Operation and maintenance rule updating method and system, device, storage medium, and program product
By identifying the causal relationship between abnormal features in the device cluster and updating the operation and maintenance rules to handle anomalies in advance, the problem of operation and maintenance rules being hit too late is solved, and the stability and reliability of the device cluster are improved.
Patent Information
- Application Number
- PCT/IB2025/051684
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-22
- Filing Date
- 2025-02-17
- Publication Date
- 2025-09-25
AI Technical Summary
In the prior art, the configuration of operation and maintenance rules has the problem of being hit too late, causing the server to be damaged for too long, especially because the causal relationship between abnormal situations is not identified and handled in a timely manner.
By obtaining multiple abnormal features of the target device cluster and their occurrence time, it is determined whether there is a correlation between the abnormal features, especially a causal relationship, and based on this, the operation and maintenance rules are updated to hit the operation and maintenance rules in advance and process them.
It improves the scientific rationality of operation and maintenance rules, reduces the occurrence of abnormal characteristics, and improves the operational stability and reliability of the equipment cluster.
Smart Images

Figure IB2025051684_25092025_PF_FP_ABST
Abstract
Description
[0001] TECHNICAL FIELD The present disclosure relates to the field of computer technology, and more particularly to a method, system, device, storage medium, and program product for updating operation and maintenance rules. Background: During server operation, abnormalities may occur in network cards, CPUs (Central Processing Units), motherboards, and other aspects, requiring the deployment of operation and maintenance rules to handle these abnormalities. In related art, operation and maintenance rules are typically configured by experts based on potential server abnormalities. When a server abnormality occurs and the abnormality matches a corresponding operation and maintenance rule, the corresponding operation and maintenance policy is automatically executed. However, since experts configure operation and maintenance rules based on their experience, some abnormalities may not have corresponding operation and maintenance rules configured. Furthermore, some abnormalities may be caused by other abnormalities. Before an abnormality matches an operation and maintenance rule, the other abnormalities may have already existed for some time. This can cause the operation and maintenance rule to be triggered too late, resulting in prolonged server damage. SUMMARY OF THE INVENTION This disclosure addresses the issue in the related art where operation and maintenance rules may be updated too late, resulting in prolonged server damage. A method, system, device, storage medium, and program product for updating operation and maintenance rules are proposed. In a first aspect, this disclosure provides a method for updating operation and maintenance rules, comprising: obtaining multiple abnormal features of a target device cluster and the occurrence time of each abnormal feature; determining, based on the multiple abnormal features and the occurrence time of each abnormal feature, whether there are any associated abnormal features among the multiple abnormal features, wherein the associated relationship is used to indicate a causal relationship between the abnormal features; and, if such associated abnormal features exist, updating the operation and maintenance rules for the target device cluster based on the associated abnormal features. A second aspect of the present disclosure proposes an operation and maintenance rule updating device, the device comprising: an acquisition module for acquiring multiple abnormal features of a target device cluster and the occurrence time of each of the abnormal features; a determination module for determining whether there are abnormal features with associated relationships among the multiple abnormal features based on the multiple abnormal features and the occurrence time of each of the abnormal features, wherein the associated relationships are used to characterize the existence of a causal relationship between the abnormal features; an update module for updating the operation and maintenance rules of the target device cluster based on the abnormal features with associated relationships when the abnormal features with associated relationships exist.A third aspect of the present disclosure provides a system for updating operation and maintenance rules, comprising a cloud server cluster and an operation and maintenance platform. The cloud servers in the cloud server cluster are configured to obtain operation data of the cloud servers and transmit the operation data to the operation and maintenance platform. The operation and maintenance platform is configured to obtain, based on the operation data of each cloud server in the cloud server cluster, multiple abnormality features of the cloud server cluster and the occurrence time of each abnormality feature. Based on the multiple abnormality features and the occurrence time of each abnormality feature, the system determines whether there are abnormality features with correlations among the multiple abnormality features, wherein the correlations are used to indicate a causal relationship between the abnormality features. If the abnormality features with correlations exist, the operation and maintenance rules of the cloud server cluster are updated based on the abnormality features with correlations. A fourth aspect of the present disclosure provides an electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor executes the program to implement the method described in the first aspect. A fifth aspect of the present disclosure provides a computer-readable storage medium having a computer program stored thereon, wherein the program is executed by the processor to implement the method described in the first aspect. An embodiment of the sixth aspect of the present disclosure provides a computer program product, including a computer program, which is executed by a processor to implement the method described in the first aspect. Based on the method for updating operation and maintenance rules described in the first aspect, the present disclosure has at least the following beneficial effects or advantages: The embodiment of the present disclosure can explore possible correlations between multiple abnormal features of a target device cluster, and, when abnormal features with correlations are determined to exist, update the operation and maintenance rules of the target device cluster based on the abnormal features with correlations. This allows the mutual influence between abnormal features to be considered in the setting of the operation and maintenance rules for the target device cluster, making the updated operation and maintenance rules more consistent with the inherent causal relationships between various abnormal features that may arise in the target device cluster, thereby improving the scientific rationality of the operation and maintenance rules. Since the causal relationship represents that the cause comes before the effect, the occurrence time of the abnormal feature that serves as the cause among the abnormal features with an associated relationship is earlier than the occurrence time of the abnormal feature that serves as the result. Therefore, the operation and maintenance rules of the target device cluster are updated based on the abnormal features with an associated relationship. The order of occurrence time between the abnormal features with a causal relationship is taken into consideration in the configuration of the operation and maintenance rules, which helps to hit the operation and maintenance rules in advance when the abnormal feature that serves as the cause among the abnormal features with an associated relationship occurs, so that the equipment can be operated and maintained as soon as possible to eliminate the abnormality, reduce the occurrence of the abnormal feature that serves as the result among the abnormal features with an associated relationship, improve the operation and maintenance effect of the target device cluster, and also improve the stability and reliability of the operation of the target device cluster.The above description is merely an overview of the technical solutions of the present disclosure. To provide a clearer understanding of the technical solutions of the present disclosure, implementation should be carried out in accordance with the description. To further enhance the aforementioned and other objectives, features, and advantages of the present disclosure, specific embodiments of the present disclosure are described below. BRIEF DESCRIPTION OF THE DRAWINGS The accompanying drawings described herein are provided to further enhance understanding of the present disclosure and constitute a part of the present disclosure. The illustrative embodiments of the present disclosure and their descriptions are provided to explain the present disclosure and are not intended to unduly limit the present disclosure. In the accompanying drawings: Figure 1 is a flowchart of a method for updating operation and maintenance rules according to some exemplary embodiments of the present disclosure; Figure 2 is a schematic diagram of a system for updating operation and maintenance rules according to some exemplary embodiments of the present disclosure; Figure 3 is a schematic diagram of an operation and maintenance system for a cloud server cluster in the related art; Figure 4 is a schematic diagram of a process flow of an operation and maintenance rule updating system according to some exemplary embodiments of the present disclosure; Figure 5 is a schematic diagram of a process flow for generating feature associations according to an exemplary embodiment of the present disclosure; Figure 6 is a schematic diagram of a cloud server operation and maintenance process according to an exemplary embodiment of the present disclosure; Figure 7 is a schematic diagram of the structure of an operation and maintenance rule updating device according to an exemplary embodiment of the present disclosure; Figure 8 is a schematic diagram of the hardware structure of an electronic device according to an exemplary embodiment of the present disclosure; Figure 9 is a schematic diagram of the structure of a storage medium according to an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS The exemplary embodiments will be described in detail herein, with examples thereof illustrated in the accompanying drawings. In the following description, when referring to the drawings, unless otherwise indicated, identical numerals in different drawings represent identical or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims. The terms used in this disclosure are for the purpose of describing particular embodiments only and are not intended to limit the disclosure. The singular forms "a," "an," "the," and "the" used in this disclosure and the appended claims are intended to include the plural forms as well, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items. It should be understood that although the terms first, second, third, etc. may be used in this disclosure to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first information may also be referred to as second information, and similarly, second information may also be referred to as first information without departing from the scope of this disclosure.Depending on the context, the term "if" as used herein can be interpreted as "at the time of," "when," or "in response to a determination," among other things. It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, and displayed data, etc.) referred to in this disclosure are all authorized by the user or fully authorized by all parties. The collection, use, and processing of relevant data must comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding operation portals are provided for users to choose to authorize or deny. Network devices such as gateways and routers, or servers, typically have operation and maintenance rules deployed to handle abnormal events such as network card failures, slow input / output (I / O) speeds, CPU failures, and motherboard failures. In related technologies, operation and maintenance rules are typically configured by experts based on their own experience and potential abnormalities in the device. When a server experiences an abnormality that first matches a corresponding operation and maintenance rule, the operation and maintenance policy corresponding to the rule is automatically executed. However, when experts configure operation and maintenance rules based on their experience, some abnormal situations may not have corresponding operation and maintenance rules configured, meaning that some abnormal situations may be missed. Furthermore, some abnormal phenomena may be triggered by other abnormal situations. Before the abnormal phenomenon hits the operation and maintenance rules, the other abnormal situations that triggered it may have existed for some time. The operation and maintenance rules may hit