Data collection method, system, and related apparatus
By receiving and preprocessing time-slice data from probe devices within the CEM platform, the problem of an excessive number of hardware devices on the CEM platform was solved, resulting in cost reduction and improved data processing reliability.
Patent Information
- Application Number
- PCT/CN2025/092069
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-26
- Filing Date
- 2025-04-29
- Publication Date
- 2026-01-29
AI Technical Summary
The existing CEM platform requires the deployment of a large number of hardware devices to process user face documents and signaling face documents reported in real time by probe devices, which increases the cost for Internet companies.
The server receives time-slice documents sent by probe devices, performs preprocessing to reduce the amount of documents to be processed, and performs anomaly detection and data processing based on communication service documents to dynamically obtain user plane documents and signaling plane documents of target network objects.
This reduces the number of hardware devices required for CEM platform deployment, lowers costs for internet companies, and improves the reliability of data processing and the accuracy of anomaly detection.
Smart Images

Figure CN2025092069_29012026_PF_FP_ABST
Abstract
Description
Data acquisition methods, systems and related devices
[0001] This application claims priority to Chinese Patent Application No. 202411021884.9, filed on July 26, 2024, entitled “Data Acquisition Method, System and Related Apparatus”, the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of communication technology, and in particular to a data acquisition method, system and related apparatus. Background Technology
[0003] With the rapid development of modern communication technology, users have increasingly higher requirements for network quality. In order to collect user feedback, various Internet companies have begun to connect to customer experience management (CEM) platforms in order to manage users' overall experience with the company.
[0004] Currently, the CEM platform can be used to process user form documents and signaling form documents reported in real time by probe devices. However, due to the massive amount of data in these documents, a large number of hardware devices (such as servers) need to be deployed for the CEM platform to process them, increasing the cost for internet companies. Summary of the Invention
[0005] This application provides a data acquisition method, system, and related apparatus to reduce the number of hardware devices deployed on a CEM platform, thereby reducing the cost investment for internet companies.
[0006] To achieve the above objectives, the embodiments of this application provide the following technical solutions:
[0007] Firstly, a data acquisition method is provided. This method can be executed by a server, or by a component of the server, such as a processor, chip, or chip system. It can also be implemented by a logic module or software capable of performing all or part of the server's functions. Taking the method being executed by a server as an example, the method includes:
[0008] The server receives communication service documents from the probe device. These documents include time-slice documents, which are obtained by statistically analyzing user plane and signaling plane documents using a first time period as the statistical unit. The statistical analysis can be a process of organizing, analyzing, and merging the user plane and signaling plane documents.
[0009] In other words, after the probe device collects user plane documents and signaling plane documents, it performs statistics on the user plane documents and signaling plane documents using the first time period as the statistical unit, and then sends the statistically obtained documents to the server. At this time, the communication service documents (time slice documents) received by the server are concise documents obtained by the probe device after preprocessing the original documents, which can significantly reduce the amount of documents to be processed by the server.
[0010] Understandably, after the server obtains the communication service documents, it can perform data processing operations such as data statistics, data analysis, or data storage based on these documents. In this way, by reducing the amount of documents to be processed by the server, the number of hardware devices deployed on the CEM platform can be reduced, thereby reducing the cost investment for internet companies.
[0011] Furthermore, based on communication service documents, the server retrieves the user face document and signaling face document of the target network object from the probe device. The target network object is the network object to be processed. In this way, for the target network object to be processed, all user face document and signaling face document can be obtained, providing a rich data foundation for subsequent data processing of the target network object and improving the reliability of data processing.
[0012] It is worth noting that after the server obtains the user form data and signaling form data of the target network object, it can also perform data processing operations such as data statistics, data analysis, or data storage based on the user form data and signaling form data of the target network object.
[0013] In conjunction with the first aspect described above, in one possible implementation, the target network object is an abnormal network object. The communication service document also includes signaling plane abnormal documents, which are signaling plane documents indicating communication failure. That is, after collecting the user plane document and the signaling plane document, the probe device also acquires the signaling plane abnormal documents indicating communication failure from the signaling plane documents, increasing the amount of information contained in the communication service document and providing a data foundation for the subsequent server to determine the abnormal network object.
