method and device, equipment and a readable storage medium, relates to the technical field of communication, and is applied to an anomaly positioning device. The method comprises the following steps: obtaining a first segment characteristic value, the first segment characteristic value being a value of a transmission characteristic of a first network segment in a network; determining N segment characteristic comparison values, the N segment characteristics comprising transmission characteristics of N network segments in the network, each segment characteristic comparison value in the N segment characteristic comparison values being within a reference value range of the transmission characteristic of the corresponding segment; inputting the N segment characteristic comparison values and the first segment characteristic value into a first prediction model to obtain a first output of the first prediction model, the first prediction model being used for determining whether the network is an abnormal network based on N+1 values corresponding to N+1 segment characteristics; and determining whether the first network segment is an abnormal network segment according to the first output. The application is used for solving the problem of low positioning efficiency when positioning the network anomaly position.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a method, apparatus, device, and readable storage medium for locating network anomalies. Background Technology

[0002] Network anomalies can degrade service quality, leading to a poor user experience. To improve user experience, it's necessary to troubleshoot network anomalies and pinpoint the source of the problem. Current methods for locating network anomalies primarily rely on manual intervention. Specifically, after a user reports a poor experience, network maintenance personnel manually investigate the network based on the complaint, locate the anomaly, and then perform maintenance accordingly. While this method addresses the issue of poor user experience, it suffers from low efficiency and high labor costs. Therefore, quickly locating network anomalies and troubleshooting network faults has become a pressing problem. Summary of the Invention

[0003] This application provides a method, apparatus, device, and readable storage medium for locating network anomalies, which solves the problem of low location efficiency when locating network anomalies.

[0004] Firstly, a method for locating network anomalies is provided, the method comprising:

[0005] When a service flow is transmitted through a service flow transmission link, the transmission characteristic value (measured value) of the first network segment of that service flow transmission link is obtained, i.e., the first segment characteristic value. Then, the comparison values ​​of the N segment characteristics corresponding to the other N network segments of the service flow transmission link are determined to obtain the corresponding N segment characteristic values. Here, the N segment characteristics indicate the transmission characteristics of the other N network segments, and the comparison value of each segment characteristic is a value within the reference value range of each segment characteristic. Then, the first segment characteristic value and the N segment characteristic comparison values ​​are input into a first prediction model to obtain the first output of the first prediction model. The first prediction model is used to determine whether the network is an abnormal network based on the N+1 values ​​corresponding to the N+1 segment characteristics of the N+1 network segments. Thus, based on the first output, it can be determined whether the transmission characteristics of the first network segment are the key characteristics that cause the network to become an abnormal network, thereby determining whether the first network segment is an abnormal network segment.

[0006] In this application, the input to the first prediction model is obtained by retaining the transmission characteristic value of the first network segment and replacing the transmission characteristic values ​​of other network segments as comparison values. Then, based on the output of the first prediction model, it is determined whether the transmission characteristic of the first network segment is a key segment feature causing the network to become an anomalous. If it is, the first network segment is an anomalous segment; otherwise, it is not. In this way, by analyzing the key segment features that cause the network to become an anomalous, anomalous segments in the network can be accurately located. Therefore, this application can quickly and accurately locate network anomalies, improving the efficiency of network anomaly localization.

[0007] In one possible implementation, after determining that the first network segment is an anomalous segment, the transmission characteristic value (measured value) of the first sub-network segment within the first network segment is further obtained, i.e., the first sub-segment characteristic value. Then, comparison values ​​of the M sub-segment characteristics corresponding to the other M sub-network segments of the first network segment are determined to obtain corresponding values ​​for the M sub-segment characteristics. Here, the M sub-segment characteristics indicate the transmission characteristics of the other M sub-network segments, and the comparison value for each sub-segment characteristic is a value within the reference value range of each sub-segment characteristic. Then, the first sub-segment characteristic value and the comparison values ​​of the M sub-segment characteristics are input into a second prediction model to obtain a second output of the second prediction model. The second prediction model is used to determine whether a network segment is an anomalous segment based on the M+1 values ​​corresponding to the M+1 sub-segment characteristics of the M+1 sub-network segments. In this way, based on the second output, it can be determined whether the transmission characteristics of the first sub-network segment are the key characteristics that cause the first network segment to become an abnormal segment, thereby determining whether the first sub-network segment is an abnormal sub-network segment in the first network segment.

[0008] In this implementation, the input to the second prediction model is obtained by retaining the transmission characteristic values ​​of the first sub-network segment and replacing the transmission characteristic values ​​of other sub-network segments as comparison values. Then, based on the output of the second prediction model, it is determined whether the transmission characteristic of the first sub-network segment is a key sub-segment characteristic that causes the first network segment to become an anomalous segment. If it is, the first sub-network segment is an anomalous sub-segment; otherwise, it is not. In this way, by analyzing the key sub-segment characteristics that cause a network segment to become an anomalous segment, the anomalous sub-segments within the anomalous segments can be accurately located. Therefore, this implementation can accurately locate network anomalies within a smaller range, further improving the accuracy of network anomaly localization.

[0009] In one possible implementation, when determining the N segment feature comparison values ​​corresponding to the other N network segments, the values ​​(measured values) of the N segment features corresponding to the other N network segments are first obtained based on the network, i.e., N segment feature values. Then, based on the reference value range of each segment feature, the N segment feature values ​​are initially screened to determine the abnormal and non-abnormal segment feature values ​​among the N segment features. For a segment feature value, if the segment feature value is an abnormal segment feature value, then the segment feature value is replaced with the reference value of the segment feature; if the segment feature value is a normal segment feature value, then the segment feature value is retained. In this way, the N segment feature comparison values ​​corresponding to the N segment features are obtained. It can be understood that all N segment feature comparison values ​​are within the reference value range of their respective segment features. In this implementation, the values ​​of the transmission characteristics of the other N segments are all controlled within their respective reference value ranges, and only the value of the transmission characteristics of the first network segment is retained. In this way, the output of the first prediction model can reflect the degree of influence of the transmission characteristics of the first network segment on whether the network becomes an abnormal network, and thus determine whether the first network segment is abnormal based on the output of the first prediction model.

[0010] In one possible implementation, the reference value for each segment feature is determined based on at least one historical feature value for each segment feature. The historical feature values ​​reflect the changing patterns of the segment features, and the normal value range for each segment feature can be determined based on its historical feature value. This allows for the precise filtering out of abnormal segment feature values ​​among the segment feature values ​​of each segment feature.

[0011] In one possible implementation, when a service flow is transmitted through a service flow transmission link, the number of low-quality service flows is determined based on the key performance indicators (KPIs) of each service flow. When the number of low-quality service flows exceeds or equals a preset threshold, a network anomaly is identified. Then, the transmission characteristics of each network segment of the service flow transmission link are obtained to locate the abnormal network location. In this way, by monitoring whether service flows will cause poor quality experiences, network anomalies can be quickly detected, and the abnormal network location can be pinpointed. This improves the timeliness and efficiency of network anomaly location, thereby enhancing network security and stability.

[0012] In one possible implementation, when the network transmits service flows, network traffic is collected in real time to obtain N+1 segment feature values ​​corresponding to the transmission characteristics of N+1 network segments. Then, the quality status of each service flow in the network traffic is monitored. This quality status indicates whether the service flow is a poor-quality service flow. Next, based on the quality status of each service flow, it is determined whether the network is abnormal, and a corresponding network label is generated. Then, first training data is generated based on the N+1 segment feature values ​​and network labels, so that a first prediction model can be trained subsequently based on the first training data. In this embodiment, the first training data can be generated in real time through network self-labeling, and multiple rounds of online training of the first prediction model can be completed based on the first training data. In this way, it is not necessary to obtain the first training samples through manual labeling, which greatly improves the efficiency of generating the first training samples, thereby improving the training efficiency of the first prediction model and reducing the training cost of the first prediction model. Furthermore, the first prediction model has self-learning capabilities and can update with changes in the network environment, improving the accuracy of the first prediction model.

[0013] In one possible implementation, when the network transmits service traffic, network traffic is collected in real time to obtain M+1 sub-segment feature values ​​corresponding to the transmission characteristics of M+1 network sub-segments of each network segment. Then, based on the N+1 segment feature values ​​and the first prediction model, it is determined whether each network segment is abnormal, and network labels corresponding to each network segment are generated. Next, second training data is generated based on the M+1 sub-segment feature values ​​and the corresponding network labels of the network segments, so that the second prediction model can be trained subsequently based on the second training data. In this embodiment, the second training data can be generated in real time through network self-labeling, and multiple rounds of online training of the second prediction model can be completed based on the second training data. This eliminates the need for manual labeling to obtain second training samples, greatly improving the efficiency of generating second training samples, thereby improving the training efficiency of the second prediction model and reducing its training cost. Furthermore, the second prediction model has self-learning capabilities and can update with changes in the network environment, improving the accuracy of the second prediction model.

[0014] Secondly, a network anomaly location device is provided, comprising: an acquisition unit for acquiring a first segment feature value, wherein the first segment feature value is the value of the transmission feature of a first network segment in the network; and a processing unit for determining N segment feature comparison values, wherein the N segment feature comparison values ​​correspond one-to-one with the N segment features, the N segment features include the transmission features of the N network segments in the network, and each segment feature comparison value is within the reference value range of the transmission feature of the corresponding segment, where N is a positive integer; inputting the N segment feature comparison values ​​and the first segment feature value into a first prediction model to obtain a first output of the first prediction model, wherein the first prediction model is used to determine whether the network is an abnormal network based on the N+1 values ​​corresponding to the N+1 segment features; and determining whether the first network segment is an abnormal network segment based on the first output.

