A communication network alarm root cause analysis method and related device
Patent Information
- Application Number
- CN202611179083.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-04
- Publication Date
- 2026-09-25
AI Technical Summary
[0002]相关技术中,大型通信网络的单一物理故障会沿信号路径引发多网元、多层次的关联告警,进而在短时间内形成告警风暴
[0015]本申请实施例至少包括以下有益效果:本申请提供一种通信网络告警根因分析方法和相关设备,该方案通过从告警库中提取历史预设时长内的白名单告警对象列表后,将白名单告警对象列表转换为结构化告警子网连接对象集合,然后对结构化告警子网连接对象集合进行纵向衍生分析得到根告警列表后,再对根告警列表中的根告警对进行横向传递分析得到根因分析结果;本实施例通过纵向衍生和横向传递的分析方式,可以自动且准确地识别出根告警和衍生告警,从而可以显著降低无效工单数量,提高告警根因分析的准确度,进而提高通信网络的运维效率。
Smart Images

Figure CN122824569A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication fault analysis technology, and in particular to a method and related equipment for root cause analysis of communication network alarms. Background Technology
[0002] In related technologies, a single physical failure in a large communication network can trigger multi-element, multi-level associated alarms along the signal path, thus forming an alarm storm in a short period of time. Current methods create a work order for each alarm, but this generates a large number of redundant work orders, leading to wasted maintenance manpower in subsequent alarm processing and potentially masking the root cause of the fault, thus reducing processing efficiency. Existing alarm root cause analysis methods mainly rely on static rules, making it difficult to adapt to dynamic changes in network topology and service paths. Furthermore, their analysis dimensions are limited, and they cannot accurately pinpoint the set of associated alarms for the same fault, resulting in low accuracy of the final alarm root cause analysis results.
[0003] In summary, the technical problems existing in the relevant technologies need to be improved. Summary of the Invention
[0004] The main objective of this application is to propose a communication network alarm root cause analysis method and related equipment, which can effectively improve the accuracy of alarm root cause analysis.
[0005] To achieve the above objectives, one aspect of this application proposes a root cause analysis method for communication network alarms, the method comprising the following steps: Extract a list of whitelisted alarm objects within a preset historical time period from the alarm database; The whitelist of alarm objects is converted into a set of structured alarm subnet connection objects; each structured alarm subnet connection object in the set of structured alarm subnet connection objects carries alarm information and an associated subnet connection list; A vertical derivation analysis is performed on the set of connected objects in the structured alarm subnet to obtain the root alarm list; Horizontal propagation analysis is performed on the root alarm pairs in the root alarm list to obtain the root cause analysis results.
[0006] In some embodiments, extracting the list of whitelisted alarm objects from the alarm database within a historical preset time period includes: Obtain the scale of the communication network; The preset sampling frequency is determined based on the scale of the communication network. Based on the current alarm table, alarm context information and alarm associated subnet connection objects within a preset time period are extracted from the alarm database using the preset sampling frequency to form the whitelist alarm object list.
[0007] In some embodiments, the step of performing vertical derivation analysis on the set of structured alarm subnet connection objects to obtain a root alarm list includes: Alarm pairs with root cause and derivative relationships are identified from the structured alarm subnet connection object set. The alarm pairs include a first alarm object and a second alarm object. Both the first alarm object and the second alarm object are alarm objects that have not been marked as derivative alarms. When the second alarm object and the first alarm object meet the preset requirements, the second alarm object is marked as a derivative alarm of the first alarm object; After completing the derivation judgment of all the alarm pairs, all unmarked first alarm objects are identified as root alarm objects, thus obtaining the root alarm list.
[0008] In some embodiments, marking the second alarm object as a derived alarm of the first alarm object when the second alarm object and the first alarm object meet preset requirements includes: Obtain the time window threshold for the fault event; When the subnet connection list of the second alarm object belongs to a subset of the subnet connection list of the first alarm object, the absolute value of the difference between the alarm time of the second alarm object and the alarm time of the first alarm object is less than the fault event time window threshold, and the network layer of the second alarm object and the network layer of the first alarm object satisfy the cross-layer derivation relationship, the second alarm object is marked as a derived alarm of the first alarm object.