[0014] Based on communication service documents, user plane documents and signaling plane documents of the target network object are obtained from the probe device, including:
[0015] The server performs anomaly detection on network objects during the communication process based on communication service documents, thereby identifying abnormal network objects. In other words, the server uses time-slice data and signaling plane anomaly data within the communication service documents to perform anomaly detection on network objects during the communication process, thus identifying abnormal network objects.
[0016] Furthermore, the server retrieves the user plane and signaling plane documents for abnormal network objects from the probe device. Given that the communication service documents received by the server are statistically derived and contain relatively little information, the server performs anomaly detection on network objects during the communication process to obtain the user plane and signaling plane documents for abnormal network objects from the probe device, ensuring that the server obtains all documents related to abnormal network objects.
[0017] In conjunction with the first aspect above, in one possible implementation, anomaly detection is performed on network objects during the communication process based on communication service documents to obtain abnormal network objects, including:
[0018] Based on this communication service document, the growth rate of each network object under different network indicators is determined. The indicator growth rate characterizes the growth of the network indicator value in the current time period compared to the network indicator value in past time periods. For example, the indicator growth rate may include at least one of year-on-year growth rate and month-on-month growth rate. The year-on-year growth rate refers to the growth rate compared to the same period of the previous year / quarter / month / week, i.e., the growth rate of a certain time period in the current period compared to a certain time period in the previous year / quarter / month / week. It can be understood that year-on-year growth is comparing data from the same period. The month-on-month growth rate refers to the growth rate compared to the previous adjacent period, i.e., the growth rate of a certain time period in the current period compared to a certain time period in the adjacent previous period. It can be understood that month-on-month growth is comparing data from adjacent periods.
[0019] For the positive network indicators of a network object, determine whether the growth rate of the positive network indicator is less than or equal to a first preset growth rate. If the growth rate of the positive network indicator is less than or equal to the first preset growth rate, then the network object is determined to be abnormal. It is understandable that since positive network indicators are those where a higher value is better, if the growth rate (year-on-year growth rate and / or month-on-month growth rate) of the positive network indicator of a network object is less than or equal to the first preset growth rate, it indicates that the growth rate of the positive network indicator value of the network object is small, suggesting poor network quality, and thus the network object is determined to be abnormal. It is worth noting that in some possible implementations, if the growth rate (year-on-year growth rate and / or month-on-month growth rate) of the positive network indicator of a network object is greater than the first preset growth rate, it indicates that the growth rate of the positive network indicator value of the network object is large, suggesting superior network quality, and thus the network object is determined not to be abnormal.
[0020] For the negative network indicators of a network object, determine whether the growth rate of the negative network indicator is greater than a second preset growth rate. If the growth rate of the negative network indicator is greater than the second preset growth rate, then the network object is determined to be abnormal. It is understandable that since negative network indicators refer to network indicators where a smaller value is better, if the growth rate (year-on-year growth rate and / or month-on-month growth rate) of a network object's negative network indicator is greater than the second preset growth rate, it indicates that the growth rate of the negative network indicator value of the network object is large, suggesting poor network quality, and thus the network object is determined to be abnormal. It is worth noting that in some possible implementations, if the growth rate (year-on-year growth rate and / or month-on-month growth rate) of a network object's negative network indicator is less than or equal to the second preset growth rate, it indicates that the growth rate of the negative network indicator value of the network object is small, suggesting good network quality, and thus the network object is determined not to be abnormal.
[0021] Furthermore, it is determined whether either the positive or negative network indicators of the network object suggest that the network object is abnormal. If either the positive or negative network indicators suggest that the network object is abnormal, then the network object is determined to be the abnormal network object. In other words, if the positive network indicators suggest that the network object is abnormal while the negative network indicators suggest that it is not abnormal, or if the positive network indicators suggest that the network object is not abnormal while the negative network indicators suggest that it is abnormal, then the network object is ultimately determined to be abnormal. It is worth noting that in some possible implementations, if both the positive and negative network indicators of the network object suggest that it is not abnormal, then the network object is determined not to be an abnormal network object.