[0015] In one possible implementation, the first network segment is an abnormal network segment, and the first network segment includes a first sub-network segment;

[0016] The acquisition unit is further configured to: acquire the first sub-segment feature value, wherein the first sub-segment feature value is the value of the transmission feature of the first sub-network segment; the processing unit is further configured to: determine M sub-segment feature comparison values, wherein the M sub-segment feature comparison values ​​correspond one-to-one with the M sub-segment features, wherein the M sub-segment features include the transmission features of the M sub-network segments in the first network segment, wherein each sub-segment feature comparison value in the M sub-segment features is within the reference value range of the corresponding sub-segment feature, and M is a positive integer; the processing unit is further configured to: input the M sub-segment feature comparison values ​​and the first sub-segment feature value into the second prediction model to obtain the second output of the second prediction model, wherein the second prediction model is used to determine whether a network segment is an abnormal network segment based on the M+1 values ​​corresponding to the M+1 sub-segment features; the processing unit is further configured to: determine whether the first sub-network segment is an abnormal sub-network segment based on the second output.

[0017] In one possible implementation, the acquisition unit is further configured to: acquire N segmented feature values ​​of the network, wherein the N segmented feature values ​​correspond one-to-one with N segmented features; the processing unit is specifically configured to: determine abnormal segmented feature values ​​and non-abnormal segmented feature values ​​among the N segmented feature values ​​acquired by the acquisition unit according to the reference value range of each segmented feature; determine the segmented feature comparison value of the segmented feature corresponding to the abnormal segmented feature value as the reference value of the corresponding segmented feature; and determine the segmented feature comparison value of the segmented feature corresponding to the non-abnormal feature value as the non-abnormal feature value.

[0018] In one possible implementation, the reference value for each segment feature is determined based on at least one historical feature value for each segment feature.

[0019] In one possible implementation, the acquisition unit is further configured to: acquire key performance indicator (KPI) data of at least one first service flow transmitted in the network; the processing unit is further configured to: determine the number of poor-quality service flows in the at least one first service flow based on the KPI data of the at least one first service flow acquired by the acquisition unit; and determine that the number of poor-quality service flows in the at least one service flow is greater than or equal to a preset threshold.

[0020] In one possible implementation, the acquisition unit is further configured to: acquire N+1 segmented feature values ​​when the network transmits at least one second service flow, wherein the N+1 segmented feature values ​​correspond one-to-one with N+1 network segments; the processing unit is further configured to: determine the quality deterioration state of each second service flow in the at least one second service flow, wherein the first quality deterioration state indicates whether each second service flow is a quality deterioration service flow; generate first training data based on the first quality deterioration state, wherein the first training data includes a first input and a first label; the first input includes the N+1 segmented feature values ​​acquired by the acquisition unit; when the number of quality deterioration service flows in the at least one second service flow is greater than or equal to a preset threshold, the first label indicates that the network is an abnormal network, and when the number of quality deterioration service flows in the at least one second service flow is less than the preset threshold, the first label indicates that the network is a non-abnormal network; the first training data is used to train a first prediction model.

[0021] In one possible implementation, the acquisition unit is further configured to: acquire M+1 sub-segment feature values ​​when the network transmits at least one second service flow, wherein the M+1 sub-segment feature values ​​correspond one-to-one with the M+1 network sub-segments; the processing unit is further configured to: determine the abnormal state of the first network segment based on the first training sample and the first prediction model, wherein the abnormal state is used to indicate whether the first network segment is an abnormal network segment; generate second training data based on the abnormal state, wherein the second training data includes a second input and a second label; the second input includes the M+1 sub-segment feature values ​​acquired by the acquisition unit, wherein the second label indicates that the first network segment is an abnormal network segment when the first network segment is an abnormal network segment, and the second label indicates that the first network segment is a non-abnormal network segment when the first network segment is a non-abnormal network segment.

[0022] Thirdly, an anomaly location device is provided, the device comprising: a processor and a memory, the memory storing instructions that, when executed by the processor, cause the device to perform a network anomaly location method as provided in the first aspect or any possible implementation thereof.

[0023] Fourthly, a chip is provided, the chip including a processor and an interface circuit, the processor and the interface circuit being used to support the chip in performing a network anomaly localization method as provided in the first aspect or any possible implementation thereof.

[0024] Fifthly, a computer-readable storage medium is provided, wherein a computer program or instructions are stored therein, which, when executed, implement the method for locating network anomalies as provided in the first aspect or any possible implementation thereof.

[0025] In another aspect of this application, a computer program product is provided, comprising: a computer program (or code, or instructions) that, when executed, causes a computer to perform a network anomaly localization method as provided in the first aspect or any possible implementation thereof.

[0026] Understandably, the beneficial effects achieved by any of the anomaly location devices, chips, computer-readable storage media, and computer program products provided above can be referred to in the context of the network anomaly location methods provided above, and will not be repeated here. Attached Figure Description

[0027] Figure 1A A network architecture diagram of a communication network provided in an embodiment of this application;

[0028] Figure 1B A network architecture diagram of another communication network provided in this application embodiment;

[0029] Figure 2 A flowchart illustrating a method for generating a first training sample provided in an embodiment of this application;

[0030] Figure 3 A schematic diagram illustrating the segmentation result of a service flow transmission link provided in an embodiment of this application;

[0031] Figure 4 A flowchart illustrating a training method for a first prediction model provided in an embodiment of this application;

[0032] Figure 5 A flowchart illustrating the method for generating second training samples provided in an embodiment of this application;

[0033] Figure 6 A flowchart illustrating a training method for a second prediction model provided in an embodiment of this application;

[0034] Figure 7 A flowchart illustrating a method for locating network anomalies provided in an embodiment of this application;

[0035] Figure 8 A flowchart illustrating another method for locating network anomalies provided in this application embodiment;

[0036] Figure 9A system architecture diagram of a network anomaly location positioning system provided in this application embodiment;

[0037] Figure 10 This is a schematic diagram of the structure of an anomaly location device provided in an embodiment of this application;

[0038] Figure 11 This is a schematic diagram of another anomaly location device provided in an embodiment of this application. Detailed Implementation

[0039] The technical solutions in the embodiments of this application will be described below with reference to the accompanying drawings. In this application, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the relationship between related objects, indicating that there are three relationships. For example, A and / or B means: A exists alone, A and B exist simultaneously, or B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the related objects before and after are in an "or" relationship. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c means: a, b, c, a and b, a and c, b and c, a, b, and c; where a, b, and c can be single or multiple. The embodiments of this application use words such as "first" and "second" to distinguish objects with similar names, functions, or roles. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity or execution order. In this application, the words "exemplarily" or "for example" are used to indicate that they are examples, illustrations, or descriptions. Any embodiment or design that is described as "exemplarily" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design options. Rather, the use of the words "exemplarily" or "for example" is intended to present the relevant concepts in a specific manner.

[0040] With the development of the internet, users have increasingly higher demands for the quality of service (QS) of network services, making user experience a core indicator of QS. Network anomalies typically impact QS; for example, network congestion can increase transmission latency, leading to lag, slow loading, and other issues on the user's end, severely affecting the user experience. Therefore, it is crucial to promptly and accurately locate network anomalies to resolve them, maintain normal service transmission, ensure QS, and ultimately improve user experience.

[0041] One method for locating network anomalies is through manual investigation. However, this method suffers from drawbacks such as low efficiency, inaccurate location results, and high labor costs.

[0042] Another possible method for locating network anomalies is as follows: Collect network features at the time of the anomaly as input data for the model. Manually label the anomaly locations as tags in the input data. This input data and tags serve as training samples to train the model, which then uses the trained model to infer the anomaly locations based on the network features. This approach also has several problems. For example, manually labeling the input data is labor-intensive and inefficient. Furthermore, the model's input consists of network features from the entire network, which may include features not strongly correlated with the anomaly, affecting the accuracy and efficiency of the location results. Additionally, due to the complexity and variability of the network environment, different networks or the same network at different times may cause different reasons for poor service quality, leading to low accuracy when using a fixed model for network anomaly localization.

[0043] To address at least one of the aforementioned problems, this application provides a novel technical solution. This solution segments the service flow transmission links in the network and accurately locates network anomalies based on the transmission characteristics of each segment and a quality deviation prediction model. Furthermore, this solution obtains training samples for the quality deviation prediction model through network self-labeling, improving the training efficiency of the model. Moreover, this application can automatically complete the online training process of the quality deviation prediction model, thus giving it online learning capabilities and enabling it to adapt to changing network environments.

[0044] The technical solutions provided in this application can be applied to various network architectures. The network architecture of this application embodiment will be described below. Figure 1A This is a network architecture diagram of a communication network provided in an embodiment of this application. Figure 1A As shown, the communication network includes a user terminal device 101, a first access device 102, a network device 103, a server device 104, and a second access device 105.

[0045] In this network, multiple network devices 103 are interconnected to form a bearer network. User terminal device 101 accesses the bearer network through the first access device 102, and server terminal device 104 accesses the bearer network through the second access device 105. User terminal device 101 and server terminal device 104 are interconnected through the bearer network.

[0046] Server device 104 is a provider of network services, used to generate and transmit service flows to user device 101. In one implementation, the second access device 105 connected to server device 104 can be an access gateway, access switch, etc., which is not limited here.