[0009] In some embodiments, the step of performing lateral propagation analysis on root alarm pairs in the root alarm list to obtain root cause analysis results includes: Obtain the target application scenario for the root alarm pairs in the root alarm list; Obtain target horizontal analysis rules based on the target application scenario; Based on the target lateral analysis rules, the root alarm pairs are subjected to lateral propagation analysis to obtain root cause analysis results.
[0010] In some embodiments, the method further includes the following steps: Obtain the alarm types from the root cause analysis results; The alarm types are statistically analyzed as the first statistical data for root alarms and as the second statistical data for derived alarms. When it is determined that the first statistical data is greater than the first threshold, the alarm type is added to the whitelist alarm object list; When the second statistical data is determined to be less than the second threshold, the alarm type is removed from the whitelist alarm object list.
[0011] To achieve the above objectives, another aspect of this application provides a communication network alarm root cause analysis device, the device comprising: The time window query module is used to extract a list of whitelisted alarm objects within a historical preset time period from the alarm database. The alarm object conversion module is used to convert the whitelist of alarm objects into a set of structured alarm subnet connection objects; each structured alarm subnet connection object in the set of structured alarm subnet connection objects carries alarm information and an associated subnet connection list; The vertical derivation analysis module is used to perform vertical derivation analysis on the set of connected objects of the structured alarm subnet to obtain the root alarm list; The lateral propagation analysis module is used to perform lateral propagation analysis on the root alarm pairs in the root alarm list to obtain root cause analysis results.
[0012] To achieve the above objectives, another aspect of this application provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the method described above.
[0013] To achieve the above objectives, another aspect of the embodiments of this application proposes a computer-readable storage medium storing a computer program that, when executed by a processor, implements the methods described above.
[0014] To achieve the above objectives, another aspect of the embodiments of this application proposes a computer program product, including a computer program that, when executed by a processor, implements the aforementioned method.
[0015] The embodiments of this application include at least the following beneficial effects: This application provides a method and related equipment for root cause analysis of communication network alarms. This scheme extracts a whitelist of alarm objects within a preset historical time period from the alarm database, converts the whitelist of alarm objects into a structured alarm subnet connection object set, then performs vertical derivation analysis on the structured alarm subnet connection object set to obtain a root alarm list, and then performs horizontal propagation analysis on the root alarm pairs in the root alarm list to obtain the root cause analysis results. This embodiment, through the vertical derivation and horizontal propagation analysis methods, can automatically and accurately identify root alarms and derived alarms, thereby significantly reducing the number of invalid work orders, improving the accuracy of alarm root cause analysis, and thus improving the operation and maintenance efficiency of the communication network. Attached Figure Description
[0016] Figure 1 This is a flowchart of a communication network alarm root cause analysis method provided in an embodiment of this application; Figure 2This is a flowchart illustrating the extraction process of the whitelist alarm object list provided in this application embodiment; Figure 3 This is a flowchart illustrating the conversion of a whitelist of alarm objects into a set of AlarmRSnc objects, as provided in this application embodiment. Figure 4 This is a flowchart of the vertical derivation analysis provided in the embodiments of this application; Figure 5 This is a schematic diagram of the lateral transfer analysis provided in the embodiments of this application; Figure 6 This is a schematic diagram of upstream and downstream MUT_LOS transmission within the OMS layer provided in an embodiment of this application; Figure 7 This is a schematic diagram of MUT_LOS transfer between OMS / OTS provided in an embodiment of this application; Figure 8 This is a schematic diagram of single-wavelength R_LOS and MUT_LOS root cause reversal provided in the embodiments of this application; Figure 9 This is a schematic diagram of intra-layer SSF / AIS transmission provided in an embodiment of this application; Figure 10 This is a schematic diagram of the structure of a communication network alarm root cause analysis device provided in an embodiment of this application; Figure 11 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit it. In the following description, when referring to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those of this application; they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of this application as detailed in the appended claims.
[0018] It is understood that the terms “first,” “second,” etc., used in this application may be used herein to describe various concepts, but unless otherwise stated, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiments of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the words “if,” “when,” or “in response to a determination” as used herein may be interpreted as “when…” or “when…” or “in response to a determination.”