the rules too late, causing equipment damage to persist for too long. To address this issue, embodiments of the present disclosure provide an operation and maintenance rule update method. Based on multiple abnormal features of a target device cluster and the occurrence time of each abnormal feature, the method determines whether any of the multiple abnormal features have associated relationships. The association relationship indicates a causal relationship between the abnormal features. If such associated abnormal features exist, the operation and maintenance rules for the target device cluster are updated based on the associated abnormal features. This method can discover causal relationships between different abnormal features, specifically, determine whether one abnormal feature is the cause of another abnormal feature. If such causal abnormal features are discovered, the operation and maintenance rules for the target device cluster are updated based on the causal abnormal features. This approach allows for the mutual influence of abnormal characteristics to be considered during the deployment of operation and maintenance rules for a target device cluster. This ensures that the updated operation and maintenance rules better align with the inherent logical relationships between the various abnormal characteristics that may arise in the target device cluster, improving the scientific rationality of operation and maintenance rule deployment and the operation and maintenance effectiveness of the target device cluster. The following detailed description of the technical solution disclosed herein and how it addresses the aforementioned technical issues is provided through specific embodiments.The specific embodiments listed above may be combined with each other, and identical or similar concepts or processes may not be described in detail in certain embodiments. The following describes the embodiments of the present disclosure in detail with reference to the accompanying drawings. Figure 1 is a flowchart of a method for updating operation and maintenance rules provided in an embodiment of the present disclosure. As shown in Figure 1, the method specifically includes the following steps 101-103. oStep 101: Obtain multiple abnormal features and the occurrence time of each abnormal feature for the target device cluster. Step 102: Based on the multiple abnormal features and the occurrence time of each abnormal feature, determine whether any abnormal features have a correlation relationship among the multiple abnormal features. The correlation relationship is used to indicate a causal relationship between the abnormal features. Step 103: If abnormal features with a correlation relationship exist, update the operation and maintenance rules of the target device cluster based on the abnormal features with a correlation relationship. The execution entity of the embodiment of the present disclosure can be a terminal, a single server, a server cluster, a cloud server, etc., for executing the operation and maintenance rule update method. The target device cluster is composed of multiple devices. These multiple devices can include one or more of various types of devices, such as terminal devices, network devices, and server devices, and the number of each type of device can be one or more. Terminal devices can be desktop computers, laptop computers, sensors, home appliances, automotive terminals, etc. Network devices can be routers, gateways, etc. Server devices can be physical servers or cloud servers, etc. Abnormal features are features extracted based on abnormal events generated on each device in the target device cluster. Abnormal events can include network card failure, memory failure, network card jitter, slow data transmission rate, high processor utilization, slow I / O speed, processor failure, and motherboard failure. Abnormal features are a further abstraction of abnormal events and are actually another description of abnormal events. For example, abnormal events such as network card failure, memory failure, processor failure, and motherboard failure can be abstracted into the abnormal feature "hardware failure"; abnormal events such as network card jitter and slow data transmission rate can be abstracted into the abnormal feature "network abnormality"; and abnormal events such as high processor utilization and slow I / O speed can be abstracted into the abnormal feature "system overload." The occurrence time of an abnormal feature can be the earliest occurrence time of the abnormal events corresponding to the abnormal feature. For example, if the abnormal feature "hardware failure" is extracted based on the abnormal events "network card failure" and "memory failure," and the occurrence time of "network card failure" is earlier than the occurrence time of "memory failure," then the occurrence time of the abnormal feature "hardware failure" can be the occurrence time of the abnormal event "network card failure." Alternatively, in other embodiments, the occurrence time of an abnormal feature may also be the extraction time of the abnormal feature based on each abnormal event. The aforementioned association relationship is used to indicate the existence of a causal relationship between abnormal features. The association relationship includes at least two abnormal features, which can be divided into two categories. The two categories of abnormal features have a causal relationship, that is, one category of abnormal features is the cause of the other category of abnormal features.The category of abnormal features serving as causes may include one or more abnormal features, and the category of abnormal features serving as results may also include one or more abnormal features. As an example, a correlation relationship includes two abnormal features, one of which is the cause of the other. Assuming the two abnormal features are features A and B, and feature A is the cause of feature B, the correlation relationship can be expressed as feature A - feature B. In the disclosed embodiment, multiple abnormal features and the occurrence times of each abnormal feature are obtained for a target device cluster within a preset historical period. Based on the obtained abnormal features and their occurrence times, the relationships between the abnormal features are analyzed. If an abnormal feature with a correlation relationship is determined, the operation and maintenance rules for the target device cluster are updated based on the abnormal feature with the correlation relationship. Specifically, the union of the first operation and maintenance rule corresponding to the abnormal feature serving as the cause and the second operation and maintenance rule corresponding to the abnormal feature serving as the result among the abnormal features with the correlation relationship is determined as the third operation and maintenance rule. The second operation and maintenance rule corresponding to the abnormal feature serving as the result configured in the target device cluster is replaced with the third operation and maintenance rule. The first operation and maintenance rule is the one that is triggered when the abnormal characteristic that is the cause occurs. When the first operation and maintenance rule is triggered, the operation and maintenance action corresponding to the first operation and maintenance rule is executed, and operation and maintenance are performed on the device to eliminate the abnormal characteristic that is the cause. Similarly, the second operation and maintenance rule is the one that is triggered when the abnormal characteristic that is the result occurs. The preset historical period can be the past 30 minutes, one hour, one day, one week, one month, or three months, for example. The present embodiment does not limit the specific value of the preset historical period; in actual applications, it can be set according to needs. Because associated abnormal characteristics have a causal relationship, the occurrence of the abnormal characteristic that is the cause has a significant impact on the occurrence of the abnormal characteristic that is the result, and may even play a decisive role. Therefore, the operation and maintenance of the abnormal characteristic that is the cause also has a significant impact on the occurrence of the abnormal characteristic that is the result. If the corresponding operation and maintenance rule can be triggered to eliminate the abnormal characteristic when the abnormal characteristic that is the cause occurs, it is very likely that the abnormal characteristic that is the result will not occur. Accordingly, if the corresponding operation and maintenance rules are not triggered until the abnormal characteristics as the result occur, the abnormal characteristics as the cause may continue to exist for a long time, which may cause greater damage to the equipment.The disclosed embodiment can mine the possible correlations between multiple abnormal features of the target device cluster, and when it is determined that there are abnormal features with correlations, update the operation and maintenance rules of the target device cluster based on the abnormal features with correlations. This realizes consideration of the mutual influence between abnormal features in the setting of the operation and maintenance rules of the target device cluster, and can make the updated operation and maintenance rules more consistent with the inherent causal relationship between various abnormal features that may be generated by the target device cluster, thereby improving the scientific rationality of the operation and maintenance rules, and helping to hit the operation and maintenance rules in advance when abnormal features with correlations occur, so as to operate and maintain the equipment as early as possible to eliminate the abnormality, reduce the occurrence of abnormal features as a result of abnormal features with correlations, improve the operation and maintenance effect of the target device cluster, and also improve the stability and reliability of the operation of the target device cluster. In some embodiments of the present disclosure, multiple abnormality features of a target device cluster can be obtained by the following method: obtaining abnormal event information generated by each device in the target device cluster within a preset historical period; extracting the abnormality features and the occurrence time of each abnormality feature from the abnormal event information corresponding to each device within the preset historical period; and deleting the abnormality features except for the earliest occurrence time from the repeated abnormality features of the same device if multiple abnormality features are present. The abnormality event information is detailed information about abnormal events occurring on the devices, including a description of the abnormal event, the occurrence time of the abnormal event, and device information about the device on which the abnormal event occurred. The description can be used to describe the specific abnormality of the abnormal event, such as a processor utilization rate of 90% and a CPU speed of 1%. OThe device information of the device where the abnormal event occurred may include a device identifier, a device model, and a URL. In some embodiments of the present disclosure, a proxy application can be deployed on devices in the target device cluster to collect device data. During device operation, the proxy application collects the device's operation logs and performance data and sends the collected operation logs and performance data to an executor device that executes the operation and maintenance rule updating method of the present disclosure. The executor can be any device, such as a terminal or server, or a service or application deployed on a server or in the cloud. The operation log records events and error information during device operation, such as system warnings and error messages, and application warnings and error messages. Device performance data may include processor usage, memory usage, and disk usage. Based on the received device operation logs and performance data, the executor analyzes abnormal events that occurred on the device. Specifically, the executor can perform anomaly analysis based on the operation logs and performance data using pre-set expert rules, statistical rules, or machine learning and deep learning algorithms to obtain abnormal event information corresponding to the abnormal event that occurred on the device. Pre-set expert rules and statistical rules can be configured by operations and maintenance personnel to determine constraints and judgment strategies for abnormal events. Machine learning and deep learning algorithms can include deep neural networks, which are used to predict the probability of abnormal events occurring in equipment based on operation logs and performance data. In some embodiments of the present disclosure, a mapping relationship between abnormal events and abnormal features is pre-configured in the execution entity. This mapping relationship includes multiple mapping records, with each mapping record including a corresponding relationship between at least one abnormal event and one abnormal feature. As an example, this mapping relationship can be shown in Table 1. Table 1 After obtaining the