[0022] The above embodiments provide an anomaly detection method that can quickly and efficiently identify abnormal network objects. Anomaly detection is achieved by referencing the growth rate of various network objects under different network metrics, increasing the amount of information referenced and thus improving the accuracy of anomaly detection. Furthermore, by distinguishing between positive and negative network metrics, and determining whether the growth rate of positive network metrics is less than or equal to a first preset growth rate, and whether the growth rate of negative network metrics is greater than a second preset growth rate, abnormal network objects are identified. This allows for more targeted anomaly detection of various network objects under different network metrics, further improving the accuracy of anomaly detection. It is worth noting that in other possible implementations, the server may also employ other implementation methods to achieve anomaly detection of network objects; this application does not limit such implementations.
[0023] In conjunction with the first aspect above, in one possible implementation, the server obtains the user face document and signaling face document of the abnormal network object from the probe device, including:
[0024] The server sends a document retrieval request for the abnormal network object to the probe device. Then, the server receives the user plane document and signaling plane document for the abnormal network object sent by the probe device in response to the document retrieval request.
[0025] The document retrieval request is used to request the user plane document and signaling plane document of the abnormal network object. For example, the document retrieval request can be a document subscription request, which is used to request subscription to the user plane document and signaling plane document of the abnormal network object. Accordingly, the server can send a document subscription request for the abnormal network object to the probe device. Then, the server receives the user plane document and signaling plane document of the abnormal network object sent by the probe device in response to the document subscription request. It is worth noting that in some other possible implementations, the server may also use other methods to obtain the user plane document and signaling plane document of the abnormal network object from the probe device; this application embodiment does not limit this approach.
[0026] In conjunction with the first aspect above, in one possible implementation, after the server sends a document subscription request for the abnormal network object to the probe device, the method further includes:
[0027] The probe device receives a subscription response message in response to the document subscription request. This subscription response message indicates whether the user-face document and signaling-face document for the abnormal network object have been subscribed to.
[0028] In the above implementation, after the server sends the document subscription request for the abnormal network object to the probe device, the probe device also returns a subscription response message to the server to indicate that the server has subscribed to the user face document and signaling face document of the abnormal network object.
[0029] In conjunction with the first aspect described above, in one possible implementation, after the server obtains the user face document and signaling face document of the abnormal network object from the probe device, the method further includes:
[0030] In response to the abnormal network object returning to normal, the acquisition of user face documents and signaling face documents for that network object from the probe device is stopped. Thus, for network objects that have returned to normal, it is unnecessary to continue acquiring the full data of that network object, avoiding the problem of an excessive number of documents pending processing on the server.
[0031] In one possible implementation, when the server has already sent a document subscription request, the process of the server stopping the acquisition of user plane documents and signaling plane documents of the abnormal network object from the probe device can be as follows: the server sends a document unsubscription request for the abnormal network object to the probe device. This document unsubscription request is used to request the unsubscription of the user plane documents and signaling plane documents of the abnormal network object. The server then receives a unsubscription response message from the probe device in response to the document unsubscription request. This unsubscription response message indicates that the subscription to the user plane documents and signaling plane documents of the abnormal network object has been unsubscribed.
[0032] In the above implementation, after the abnormal network object has returned to normal, a method is provided to unsubscribe from the user face document and signaling face document of the abnormal network object. This is achieved by triggering a document unsubscription request for the abnormal network object, thereby requesting the unsubscription of the user face document and signaling face document of that abnormal network object. Furthermore, upon receiving a unsubscription response message from the probe device in response to the document unsubscription request, it indicates that the unsubscription of the user face document and signaling face document of the abnormal network object has been successfully completed.
[0033] In conjunction with the first aspect described above, in one possible implementation, after the server obtains the user face document and signaling face document of the abnormal network object from the probe device, the method further includes:
[0034] Determine whether the abnormal network object has returned to normal. If the growth rate of the positive network indicator of the abnormal network object is greater than the first preset growth rate within a preset time period, and the growth rate of the negative network indicator of the abnormal network object is less than or equal to the second preset growth rate within a preset time period, then it is determined that the abnormal network object has returned to normal.
[0035] In the above implementation, after the server successfully subscribes to the user face document and signaling face document of the abnormal network object, it also provides a recovery detection method for the abnormal network object to determine whether the abnormal network object has returned to normal.