[0019] As used in this application, the terms "at least one", "multiple", "each", "any", etc., "at least one" includes one, two or more, "multiple" includes two or more, "each" refers to each of the corresponding multiples, and "any" refers to any one of the multiples.
[0020] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.
[0021] Before providing a detailed description of the embodiments of this application, some of the nouns and terms used in the embodiments of this application will be explained first. The nouns and terms used in the embodiments of this application shall be interpreted as follows: SNC (Subnetwork Connection) is used to express the logical channel between two points in the transmission channel. It is the bearer object of alarm association. There are bearer relationships between SNCs at different signal layers. For example, OCH is carried on OMS. It is used to determine the bearer transmission characteristics between alarms in vertical derivation analysis by the inclusion relationship of the SNC list.
[0022] SNC signal flow: The signal propagation path of SNC is used to determine the upstream and downstream positions of alarm ports in lateral propagation analysis, ensuring that the propagation direction is consistent with the physical signal propagation direction.
[0023] OCH (Optical Channel) is a core concept in Optical Transport Network (OTN) and is the basic optical layer transmission entity in the OTN architecture used to carry customer signals (such as SDH and Ethernet).
[0024] In related technologies, a single physical failure in a large communication network can trigger multi-element, multi-level correlated alarms along the signal path, leading to an alarm storm in a short period of time. Current methods create a work order for each alarm, but this generates a large number of redundant work orders, resulting in wasted maintenance manpower in subsequent alarm processing and potentially masking the root cause of the fault, thus reducing processing efficiency. Existing alarm root cause analysis methods mainly suffer from the following drawbacks: Defect 1: It relies on static rules, making it difficult to adapt to dynamic changes in network topology and business paths; Defect 2: The analysis dimension is too limited, relying solely on alarm names and time similarity, resulting in a high false positive rate and failing to utilize the actual network signal flow carrying structure. Defect 3: Lacks cross-layer analysis capabilities, unable to handle alarm transmission and reversal scenarios between the optical layer and the business layer; Defect 4: The time window setting is crude, making it impossible to accurately pinpoint the associated alarm set for the same fault.
[0025] In view of this, this application provides a communication network alarm root cause analysis method and related equipment. This solution constructs an analysis method of vertical derivation and horizontal transmission, which can automatically and accurately identify root alarms and derived alarms, thereby significantly reducing the number of invalid work orders, improving the accuracy of alarm root cause analysis, and thus improving the operation and maintenance efficiency of the communication network.
[0026] This application provides a method for root cause analysis of communication network alarms, relating to the field of communication fault analysis technology. This method can be applied to terminals, servers, or software running on either terminal or server. In some embodiments, the terminal can be a smartphone, tablet, laptop, desktop computer, smart speaker, smartwatch, or vehicle terminal, but is not limited thereto. The server can be configured as an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The server can also be a node server in a blockchain network. The software can be an application implementing a communication network alarm root cause analysis method, but is not limited to the above forms.
[0027] This application can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics devices, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0028] The embodiments of this application will be described in detail below with reference to the accompanying drawings: Figure 1 This is an optional flowchart of a communication network alarm root cause analysis method provided in an embodiment of this application. Figure 1 The method may include, but is not limited to, steps S110 to S140: Step S110: Extract the list of whitelisted alarm objects within the historical preset time period from the alarm database; Step S120: Convert the whitelist of alarm objects into a set of structured alarm subnet connection objects; wherein each structured alarm subnet connection object in the set of structured alarm subnet connection objects carries alarm information and an associated subnet connection list; Step S130: Perform vertical derivation analysis on the set of connected objects in the structured alarm subnet to obtain the root alarm list; Step S140: Perform lateral propagation analysis on the root alarm pairs in the root alarm list to obtain the root cause analysis results.