abnormal event information generated by each device in the target device cluster within a preset historical period through the above method, the execution entity queries the abnormal features corresponding to each abnormal event information based on the above mapping relationship and uses the occurrence time of the earliest abnormal event among the abnormal events corresponding to the abnormal feature as the occurrence time of the abnormal feature, or uses the time when the abnormal feature is obtained as the occurrence time of the abnormal feature. If the device does not undergo maintenance to eliminate the abnormal event after the abnormal event occurs, the abnormal event may persist. In this case, the device will continue to issue alarms for the abnormal event, resulting in multiple alarm data for the abnormal event in the device's operation log and performance data. This can lead to multiple identical abnormal events being identified for the device based on the operation log and performance data, resulting in the multiple abnormal features ultimately obtained for the device including multiple duplicate abnormal features, however, the occurrence times of these duplicate abnormal features are different. The algorithm used to subsequently determine whether there are associated abnormal features may not be able to process duplicate abnormal features, or the duplicate abnormal features may affect the accuracy of the algorithm. Therefore, after obtaining multiple abnormality features for each device using the above method, the system also traverses these multiple abnormality features for the same device to determine whether any of them are duplicated. If no duplicates exist, subsequent processing is performed based on these multiple abnormality features. If duplicates exist, the one with the earliest occurrence time is retained and the remaining duplicates are deleted. Using the above method, multiple abnormality features and the occurrence time of each abnormality feature for the target device cluster within a preset historical period are obtained, and duplicates are removed from the obtained abnormality features for each device. By extracting abnormality features from numerous abnormal events, the data for subsequent processing is more refined, reducing the amount of data required, helping to reduce the amount of computation and improve efficiency. Deduplication also prepares data for subsequent exploration of correlations between abnormal features, helping to improve the accuracy of subsequent correlation analysis and, in turn, the accuracy of operation and maintenance rule updates. In some embodiments of the present disclosure, multiple abnormal features of the target device cluster and the occurrence time of each abnormal feature are obtained in the above-mentioned manner. The multiple abnormal features of a device in the target device cluster within a preset historical period can be used as an abnormal data. In this way, each device in the target device cluster will have a corresponding abnormal data, and these multiple abnormal data are combined into an abnormal feature set.Based on the abnormal feature set and the occurrence time of each abnormal feature, the following methods can be used to determine whether any abnormal features with a correlation exist among the multiple abnormal features. Specifically, the following methods are used: Based on the occurrence time of each abnormal feature, a temporal relationship between the abnormal features is determined. This temporal relationship characterizes the temporal order of the occurrence of the abnormal features; Based on the multiple abnormal features, a feature relationship set is generated using a preset feature mining algorithm. This feature relationship set includes multiple feature relationships, each of which characterizes a causal relationship between abnormal features belonging to the same feature relationship; Based on the temporal relationship and the feature relationship set, it is determined whether any abnormal features with a correlation exist among the multiple abnormal features of the target device cluster. The temporal relationship can be obtained by sorting the abnormal features in order of their occurrence time from earliest to latest. The preset feature mining algorithm can include a mining algorithm for mining association rules, such as the FP-Growth (Frequent Pattern Growth) algorithm or the Apriori (Association Rule Algorithm). Taking the FP-Growth algorithm as an example, it is an effective algorithm for discovering frequent itemsets in data mining. A frequent itemset is a set of items (or articles) that frequently appear in multiple transactions. In the embodiments of the present disclosure, if an abnormal feature frequently appears with another abnormal feature, then the two abnormal features constitute a frequent itemset, indicating a possible causal relationship between the two abnormal features, such as one abnormal feature causing the other. Multiple abnormal features of the target device cluster in the abnormal feature set are input into a preset feature mining algorithm, which mines the relationships between the different abnormal features. If the abnormal features are all uncorrelated, the preset feature mining algorithm outputs an empty set, confirming that no abnormal features with a correlation exist among the multiple abnormal features of the target device cluster. If different abnormal features frequently appear together in the abnormal feature set, the preset mining algorithm mines these different abnormal features and organizes them into a feature relationship for output. A feature relationship includes multiple abnormal features, each of which has a causal relationship. The multiple feature relationships output by the preset feature mining algorithm constitute the feature relationship set. The aforementioned different anomaly features that appear together can refer to different anomaly features that frequently appear in the same piece of anomaly data within the anomaly feature set. Taking the FP-Growth algorithm as an example, multiple pieces of anomaly data from the target device cluster within the anomaly feature set are fed into the FP-Growth algorithm. The FP-Growth algorithm then mines for frequent itemsets that may exist within the anomaly feature set.Suppose that among the multiple pieces of abnormal data included in the abnormal feature set, abnormal features A and B often appear together in the same piece of abnormal data, and features E and F often appear together in the same piece of abnormal data. The frequent itemsets mined by the FP-Growth algorithm include A-B, B-A, E-F, and FE. These frequent itemsets are the feature relationships mentioned above, so the final feature relationship set is {AB, BA, EF, FE}. oHere, "..." is used to represent causal relationships. For example, AB indicates that A causes B, while BA indicates that B causes A. Since the FP-Growth algorithm is used to mine frequent itemsets and cannot process time series information, it outputs various possible scenarios in which these abnormal features influence each other for different abnormal features with a certain causal relationship. For example, if there is a certain causal relationship between abnormal features A and B, the FP-Growth algorithm will output both A-B and B-A. After obtaining the feature relationship set obtained by the preset feature mining algorithm, the temporal relationships between the multiple abnormal features of the target device cluster and the feature relationship set are used to determine whether any abnormal features of the target device cluster have associated relationships. Introducing the temporal relationships of the abnormal features based on the preset feature mining algorithm helps to more clearly identify abnormal features with true causal relationships from the feature relationship set. The above embodiment uses the preset feature mining algorithm to mine for abnormal features of the target device cluster that have causal relationships. Based on the output of a preset feature mining algorithm and incorporating the temporal relationships between multiple abnormal features, the resulting association relationship is ensured to closely match the temporal relationships between the abnormal features. The resulting association relationship is more closely aligned with the actual causal logic between the corresponding abnormal features, resulting in highly accurate association relationship determination. This helps improve the accuracy of subsequent operation and maintenance rule updates based on the association relationships, thereby improving the operation and maintenance performance of the target device cluster. In some embodiments of the present disclosure, determining whether there are abnormal features with an association relationship among the multiple abnormal features based on the aforementioned temporal relationships and the feature relationship set specifically includes: based on the aforementioned temporal relationships, removing from the feature relationship set any feature relationships that do not meet a preset temporal condition; the preset temporal condition is used to constrain the occurrence time of the abnormal feature serving as the cause of two abnormal features with a causal relationship to be earlier than the occurrence time of the abnormal feature serving as the result; if there are any remaining feature relationships in the feature relationship set after removal, calculating an evaluation index for the remaining feature relationships, the evaluation index being used to characterize the accuracy of the remaining feature relationships as association relationships; and if there is a target feature relationship whose evaluation index is greater than a preset threshold, determining the abnormal feature corresponding to the target feature relationship as an abnormal feature with an association relationship. For example, in the feature relationship set {AB, B-A, E-F, FE} in the above example, assume that in the time series relationship, the occurrence time of abnormal feature A is earlier than that of abnormal feature B, and the occurrence time of abnormal feature E is earlier than that of abnormal feature F.Based on this temporal relationship, the feature relationships B^A and F*E are removed from the feature relationship set {A-B, B-A, E-F, FE}, resulting in the feature relationship set {A^B, E*F}. In some embodiments, after this removal, the feature relationship set may become an empty set. In this case, it is determined that no abnormal features with associated relationships exist in the target device cluster. If there are remaining feature relationships in the feature relationship set after removal, an evaluation index is calculated for each remaining feature relationship. Only when the evaluation index exceeds a preset threshold is the feature relationship determined to be a relationship that truly represents a causal relationship between abnormal features. In the above embodiment, feature relationships that do not meet the preset temporal conditions are removed so that the occurrence time of the abnormal feature serving as the cause in the remaining feature relationships is always earlier than the occurrence time of the abnormal feature serving as the result. This ensures that the abnormal features in the ultimately determined association relationships conform to the temporal sequence of cause and effect in the causal relationship. For the feature relationships remaining after the elimination operation, the evaluation indicators of these feature relationships are also used to determine whether these feature relationships are association relationships that can truly represent causal relationships. This further improves the accuracy of the ultimately determined association relationships. In some embodiments of the present disclosure, feature relationships that do not meet preset timing conditions are eliminated from the feature relationship set. Specifically, the following steps are performed: From the aforementioned timing relationships, the timing relationship between a first abnormal feature and a second abnormal feature corresponding to a first feature relationship is determined. The first feature relationship is any feature relationship in the feature relationship set, and the first feature relationship is used to indicate that the first abnormal feature is the cause of the second abnormal feature. If the timing relationship between the first abnormal feature and the second abnormal feature indicates that the occurrence time of the first abnormal feature is later than the occurrence time of the second abnormal feature, then the first feature relationship is eliminated from the feature relationship set. In the first feature relationship, the first abnormal feature serving as the cause may include one or more abnormal features, and the second abnormal feature serving as the result may also include one or more abnormal features. If both the first abnormal feature and the second abnormal feature include multiple abnormal features, the first feature relationship is determined to satisfy a preset time sequence condition if the latest abnormal feature among the multiple abnormal features included in the first abnormal feature occurs earlier than the earliest abnormal feature