[0036] In conjunction with the first aspect above, in one possible implementation, the server performs anomaly detection on network objects during the communication process based on the communication service document to obtain abnormal network objects, including:
[0037] Every second time period, based on the communication service documents within that second time period, an anomaly detection is performed on the network objects in the communication process to obtain the abnormal network objects within that second time period.
[0038] In the above embodiments, a periodic anomaly detection method is provided. Through periodic anomaly detection, abnormal network objects in different time periods can be identified quickly and efficiently, thereby successfully completing data collection in different time periods.
[0039] Secondly, a data acquisition method is provided. This method can be executed by a probe device, or by a component of the probe device, such as its processor, chip, or chip system. It can also be implemented by a logic module or software capable of performing all or part of the probe device's functions. Taking the method being executed by a probe device as an example, the method includes:
[0040] The probe device acquires communication service documents. These documents include time-slice documents, which are obtained by statistically analyzing user plane and signaling plane documents using a first time period as the statistical unit. After collecting user plane and signaling plane documents, the probe device performs statistical analysis on them using the first time period as the statistical unit. The resulting documents are concise and simplified versions of the original documents, significantly reducing the document volume.
[0041] The communication service document is sent to the server. This document is used to obtain the user plane and signaling plane documents of the target network object from the probe device. The target network object is the network object to be processed. The communication service document (time-slice document) received by the server at this time is a simplified document obtained after the probe device preprocesses the original document, significantly reducing the amount of documents to be processed by the server. This reduction in the number of documents to be processed by the server reduces the number of hardware devices deployed on the CEM platform, thereby reducing costs for internet companies. Furthermore, for the target network object to be processed, the server can obtain the full amount of user plane and signaling plane documents from the probe device, providing a rich data foundation for subsequent data processing of the target network object and improving the reliability of data processing.
[0042] In conjunction with the second aspect described above, in one possible implementation, the target network object is an abnormal network object. The communication service document also includes a signaling plane abnormal document, which is a signaling plane abnormal document indicating communication failure. That is, after collecting the user plane document and the signaling plane document, the probe device also acquires the signaling plane abnormal document indicating communication failure from the signaling plane document, increasing the amount of information contained in the communication service document and providing a data foundation for the server to subsequently identify the abnormal network object.
[0043] After the probe device sends the communication service document to the server, the method further includes: in response to the document retrieval request for the abnormal network object returned by the server based on the communication service document, the probe device sends the user plane document and signaling plane document of the abnormal network object to the server. The document retrieval request is used to request the retrieval of the user plane document and signaling plane document of the abnormal network object.
[0044] Understandably, considering that the communication service documents received by the server are statistically derived documents and contain relatively little information, the server performs anomaly detection on network objects during the communication process. This allows the server to obtain the user plane and signaling plane documents of the abnormal network objects from the probe device. This ensures the server obtains all the documents related to the abnormal network objects, providing a data foundation for subsequent processing and improving the reliability of data processing.
[0045] For example, a document retrieval request can be a document subscription request, which requests to subscribe to the user plane document and signaling plane document of the abnormal network object. In one possible implementation, in response to the document subscription request of the abnormal network object returned by the server based on the communication service document, the probe device sends the user plane document and signaling plane document of the abnormal network object to the server.
[0046] Furthermore, in one possible implementation, in response to the server's document subscription request for an abnormal network object returned based on the communication service document, the probe device also sends a subscription response message to the server. This subscription response message indicates that the user plane document and signaling plane document for the abnormal network object have been subscribed to. Thus, after the server sends the document subscription request for the abnormal network object to the probe device, the probe device also returns a subscription response message to the server, indicating that the server has subscribed to the user plane document and signaling plane document for the abnormal network object.
[0047] In conjunction with the second aspect above, in one possible implementation, after the probe device sends the user face document and signaling face document of the abnormal network object to the server, the method further includes:
[0048] Once the abnormal network object has returned to normal, the probe device receives a document unsubscription request from the server for that abnormal network object. This document unsubscription request requests the unsubscription of both the user plane and signaling plane documents for the abnormal network object. Subsequently, in response to the document unsubscription request, the probe device sends a unsubscription response message to the server. This unsubscription response message indicates that the user plane and signaling plane documents for the abnormal network object have been unsubscribed.