[0029] It is understandable that the process of extracting the whitelist of alarm objects within a historical preset time period from the alarm database in this embodiment can be achieved by obtaining the communication network size, determining the preset sampling frequency based on the communication network size, and then, based on the current alarm table, extracting alarm context information and alarm-related subnet connection objects from the alarm database within a historical preset time period using the preset sampling frequency to form the whitelist of alarm objects. This embodiment sets the preset sampling frequency based on the communication network size, thereby adapting to the alarm generation rate under different network sizes. For example, for large networks with frequent alarm storms, a preset sampling frequency of 30 seconds can be used for data collection, thereby capturing newly generated alarms faster and shortening the root cause analysis delay; for networks with a smaller alarm volume, a preset sampling frequency of 2 minutes can be used for data collection, thereby effectively reducing system load.
[0030] Specifically, such as Figure 2 As shown, this embodiment can collect the current alarm at a preset sampling frequency, and then extract the subnet connection (SNC) objects associated with the current alarm within a preset historical time period from the alarm database through multi-table association queries. It then obtains the alarm context information of the associated SNC objects and the current alarm to form a whitelist of alarm objects. The alarm context information includes, but is not limited to, basic fields such as alarm identifier number, network element alarm time, network management alarm time, alarm name, alarm object, and alarm layer rate. The associated SNC objects include information such as alarm representation number, SNC number, and SNC signal layer rate.
[0031] Specifically, in this embodiment, when data is collected at a preset sampling frequency, the collection duration corresponding to each preset sampling frequency will cover a sliding time window of a specific duration in the past, thereby ensuring the timeliness and completeness of alarm data collection.
[0032] It is understood that, in this embodiment, after obtaining the whitelist of alarm objects, the whitelist of alarm objects is converted into a structured alarm subnet connection object set (AlarmRSnc object set). Each AlarmRSnc object carries complete alarm information and an associated subnet connection list (SNCS). Specifically, as shown... Figure 3 As shown, after obtaining the whitelist of alarm objects, the conversion logic is executed based on the whitelist of alarm objects to obtain the AlarmRSnc object set. The conversion logic process involves traversing the alarm records in the whitelist of alarm objects to extract the SNC number, thereby forming an associated subnet connection list (SNCS).
[0033] It is understandable that, after obtaining the AlarmRSnc object set, this embodiment performs vertical derivation analysis on the structured alarm subnet connection object set to obtain the root alarm list. The execution process of this embodiment includes the following steps: Alarm pairs with root cause and derivative relationships are identified from the structured alarm subnet connection object set. The alarm pairs include a first alarm object and a second alarm object. Both the first alarm object and the second alarm object are alarm objects that have not been marked as derivative alarms. When the second alarm object and the first alarm object meet the preset requirements, the second alarm object is marked as a derivative alarm of the first alarm object; After completing the derivation judgment of all alarm pairs, all unmarked first alarm objects are identified as root alarm objects, resulting in the root alarm list.
[0034] Specifically, in this embodiment, each object in the structured alarm subnet connection object set contains key fields such as the associated SNC list, alarm time, alarm type, and network layer. This embodiment generally traverses all alarm objects in the structured alarm subnet connection object set, determines the relationships between alarm objects, and then obtains the root alarm list. In this embodiment, after obtaining the fault event time window threshold, when the subnet connection list of the second alarm object is a subset of the subnet connection list of the first alarm object, the absolute value of the difference between the alarm time of the second alarm object and the alarm time of the first alarm object is less than the fault event time window threshold, and the network layer of the second alarm object and the network layer of the first alarm object satisfy a cross-layer derivation relationship, the second alarm object is marked as a derived alarm of the first alarm object. For example, as shown... Figure 4As shown, taking X as the first alarm object and Y as the second alarm object as an example, this embodiment iterates through all alarm objects X that are not marked as derivative alarms; for each alarm object X, it iterates through all other alarm objects Y that are also not marked as derivative alarms. To determine whether Y is a derived alarm of X, three conditions must be met simultaneously: First, the SNC list of alarm object Y must be a subset of the SNC list of X, meaning that every SNC bearer relationship affected by alarm object Y is completely covered by alarm object X, thus reflecting the hierarchical transmission characteristics of signal flow from root cause to derivative; Second, the absolute value of the difference between the alarm times of alarm object X and alarm object Y does not exceed the preset fault event time window threshold (configurable, such as 3 minutes), thus ensuring that both belong to the same fault event time window; Third, the alarm types and network layers of alarm object X and alarm object Y must satisfy the cross-layer derivation relationship defined in the fault diagnosis alarm derivation and transmission relationship table. For example, an alarm at the optical transport segment layer can derive an alarm at the optical channel layer, thus filtering out alarm pairs that are coincidentally timed but have no causal relationship.