among the multiple abnormal features included in the second abnormal feature. Otherwise, the first feature relationship is determined to not satisfy the preset time sequence condition, and the first feature relationship is removed from the feature relationship set.Based on the temporal order of the causal abnormal features represented by the feature relationships, feature relationships in which the abnormal feature serving as the cause occurs later than the abnormal feature serving as the result are eliminated from the feature relationship set. The abnormal feature serving as the cause in the remaining feature relationships all occurs earlier than the abnormal feature serving as the result. This ensures that the temporal order of the abnormal features in the remaining feature relationships conforms to the logical relationship of cause before effect in causal relationships, helping to improve the accuracy of the ultimately determined association relationships. In some embodiments of the present disclosure, to facilitate the description of the specific calculation process for calculating the evaluation index for the remaining feature relationships, any feature relationship in the remaining feature relationships is referred to as a second feature relationship. The second feature relationship corresponds to the third abnormal feature and the fourth abnormal feature, and the third abnormal feature is the cause of the fourth abnormal feature. Calculating the evaluation index for the remaining feature relationships specifically includes: determining the number of first devices in the target device cluster that experience the third abnormal feature, and the number of target devices that experience both the third and fourth abnormal features; and calculating the evaluation index for the second feature relationship based on the number of first devices and the number of target devices. Abnormal features are extracted based on abnormal events occurring on devices in the target device cluster. For the second characteristic relationship, the number of first devices in the target device cluster that exhibit the third abnormal feature corresponding to the second characteristic relationship and the number of target devices that exhibit both the third and fourth abnormal features are counted. The first devices may include one or more devices. An evaluation index for the second characteristic relationship is calculated based on the counted number of first devices and the number of target devices. This ensures that the calculated evaluation index for the second characteristic relationship conforms to statistical laws, and the resulting evaluation index more accurately represents the degree to which the second characteristic relationship truly reflects the causal relationship between the third and fourth abnormal features. In some embodiments of the present disclosure, the evaluation index may include one or more of confidence, imbalance rate, and lift. Confidence represents the probability of the occurrence of the abnormal feature as a result given the occurrence of the abnormal feature as a cause in the characteristic relationship. Imbalance rate represents the difference between the number of occurrences of the abnormal feature as a cause and the number of occurrences of the abnormal feature as a result in the characteristic relationship. Lift represents the degree to which the occurrence of the abnormal feature as a cause increases the probability of the occurrence of the abnormal feature as a result in the characteristic relationship. Based on the above-stated number of first devices and the number of target devices, an evaluation index of the second characteristic relationship is calculated, specifically including: calculating a first ratio between the number of target devices and the number of first devices to obtain a confidence level of the second characteristic relationship; the confidence level is used to characterize the probability of the fourth abnormal feature occurring under the premise that the third abnormal feature occurs.The target device count refers to the number of devices in the target device cluster that exhibit both the third and fourth abnormal characteristics. The confidence level can be calculated using the following formula (1): / count (A) (1). The third abnormal feature, B is the fourth abnormal feature. P (B | A) is the probability of the fourth abnormal feature B occurring under the premise of the occurrence of the third abnormal feature A, that is, the confidence level. Count (AUB) represents the number of target devices, and count (A) represents the number of first devices. It can be seen from formula (1) that the confidence level actually calculates the proportion of devices where both the third abnormal feature and the fourth abnormal feature occur among all devices where the third abnormal feature occurs. This proportion can reflect the impact of the occurrence of the third abnormal feature on the occurrence of the fourth abnormal feature. In other words, under the premise of the occurrence of the third abnormal feature, the probability of the occurrence of the fourth abnormal feature is the above confidence level. Therefore, this confidence level can well reflect the accuracy of the second characteristic relationship in characterizing the causal relationship between the third abnormal feature and the fourth abnormal feature. The greater the confidence level, the higher the accuracy of the second characteristic relationship in characterizing the causal relationship between the third abnormal feature and the fourth abnormal feature. In some embodiments, when the number of occurrences of the third abnormal feature differs greatly from the number of occurrences of the fourth abnormal feature, the fourth abnormal feature will occur every time the third abnormal feature occurs. For example, suppose that a total of 3,000 abnormal data are collected in the target device cluster, and abnormal feature B occurs in each abnormal data, while abnormal feature A occurs in only 4 abnormal data, and the occurrence time of abnormal feature A is earlier than the occurrence time of abnormal feature B. Then, abnormal feature B will occur after each occurrence of abnormal feature A, and abnormal feature A is likely to be mistakenly judged as the cause of abnormal feature B. Based on this, the embodiment of the present disclosure also sets an evaluation indicator, the imbalance rate, to evaluate the degree of difference between the number of occurrences of the third abnormal feature and the fourth abnormal feature. Specifically, the number of second devices in the target device cluster that have the fourth abnormal feature is determined; a first ratio between the number of target devices and the number of the first devices is calculated; a second ratio between the total number of devices in the target device cluster and the number of second devices is calculated, and the product of the first ratio and the second ratio is calculated to obtain the imbalance rate of the second characteristic relationship. The imbalance rate is used to characterize the degree of difference between the number of occurrences of the third abnormal feature and the number of occurrences of the fourth abnormal feature. The second device may include one or more devices. The imbalance rate can be calculated using the following formula (2):
[0002] IR (A, B) = | sup (A) -sup (B) | / [sup (A) +sup (B) -sup (AUB) ] (2) In the above formula (2), IR (A, B) is the imbalance rate, sup (A) is the support of the third abnormal feature A, sup (A) = count (A) / count (total), which indicates the proportion of devices that have the third abnormal feature A among all devices in the target device cluster. sup (B) is the support of the fourth abnormal feature B, sup (B) = count (B) / count (total), which indicates the proportion of devices that have the fourth abnormal feature B among all devices in the target device cluster. sup (AUB) is the support of both the third abnormal feature A and the fourth abnormal feature B, sup (AUB) = count (AUB) / count (total), which indicates the proportion of devices that have both the third abnormal feature A and the fourth abnormal feature B among all devices in the target device cluster. From formula (2), it can be seen that the imbalance rate is calculated as the difference between the number of occurrences of the third abnormal feature A and the number of occurrences of the fourth abnormal feature B, as a proportion of the total number of occurrences of the third abnormal feature A and the fourth abnormal feature B. The total number of occurrences here is obtained by subtracting the number of occurrences of both the third abnormal feature A and the fourth abnormal feature B. The larger the imbalance rate, the greater the difference between the number of occurrences of the third abnormal feature and the fourth abnormal feature. The smaller the imbalance rate, the smaller the difference between the number of occurrences of the third abnormal feature and the fourth abnormal feature. For example, in the above example, among the 3000 abnormal data, abnormal feature B occurred 3000 times and abnormal feature A occurred 4 times. According to the above formula (2), the imbalance rate is 0.999. oThis indicates a serious imbalance between the occurrences of abnormal features A and B. Therefore, it is unreasonable to attribute abnormal feature A to abnormal feature B. The above example demonstrates that the imbalance rate evaluation metric can effectively characterize feature relationships with imbalanced occurrences of abnormal features. Using the imbalance rate, such feature relationships can be accurately eliminated, thereby improving the accuracy of the ultimately determined association. In particular, for feature relationships with high confidence, combining the imbalance rate evaluation metric can further eliminate those that fail to truly represent causal relationships from those that meet the confidence requirements. The calculation of lift specifically includes: determining the number of second devices in the target device cluster that exhibit the fourth abnormal feature; calculating the ratio between the number of first devices and the total number of devices in the target device cluster to obtain a first support; calculating the ratio between the number of second devices and the total number of devices to obtain a second support; and calculating the ratio between the number of target devices and the total number of devices to obtain a third support. Based on the first, second, and third supports, the lift of the second feature relationship is calculated. The lift represents the degree to which the occurrence of the third abnormal feature increases the probability of the occurrence of the fourth abnormal feature. The above-mentioned improvement can be calculated by the following formula (3):
[0003] Lift (B | A) = P (B | A) / P (B) = [count (AUB) / count (A) ] * [count ( total ) / count (B)] (3) In formula (3), Lift (B | A) is the lift, P (B | A) is the confidence level, P (B) is the proportion of devices in the target device cluster that have the fourth abnormal feature B to all devices in the target device cluster. Count (AUB) represents the number of target devices, and count (A) represents the number of first devices. oCount (total) represents the total number of devices in the target device cluster, and count (B) represents the number of second devices. As can be seen from formula (3), lift refers to the ratio between the probability of the fourth abnormal feature B occurring under the premise of the occurrence of the third abnormal feature A and the probability of the fourth abnormal feature B occurring in the total data set. In the case where the third abnormal feature A does trigger the fourth abnormal feature B, the probability of the fourth abnormal feature B occurring under the premise of the occurrence of the third abnormal feature A will be greater than the probability of the fourth abnormal feature B occurring in the total data set, so that the lift (B | A) is greater than 1. The stronger the causal relationship between the third abnormal feature A and the fourth abnormal feature B, the higher the lift. Through the evaluation index of lift, the degree of improvement in the probability of the occurrence of the fourth abnormal feature B caused by the occurrence of the third abnormal feature A can be intuitively quantified, which helps to improve the accuracy of the final determined association relationship. After eliminating the feature relationships that do not meet the time series requirements from the feature relationship set output by the preset feature mining algorithm, the evaluation index of each remaining feature relationship in the feature relationship set is calculated by the above method. The evaluation index of each feature relationship is then compared with the corresponding preset threshold. If the evaluation metric includes confidence, the confidence of the feature relationship is compared with a preset confidence threshold. If the confidence of the feature relationship is greater than or equal to the preset confidence threshold, the confidence of the feature relationship is determined to meet the confidence requirement of the association relationship. If the evaluation metric includes