[0049] In the above implementation, the server triggers a document unsubscribe request for the abnormal network object to request the unsubscribement of the user plane and signaling plane documents for that abnormal network object. Then, when the probe device responds to the document unsubscribe request by sending an unsubscribe response message, it indicates that it has successfully unsubscribed from the user plane and signaling plane documents of the abnormal network object. Thus, for network objects that have recovered, it is unnecessary to continue acquiring the full data of that network object, avoiding the problem of an excessive number of documents pending server processing.
[0050] Thirdly, a data acquisition device is provided for implementing any of the methods provided in the first aspect. This data acquisition device includes modules, units, or means corresponding to the aforementioned methods. The actions performed by these modules, units, or means can be implemented in hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the aforementioned functions.
[0051] In one possible implementation, the device may include a receiving module and a processing module; wherein:
[0052] The receiving module is used to receive communication service documents from the probe device. The communication service documents include time slice documents, which are documents obtained by statistically analyzing user plane documents and signaling plane documents with a first time period as the statistical unit.
[0053] The acquisition module is also used to acquire the user face document and signaling face document of the target network object from the probe device based on the communication service document. The target network object is the network object to be processed.
[0054] Fourthly, a data acquisition device is provided for implementing any of the methods provided in the second aspect above. The data acquisition device includes modules, units, or means corresponding to the above methods. The actions performed by these modules, units, or means can be implemented in hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0055] In one possible implementation, the device may include an acquisition module and a transmission module; wherein:
[0056] The acquisition module is used to acquire communication service documents, which include time slice documents. The time slice documents are obtained by statistically analyzing user plane documents and signaling plane documents with a first time period as the statistical unit.
[0057] The sending module is used to send the communication service document to the server. This communication service document is used to obtain the user plane document and signaling plane document of the target network object from the probe device. The target network object is the network object to be processed.
[0058] Fifthly, a server is provided, comprising: a memory and a processor, the memory and the processor being connected; the memory being used to store computer-executed instructions; and the processor being used to invoke the computer-executed instructions, thereby implementing the method of the first aspect above or any implementation thereof.
[0059] The server in the fifth aspect can be: a server in any implementation of the first aspect, or an apparatus containing the server, or an apparatus contained in the server, such as a chip.
[0060] In a sixth aspect, a probe device is provided, comprising: a memory and a processor, the memory and the processor being connected; the memory being used to store computer-executed instructions; and the processor being used to invoke the computer-executed instructions to implement the method of the second aspect above or any implementation thereof.
[0061] The probe device in the sixth aspect can be: a probe device in any implementation of the second aspect, or a device containing the probe device, or a device contained in the probe device, such as a chip.
[0062] In a seventh aspect, a data acquisition system is provided, comprising a server for performing the method described in the first aspect or a probe device for performing the method described in the second aspect.
[0063] The probe device is used to acquire communication service documents, which include time slice documents. These time slice documents are obtained by statistically analyzing user plane documents and signaling plane documents using a first time period as the statistical unit. The device then sends these communication service documents to the server.
[0064] The server is used to receive communication service documents from the probe device; based on the communication service documents, it obtains the user plane documents and signaling plane documents of the target network object from the probe device. The target network object is the network object to be processed.
[0065] Eighthly, a chip is provided, comprising: a processor and an interface circuit; the interface circuit for receiving computer execution instructions and transmitting them to the processor; and the processor for executing the computer execution instructions to perform the methods of the first aspect, the second aspect, or any implementation thereof described above.
[0066] A ninth aspect provides a computer-readable storage medium including computer-executable instructions that, when executed on a server, cause the server to perform the method described in the first aspect or any implementation thereof, and when executed on a probe device, cause the probe device to perform the method described in the second aspect or any implementation thereof.
[0067] In a tenth aspect, a computer program product is provided, comprising computer execution instructions that, when the computer execution instructions are executed on a server, cause the server to execute the method described in the first aspect or any implementation thereof, and when the computer execution instructions are executed on a probe device, cause the probe device to execute the method described in the second aspect or any implementation thereof.
[0068] It should be noted that the technical effects of any of the implementation methods in the third to tenth aspects can be found in the technical effects of the corresponding implementation methods in the first or second aspects, and will not be repeated here.