[0047] User terminal device 101 is a user of network services and is used to receive service streams. User terminal device 101 can be a terminal, mobile phone, tablet, computer with wireless transceiver capabilities, virtual reality (VR) terminal device, augmented reality (AR) terminal device, etc., and is not limited here. In one implementation, user terminal device 101 accesses the first access device 102 wirelessly. The first access device 102 can be a base station, evolved NodeB (eNodeB), transmission reception point (TRP), next-generation NodeB (gNB) in a 5G mobile communication system, a base station in a future mobile communication system, or an access node in a WiFi system, etc., and is not limited here.

[0048] Network device 103 in the bearer network is used to transmit service flows. For example, network device 103 forwards service flows sent by server device 104 to user device 101. Exemplarily, the hardware implementation of network device 103 may be a router, switch, etc.

[0049] It is understood that the embodiments of this application do not limit the number of devices included in the communication network. For example, the communication network may include multiple user terminal devices 101 and multiple server terminal devices 104. One user terminal device 101 may be connected to multiple server terminal devices 104, and one server terminal device 104 may also be connected to multiple user terminal devices 101.

[0050] In this embodiment of the application, the communication network includes multiple service flow transmission links from server device 104 to user device 101. Each service flow transmission link can be divided into multiple network segments (hereinafter referred to as segments), and each segment includes at least two devices connected sequentially on the service flow transmission link.

[0051] In one implementation, a service flow transmission link is divided into three segments. The first segment extends from the server device 104 to the second access device 105, and can be referred to as the content source side network segment; the second segment extends from the second access device 105 to the first access device 102, and can be referred to as the bearer side network segment; the third segment extends from the first access device 102 to the user device 101, and can be referred to as the user side network segment.

[0052] It is understood that this implementation divides the service flow transmission link according to the role of each device in the service flow transmission link. In actual scenarios, other methods can also be used for division, and this application embodiment does not limit the specific division method. For example, the service flow transmission link can be segmented according to the physical location of each device in the service flow transmission link, the virtual local area network to which each device belongs, etc.

[0053] Furthermore, each segment can be further divided into finer-grained sub-segments, that is, each segment can be divided into multiple smaller sub-network segments (hereinafter referred to as sub-segments). For example, two sequentially connected devices (i.e., hop-by-hop links) within a segment can be divided into a sub-segment of that segment. The following section combines... Figure 1B An example is provided to illustrate the division of segments and subsegments.

[0054] like Figure 1B As shown, server device 104-1 and server device 104-2 provide network service to user device 101-1 respectively, and server device 104-3 provides network service to user device 101-2.

[0055] The service flow transmission link 1 from server device 104-1 to user device 101-1 includes server device 104-1, second access device 105-1, network device 103-2, network device 103-1, first access device 102-1, and user device 101-1 connected in sequence; the service flow transmission link 2 from server device 104-2 to user device 101-1 includes server device 104-2, second access device 105-2, network device 103-3, first access device 102-2, and user device 101-1 connected in sequence; the service flow transmission link 3 from server device 104-3 to user device 101-2 includes server device 104-3, second access device 105-2, network device 103-5, network device 103-4, first access device 102-2, and user device 101-2 connected in sequence.

[0056] Based on the above segmentation and sub-segmentation method, for the service flow transmission link 1, the scope of the first segment is from the server device 104-1 to the second access device 105-1, the scope of the second segment is from the second access device 105-1 to the first access device 102-1, and the scope of the third segment is from the first access device 102-1 to the user device 101-1.

[0057] Furthermore, the second segment in the service flow transmission link 1 can be further divided into three sub-segments, the ranges of which are as follows: from the second access device 105-1 to the network device 103-2, from the network device 103-2 to the network device 103-1, and from the network device 103-1 to the first access device 102-1.

[0058] For the service flow transmission link 2, the first segment extends from the server device 104-2 to the second access device 105-2, the second segment extends from the second access device 105-2 to the first access device 102-2, and the third segment extends from the first access device 102-2 to the user device 101-1.

[0059] Furthermore, the second segment in the service flow transmission link 2 can be further divided into two sub-segments, the ranges of which are as follows: from the second access device 105-2 to the network device 103-3, and from the network device 103-3 to the first access device 102-2.

[0060] For the service flow transmission link 3, the first segment extends from the server device 104-3 to the second access device 105-2, the second segment extends from the second access device 105-2 to the first access device 102-2, and the third segment extends from the first access device 102-2 to the user device 101-2.

[0061] Furthermore, the second segment in the service flow transmission link 3 can be further divided into three sub-segments, the ranges of which are as follows: from the second access device 105-2 to the network device 103-5, from the network device 103-5 to the network device 103-4, and from the network device 103-4 to the first access device 102-2.

[0062] It is understood that the above-described network architecture, network segmentation method, and network sub-segmentation method are merely examples, and the embodiments of this application do not limit the network structure, network segmentation method, and network sub-segmentation method. For example, the embodiments of this application can also be applied to data center (DC) networks. Exemplarily, a DC network includes a first server, a second server, and a data center, with the first server and the second server communicating through the data center. This DC network can be divided into three segments: the first segment extends from the first server to the access device connecting the first server to the data center; the second segment extends to the data center itself; and the third segment extends from the access device connecting the second server to the data center to the second server. Exemplarily, the data center can also be further divided into multiple sub-segments. For example, the hop-by-hop links of the data center can be divided into a sub-segment, or every two hops of the data center can be divided into a sub-segment, or the links between every two nodes among the multiple nodes to be monitored in the data center can be divided into a sub-segment based on positioning requirements. When applied, the embodiments of this application can be divided based on the actual network architecture and anomaly positioning requirements. The following uses the above-described... Figure 1A The network architecture shown and Figure 1B Taking the segmented results shown as an example, this application introduces the method for obtaining training samples of the prediction model, the method for training the prediction model, the method for locating network anomalies, and an example of the network anomaly location system provided in the embodiments of this application.

[0063] In one implementation, the network anomaly localization system includes a first prediction model. This first prediction model determines whether an anomaly has occurred in the service flow transmission link based on the segmentation characteristics of each segment during service flow transmission. The first prediction model is trained based on a first training sample, which includes a first input and a first label. Figure 2 A flowchart illustrating a method for generating a first training sample provided in an embodiment of this application is shown below. Figure 2 As shown, the method includes steps S201 to S204.

[0064] S201. Analyze network traffic to determine the segmentation characteristics of each segment of the service transmission link.

[0065] Segmentation characteristics, also known as transmission characteristics, are used to indicate the transmission status of network traffic across segments. Transmission characteristics reflect transmission metrics when network traffic is transmitted across segments. These metrics can include, for example, latency, jitter, throughput, and packet loss.

[0066] When a service transmission link transmits network traffic, segmentation characteristics can be obtained by measuring transmission metrics. For example, segmentation characteristics can be determined by measuring the average metric over a certain period; alternatively, segmentation characteristics can be determined by measuring multiple metric values ​​and basing the results on the statistical values ​​of these values, such as the median. In a specific example, based on the above... Figure 1B The segmentation results shown can include the segmentation characteristics of the service transmission link as follows: average latency of the user-side network segment, average packet loss of the user-side network segment, average latency of the bearer-side network segment, average packet loss of the bearer-side network segment, average latency of the content source-side network segment, and average packet loss of the content source-side network segment.

[0067] The process of determining segmentation features is described below using specific examples of the segmentation features mentioned above:

[0068] For a single service flow transmission link, when the service flow is transmitted, each device on the service flow transmission link collects network traffic. By analyzing the network traffic collected by the edge devices passing through each segment, the segmentation characteristics of each segment are determined.

[0069] Based on the above Figure 1B Taking service flow transmission link 1 in the network architecture as an example, Figure 3 The segmentation results of service flow transmission link 1 are shown. For example... Figure 3 As shown, the edge devices in the first segment are server device 104-1 and second access device 105-1. Server device 104-1 collects network traffic and obtains the time it takes for the network traffic to pass through server device 104-1 and the number of data packets. Second access device 105-1 collects the network traffic and obtains the time it takes for the network traffic to pass through second access device 105-1 and the number of data packets. Then, second access device 105-1 obtains the average latency of the content source side network segment based on the time it takes for the network traffic to pass through server device 104-1 and the time it takes for the network traffic to pass through second access device 105-1. Second access device 105-1 obtains the average packet loss of the content source side network segment based on the number of data packets that pass through server device 104-1 and the number of data packets that pass through second access device 105-1.

[0070] The edge devices for the second segment are the second access device 105-1 and the first access device 102-1. The first access device 102-1 collects the network traffic and obtains the time and number of data packets that the network traffic takes to pass through the first access device 102-1. Based on the time that the network traffic takes to pass through the second access device 105-1 and the time that it takes to pass through the first access device 102-1, the first access device 102-1 obtains the average latency of the bearer-side network segment. Based on the number of data packets that the network traffic takes to pass through the second access device 105-1 and the number of data packets that it takes to pass through the first access device 102-1, the first access device 102-1 obtains the average packet loss of the bearer-side network segment.

[0071] Similarly, the edge devices of the third segment are the first access device 102-1 and the user terminal device 101-1; the user terminal device 101-1 collects the network traffic and obtains the time and number of data packets that the network traffic takes to pass through the user terminal device 101-1; the user terminal device 101-1 obtains the average latency of the user-side network segment based on the time that the network traffic takes to pass through the first access device 102-1 and the time that the network traffic takes to pass through the user terminal device 101-1; the user terminal device 101-1 obtains the average packet loss of the user-side network segment based on the number of data packets that the network traffic takes to pass through the first access device 102-1 and the number of data packets that the network traffic takes to pass through the user terminal device 101-1.