imbalance rate, the imbalance rate of the feature relationship is compared with a preset imbalance rate threshold. If the imbalance rate of the feature relationship is less than or equal to the preset imbalance rate threshold, the imbalance rate of the feature relationship is determined to meet the imbalance rate requirement of the association relationship. If the evaluation metric includes lift, the lift of the feature relationship is compared with a preset lift threshold. If the lift of the feature relationship is greater than or equal to the preset lift threshold, the lift of the feature relationship is determined to meet the lift requirement of the association relationship. The preset confidence threshold can be 0.85, 0.9, 0.95, 0.98, etc. The preset imbalance rate threshold can be 0.7, 0.6, 0.5, 0.4, etc. The preset lift threshold may be 1, 1.2, 1.5, 1.8, etc. The presently disclosed embodiments do not limit the specific values of the preset confidence threshold, the preset imbalance rate threshold, and the preset lift threshold; these values may be set as needed in practical applications. If all indicators included in the evaluation index of the feature relationship meet the corresponding preset threshold requirements, the feature relationship is determined to truly represent the causal relationship of the abnormal feature and is determined to be a correlation relationship.If at least one of the evaluation indicators for the characteristic relationship fails to meet the corresponding preset threshold, the characteristic relationship is determined to be unable to truly represent the causal relationship of the abnormal feature and is eliminated. Through the above method, if it is ultimately determined that none of the evaluation indicators for each characteristic relationship meet the corresponding threshold, it is determined that no abnormal feature with an associated relationship exists in the target device cluster. If at least one associated relationship is ultimately determined, it is determined that an abnormal feature with an associated relationship exists in the target device cluster. If an associated relationship is determined to exist, the operation and maintenance rules for the target device cluster are updated based on the abnormal feature with an associated relationship. Specifically, the following steps are performed: The union of the first operation and maintenance rule corresponding to the abnormal feature with an associated relationship and the second operation and maintenance rule corresponding to the abnormal feature with an associated relationship is used as a third operation and maintenance rule; and the second operation and maintenance rule corresponding to the abnormal feature with an associated relationship configured in the target device cluster is replaced with the third operation and maintenance rule. The first operation and maintenance rule is the one that is triggered when the abnormal characteristic that is the cause occurs. Hitting the first operation and maintenance rule triggers the execution of the operation and maintenance action corresponding to the first operation and maintenance rule, performing operation and maintenance on the device to eliminate the abnormal characteristic that is the cause. Similarly, the second operation and maintenance rule is the one that is triggered when the abnormal characteristic that is the result occurs. The union of the first and second operation and maintenance rules is used as the third operation and maintenance rule, and the operation and maintenance rule corresponding to the abnormal characteristic that is the result is adjusted to this third operation and maintenance rule. Thus, in the operation and maintenance rules configured for the target device cluster, the operation and maintenance rule corresponding to the abnormal characteristic that is the cause is the first operation and maintenance rule, and the operation and maintenance rule corresponding to the abnormal characteristic that is the result is the third operation and maintenance rule. The third operation and maintenance rule is the union of the first and second operation and maintenance rules. Therefore, when an abnormality characteristic of the seat cause occurs, it can hit both the first and third operation and maintenance rules. When an abnormality characteristic of the result occurs, it can also hit the third operation and maintenance rule. Since the abnormality characteristic of the cause occurs earlier than the abnormality characteristic of the result, the third operation and maintenance rule will be hit when the abnormality characteristic of the cause occurs, triggering the corresponding operation and maintenance action. Compared to the previous situation where only the second operation and maintenance rule was matched to the abnormality characteristic of the result, after the update, the operation and maintenance rule will be matched earlier, triggering the operation and maintenance action, allowing for more timely operation and maintenance of the equipment, shortening the time it takes for equipment to be damaged. Furthermore, after the update, the third operation and maintenance rule corresponding to the abnormality characteristic of the result includes a richer set of rules, matching more cases with the third operation and maintenance rule, effectively reducing the number of missed operation and maintenance cases caused by some abnormal cases not matching the operation and maintenance rules before the update.In other embodiments of the present disclosure, before replacing the second operation and maintenance rule corresponding to the resulting abnormal feature with the third operation and maintenance rule, it may be further determined whether the third operation and maintenance rule can truly achieve better operation and maintenance results than the original second operation and maintenance rule. Specifically, first operation and maintenance data obtained by running for a preset duration when the resulting abnormal feature is configured with the second operation and maintenance rule is obtained, and second operation and maintenance data obtained by running for a preset duration when the resulting abnormal feature is configured with the third operation and maintenance rule is obtained. Based on the first operation and maintenance data and the second operation and maintenance data, operation and maintenance difference data is determined, the operation and maintenance difference data being used to characterize the difference in the abnormal feature matching the rule when the second operation and maintenance rule are configured and the third operation and maintenance rule is configured. Based on the operation and maintenance difference data, if it is determined that the third operation and maintenance rule meets the preset operation and maintenance validity conditions, the second operation and maintenance rule corresponding to the second abnormal feature configured in the target device cluster is replaced with the third operation and maintenance rule. The preset duration may be 3 days, 5 days, or a week, for example. The embodiments of the present disclosure do not limit the specific value of the preset duration; it can be set according to actual needs. The preset operation and maintenance validity condition is used to indicate that the operation and maintenance effect of the third operation and maintenance rule is better than that of the second operation and maintenance rule. The preset operation and maintenance validity condition may include a condition for constraining the operation and maintenance effect of the third operation and maintenance rule to be better than that of the second operation and maintenance rule. For example, the preset operation and maintenance validity condition may include a hit rate of the third operation and maintenance rule being higher than the hit rate of the second operation and maintenance rule, an earliest hit time of the third operation and maintenance rule being earlier than the earliest hit time of the second operation and maintenance rule, etc. The first operation and maintenance data includes abnormal characteristics generated by each device in the target device cluster when the second operation and maintenance rule is configured, the operation and maintenance rules that the abnormal characteristics match, and a record of operation and maintenance actions triggered by the operation and maintenance rule matches. The second operation and maintenance data includes abnormal characteristics generated by each device in the target device cluster when the third operation and maintenance rule is configured, the operation and maintenance rules that the abnormal characteristics match, and a record of operation and maintenance actions triggered by the operation and maintenance rule matches. The aforementioned operation and maintenance difference data may include information such as the same anomaly feature matching different operation and maintenance rules when the second operation and maintenance rule is configured and the third operation and maintenance rule is configured, the same anomaly feature matching the same operation and maintenance rule at different times, the same anomaly feature not matching an operation and maintenance rule in one case but matching an operation and maintenance rule in another case, and so on. In some embodiments of the present disclosure, after obtaining the operation and maintenance difference data by comparing the first operation and maintenance data with the second operation and maintenance data, the operation and maintenance difference data may be sent to a preset operation and maintenance terminal for display. The preset operation and maintenance terminal may be a terminal of an operation and maintenance expert. The operation and maintenance expert reviews the operation and maintenance difference data to determine whether the operation and maintenance effect of the third operation and maintenance rule is superior to that of the second operation and maintenance rule. If so, the preset operation and maintenance terminal returns an indication indicating that the third operation and maintenance rule update is valid to the execution subject of the present disclosure embodiment.After receiving the instruction, the execution entity determines that the third operation and maintenance rule meets the preset operation and maintenance validity conditions, and then replaces the second operation and maintenance rule corresponding to the second abnormality characteristic configured in the target device cluster with the third operation and maintenance rule. Through the above method, the first operation and maintenance data corresponding to the second operation and maintenance rule and the second operation and maintenance data corresponding to the third operation and maintenance rule within a preset time period are reviewed, and operation and maintenance difference data between the two is analyzed. Based on this operation and maintenance difference data, the execution entity evaluates whether the third operation and maintenance rule has a better operation and maintenance effect than the second operation and maintenance rule. Only when the third operation and maintenance rule is determined to have a better effect is the second operation and maintenance rule updated to the third operation and maintenance rule. This improves the accuracy and reliability of operation and maintenance rule updates and effectively improves the operation and maintenance effect of the target device cluster. If the above method determines that the third operation and maintenance rule does not meet the preset operation and maintenance validity conditions, the target association corresponding to the third operation and maintenance rule can also be added to a preset invalid association set. If the target association is again determined to exist in the target device cluster, the target association is determined to be an invalid association based on the preset invalid association set. Subsequent operation and maintenance rule updates are no longer performed based on this target association, thereby saving computing resources. In the disclosed embodiments, possible correlations between multiple abnormal features of a target device cluster are explored. When correlated abnormal features are identified, the target device cluster's operation and maintenance rules are updated based on these correlated abnormal features. This allows for the consideration of the mutual influences between the abnormal features in the design of the target device cluster's operation and maintenance rules. This ensures that the updated operation and maintenance rules better reflect the inherent causal relationships between the various abnormal features that may arise in the target device cluster, improving the scientific rationality of the operation and maintenance rules. This helps ensure that correlated abnormal features are matched to the operation and maintenance rules in advance, allowing for early device operation and maintenance to eliminate the anomalies and reducing the occurrence of abnormal features that are the result of the correlated abnormal features. The updated operation and maintenance rules also ensure that more abnormal situations are matched to the