[0069] It should be noted that any of the possible implementations of any of the above aspects can be combined, provided that the solutions do not contradict each other. Attached Figure Description
[0070] Figure 1 is a schematic diagram of data acquisition on a CEM platform provided by related technologies;
[0071] Figure 2 is a schematic diagram of the platform expansion trend of a CEM platform provided by related technologies;
[0072] Figure 3 is a schematic diagram illustrating the usage effect of a CEM platform provided by related technologies;
[0073] Figure 4 is a schematic diagram of the system architecture of a data acquisition method provided in an embodiment of this application;
[0074] Figure 5 is a schematic diagram of the hardware structure of a server or probe device provided in an embodiment of this application;
[0075] Figure 6 is a flowchart illustrating a data acquisition method provided in an embodiment of this application;
[0076] Figure 7 is a flowchart illustrating another data acquisition method provided in an embodiment of this application;
[0077] Figure 8 is a schematic diagram of the interaction process between a probe device and a CEM platform provided in an embodiment of this application;
[0078] Figure 9 is a schematic diagram of data acquisition on a CEM platform provided in an embodiment of this application;
[0079] Figure 10 is a schematic diagram of a data acquisition device provided in an embodiment of this application;
[0080] Figure 11 is a schematic diagram of another data acquisition device provided in an embodiment of this application. Detailed Implementation
[0081] In the description of this application, unless otherwise stated, " / " indicates that the objects before and after are in an "or" relationship. For example, A / B can mean A or B. "And / or" in this application is merely a description of the relationship between the related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. A and B can be singular or plural.
[0082] In the description of this application, unless otherwise stated, "multiple" means two or more. "At least one of the following or similar expressions" refers to any combination of these items, including any combination of single or multiple items. For example, at least one of a, b and / or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple.
[0083] Furthermore, to facilitate a clear description of the technical solutions in the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish identical or similar items with substantially the same function and effect. Those skilled in the art will understand that the terms "first" and "second" do not limit the quantity or execution order, and the terms "first" and "second" are not necessarily different.
[0084] In the embodiments of this application, the words "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplarily" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of the words "exemplarily" or "for example" is intended to present the relevant concepts in a specific manner to facilitate understanding.
[0085] It is understood that the term "embodiment" used throughout the specification means that a specific feature, structure, or characteristic related to an embodiment is included in at least one embodiment of this application. Therefore, throughout the specification, various embodiments do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It is understood that in the various embodiments of this application, the sequence number of each process does not imply the order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0086] It is understood that some optional features in the embodiments of this application can be implemented independently in certain scenarios without relying on other features, such as the current solution on which they are based, to solve the corresponding technical problems and achieve the corresponding effects. Alternatively, they can be combined with other features as needed in certain scenarios. Correspondingly, the apparatus given in the embodiments of this application can also implement these features or functions, which will not be elaborated here.
[0087] In this application, unless otherwise specified, the same or similar parts between the various embodiments can be referred to each other. In the various embodiments of this application, unless otherwise specified or logically conflicting, the terminology and / or descriptions between different embodiments are consistent and can be mutually referenced. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships. The following embodiments of this application do not constitute a limitation on the scope of protection of this application.
[0088] The following provides an exemplary description of the application scenarios of the embodiments of this application.
[0089] With the rapid development of modern communication technology, users have increasingly higher requirements for network quality. In order to collect user feedback, various internet companies have begun to connect to the CEM platform to manage the overall user experience of the company. The CEM platform is a digital platform for managing the overall user experience of the company, including product experience, service experience, brand experience, marketing experience, and channel experience.
[0090] Currently, the CEM platform can be used to process user plane and signaling plane documents reported in real time by probe devices, such as user plane and signaling plane documents collected in real time in seconds (s). Documents refer to message records generated during communication, such as user plane message records or signaling plane message records generated during a user's internet access. In this embodiment, documents may include user plane documents and signaling plane documents. The user plane is mainly responsible for transmitting actual data, i.e., real business data, such as voice data. The signaling plane, also known as the control plane, is mainly responsible for transmitting control signaling or control messages, such as those used to control the establishment, maintenance, and release of a call process.