[0072] Understandably, the calculation methods for the segment characteristics of other service flow transmission links are similar to those for service flow transmission link 1, and will not be elaborated upon here. Furthermore, the calculation methods for the segment characteristics of sub-segments are similar to those for segments, except that the network links corresponding to the sub-segments and segments are different.

[0073] S202. Determine the first input based on the segmentation characteristics of each segment of the service transmission link.

[0074] Taking the above segmentation features as a specific example, the first input can be a six-dimensional segmentation feature vector composed of the average latency of the user-side network segment, the average packet loss of the user-side network segment, the average latency of the bearer-side network segment, the average packet loss of the bearer-side network segment, the average latency of the content source-side network segment, and the average packet loss of the content source-side network segment.

[0075] S203. Based on the quality difference analysis results of each service flow in the network traffic, determine the first label.

[0076] Among them, the service flow quality analysis result indicates whether the service flow is a poor quality service flow that can cause poor quality experience, and the first label indicates whether the service flow transmission link of the transmission service flow is an abnormal link.

[0077] For example, the network traffic transmitted in the service flow transmission link includes at least one service flow. For each service flow, the KPIs of that service flow can be determined based on its service type. Then, based on the KPIs and the actual transmission status of the service flow, it can be determined whether the service flow is a poor-quality service flow that can cause a poor user experience. The KPIs of the service flow are indicators that measure the transmission quality and performance of the service flow. Based on the KPIs, it can be determined whether the service flow can be received normally by the user and whether the transmission of the service flow will affect the user's service experience. For example, KPIs can be transmission latency, retransmission rate, packet loss, etc. Understandably, different types of service flows correspond to different KPIs. Taking video streams as an example, excessive transmission latency of video streams can cause stuttering on user devices, resulting in a poor user experience. Therefore, the KPI for video streams is transmission latency. When a service flow in network traffic is identified as a video stream, the transmission latency of the video stream to the user device is obtained, and then the transmission latency of the video stream is compared with the transmission latency index value to obtain the quality analysis result of the video stream. For example, when the transmission latency of the video stream is greater than the transmission latency index value, the video stream is determined to be a poor-quality service flow that will cause a poor user experience; otherwise, the video stream is determined to be a normal service flow that will not cause a poor user experience.

[0078] A first label can be obtained based on the proportion of poor-quality service flows in network traffic. In one implementation, when the proportion of poor-quality service flows in the network traffic transmitted on the service flow transmission link reaches a preset threshold, a first label indicating that the service flow transmission link is an abnormal link is generated; when the proportion of poor-quality service flows in the network traffic transmitted on the service flow transmission link does not reach the preset threshold, a first label indicating that the service flow transmission link is a normal link is generated.

[0079] S204. Generate the first training sample based on the first input and the first label.

[0080] The first training sample includes the first input generated in step S202 and the first label generated in step S203. That is, the first input of a training sample corresponds to the segmentation characteristics of each segment when a service flow transmission link transmits network traffic during a certain time period, and the first label indicates whether the service flow transmission link is an abnormal link during that time period. It can be understood that for a single service flow transmission link, network traffic can be periodically collected and analyzed to obtain multiple first training samples corresponding to network traffic at different time periods. Simultaneously, for multiple service flow transmission links in the communication network, multiple first training samples corresponding to different network traffic at the same time period can be obtained. For example, the generated multiple first training samples are stored in a first training sample set for subsequent use in training the first prediction model.

[0081] Based on the first training samples generated in the above embodiments, the online training process of the first prediction model will be described in detail below. Figure 4 This is a flowchart illustrating a training method for a first prediction model provided in an embodiment of this application. Figure 4 As shown, the training method for the first prediction model includes steps S401 and S402.

[0082] S401. When the number of first training samples in the first training sample set exceeds the first quantity threshold, train the first prediction model based on the first training samples.

[0083] The first prediction model takes as input the segmentation features of each segment of a service flow transmission link and outputs whether the service flow transmission link is an abnormal link. An abnormal link indicates that the service flow transmitted on the service flow transmission link will cause a poor user experience. In an optional implementation, the first prediction model is a multilayer perceptron (MLP) model, where the input is of fixed length. For example, the input to the first prediction model can be a 6-dimensional segmented feature vector composed of the average latency of the user-side network segment, the average packet loss of the user-side network segment, the average latency of the bearer-side network segment, the average packet loss of the bearer-side network segment, the average latency of the content source-side network segment, and the average packet loss of the content source-side network segment.

[0084] When the number of training samples in the first training sample set exceeds a first quantity threshold, the first prediction model is trained using the first training samples in the first training sample set. It can be understood that the first quantity threshold is a threshold value for initiating the training process of the first prediction model.

[0085] The training process of the first prediction model includes: for each first training sample, inputting the first input into the first prediction model to obtain the output of the first prediction model. Then, adjusting the model parameters of the first prediction model based on the loss value between the output and the first label to minimize the loss value between the output and the first label.

[0086] S402. Once the first preset training condition is met, stop training the first prediction model.

[0087] For example, the first preset training condition may be that the number of training iterations reaches a preset number, or that the model parameters of the first prediction model converge to a preset range. Once the first preset training condition is met, training of the first prediction model is stopped to obtain a well-trained first prediction model.

[0088] Understandably, embodiments of this application can generate first training samples in real time during the transmission of service flows in a communication network. Based on these real-time generated first training samples, the first prediction model can undergo multiple rounds of online training. For example, starting from the end of the previous training round, when the number of newly added first training samples exceeds a second threshold, the first prediction model can undergo another round of incremental training. For example, the incremental training process includes: using the first prediction model obtained in the previous training round as the initial model, training the initial model using a portion of the old first training samples and newly added first training samples from the first training sample set, thereby obtaining an updated first prediction model.

[0089] In this embodiment, the first input of the first training sample is obtained by analyzing network traffic, and the first label is obtained by analyzing service flow. That is, this embodiment can generate the first training sample through network self-annotation. This eliminates the need for manual annotation, significantly improving the efficiency of generating the first training sample, thereby increasing the training efficiency of the first prediction model and reducing its training cost. Furthermore, multiple rounds of training of the first prediction model can be completed based on the real-time generated first training samples. This gives the first prediction model self-learning capabilities, allowing it to update as the network environment changes, enabling it to adapt to different network environments and improving its accuracy.

[0090] Furthermore, in one implementation, the network anomaly localization system also includes a second prediction model. This second prediction model is used to determine whether an anomaly has occurred in a segment based on the sub-segment characteristics of each sub-segment during the transmission of service flows. For example, a second training sample can be obtained based on the aforementioned first quality defect prediction model, and the second prediction model can be trained based on the second training sample. The second training sample includes a second input and a second label. The generation process of the second training sample will be described below. Figure 5 This is a flowchart illustrating the method for generating the second training sample provided in an embodiment of this application. Figure 5 As shown, the method includes steps S501 to S505.

[0091] S501. Obtain the segmentation characteristics of each segment of the service flow transmission link.

[0092] For a given service flow transmission link, when transmitting the service flow, the segmentation characteristics of each segment of the service flow transmission link are obtained. The process of obtaining the segmentation characteristics of each segment of the service flow transmission link is described in [reference needed]. Figure 2 The content of embodiment S201 shown will not be repeated here.

[0093] S502. Based on the segmentation characteristics of each segment and the first prediction model, determine the anomaly analysis results corresponding to each segment.

[0094] The anomaly analysis results for each segment indicate whether that segment is an anomalous segment.

[0095] In one implementation, the process of obtaining the anomaly analysis results for each segment includes:

[0096] N segment features corresponding to the service flow transmission link are obtained. For one segment feature i, the feature values ​​of the other N-1 segment features are replaced with their corresponding reference values. Then, segment feature i and the replaced N-1 segment features are input into the first prediction model to obtain an output result indicating whether the service flow transmission link is abnormal. In this way, each segment feature corresponds to one output result. Based on the N output results, at least one segment feature k that causes the service flow transmission link to be abnormal is determined, and the segment corresponding to each segment feature k is determined to be an abnormal segment, and the other segments are determined to be normal segments. The process of determining the abnormal analysis result of each segment is described below. Figure 7 The contents described in the illustrated embodiments will not be repeated here.

[0097] S503. Generate a second label based on the anomaly analysis results corresponding to the target segment.

[0098] For a segment (target segment), when the anomaly analysis result of the target segment is an anomalous segment, a second label indicating that the target segment is an anomalous segment is generated; when the anomaly analysis result of the target segment is a normal segment, a second label indicating that the target segment is a normal segment is generated.

[0099] S504. Obtain the sub-segment features of each sub-segment of the target segment and determine the second input.

[0100] Sub-segment characteristics indicate the transmission status of network traffic on sub-segments, including latency, packet loss, jitter, etc. In one implementation, based on the sub-segmentation results of the above example, the sub-segmentation characteristics of each segment can be the latency, packet loss, and jitter of the hop-by-hop link of that segment.

[0101] The process of determining sub-segment features is described below:

[0102] For a segment of a service flow transmission link, when the service flow is transmitted, each device on the service flow transmission link collects network traffic. By analyzing the network traffic collected by the two devices passing through each sub-segment, the sub-segment characteristics of each sub-segment are determined.