operation and maintenance rules, reducing the number of missed operations and maintenance due to abnormal features not matching the operation and maintenance rules. This improves the operation and maintenance effectiveness of the target device cluster and enhances the stability and reliability of the target device cluster's operations.Some embodiments of the present disclosure also provide an operation and maintenance rule update system. As shown in Figure 2, the system includes a cloud server cluster and an operation and maintenance platform. The cloud servers in the cloud server cluster are configured to obtain operational data of the cloud servers and transmit the operational data to the operation and maintenance platform. The operation and maintenance platform is configured to obtain multiple abnormal features of the cloud server cluster and the occurrence time of each abnormal feature based on the operational data of each cloud server in the cloud server cluster. Based on the multiple abnormal features and the occurrence time of each abnormal feature, the operation and maintenance platform determines whether there are any abnormal features with correlations among the multiple abnormal features, where the correlations are used to indicate a causal relationship between the abnormal features. If there are abnormal features with correlations, the operation and maintenance rules of the cloud server cluster are updated based on the abnormal features with correlations. The operational data of the cloud servers includes operational logs and performance data of the cloud servers. An agent application is installed on each cloud server in the cloud server cluster. The agent application on the cloud server is responsible for collecting the operational data of the cloud server and uploading the collected operational data to the operation and maintenance platform. The operation and maintenance platform can be a physical server independent of the cloud server cluster, a cloud server, a service or application deployed in the cloud, etc. The cloud servers upload their respective operating data to the operation and maintenance platform. Based on the operating data, the operation and maintenance platform identifies abnormal characteristics of the cloud server cluster and their occurrence times in advance, explores possible correlations between these abnormal characteristics, and, if abnormal characteristics with correlations are identified, updates the cloud server cluster's operation and maintenance rules based on these correlations. Taking the mutual influence of abnormal characteristics into account when setting operation and maintenance rules ensures that the updated operation and maintenance rules better align with the inherent causal relationships between various abnormal characteristics that may arise in cloud servers, improving the scientific rationality of the operation and maintenance rules. This helps ensure that abnormal characteristics with correlations are matched to the operation and maintenance rules in advance, allowing for early device operation and maintenance to eliminate the abnormalities and reducing the occurrence of abnormal characteristics that are the result of abnormal characteristics with correlations. Updating the operation and maintenance rules also ensures that more abnormal situations match the operation and maintenance rules, reducing the number of missed operations and maintenance due to abnormal characteristics that fail to match the operation and maintenance rules. This improves the operation and maintenance effectiveness of the cloud servers and enhances the stability and reliability of the cloud server cluster. To more clearly illustrate the differences between the embodiments of the present disclosure and related technologies, the following description is provided with reference to Figures 3 and 4. Figure 3 shows a schematic diagram of an operation and maintenance system for a cloud server cluster in related art, and Figure 4 shows a schematic diagram of an operation and maintenance rule update system in an embodiment of the present disclosure. As shown in Figure 3 , the cloud server cluster includes multiple cloud servers, each of which has an agent application installed. The operation and maintenance platform includes an anomaly detection system and an operation and maintenance center. The agent application on the cloud server collects the cloud server's operating data and uploads it to the anomaly detection system.The anomaly detection system analyzes abnormal events occurring on cloud servers based on operational data. It then extracts abnormal feature data based on these abnormal events and transmits this feature data to the operations and maintenance center. If the operations and maintenance center determines that the abnormal features in the feature data match the operations and maintenance rules, it executes the corresponding operations and maintenance actions to perform abnormal operations and maintenance on the cloud servers in the cloud server cluster. Based on the system structure of the related art shown in Figure 3, as shown in Figure 4, the present embodiment adds a rule update module and an update evaluation module to the operations and maintenance platform. After extracting abnormal feature data based on abnormal events, the anomaly detection system transmits this feature data, including the abnormal features and the time of their occurrence, to the rule update module. The rule update module performs data preprocessing on the received feature data, generating time-series relationships between the abnormal features and using a pre-set feature mining algorithm to mine for possible associations between the abnormal features. Figure 4 illustrates the pre-set feature mining algorithm using the FP-Growth algorithm as an example. The rule update module derives the final feature associations based on the time-series relationships and the feature relationship set output by the FP-Growth algorithm. The process of generating feature associations in the rule update module can be illustrated in Figure 5. First, the feature data set is deduplicated. A feature temporal relationship is generated based on the deduplicated feature data set. Frequent itemsets are extracted from the deduplicated feature data set. An FP-tree (Frequent Pattern Tree) is generated based on the extracted frequent itemsets using the FP-Growth algorithm. Finally, the final feature associations are derived based on the feature temporal relationship and the generated FP-tree. As shown in Figure 4, the operation and maintenance center also transmits the original operation and maintenance rules configured for the cloud server cluster to the rule update module. The rule update module generates updated rules based on the original operation and maintenance rules and the generated feature associations, and transmits the updated rules to the update evaluation module. The update evaluation module performs operation and maintenance backtracking based on the updated rules and the original rules before the update. It analyzes the operational differences between the two operation and maintenance data, including multiple hits, fewer hits, earlier hits, and later hits. If the operation and maintenance experts confirm that the updated operation and maintenance rules have better operational performance, the updated rules are sent to the operation and maintenance center. The Operations and Maintenance Center replaces the pre-updated Operations and Maintenance rules with the updated rules. If the Operations and Maintenance Experts confirm based on the Operations and Maintenance Difference Data that the updated Operations and Maintenance Rules do not achieve better Operations and Maintenance results, the updated rules will not be adopted and will be returned to the Rule Update Module.After receiving an unadopted update rule, the rule update module adds the association corresponding to the update rule to a preset invalid relationship set. When the association is subsequently determined again, the preset invalid relationship set can be used to determine that the association is invalid for the operation and maintenance rule update, and the subsequent update operation is not performed. The operation and maintenance rules in the operation and maintenance center, including the original, unupdated rules and the updated rules, can be operated and maintained for cloud servers in a cloud server cluster based on the operation and maintenance rules, as shown in FIG6 . The agent application in the cloud server collects logs. As shown in FIG6 , the collected system log records a network card failure, and the collected performance data indicates a disk read latency of 1000ms. oThe anomaly detection system in the operation and maintenance platform detects anomalies based on data collected by the agent application. As shown in Figure 6, the anomaly detection system detects a network card connection warning with a critical warning level. It also detects a slow virtual machine with a critical warning level. The anomaly detection system extracts features based on these detected anomalies. As shown in Figure 6, the extracted anomaly features include network card jitter and 10% slowness. After the anomaly detection system transmits the anomaly features to the operation and maintenance center, the center determines that the network card jitter and 10% slowness features match the operation and maintenance rule related to network card failure causing 10% slowness and executes the corresponding operation and maintenance action "offline migration" for this operation and maintenance rule. Testing of the operation and maintenance rule update system provided by the present embodiment has confirmed that the probability of updated rules ultimately being verified as valid by operation and maintenance experts reaches 73%. After the update, the probability of anomaly features hitting the operation and maintenance rules in advance reaches 80%, and the longest lead time for hitting the operation and maintenance rules reaches hours. The present embodiment uses a preset feature mining algorithm and combines the temporal relationships between anomaly features to achieve feature association mining that considers temporal relationships. When updating rules, using the update logic of the union of operation and maintenance rules corresponding to abnormal features with causal relationships can cover the operation and maintenance conditions of the original operation and maintenance rules, avoid missed and delayed operations, and enable early detection and discovery of scenarios where operations were missed by the original operation and maintenance rules. Corresponding to the aforementioned embodiments of the operation and maintenance rule updating method, the present disclosure also provides embodiments of an operation and maintenance rule updating device. Figure 7 is a schematic structural diagram of an operation and maintenance rule updating device, according to an exemplary embodiment. The device is configured to perform the operation and maintenance rule updating method provided in any of the aforementioned embodiments. As shown in Figure 7, the operation and maintenance rule updating device includes: an acquisition module 201 for acquiring multiple abnormal features and the occurrence time of each abnormal feature for a target device cluster; a determination module 202 for determining, based on the multiple abnormal features and the occurrence time of each abnormal feature, whether any abnormal features have a correlation among the multiple abnormal features, where the correlation indicates a causal relationship between the abnormal features; and an update module 203 for, if any abnormal features have a correlation, updating the operation and maintenance rules for the target device cluster based on the correlated abnormal features.The determination module 202 is configured to determine the temporal relationships between the abnormal features based on their occurrence times. The temporal relationships characterize the chronological order of the occurrence times of the abnormal features. Based on the multiple abnormal features, a preset feature mining algorithm is used to generate a feature relationship set for the multiple abnormal features. The feature relationship set includes multiple feature relationships, and the feature relationships characterize the causal relationships between the abnormal features belonging to the same feature relationship. Based on the temporal relationships and the feature relationship set, the determination module 202 determines whether any abnormal features within the multiple abnormal features have a correlation relationship. Specifically, based on the temporal relationships, the determination module 202 is configured to remove feature relationships from the feature relationship set that do not meet a preset temporal condition. The preset temporal condition is configured to constrain the occurrence time of the causal abnormal feature of two abnormal features with a causal relationship to be earlier than the occurrence time of the resulting abnormal feature. If any feature relationships remain in the feature relationship set after removal, an evaluation index is calculated for the remaining feature relationships. The evaluation index