[0091] User-defined documents can be stream documents. Stream documents can be generated based on a Transmission Control Protocol (TCP) stream or a User Datagram Protocol (UDP) stream. For example, a stream document can be generated from an Internet Protocol address (IP), a port, and a protocol 5-tuple. For instance, the user's (i.e., the client's) IP / port and the server's IP / port. The protocol 5-tuple indicates five basic attributes of a network packet, including the source IP address, destination IP address, source port number, destination port number, and transport protocol.
[0092] Signaling plane documents can include transaction documents and process documents. Transaction documents are documents generated based on a pair of request / response messages. Process documents are documents generated by recording all messages from request to completion based on the access-side interface. For example, the access-side interface can be a control plane interface (S1-MME interface), an N1 interface, or an N2 interface. The S1-MME interface connects the base station to the mobility management entity (MME), specifically for transmitting signaling plane messages (or control plane information). The N1 interface is the logical interface between the terminal and the access and mobility management function (AMF), specifically for transmitting user plane messages. The N2 interface is the logical interface between the base station and the AMF, specifically for transmitting signaling plane messages.
[0093] For example, Figure 1 is a schematic diagram of data acquisition on a CEM platform provided by related technologies. Referring to Figure 1, the probe device can collect user plane documents (user plane flow documents as shown in Figure 1) and signaling plane documents (signaling plane transaction documents as shown in Figure 1) through code stream parsing and processing. Then, the collected user plane flow documents and signaling plane transaction documents are sent to the CEM platform so that the CEM platform can perform data processing operations such as data statistics, data analysis and data storage.
[0094] However, due to the massive amount of user form documents and signaling form documents reported in real time by the probe devices, a large number of hardware devices (such as servers) need to be deployed for the CEM platform in order to process them. Furthermore, as the amount of user form documents and signaling form documents continues to increase, even more hardware devices need to be deployed, making the hardware consumption of the CEM platform linearly related to the amount of documents processed, thus increasing the cost investment for Internet companies.
[0095] For example, Figure 2 is a schematic diagram of the platform expansion trend of a CEM platform provided by related technologies. Referring to Figure 2, (2-1) of Figure 2 shows the traffic increase and platform expansion trend of Enterprise 1. It can be seen that during the period of use of the CEM platform from 2018 to 2022, as the traffic (unit: bit rate Gbps) gradually increased, it meant that the amount of user face documents and signaling face documents reported in real time by the probe devices increased, and the number of servers deployed on the CEM platform (unit: units) also gradually increased, indicating a gradually increasing expansion trend. Figure 2 (2-2) shows the traffic increase and platform expansion trend of Enterprise 2. It can be seen that during the period of use of the CEM platform from 2018 to 2023, as the traffic gradually increased, it meant that the amount of user face documents and signaling face documents reported in real time by the probe devices increased, and the number of servers deployed on the CEM platform also gradually increased, indicating a gradually increasing expansion trend. As a result, the rapid increase in traffic has led to the continuous expansion of the CEM platform's hardware and the heavy configuration of its products, resulting in a continuous increase in customers' capital expenditure (CAPEX).
[0096] Clearly, the customer experience management services provided by the CEM platform to internet companies contradict the commercial value of these companies. For example, Figure 3 illustrates the usage effect of a CEM platform provided by related technologies. Referring to Figure 3, (3-1) shows a comparison of the expected investment effect (in M$) of internet companies and the expected product effect (in M$) of the CEM platform during the period from 2021 to 2026. Solid lines represent the expected investment effect of internet companies, and dashed lines represent the expected product effect of the CEM platform. It can be observed that the expected investment effect of internet companies decreases with increasing traffic (in Gbps), while the expected product effect of the CEM platform increases with increasing traffic, creating a scissors difference between the two. Figure 3 (3-2) shows the changes in the UC value of internet companies and the hardware investment of the CEM platform over time. Solid lines represent traffic, dashed lines represent the UC value of internet companies, and dashed lines represent the hardware investment of the CEM platform. It can be observed that while traffic continues to rise, the UC value of internet companies is only slightly increasing, while the hardware investment of CEM platforms continues to increase with the rise in traffic, creating a scissors gap between the UC value of internet companies and the hardware investment of CEM platforms.