[0103] The target segment is as described above. Figure 3 Taking the second segment as an example, as shown Figure 3As shown, the second segment includes the first sub-segment, the second sub-segment, and the third sub-segment.

[0104] The first sub-segment includes a second access device 105-1 and a network device 103-2. The second access device 105-1 collects network traffic and obtains the time it takes for the network traffic to pass through the second access device 105-1 and the number of data packets. Then, the network device 103-2 collects the same network traffic and obtains the time it takes for the network traffic to pass through the network device 103-2 and the number of data packets. Next, based on the time it takes for the network traffic to pass through the second access device 105-1 and the time it takes to pass through the network device 103-2, the latency feature and jitter feature of the first sub-segment are obtained. Based on the number of data packets that pass through the second access device 105-1 and the number of data packets that pass through the network device 103-2, the packet loss feature of the first sub-segment is obtained.

[0105] The second sub-segment includes network device 103-2 and network device 103-1. Network device 103-1 collects the network traffic and obtains the time and number of data packets that the network traffic takes to pass through network device 103-1. Then, based on the time that the network traffic takes to pass through network device 103-2 and the time that it takes to pass through network device 103-1, the second sub-segment latency characteristics and the second sub-segment jitter characteristics are obtained. Based on the number of data packets that the network traffic takes to pass through network device 103-2 and the number of data packets that it takes to pass through network device 103-1, the second sub-segment packet loss characteristics are obtained.

[0106] Similarly, the third segment includes network device 103-1 and first access device 102-1; the first access device 102-1 collects the network traffic and obtains the time and number of data packets that the network traffic takes to pass through the first access device 102-1; then, based on the time that the network traffic takes to pass through network device 103-1 and the time that it takes to pass through the first access device 102-1, the third sub-segment delay characteristics and the third sub-segment jitter characteristics are obtained; based on the number of data packets that the network traffic takes to pass through network device 103-1 and the number of data packets that it takes to pass through the first access device 102-1, the third sub-segment packet loss characteristics are obtained.

[0107] Understandably, the network traffic analyzed in step S501 when determining segment characteristics and the network traffic analyzed in this step when determining sub-segment characteristics are the same network traffic. That is, as network traffic passes through each device in sequence, each device analyzes the network traffic in sequence, and then each segment and each sub-segment edge device determines the segment characteristics corresponding to each segment and the sub-segment characteristics corresponding to each sub-segment based on their respective analysis results.

[0108] For example, the second input is a sub-segment feature vector composed of the sub-segment features of each sub-segment of a segment. For instance, in the example above, the second input is a nine-dimensional sub-segment feature vector composed of the first sub-segment delay feature, the first sub-segment jitter feature, the first sub-segment packet loss feature, the second sub-segment delay feature, the second sub-segment jitter feature, the second sub-segment packet loss feature, the third sub-segment delay feature, the third sub-segment jitter feature, and the third sub-segment packet loss feature.

[0109] Understandably, because the link lengths of each segment are different, the number of sub-segments included in each segment is also different. For example... Figure 3 The first and second segments shown only have two devices each, and these two segments can themselves be considered as sub-segments. The number of sub-segments corresponding to the second segment may differ for different service flow transmission links; therefore, the number of sub-segment features corresponding to each segment is not necessarily the same. Thus, the dimension of the second input may differ for different segments. For example, if the target segment is... Figure 3 The first segment shown is considered as a sub-segment. The second input is a three-dimensional sub-segment feature vector composed of the first segment delay feature, the first segment jitter feature, and the first segment packet loss feature.

[0110] S505. Generate a second training sample based on the second input and the second label.

[0111] The second training sample includes a second input and a second label, wherein the second input is the sub-segment feature of a sub-segment corresponding to a segment. The second label indicates whether the segment is an anomalous segment.

[0112] Understandably, for a single service flow transmission link, multiple second training samples corresponding to multiple segments can be obtained within the same time period, and multiple second training samples corresponding to each segment can be obtained at different time periods. For different service flow transmission links, multiple second training samples corresponding to multiple segments of each service flow transmission link can be obtained within the same time period. The generated second training samples are stored in a second training sample set for use in subsequent training of the second prediction model.

[0113] Based on the second training samples generated in the above embodiments, the online training process of the second prediction model will be described in detail below. Figure 6 This is a flowchart illustrating a training method for a second prediction model provided in an embodiment of this application. Figure 6 As shown, the training method for the second prediction model includes steps S601 and S602.

[0114] S601. When the number of second training samples in the second training sample set exceeds the third quantity threshold, train the second prediction model based on the second training samples.

[0115] The second prediction model takes as input the sub-segment features of each sub-segment of a segment, and outputs whether the segment is an anomalous segment. An anomalous segment indicates that the service flow transmitted on that segment will cause a poor user experience. In an optional implementation, the second quality-defect prediction model is a recurrent neural network (RNN) model, where the input to the RNN model is of variable length.

[0116] Once the number of second training samples in the second training sample set exceeds the third threshold, the second prediction model is trained using the second training samples in the second training sample set. Understandably, the third threshold is the threshold value for initiating the training process of the second prediction model.

[0117] The training process of the second prediction model includes: for each second training sample, inputting the second input into the second prediction model to obtain the output of the second prediction model. Then, adjusting the model parameters of the second prediction model based on the loss value between the output and the second label to minimize the loss value between the output and the second label.

[0118] S602. Once the second preset training conditions are met, stop training the second prediction model.

[0119] For example, the second preset training condition may be that the number of training iterations reaches a preset number, or that the model parameters of the second poor quality prediction model converge to a preset range; when the second preset training condition is reached, the training of the second prediction model is stopped to obtain the trained second prediction model.

[0120] Similarly, second training samples can be generated in real time during the transmission of service flows in the communication network. This allows for multiple rounds of online training of the second prediction model based on these real-time generated second training samples. In one optional implementation, starting from the end of the previous training round, when the number of newly added second training samples exceeds a fourth threshold, the second poor-quality prediction model undergoes another round of incremental training. For example, the incremental training process includes: using the second prediction model obtained in the previous training round as the initial model, training the initial model using a portion of the old second training samples and newly added second training samples from the second training sample set, thereby obtaining an updated second poor-quality prediction model.

[0121] This application's embodiments generate second training samples through network self-annotation, eliminating the need for manual annotation and significantly improving the efficiency of second training sample generation. This, in turn, enhances the training efficiency of the second prediction model and reduces its training cost. Furthermore, the second prediction model can undergo multiple rounds of training based on the real-time generated second training samples. This gives the second prediction model self-learning capabilities, allowing it to update as the network environment changes, thus adapting to different network conditions and improving its accuracy. Moreover, the second prediction model corresponds to inputs at a smaller network granularity, providing more precise reference information for subsequent anomaly location positioning.

[0122] The first prediction model obtained based on the above training Figure 7 This is a flowchart illustrating a method for locating network anomalies provided in an embodiment of this application. Figure 7 As shown, the positioning method includes steps S701 to S708.

[0123] S701. Determine that the service flow transmitted on the service flow transmission link is a poor quality service flow.

[0124] Among them, poor-quality business flows are those that can lead to a poor user experience. For example, whether a business flow will lead to a poor user experience is determined based on the KPIs corresponding to that business flow.

[0125] During service flow transmission, the service flow transmission link detects each service flow; determines the KPIs corresponding to each service flow based on its type, and then analyzes whether the service flow will cause poor quality experience based on the KPIs. Taking video streams as an example, it determines whether the video stream is a poor quality service flow by judging the transmission latency of the video stream.

[0126] In one implementation, if the proportion of poor-quality service flows in the service flow transmission link exceeds a preset threshold, it is determined that the service flow transmission link is abnormal, and then the location of the network abnormality is located.

[0127] S702. Obtain the segmentation characteristics of each segment of the service flow transmission link to obtain the third input.

[0128] When an anomaly is determined in the service flow transmission link, the segmentation characteristics of each segment of that service flow transmission link are obtained. For example, the segmentation characteristics corresponding to the service flow transmission link reflect the transmission metrics of network traffic when transmitted on the segments, such as latency, jitter, throughput, and packet loss. In a specific example, the segmentation characteristics may include the average latency of the user-side network segment, the average packet loss of the user-side network segment, the average latency of the bearer-side network segment, the average packet loss of the bearer-side network segment, the average latency of the content source-side network segment, and the average packet loss of the content source-side network segment; the third input is a 6-dimensional feature vector composed of the above segmentation characteristics. The segmentation method of the service flow transmission link and the method for obtaining the segmentation characteristics are described above and will not be repeated here.

[0129] S703. Determine the N abnormal segmentation features in the segmentation features.

[0130] After obtaining the segmentation features, the feature value of each segmentation feature is compared with the initial screening value of that segmentation feature to filter out abnormal segmentation features among all segmentation features. In one implementation, the initial screening value of a segmentation feature is determined based on the historical feature values ​​of that segmentation feature. Taking a service flow transmission link as an example, the initial screening value of the average latency of the bearer-side network segment corresponding to the service flow transmission link is determined based on the historical average latency of that bearer-side network segment; for example, the initial screening value can be the 80th percentile of multiple historical feature values. For example, if the feature value of a segmentation feature exceeds (or is lower than) the initial screening value corresponding to that segmentation feature, then that segmentation feature is determined to be an abnormal segmentation feature.