characterizes the accuracy of the remaining feature relationships as correlation relationships. If a target feature relationship exists whose evaluation index exceeds a preset threshold, the abnormal feature corresponding to the target feature relationship is determined as an abnormal feature with a correlation relationship. The determination module 202 is configured to determine, from the temporal relationships, a temporal relationship between a first abnormal feature and a second abnormal feature corresponding to a first characteristic relationship. The first characteristic relationship is any characteristic relationship in a characteristic relationship set, and the first characteristic relationship indicates that the first abnormal feature is the cause of the second abnormal feature. If the temporal relationship between the first abnormal feature and the second abnormal feature indicates that the first abnormal feature occurs later than the second abnormal feature, the first characteristic relationship is removed from the characteristic relationship set. In some embodiments of the present disclosure, the second characteristic relationship is any characteristic relationship among the remaining characteristic relationships, and the second characteristic relationship corresponds to a third abnormal feature and a fourth abnormal feature, and the third abnormal feature is the cause of the fourth abnormal feature. The determination module 202 is configured to respectively determine a first device in the target device cluster that has the third abnormal feature and a second device that has the fourth abnormal feature; and calculate an evaluation index for the second characteristic relationship based on the first device and the second device.The determination module 202 is configured to determine, based on the first and second devices, the number of target devices that exhibit both the third and fourth abnormal characteristics; calculate a first ratio between the number of target devices and the number of first devices to obtain a confidence level for the second characteristic relationship; the confidence level being used to characterize the probability of the fourth abnormal characteristic occurring given the occurrence of the third abnormal characteristic; and / or calculate a second ratio between the total number of devices in the target device cluster and the number of second devices, and calculate the product of the first ratio and the second ratio to obtain an imbalance rate for the second characteristic relationship, the imbalance rate being used to characterize the degree of difference between the number of occurrences of the third abnormal characteristic and the number of occurrences of the fourth abnormal characteristic; and / or calculate a ratio between the number of first devices and the total number of devices to obtain a first support level; calculate a ratio between the number of second devices and the total number of devices to obtain a second support level; calculate a ratio between the number of target devices and the total number of devices to obtain a third support level; and calculate a lift of the second characteristic relationship based on the first, second, and third support levels, the lift being used to characterize the degree to which the occurrence of the third abnormal characteristic increases the probability of the fourth abnormal characteristic. An updating module 203 is configured to take the union of the first operation and maintenance rule corresponding to the abnormal feature serving as the cause and the second operation and maintenance rule corresponding to the abnormal feature serving as the result, among the associated abnormal features, as a third operation and maintenance rule; and replace the second operation and maintenance rule corresponding to the abnormal feature serving as the result, configured in the target device cluster, with the third operation and maintenance rule. The apparatus also includes an update validity determination module configured to obtain first operation and maintenance data obtained by running for a preset duration when the second operation and maintenance rule is configured for the abnormal feature serving as the result, and to obtain second operation and maintenance data obtained by running for a preset duration when the third operation and maintenance rule is configured for the abnormal feature serving as the result; determine operation and maintenance difference data based on the first operation and maintenance data and the second operation and maintenance data, the operation and maintenance difference data representing the difference in the rule matching between the abnormal feature and the second operation and maintenance rule; and replace the second operation and maintenance rule corresponding to the abnormal feature serving as the result, configured in the target device cluster, with the third operation and maintenance rule if it is determined based on the operation and maintenance difference data that the third operation and maintenance rule meets the preset operation and maintenance validity condition. The device also includes: a preset invalid relationship set management module, which is used to determine that the third operation and maintenance rule does not meet the preset operation and maintenance validity conditions, and add the target association relationship corresponding to the third operation and maintenance rule to the preset invalid relationship set; when it is determined again that the target association relationship exists in the target device cluster, the target association relationship is determined to be an invalid association relationship based on the preset invalid relationship set.Acquisition module 201 is configured to acquire information on abnormal events generated by a target device cluster within a preset historical period; extract from each abnormal event information the abnormal features and occurrence times of each abnormal feature that occurred within the preset historical period; and, if duplicate abnormal features exist among the extracted abnormal features, delete the duplicate abnormal features except for the one with the earliest occurrence time. The operation and maintenance rule updating apparatus provided in the embodiments of the present disclosure and the operation and maintenance rule updating method provided in the embodiments of the present disclosure are based on the same inventive concept and have the same beneficial effects as the methods employed, executed, or implemented therein. The implementation of the functions and effects of each module in the apparatus is described in detail in the implementation of the corresponding steps in the method and will not be repeated here. Since the apparatus embodiment substantially corresponds to the method embodiment, reference will be made to the description of the method embodiment for relevant details. The apparatus embodiment described above is merely illustrative. The modules described as separate components may or may not be physically separate, and the components described as modules may or may not be physical modules; that is, they may be located in one location or distributed across multiple network elements. Some or all of these modules may be selected to achieve the objectives of the present disclosure as needed. Those skilled in the art can understand and implement the above-described operation and maintenance rule updating method without inventive effort. Some embodiments of the present disclosure also provide an electronic device corresponding to the operation and maintenance rule updating method provided in the aforementioned embodiments, to perform the aforementioned operation and maintenance rule updating method. Figure 8 is a hardware structure diagram of an electronic device according to an exemplary embodiment. The electronic device includes: a communication interface 601, a processor 602, a memory 603, and a bus 604. The communication interface 601, the processor 602, and the memory 603 communicate with each other via the bus 604. The processor 602 executes the operation and maintenance rule updating method described above by reading and executing machine-executable instructions corresponding to the control logic of the operation and maintenance rule updating method in the memory 603. The details of this method are described in the aforementioned embodiments and will not be repeated here. The memory 603 mentioned in the embodiments of the present disclosure can be any electronic, magnetic, optical, or other physical storage device, and can contain stored information, such as executable instructions, data, and so on. Specifically, the memory 603 may be a RAM (Random Access Memory), a flash memory, a storage drive (such as a hard disk drive), any type of storage disk (such as an optical disk, a DVD, etc.), or a similar storage medium, or a combination thereof.The communication connection between the system network element and at least one other network element is achieved via at least one communication interface 601 (which may be wired or wireless). This interface may include the Internet, a wide area network (WAN), a local area network (LAN), a metropolitan area network (MAN), or the like. Bus 604 may be an ISA bus, a PCI bus, or an EISA bus. Such buses may be classified as address buses, data buses, or control buses. Memory 603 is used to store programs, and processor 602 executes the programs upon receiving execution instructions. Processor 602 may be an integrated circuit chip with signal processing capabilities. During implementation, the steps of the above method may be completed by hardware integrated logic circuits or software instructions within processor 602. Processor 602 may be a general-purpose processor, including a network processor (NP), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware controls. The methods, steps, and logic block diagrams disclosed in the embodiments of this disclosure may be implemented or executed. A general-purpose processor can be a microprocessor, or any conventional processor. The steps of the method disclosed in conjunction with the embodiments of the present disclosure can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules within the decoding processor. The electronic device provided in the embodiments of the present disclosure and the method for updating operation and maintenance rules provided in the embodiments of the present disclosure are based on the same inventive concept and have the same beneficial effects as the methods employed, executed, or implemented therein. The embodiments of the present disclosure also provide a computer-readable storage medium corresponding to the method for updating operation and maintenance rules provided in the aforementioned embodiments. Please refer to FIG. 9 , which shows a computer-readable storage medium as an optical disc 30 storing a computer program (i.e., a program product). When executed by a processor, the computer program executes the method for updating operation and maintenance rules provided in any of the aforementioned embodiments. It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory, or other optical or magnetic storage media, and are not listed here one by one.The computer-readable storage medium provided in the above-mentioned embodiments of the present disclosure and the operation and maintenance rule updating method provided in the above-mentioned embodiments of the present disclosure are based on the same inventive concept and have the same beneficial effects as the method used, executed, or implemented by the application program stored therein. The present disclosure also provides a computer program product corresponding to the operation and maintenance rule updating method provided in the above-mentioned embodiments. This computer program product includes a computer program that is executed by a processor to implement the operation and maintenance rule updating method provided in the above-mentioned embodiments. The computer program product provided in the above-mentioned embodiments of the present disclosure and the operation and maintenance rule updating method provided in the above-mentioned embodiments of the present disclosure are based on the same inventive concept and have the same beneficial effects as the method used, executed, or implemented by the application program stored therein. Other embodiments of the present disclosure will be readily apparent to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only; the true scope and spirit of the present disclosure are indicated by the claims. It should also be noted that the terms "comprise," "include," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, product, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, product, or apparatus. In the absence of further limitations, elements defined by the phrase "comprising a..." do not preclude the presence of additional identical elements in the process, method, product, or apparatus comprising the recited elements. The foregoing description is merely a preferred embodiment of the present disclosure and is not intended to limit the present disclosure. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present disclosure are intended to be included within the scope of protection of the present disclosure.