[0035] In this embodiment, when all three conditions mentioned above are met, alarm object Y is marked as a derived alarm of alarm object X. After traversing all alarm pairs, all alarm objects X that are not marked as derived alarms are identified as root alarms within the current time window, forming a root alarm list Xs. This embodiment, through precise matching of SNC bearer relationships, combined with the dual constraints of time windows and cross-layer rules, can achieve accurate extraction of root cause alarms in alarm storms, providing effective data input for subsequent horizontal propagation analysis.
[0036] It is understood that, after obtaining the root alarm list through vertical derivation analysis, this embodiment can obtain the target application scenario of the root alarm pairs in the root alarm list, obtain the target horizontal analysis rules based on the target application scenario, and then perform horizontal propagation analysis on the root alarm pairs based on the target horizontal analysis rules to obtain the root cause analysis results. In this embodiment, the absolute value of the time difference between the alarm pairs and the corresponding alarms does not exceed a set time threshold, thereby effectively improving the timeliness of alarm analysis. Specifically, as... Figure 5 As shown, the target application scenarios in this embodiment include scenario 1, scenario 2, scenario 3, and scenario 4. Scenario 1 is the upstream and downstream MUT_LOS transfer scenario within the OMS layer; scenario 2 is the MUT_LOS transfer scenario across OMS / OTS; scenario 3 is the root cause reversal scenario between single-wavelength R_LOS and MUT_LOS; and scenario 4 is the intra-layer SSF / AIS transfer scenario.
[0037] Understandably, in situations like Figure 6In the upstream and downstream MUT_LOS transmission scenario within the OMS layer shown, the corresponding target lateral analysis rule is as follows: when multiple OMS layer LOS root alarms are associated with the same OMS object, the upstream and downstream positions of the alarm port are determined by obtaining the signal flow of that OMS. Specifically, firstly, the OMS identifier is extracted from the OTS or alarm object associated with the alarm, then the signal flow path of that OMS is queried, and the alarm port is correctly attached to the signal flow. Alarms located upstream of the signal flow are determined to be root alarms, and downstream alarms are marked as derived alarms. This embodiment ensures that the transmission direction is consistent with the physical signal propagation direction by relying on the directionality of the signal flow.
[0038] Understandably, in situations like Figure 7 In the cross-OMS / OTS MUT_LOS transmission scenario shown, the corresponding target lateral analysis rule is as follows: multiple LOS-type root alarms are associated with different OMS / OTS objects, but these objects share the same OCH object list. The upstream and downstream are determined by comparing the inclusion relationship of the OCH lists of each root alarm. Specifically, if the OCH list of root alarm A1 contains the OCH list of root alarm A2 but they are not equal, then A1 is the root alarm; if they are equal, then the OTS and OMS objects of root alarms A1 and A2 need to be further obtained, and one OCH is taken, with all OTS and OMS attached to the signal flow of that OCH. The upstream and downstream are determined based on the preceding and following positions of the signal flow; if the OCH list of root alarm A2 contains that of root alarm A1, then root alarm A2 is the root alarm; if they do not contain each other, the two alarms are not associated. This embodiment utilizes OCH as a bearer link, combined with signal flow topology, to achieve root cause localization across OMS / OTS.
[0039] Understandably, in situations like Figure 8 In the single-wavelength R_LOS and MUT_LOS root cause reversal scenario shown, the corresponding target lateral analysis rule is as follows: when a LOS-type root alarm in the OMS layer is associated with only one OCH object, and its derived alarm list contains a LOS alarm for that OCH, root cause reversal is performed. Specifically, a single-wavelength R_LOS alarm, i.e., a LOS in the OCH layer, is determined as a root alarm, while a MUT_LOS alarm in the OMS layer is marked as a derived alarm. This reversal process is based on the physical layer fault propagation law: a single-wavelength fault, such as abnormal optical power, will trigger a multiplex section alarm in the upper-layer OMS, therefore the root cause should be located in the lower-layer OCH.