[0131] The following explanation uses the specific examples above to illustrate abnormal segmentation features and non-abnormal segmentation features:

[0132] Table 1

[0133] Segmented feature types Eigenvalues Initial screening value Feature anomaly judgment results Average latency of user-side network segment 15 10 1 Average packet loss on the user-side network segment 55 50 1 Average latency of bearer-side network segment 50 30 1 Average packet loss on the bearer side network segment 70 100 0 Average latency of content source network segment 10 15 0 Average packet loss on the content source network segment 40 50 0

[0134] As shown in Table 1, the characteristic values ​​of the average latency of the user-side network segment, the average packet loss of the user-side network segment, and the average latency of the bearer-side network segment all exceed their respective initial screening values. Therefore, the average latency of the user-side network segment, the average packet loss of the user-side network segment, and the average latency of the bearer-side network segment are determined to be abnormal segmentation characteristics, and the abnormal judgment result is marked as 1. On the other hand, the average packet loss of the bearer-side network segment, the average latency of the content source-side network segment, and the average packet loss of the content source-side network segment all do not exceed their respective initial screening values. Therefore, the average packet loss of the bearer-side network segment, the average latency of the content source-side network segment, and the average packet loss of the content source-side network segment are determined to be non-abnormal segmentation characteristics, and the abnormal judgment result is marked as 0.

[0135] S704. For each abnormal segment feature, replace the feature values ​​of the other N-1 abnormal segment features to obtain the fourth input corresponding to each abnormal segment feature.

[0136] Each segmented feature corresponds to a reference value, which is determined based on the historical feature values ​​of that segmented feature. For example, the reference value is the mean or median of multiple historical feature values. Understandably, the reference value represents the normal feature value of the segmented feature. Compared to the initial screening value of the segmented feature, the reference value is closer to the normal state of the feature value of the segmented feature.

[0137] After obtaining the anomalous segmentation features from the segmentation features, for each anomalous segmentation feature, the feature value of that anomalous segmentation feature is retained, and the feature values ​​of other anomalous segmentation features are replaced with reference values ​​to obtain the fourth input. Understandably, if there are N anomalous segmentation features, then N fourth inputs are obtained.

[0138] The following examples illustrate this point. Table 2 shows the replacement values ​​corresponding to each segment feature:

[0139] Table 2

[0140]

[0141]

[0142] As shown in Tables 1 and 2, the third input is [15, 55, 50, 70, 10, 40];

[0143] Among them, the average latency of the user-side network segment, the average packet loss of the user-side network segment, and the average latency of the bearer-side network segment are abnormal segmentation features. For the average latency of the user-side network segment, the feature value of the average latency of the user-side network segment is retained, and the feature values ​​of the average packet loss of the user-side network segment and the average latency of the bearer-side network segment are replaced to obtain the fourth input [15, 40, 25, 70, 10, 40] corresponding to the average latency of the user-side network segment. For the average packet loss of the user-side network segment, the feature value of the average packet loss of the user-side network segment is retained, and the feature values ​​of the average latency of the user-side network segment and the average latency of the bearer-side network segment are replaced to obtain the fourth input [6, 55, 25, 70, 10, 40] corresponding to the average latency of the user-side network segment. For the average latency of the bearer-side network segment, the feature value of the average latency of the bearer-side network segment is retained, and the feature values ​​of the average latency of the user-side network segment and the average packet loss of the user-side network segment are replaced to obtain the fourth input [6, 40, 50, 70, 10, 40] corresponding to the average latency of the bearer-side network segment.

[0144] S705. Input the third input into the first prediction model to obtain the first output result.

[0145] The third input is fed into the first model to obtain the first output result. This first output result indicates the prediction result of the first prediction model based on the segmentation characteristics of the current network to determine whether the service flow transmission link is an abnormal link. It can be understood that the segmentation characteristics are obtained when the proportion of poor-quality service flows in the service flow transmission link exceeds a preset threshold. Therefore, the first output result corresponding to the third input indicates that the service flow transmission link is an abnormal link.

[0146] S706. Input the N fourth inputs into the first prediction model respectively to obtain N second output results.

[0147] The N fourth inputs are respectively input into the first prediction model to obtain the second output result, wherein the second output result indicates the prediction result of the first prediction model based on the replaced segmented features to predict whether the service flow transmission link is an abnormal link.

[0148] S707. Compare the N second output results with the first output results respectively to obtain the target abnormal segmentation features among the N abnormal segmentation features.

[0149] By comparing the N second output results with the first output result, the degree of influence of each segment feature on the output of the first prediction model is determined. Based on this degree of influence, the key segment features that cause anomalies in the service flow transmission link are identified. Among them, the key segment features that cause anomalies in the service flow transmission link are the target anomaly segment features.

[0150] Taking an abnormal segmentation feature as an example, if the fourth input corresponding to this abnormal segmentation feature is input into the first prediction model, and the obtained second output result indicates that the service flow transmission link is an abnormal link, that is, the service flow transmission link is still an abnormal link even when all other segmentation features are within the normal range, then this abnormal segmentation feature is a key segmentation feature causing the abnormality of the service flow transmission link. If the obtained second output result indicates that the service flow transmission link is a normal link, that is, the service flow transmission link is still a normal link even when the segmentation feature is abnormal, then this abnormal segmentation feature is not a key segmentation feature causing the abnormality of the service flow transmission link.

[0151] Based on the specific examples above, Table 3 shows the output results for each input, as shown in Table 3:

[0152] Table 3 (Scoring threshold: 75)

[0153]

[0154] The second output result corresponding to the average latency of the user-side network segment is 0.25, indicating that the probability of an anomaly in the service flow transmission link is 0.25. Therefore, the score for the impact of the average latency of the user-side network segment on the anomaly of the service flow transmission link is 25, which is less than the scoring threshold of 75. This means that the average latency of the user-side network segment is not a key segment feature causing anomalies in the service flow transmission link. The second output result corresponding to the average packet loss of the user-side network segment is 0.20, indicating that the probability of an anomaly in the service flow transmission link is 0.20. Therefore, the average packet loss of the user-side network segment does not significantly affect the impact of anomalies in the service flow transmission link. The impact score is 20, which is less than the score threshold of 75, meaning that the average packet loss on the user-side network segment is not a key segment feature causing abnormalities in the service flow transmission link. The second output result corresponding to the average latency on the bearer-side network segment is 0.95, which is greater than the score threshold of 75, indicating that the probability of abnormalities in the service flow transmission link is 0.95. Thus, the impact score of the average latency on the bearer-side network segment on abnormalities in the service flow transmission link is 95. The average latency on the bearer-side network segment is a key segment feature causing abnormalities in the service flow transmission link, and therefore the average latency on the bearer-side network segment is the target abnormal segment feature.

[0155] S708. Determine the abnormal segments of the segments corresponding to the abnormal segmentation features of the target.

[0156] The segment corresponding to the key segment characteristics that cause an anomaly in the service flow transmission link is the anomalous segment, which is the located abnormal location in the service flow transmission link. In the example above, the bearer-side network segment corresponding to the average latency of the bearer-side network segment is the anomalous segment.

[0157] In this embodiment, the abnormal segment in the service flow transmission link is located by analyzing the key segment characteristics that cause the abnormality of the service flow transmission link. In this way, the abnormal location of the network can be accurately located, and the accuracy of network abnormality location can be improved.

[0158] Furthermore, the abnormal segments obtained in the above embodiments can be re-located to obtain abnormal sub-segments with a smaller range. Figure 8 This is a flowchart illustrating another method for locating network anomalies provided in an embodiment of this application. Figure 8 As shown, the positioning method includes steps S801 to S808.

[0159] S801, Obtain abnormal segments in the service flow transmission link.

[0160] When transmitting service flows, the service flow transmission link detects whether each service flow in the link is a low-quality service flow. If the proportion of low-quality service flows in the service flow transmission link exceeds a preset threshold, the network anomaly location is located, and an abnormal segment is obtained. For details on the process of locating abnormal segments in the service flow transmission link, please refer to [link to relevant documentation]. Figure 7The contents described in S701-S708 of the illustrated embodiment will not be repeated here.

[0161] S802. Obtain the sub-segment features of each sub-segment of the abnormal segment to obtain the fifth input.

[0162] For example, the sub-segment features corresponding to the abnormal segment include the link features of the hop-by-hop link. The method for dividing the abnormal segment into sub-segments and the method for obtaining the sub-segment features are similar to the segmentation method and the method for obtaining the segment features of the above-mentioned service flow transmission link, except that the range of the sub-segments and segments is different, which will not be elaborated here.

[0163] S803. Determine the N abnormal sub-segment features in the sub-segment features.

[0164] After obtaining the sub-segment features, the feature value of each sub-segment feature is compared with its initial screening value to filter out abnormal sub-segment features from all sub-segment features. In one implementation, the initial screening value of a sub-segment feature is determined based on its historical feature values. For example, the initial screening value can be the 80th percentile of multiple historical feature values. For example, if the feature value of a sub-segment feature exceeds (or is lower than) the initial screening value corresponding to that sub-segment feature, then that sub-segment feature is determined to be an abnormal sub-segment feature. For instance, if the sub-segment features include a first sub-segment delay feature, and the initial screening value of the first sub-segment delay feature is 30 (ms), and the value of the first sub-segment delay feature is 50, then the value of the first sub-segment delay feature exceeds the initial screening value, and the first sub-segment delay feature is determined to be an abnormal sub-segment feature. For example, the sub-segment features include the throughput features of the first sub-segment. If the initial screening value of the throughput features of the first sub-segment is 300 and the throughput feature value of the first sub-segment is 200, then the throughput feature value of the first sub-segment is lower than the initial screening value, and the throughput feature value of the first sub-segment is an abnormal sub-segment feature.