Claims
Claims 1. A method for updating operation and maintenance rules, the method comprising: Obtaining multiple abnormal features of the target device cluster and the occurrence time of each abnormal feature; Based on the multiple abnormal features and the occurrence time of each of the abnormal features, determine whether there are abnormal features with correlation among the multiple abnormal features, and the correlation is used to characterize the existence of a causal relationship between the abnormal features; in the case where there are abnormal features with correlation, the operation and maintenance rules of the target device cluster are updated based on the abnormal features with correlation.
2. The method according to claim 1, wherein: The determining whether there are abnormal features with associated relationships among the multiple abnormal features based on the multiple abnormal features and the occurrence time of each abnormal feature includes: determining the time series relationship between the abnormal features based on the occurrence time of each abnormal feature, the time series relationship is used to characterize the chronological relationship of the occurrence time of each abnormal feature; generating a feature relationship set of the multiple abnormal features through a preset feature mining algorithm based on the multiple abnormal features, the feature relationship set includes multiple feature relationships, and the feature relationship is used to characterize the existence of a causal relationship between the abnormal features belonging to the same feature relationship; determining whether there are abnormal features with associated relationships among the multiple abnormal features based on the time series relationship and the feature relationship set.
3. The method according to claim 2, wherein: The method of determining whether there are abnormal features with an associated relationship among the multiple abnormal features based on the time series relationship and the feature relationship set includes: eliminating feature relationships that do not meet preset time series conditions from the feature relationship set based on the time series relationship; the preset time series conditions are used to constrain the occurrence time of the abnormal feature that serves as the cause of two abnormal features with a causal relationship to be earlier than the occurrence time of the abnormal feature that serves as the result; in the case where there are remaining feature relationships in the feature relationship set after elimination, calculating an evaluation index of the remaining feature relationship, the evaluation index is used to characterize the accuracy of the remaining feature relationship as the associated relationship; in the case where there is a target feature relationship whose evaluation index is greater than a preset threshold, determining the abnormal feature corresponding to the target feature relationship as the abnormal feature with the associated relationship.
4. The method according to claim 3, wherein: The step of eliminating feature relationships that do not meet a preset timing condition from the feature relationship set based on the timing relationship between each of the abnormal features includes: determining a timing relationship between a first abnormal feature and a second abnormal feature corresponding to a first feature relationship from the timing relationship, wherein the first feature relationship is any feature relationship in the feature relationship set, and the first feature relationship is used to characterize that the first abnormal feature is the cause of the second abnormal feature; if the timing relationship between the first abnormal feature and the second abnormal feature indicates that the first abnormal feature is the cause of the second abnormal feature, 25 If the occurrence time of the normal feature is later than the occurrence time of the second abnormal feature, the first feature relationship is removed from the feature relationship set.
5. The method according to claim 3, wherein: The second characteristic relationship is any characteristic relationship among the remaining characteristic relationships, the second characteristic relationship corresponds to the third abnormal characteristic and the fourth abnormal characteristic, and the third abnormal characteristic is the cause of the fourth abnormal characteristic; the calculation of the evaluation index of the remaining characteristic relationships includes: respectively determining the number of first devices in the target device cluster that have the third abnormal characteristic, and the number of target devices that have both the third abnormal characteristic and the fourth abnormal characteristic; calculating the evaluation index of the second characteristic relationship based on the number of the first devices and the number of the target devices.
6. The method according to claim 5, wherein: The calculating of the evaluation index of the second characteristic relationship based on the number of the first devices and the number of the target devices includes: calculating a first ratio between the number of the target devices and the number of the first devices to obtain the confidence of the second characteristic relationship; the confidence is used to characterize the probability of the fourth abnormal feature occurring under the premise that the third abnormal feature occurs.
7. The method according to claim 5 or 6, wherein: The calculating of the evaluation index of the second characteristic relationship based on the number of the first devices and the number of the target devices includes: determining the number of second devices in the target device cluster that have the fourth abnormal characteristic; calculating a first ratio between the number of target devices and the number of the first devices; calculating a second ratio between the total number of devices in the target device cluster and the number of the second devices; and calculating the product of the first ratio and the second ratio to obtain an imbalance rate of the second characteristic relationship, where the imbalance rate is used to characterize the degree of difference between the number of occurrences of the third abnormal characteristic and the number of occurrences of the fourth abnormal characteristic.
8. The method according to claim 5 or 6, wherein: The calculation of the evaluation index of the second characteristic relationship based on the number of the first devices and the number of the target devices includes: determining the number of second devices in the target device cluster in which the fourth abnormal characteristic occurs; calculating the ratio between the number of the first devices and the total number of devices in the target device cluster to obtain a first support; calculating the ratio between the number of the second devices and the total number of devices to obtain a second support; calculating the ratio between the number of the target devices and the total number of devices to obtain a third support; calculating the lift of the second characteristic relationship based on the first support, the second support and the third support, wherein the lift is used to characterize the degree to which the occurrence of the third abnormal characteristic increases the probability of the occurrence of the fourth abnormal characteristic.
9. The method according to any one of claims 1 to 6, wherein: The method is based on the associated The operation and maintenance rules of the target device cluster are updated according to the abnormal characteristics of the system, including: taking the union of the first operation and maintenance rule corresponding to the abnormal characteristic as the cause and the second operation and maintenance rule corresponding to the abnormal characteristic as the result among the abnormal characteristics with the associated relationship as the third operation and maintenance rule; and replacing the second operation and maintenance rule corresponding to the abnormal characteristic as the result configured in the target device cluster with the third operation and maintenance rule.
10. The method according to claim 9, wherein: Before replacing the second operation and maintenance rule corresponding to the resulting abnormal feature configured in the target device cluster with the third operation and maintenance rule, it also includes: obtaining first operation and maintenance data obtained by running for a preset time when the resulting abnormal feature is configured with the second operation and maintenance rule, and obtaining second operation and maintenance data obtained by running for the preset time when the resulting abnormal feature is configured with the third operation and maintenance rule; determining operation and maintenance difference data based on the first operation and maintenance data and the second operation and maintenance data, the operation and maintenance difference data is used to characterize the difference in the abnormal feature hitting rules under the two situations of configuring the second operation and maintenance rule and the third operation and maintenance rule; based on the operation and maintenance difference data, determining that the third operation and maintenance rule meets the preset operation and maintenance validity condition, executing the operation of replacing the second operation and maintenance rule corresponding to the resulting abnormal feature configured in the target device cluster with the third operation and maintenance rule.
11. The method according to claim 10, wherein: The method also includes: determining that the third operation and maintenance rule does not meet the preset operation and maintenance validity condition, and adding the target association relationship corresponding to the third operation and maintenance rule to a preset invalid relationship set; when it is determined again that the target association relationship exists in the target device cluster, determining that the target association relationship is an invalid association relationship based on the preset invalid relationship set.
12. The method according to any one of claims 1 to 6, wherein: The method of obtaining multiple abnormal features of the target device cluster includes: obtaining information on various abnormal events generated by each device in the target device cluster within a preset historical period; for the abnormal event information corresponding to each device, extracting the various abnormal features and the occurrence time of each abnormal feature that occurred in the device within the preset historical period from the abnormal event information corresponding to the device; in the case where there are multiple repeated abnormal features among the abnormal features of the same device, deleting the abnormal features except for the abnormal feature with the earliest occurrence time among the multiple repeated abnormal features.
13. A device for updating operation and maintenance rules, the device comprising: An acquisition module, configured to acquire multiple abnormal features of a target device cluster and the occurrence time of each abnormal feature; A determination module is configured to determine, based on the plurality of abnormal features and the occurrence time of each abnormal feature, Whether there are abnormal features with associated relationships among the multiple abnormal features, and the associated relationships are used to characterize the existence of a causal relationship between the abnormal features; an update module, which is used to update the operation and maintenance rules of the target device cluster based on the abnormal features with associated relationships when the abnormal features with associated relationships exist.
14. A system for updating operation and maintenance rules, comprising a cloud server cluster and an operation and maintenance platform; cloud servers in the cloud server cluster are configured to obtain operation data of the cloud servers and send the operation data to the operation and maintenance platform; the operation and maintenance platform is configured to obtain multiple abnormal features of the cloud server cluster and the occurrence time of each abnormal feature based on the operation data of each cloud server in the cloud server cluster; based on the multiple abnormal features and the occurrence time of each abnormal feature, determine whether there are abnormal features with associated relationships among the multiple abnormal features, wherein the associated relationships are used to characterize the existence of a causal relationship between the abnormal features; and in the case where the abnormal features with associated relationships exist, update the operation and maintenance rules of the cloud server cluster based on the abnormal features with associated relationships.
15. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method according to any one of claims 1 to 12.
16. A computer-readable storage medium having a computer program stored thereon, wherein the program is executed by a processor to implement the method according to any one of claims 1 to 12.
17. A computer program product, comprising a computer program, wherein the computer program is executed by a processor to implement the method according to any one of claims 1 to 2. 28
Citation Information
Patent Citations
Management method of multi-layer topology network resource object
CN111125450A
Fault reason processing method and device of service system, equipment and storage medium
CN114327964A
Alarm analysis method and device
CN115118580A
Method And System For The On-Demand Generation Of Graph-Like Models Out Of Multidimensional Observation Data
US20220358023A1