[0040] Understandably, in situations like Figure 9In the intra-layer SSF / AIS transmission scenario shown, the corresponding target lateral analysis rule is as follows: when multiple SSF / AIS root alarms are associated with the same SNC object, the signal level derived or transmitted within the same layer is obtained by querying the alarm rule table. Then, alarms at the specified signal level and belonging to the same SNC are selected and correctly attached to the SNC signal stream. Alarms located upstream of the signal stream are determined to be root alarms, and downstream alarms are derived alarms. This embodiment ensures that the transmission direction is consistent with the signal stream direction by relying on the directionality and hierarchical rules of the signal stream.
[0041] As can be seen from the above, this embodiment can achieve high-order extended analysis of root alarm pairs by performing rule-based processing on each scenario, thereby effectively solving problems such as multiple root cause overlap and cross-layer root inversion in complex network topologies, and improving the accuracy and robustness of root cause localization.
[0042] It is understood that, after completing the root cause analysis at the current time point, the method of this embodiment can obtain the alarm types in the root cause analysis results and statistically analyze the alarm types as the first statistical data of root alarms and the second statistical data as derived alarms; when the first statistical data is greater than a first threshold, the alarm type is added to the whitelist alarm object list; when the second statistical data is less than a second threshold, the alarm type is removed from the whitelist alarm object list. This allows for dynamic management of the whitelist alarm object list to adapt to changes in network alarm patterns and improve the accuracy of subsequent root cause analysis.
[0043] Please see Figure 10 This application also provides a communication network alarm root cause analysis device, which includes: The time window query module is used to extract a list of whitelisted alarm objects within a historical preset time period from the alarm database. The alarm object conversion module is used to convert a whitelist of alarm objects into a structured set of alarm subnet connection objects; each structured alarm subnet connection object in the structured alarm subnet connection object set carries alarm information and an associated list of subnet connections. The vertical derivation analysis module is used to perform vertical derivation analysis on the set of connected objects in the structured alarm subnet to obtain the root alarm list; The lateral propagation analysis module is used to perform lateral propagation analysis on root alarm pairs in the root alarm list to obtain root cause analysis results.
[0044] It is understood that the content of the above method embodiments is applicable to the present device embodiments. The specific functions implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0045] This application also provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the above-described method. This electronic device can be any smart terminal, including tablet computers, in-vehicle computers, etc.
[0046] It is understood that the content of the above method embodiments is applicable to this device embodiment. The specific functions implemented by this device embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0047] Please see Figure 11 , Figure 11 The hardware structure of an electronic device according to another embodiment is illustrated. The electronic device includes: The processor 901 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application. The memory 902 can be implemented as a read-only memory (ROM), static storage device, dynamic storage device, or random access memory (RAM). The memory 902 can store the operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 902 and is called and executed by the processor 901 using the methods described in the embodiments of this application. The input / output interface 903 is used to implement information input and output; The communication interface 904 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.). Bus 905 transmits information between various components of the device (e.g., processor 901, memory 902, input / output interface 903, and communication interface 904); The processor 901, memory 902, input / output interface 903, and communication interface 904 are connected to each other within the device via bus 905.
[0048] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method.
[0049] It is understood that the content of the above method embodiments is applicable to this storage medium embodiment. The specific functions implemented in this storage medium embodiment are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those achieved in the above method embodiments.
[0050] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.
[0051] It is understood that the content of the above method embodiments is applicable to the embodiments of this program product. The specific functions implemented by the embodiments of this program product are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0052] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0053] This application provides a communication network alarm root cause analysis method and related equipment. During vertical derivation analysis, it identifies root alarms and derived alarms based on triple constraints of SNC bearer relationships, time windows, and cross-layer rules. Through precise matching of SNC bearer relationships, combined with time windows and cross-layer rules, it can effectively filter alarm pairs that are coincidentally timed but have no causal relationship, accurately extracting root alarms from alarm storms. Furthermore, by utilizing the directionality of signal flow, it ensures that the transmission direction is consistent with the physical signal propagation direction, avoiding misjudgments of upstream and downstream relationships. This effectively solves the root cause analysis of alarms propagated within the same OMS, across OMSs, and other SNC layers. Simultaneously, this embodiment also improves the accuracy of root cause location by employing different transmission analysis methods based on different scenarios during horizontal transmission analysis.