[0165] It is understood that this step is similar to S703 in the above embodiment, and the relevant content can be referred to the content described in S703, which will not be repeated here.

[0166] S804. For each abnormal sub-segment feature, replace the feature values ​​of the other N-1 abnormal sub-segment features to obtain the sixth input corresponding to each abnormal sub-segment feature.

[0167] Each sub-segment feature corresponds to a reference value, which is determined based on the historical feature values ​​of that sub-segment feature. For example, the reference value is the mean or median of multiple historical feature values. Understandably, the reference value represents the normal feature value of the sub-segment feature. Compared to the initial screening value of the sub-segment feature, the reference value is closer to the normal state of the feature value of the sub-segment feature.

[0168] After obtaining the abnormal sub-segment features from the sub-segment features, for each abnormal sub-segment feature, the feature value of that abnormal sub-segment feature is retained, and the feature values ​​of other abnormal sub-segment features are replaced with reference values ​​to obtain the sixth input. It is understood that if there are N abnormal sub-segment features, then N sixth inputs are obtained. It is understood that this step is similar to S704 in the above embodiment, and related content can be referred to the description in S704, which will not be repeated here.

[0169] S805. Input the fifth input into the second prediction model to obtain the third output result corresponding to the fifth input.

[0170] The fifth input is fed into the second prediction model to obtain the third output, which indicates whether the second prediction model predicts whether a segment is abnormal based on the sub-segment features. It can be understood that the fifth input is the sub-segment features of the abnormal segment; therefore, the third output corresponding to the fifth input indicates that the segment corresponding to the sub-segment features is an abnormal segment.

[0171] S806. Input the N sixth inputs into the second prediction model respectively to obtain N fourth output results.

[0172] Each sixth input is fed into the second prediction model to obtain the fourth output, which indicates whether the second prediction model predicts whether the segment is abnormal based on the replaced sub-segment features.

[0173] S807. Compare the N fourth output results and the third output results respectively to obtain the target abnormal sub-segment features among the N abnormal sub-segment features.

[0174] By comparing the N fourth output results with the third output results, the degree of influence of each abnormal sub-segment feature on the output result of the second prediction model is determined. Based on this degree of influence, the key sub-segment features that cause segment anomalies are identified. These key sub-segment features are the target abnormal sub-segment features. Specifically, this step is similar to S707 in the above embodiment, and the relevant content can be found in S707, which will not be repeated here.

[0175] S808. Determine the abnormal sub-segment of the sub-segment corresponding to the feature of the target abnormal sub-segment.

[0176] Understandably, the sub-segment corresponding to the key sub-segment feature that causes the segment to malfunction is the abnormal sub-segment, and this abnormal sub-segment is the abnormal location of the service flow transmission link that has been located.

[0177] This application embodiment can locate abnormal segments based on the sub-segment features of abnormal segments, obtaining abnormal sub-segments with a smaller range. This further improves the accuracy of the location, achieving the goal of precisely locating network anomalies.

[0178] Based on the above, Figure 9 This is a system architecture diagram of a network anomaly location positioning system provided in an embodiment of this application. Figure 9 As shown, the network anomaly location positioning system includes a first device 20 and a second device 21. The first device 20 is as described above. Figure 1A or Figure 1B The second device 21 is an analysis device for performing network analysis. Optionally, the analysis device can be a standalone analysis device or a chip within an analysis device, or it can be one of the aforementioned devices. Figure 1A or Figure 1B The module used for network analysis in any device in the communication network shown is not limited in this application embodiment.

[0179] The first device 20 includes a flow acquisition module 201, a quality assessment module 202, a feature calculation module 203, and a threshold setting module 204.

[0180] The traffic acquisition module 201 is used to collect network traffic passing through the first device 20, and the network traffic includes at least one service flow.

[0181] The poor quality assessment module 202 is used to determine whether each business flow will cause a poor quality experience based on the key performance indicators (KPIs) corresponding to each business flow. For example, the poor quality assessment module 202 executes S701 and other steps shown in the above embodiments to determine whether a business flow is a poor quality business flow.

[0182] The feature calculation module 203 is used to determine the segment characteristics (and / or the sub-segment characteristics of each segment) in the service flow transmission link; exemplarily, the feature calculation module 203 executes S201, S501, S504, S702 and other steps for determining segment characteristics or determining sub-segment characteristics shown in the above embodiments.

[0183] The threshold setting module 204 is used to set the number threshold of each training sample in the second device 21, wherein the number threshold is used to control the second device 21 to start the model training process.

[0184] The second device 21 includes an online training module 211, a first positioning module 212, and a second positioning module 213.

[0185] The online training module 211 is used to generate training samples based on the outputs of the feature calculation module 203 and the quality difference evaluation module 202, and to train a first prediction model and a second prediction model based on the training samples. Exemplarily, the online training module 211 executes steps S202, S203, S204, S401, S402, S503, S505, S601, S602, and other steps for generating training samples and training models as shown in the above embodiments.

[0186] The first positioning module 212 includes a first prediction model, used to locate abnormal segments in the service flow transmission link based on the segmentation characteristics of the service flow transmission link and the first quality defect prediction module. For example, the first positioning module 212 executes the steps of locating abnormal segments, such as S502, S703 to S708, as described in the above embodiments.

[0187] The second positioning module 213 includes a second prediction model, used to obtain the abnormal segments output by the first positioning module 212, and locate the abnormal sub-segments in the abnormal segments according to the sub-segment features of the abnormal segments and the second prediction model. For example, the second positioning module 213 executes the steps S801 to S808 described in the above embodiments for locating abnormal sub-segments.

[0188] Optionally, the second device may also include a bandwidth recommendation module 214, which is used to determine the bandwidth expansion recommendation value of the abnormal sub-segment based on the abnormal sub-segment location result output by the second positioning module 213.

[0189] The above primarily describes the solutions provided in this application from the perspective of an anomaly location device. It is understood that, in order to achieve the above functions, the anomaly location device includes corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, based on the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0190] This application embodiment can divide the anomaly location device into functional modules according to the above method example. For example, each function can be divided into its own functional modules, or two or more functions can be integrated into one module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods. The following description uses the division of functional modules according to each function as an example.

[0191] When using integrated units, Figure 10 A schematic diagram of an anomaly localization device according to the above embodiments is shown. The device includes an acquisition unit 1001 and a processing unit 1002. In one possible embodiment, the acquisition unit 1001 supports the device in executing S201 of the above method embodiments, and the processing unit 1002 supports the device in executing S202-S204 of the above method embodiments. In another possible embodiment, the processing unit 1002 supports the device in executing S401-S402 of the above method embodiments. In another possible embodiment, the acquisition unit 1001 supports the device in executing S501 and S504 of the above method embodiments, and the processing unit 1002 supports the device in executing S502, S503, and S505 of the above method embodiments. In another possible embodiment, the processing unit 1002 supports the device in executing S601 and S602 of the above method embodiments. In another possible embodiment, the acquisition unit 1001 is used to support the device in executing S702 of the above method embodiment, and the processing unit 802 is used to support the device in executing S701, S703-S708 of the above method embodiment. In another possible embodiment, the acquisition unit 1001 is used to support the device in executing S801 and S802 of the above method embodiment, and the processing unit 802 is used to support the device in executing S803-S808 of the above method embodiment.

[0192] All relevant content of each step involved in the above method embodiments can be referenced from the functional description of the corresponding functional module, and will not be repeated here in the embodiments of this application.

[0193] Based on hardware implementation, the acquisition unit 1001 in this application embodiment can be the receiver of the device, and the processing unit 1002 can be the processor of the device.

[0194] like Figure 11The diagram shown is a structural schematic of another anomaly location device involved in the above embodiments provided in this application. The device includes a processor 1112 and a transceiver 1113. Further, the device also includes a memory 1111 and a bus 1114. The processor 1112, the memory 1111 and the transceiver 1113 are connected through the bus 1114.

[0195] The processor 1112 is used to control and manage the operation of the device. In one possible embodiment, the processor 1112 is used to support the device in executing S202-S204, S401-S402, S703-S708, S803-S808 and / or other technical processes described herein in the above method embodiments. The transceiver 1113 is used to support the device in communication.

[0196] In this embodiment, processor 1112 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a digital signal processor and a microprocessor, etc. The aforementioned bus 1114 may include an address bus, a data bus, a control bus, etc.

[0197] It is understood that all relevant content of each step involved in the above method embodiments can be referenced in the embodiments of the anomaly location device, and the embodiments of this application will not be repeated here.

[0198] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of modules or units is merely a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another apparatus, or some features may be ignored or not executed.

[0199] The units described as separate components may or may not be physically separate. A component shown as a unit can be one or more physical units; that is, it can be located in one place or distributed in multiple different locations. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0200] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. This readable storage medium may include various media capable of storing program code, such as a USB flash drive, external hard drive, read-only memory, random access memory, magnetic disk, or optical disk. Based on this understanding, the technical solution of the embodiments of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product.

[0201] In another embodiment of this application, a chip is provided, which includes a processor and an interface circuit. The processor and the interface circuit are used to support the chip in performing one or more steps performed by the anomaly location device in the method embodiments provided above.

[0202] In another embodiment of this application, a computer-readable storage medium is provided, which stores a computer program or instructions that, when executed, implement one or more steps performed by the anomaly location device in the method embodiments provided above.

[0203] In another embodiment of this application, a computer program product is provided, comprising: a computer program (or code, or instructions) that, when executed, causes a computer to perform one or more steps as performed by the anomaly locator in the method embodiments provided above.

[0204] Finally, it should be noted that the above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for locating network anomalies, characterized in that, The method includes: Obtain the first segment feature value, where the first segment feature value is the value of the transmission feature of the first network segment in the network; N segment feature comparison values ​​are determined, and the N segment feature comparison values ​​correspond one-to-one with the N segment features. The N segment features include the transmission features of the N network segments in the network. Each segment feature comparison value in the N segment feature comparison values ​​is within the reference value range of the transmission feature of the corresponding segment, and N is a positive integer. The N segmented feature comparison values ​​and the first segmented feature value are input into the first prediction model to obtain the first output of the first prediction model. The first prediction model is used to determine whether the network is an abnormal network based on the N+1 values ​​corresponding to the N+1 segmented features. Based on the first output, determine whether the first network segment is an abnormal network segment.

2. The method according to claim 1, characterized in that, The first network segment is an abnormal network segment, the first network segment includes a first sub-network segment, and the method further includes: Obtain the first sub-segment feature value, where the first sub-segment feature value is the value of the transmission feature of the first sub-network segment; M sub-segment feature comparison values ​​are determined, and the M sub-segment feature comparison values ​​correspond one-to-one with the M sub-segment features. The M sub-segment features include the transmission features of the M sub-network segments in the first network segment. The comparison value of each sub-segment feature in the M sub-segment features is within the reference value range of the corresponding sub-segment feature, and M is a positive integer. The M sub-segment feature comparison values ​​and the first sub-segment feature value are input into the second prediction model to obtain the second output of the second prediction model. The second prediction model is used to determine whether a network segment is an abnormal network segment based on the M+1 values ​​corresponding to the M+1 sub-segment features. The second output determines whether the first sub-network segment is an abnormal sub-network segment.

3. The method according to claim 1 or 2, characterized in that, The determination of N segmented feature comparison values ​​includes: Obtain N segmented feature values ​​of the network, wherein the N segmented feature values ​​correspond one-to-one with the N segmented features; Based on the reference value range of each segment feature, determine the abnormal segment feature values ​​and non-abnormal segment feature values ​​among the N segment feature values; The segment feature comparison value corresponding to the abnormal segment feature value is determined as the reference value of the corresponding segment feature; The segment feature comparison value corresponding to the non-abnormal feature value is determined as the non-abnormal feature value.

4. The method according to claim 3, characterized in that, The reference value for each segment feature is determined based on at least one historical feature value of each segment feature.

5. The method according to any one of claims 1 to 4, characterized in that, Before obtaining the first segment feature value, the method further includes: Obtain key performance indicator (KPI) data for at least one first service flow transmitted in the network; The number of poor-quality service flows in the at least one first service flow is determined based on the KPI data of the at least one first service flow; The number of poor-quality service flows in the at least one service flow is determined to be greater than or equal to a preset threshold.

6. The method according to claim 5, characterized in that, The method further includes: Obtain N+1 segment feature values ​​when the network transmits at least one second service flow, wherein the N+1 segment feature values ​​correspond one-to-one with N+1 network segments; Determine the poor quality status of each of the at least one second service flow, wherein the first poor quality status indicates whether each of the second service flows is a poor quality service flow; First training data is generated based on the first poor quality state. The first training data includes a first input and a first label. The first input includes the N+1 segmented feature values. When the number of poor quality service flows in at least one second service flow is greater than or equal to the preset threshold, the first label indicates that the network is an abnormal network. When the number of poor quality service flows in at least one second service flow is less than the preset threshold, the first label indicates that the network is a non-abnormal network. The first training data is used to train the first prediction model.

7. The method according to claim 6, characterized in that, The method further includes: Obtain M+1 sub-segment feature values ​​when the network transmits the at least one second service flow, wherein the M+1 sub-segment feature values ​​correspond one-to-one with the M+1 network sub-segments; Based on the first training sample and the first prediction model, the abnormal state of the first network segment is determined, and the abnormal state is used to indicate whether the first network segment is an abnormal network segment. The second training data is generated based on the abnormal state. The second training data includes a second input and a second label. The second input includes the M+1 sub-segment feature values. When the first network segment is an abnormal network segment, the second label indicates that the first network segment is an abnormal network segment. When the first network segment is a non-abnormal network segment, the second label indicates that the first network segment is a non-abnormal network segment.

8. A network anomaly location device, characterized in that, The device includes: The acquisition unit is used to acquire the first segment feature value, wherein the first segment feature value is the value of the transmission feature of the first network segment in the network; The processing unit is used to determine N segment feature comparison values, wherein the N segment feature comparison values ​​correspond one-to-one with N segment features, the N segment features include the transmission features of N network segments in the network, and each segment feature comparison value in the N segment feature comparison values ​​is within the reference value range of the transmission feature of the corresponding segment, where N is a positive integer; The processing unit is further configured to input the N segmented feature comparison values ​​and the first segmented feature value into the first prediction model to obtain the first output of the first prediction model. The first prediction model is configured to determine whether the network is an abnormal network based on the N+1 values ​​corresponding to the N+1 segmented features. The processing unit is further configured to determine whether the first network segment is an abnormal network segment based on the first output.

9. The apparatus according to claim 8, characterized in that, The first network segment is an abnormal network segment, and the first network segment includes a first sub-network segment; The acquisition unit is further configured to acquire a first sub-segment feature value, wherein the first sub-segment feature value is the value of the transmission feature of the first sub-network segment; The processing unit is further configured to determine M sub-segment feature comparison values, wherein the M sub-segment feature comparison values ​​correspond one-to-one with M sub-segment features, the M sub-segment features include the transmission features of the M sub-network segments in the first network segment, and each sub-segment feature comparison value in the M sub-segment features is within the reference value range of the corresponding sub-segment feature, where M is a positive integer; The processing unit is further configured to input the M sub-segment feature comparison values ​​and the first sub-segment feature value into the second prediction model to obtain the second output of the second prediction model. The second prediction model is configured to determine whether a network segment is an abnormal network segment based on the M+1 values ​​corresponding to the M+1 sub-segment features. The processing unit is further configured to determine whether the first sub-network segment is an abnormal sub-network segment based on the second output.

10. The apparatus according to claim 8 or 9, characterized in that, The acquisition unit is further configured to acquire N segment feature values ​​of the network, wherein the N segment feature values ​​correspond one-to-one with the N segment features; The processing unit is specifically used to determine, based on the reference value range of each segment feature, the abnormal segment feature value and the non-abnormal segment feature value among the N segment feature values ​​obtained by the acquisition unit; and to determine the segment feature comparison value of the segment feature corresponding to the abnormal segment feature value as the reference value of the corresponding segment feature. The segment feature comparison value corresponding to the non-abnormal feature value is determined as the non-abnormal feature value.

11. The apparatus according to claim 10, characterized in that, The reference value for each segment feature is determined based on at least one historical feature value of each segment feature.

12. The apparatus according to any one of claims 8 to 11, characterized in that, The acquisition unit is also used to acquire key performance indicator (KPI) data of at least one first service flow transmitted in the network; The processing unit is further configured to determine the number of poor-quality service flows in the at least one first service flow based on the KPI data of the at least one first service flow obtained by the acquisition unit; and to determine that the number of poor-quality service flows in the at least one service flow is greater than or equal to a preset threshold.

13. The apparatus according to claim 12, characterized in that, The acquisition unit is further configured to acquire N+1 segment feature values ​​when the network transmits at least one second service flow, wherein the N+1 segment feature values ​​correspond one-to-one with N+1 network segments; The processing unit is further configured to determine the quality deterioration state of each of the at least one second service flow, wherein the first quality deterioration state indicates whether each of the second service flows is a quality deterioration service flow; generate first training data based on the first quality deterioration state, wherein the first training data includes a first input and a first label; the first input includes the N+1 segmented feature values ​​obtained by the acquisition unit; when the number of quality deterioration service flows in the at least one second service flow is greater than or equal to the preset threshold, the first label indicates that the network is an abnormal network, and when the number of quality deterioration service flows in the at least one second service flow is less than the preset threshold, the first label indicates that the network is a non-abnormal network; the first training data is used to train the first prediction model.

14. The apparatus according to claim 13, characterized in that, The acquisition unit is further configured to acquire M+1 sub-segment feature values ​​when the network transmits the at least one second service flow, wherein the M+1 sub-segment feature values ​​correspond one-to-one with the M+1 network sub-segments; The processing unit is further configured to determine the abnormal state of the first network segment based on the first training sample and the first prediction model, wherein the abnormal state is used to indicate whether the first network segment is an abnormal network segment; generate second training data based on the abnormal state, wherein the second training data includes a second input and a second label; the second input includes the M+1 sub-segment feature values ​​obtained by the acquisition unit, wherein the second label indicates that the first network segment is an abnormal network segment when the first network segment is an abnormal network segment, and the second label indicates that the first network segment is a non-abnormal network segment when the first network segment is a non-abnormal network segment.

15. An anomaly location device, characterized in that, The anomaly location device includes a processor and a memory, wherein the memory stores instructions, and when the processor executes the instructions, the anomaly location device performs the network anomaly location method as described in any one of claims 1-7.

16. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed on the device, cause the device to perform the network anomaly location method as described in any one of claims 1-7.