[0054] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.
[0055] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.
[0056] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0057] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.
[0058] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0059] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0060] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0061] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0062] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0063] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0064] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application.
Claims
1. A method for root cause analysis of communication network alarms, characterized in that, The method includes the following steps: Extract a list of whitelisted alarm objects within a preset historical time period from the alarm database; The whitelist of alarm objects is converted into a set of structured alarm subnet connection objects; each structured alarm subnet connection object in the set of structured alarm subnet connection objects carries alarm information and an associated subnet connection list; A vertical derivation analysis is performed on the set of connected objects in the structured alarm subnet to obtain the root alarm list; Horizontal propagation analysis is performed on the root alarm pairs in the root alarm list to obtain the root cause analysis results.
2. The method according to claim 1, characterized in that, The step of retrieving a list of whitelisted alarm objects from the alarm database within a preset historical time period includes: Obtain the scale of the communication network; The preset sampling frequency is determined based on the scale of the communication network. Based on the current alarm table, alarm context information and alarm associated subnet connection objects within a preset time period are extracted from the alarm database using the preset sampling frequency to form the whitelist alarm object list.
3. The method according to claim 1, characterized in that, The vertical derivation analysis of the structured alarm subnet connection object set yields a root alarm list, including: Alarm pairs with root cause and derivative relationships are identified from the structured alarm subnet connection object set. The alarm pairs include a first alarm object and a second alarm object. Both the first alarm object and the second alarm object are alarm objects that have not been marked as derivative alarms. When the second alarm object and the first alarm object meet the preset requirements, the second alarm object is marked as a derivative alarm of the first alarm object; After completing the derivation judgment of all the alarm pairs, all unmarked first alarm objects are identified as root alarm objects, thus obtaining the root alarm list.
4. The method according to claim 3, characterized in that, The step of marking the second alarm object as a derived alarm of the first alarm object when the second alarm object and the first alarm object meet preset requirements includes: Obtain the time window threshold for the fault event; When the subnet connection list of the second alarm object belongs to a subset of the subnet connection list of the first alarm object, the absolute value of the difference between the alarm time of the second alarm object and the alarm time of the first alarm object is less than the fault event time window threshold, and the network layer of the second alarm object and the network layer of the first alarm object satisfy the cross-layer derivation relationship, the second alarm object is marked as a derived alarm of the first alarm object.
5. The method according to claim 1, characterized in that, The lateral propagation analysis of the root alarm pairs in the root alarm list to obtain root cause analysis results includes: Obtain the target application scenario for the root alarm pairs in the root alarm list; Obtain target horizontal analysis rules based on the target application scenario; Based on the target lateral analysis rules, the root alarm pairs are subjected to lateral propagation analysis to obtain root cause analysis results.
6. The method according to claim 1, characterized in that, The method further includes the following steps: Obtain the alarm types from the root cause analysis results; The alarm types are statistically analyzed as the first statistical data for root alarms and as the second statistical data for derived alarms. When it is determined that the first statistical data is greater than the first threshold, the alarm type is added to the whitelist alarm object list; When the second statistical data is determined to be less than the second threshold, the alarm type is removed from the whitelist alarm object list.
7. A communication network alarm root cause analysis device, characterized in that, The device includes: The time window query module is used to extract a list of whitelisted alarm objects within a historical preset time period from the alarm database. The alarm object conversion module is used to convert the whitelist of alarm objects into a set of structured alarm subnet connection objects; each structured alarm subnet connection object in the set of structured alarm subnet connection objects carries alarm information and an associated subnet connection list; The vertical derivation analysis module is used to perform vertical derivation analysis on the set of connected objects of the structured alarm subnet to obtain the root alarm list; The lateral propagation analysis module is used to perform lateral propagation analysis on the root alarm pairs in the root alarm list to obtain root cause analysis results.
8. An electronic device, characterized in that, include: At least one processor; At least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor implements the method as described in any one of claims 1 to 6.
9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 6.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 6.