[0097] In view of this, this application provides a data acquisition method applicable to scenarios involving document acquisition in communication networks, such as mobile network document acquisition or fixed network document acquisition. The server receives time-slice documents from the probe device. Since the time-slice documents are obtained by statistically analyzing user plane documents and signaling plane documents using a first time period as the statistical unit, the time-slice documents received by the server are concise documents obtained by the probe device after preprocessing the original documents. This significantly reduces the amount of documents to be processed, thereby reducing the number of hardware devices deployed on the CEM platform and reducing costs for internet companies. Furthermore, for the target network object to be processed, the full amount of user plane documents and signaling plane documents can be obtained, providing a rich data foundation for subsequent data processing of the target network object and improving the reliability of data processing.
[0098] It can be seen that, compared with the data acquisition method of the CEM platform in related technologies, the data acquisition method provided in this application embodiment has two advantages. First, it changes from the traditional default processing of all user face documents and signaling face documents to default processing of time slice documents, which can significantly reduce the amount of documents processed by the platform and achieve the purpose of reducing the server resource consumption of the CEM platform. Second, it can also dynamically and adaptively collect user face documents and signaling face documents of the target network object on demand to ensure the comprehensiveness of the documents of the target network object.
[0099] To facilitate understanding of the embodiments of this application, the following points will be explained before introducing the embodiments of this application.
[0100] 1. In the embodiments of this application, "instruction" can include direct instruction and indirect instruction. The information indicated by a certain piece of information is called the information to be instructed. In the specific implementation process, there are many ways to indicate the information to be instructed, such as, but not limited to, directly indicating the information to be instructed, such as the information to be instructed itself or its index. Alternatively, the information to be instructed can be indirectly indicated by indicating other information, where there is a correlation between the other information and the information to be indicated.
[0101] Furthermore, the specific instruction method can also be any existing instruction method, such as, but not limited to, the above-mentioned instruction methods and their various combinations. Specific details of various instruction methods can be found in existing technologies, and will not be repeated here. In the specific implementation process, the required instruction method can be selected according to specific needs. This application embodiment does not limit the selected instruction method; therefore, the instruction methods involved in this application embodiment should be understood to cover various methods that enable the party to be instructed to obtain the information to be instructed.
[0102] 2. "Pre-setting" can be achieved by pre-saving corresponding codes, tables, or other means that can be used to indicate relevant information in the device (e.g., a server or probe device). This application does not limit the specific implementation method. "Saving" can refer to saving in one or more memories. The one or more memories can be separate installations or integrated into the encoder or decoder, processor, or data acquisition device. Alternatively, some memories can be separately installed, while others are integrated into the decoder, processor, or data acquisition device. The type of memory can be any form of storage medium, and this application does not limit this.
[0103] 3. In the embodiments of this application, the descriptions such as "in the case of", "if" and "if" all refer to the fact that the device (such as a server or probe device) will make corresponding processing under certain objective circumstances. They are not time limits, nor do they require the device (such as a server or probe device) to have a judgment action when implementing it, nor do they mean that there are other limitations.
[0104] Furthermore, the system architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0105] Furthermore, the actions, terms, etc., involved in the various embodiments of this application can be referenced interchangeably without limitation. The message names or parameter names in the messages exchanged between the various devices in the embodiments of this application are merely examples, and other names may be used in specific implementations without limitation.
[0106] The system architecture of the embodiments of this application will be described exemplarily below.
[0107] In some embodiments, the data acquisition method provided in this application can be applied to the system architecture shown in FIG4. FIG4 is, for example, a schematic diagram of a system architecture for a data acquisition method provided in an embodiment of this application. Referring to FIG4, the system architecture may include: a probe device 401 and a server 402.
[0108] Among them, probe device 401 is a signal transmission detection tool used to parse the code stream during the communication process to obtain the message records generated during the communication process, thereby generating documents such as user face documents and signaling face documents.
[0109] In one possible implementation, the probe device 401 can be deployed corresponding to a network object, such as on the network object or around the network object. The network object can be a cell or a network element. A cell refers to a wireless communication service area covering a specific geographical region, such as the wireless communication service area of a city, district, or county. A network element refers to the basic components or equipment that constitute a communication network, such as a base station, serving gateway (SGW), packet data network gateway (PGW), access and mobility management function (AMF), user plane function (UPF), eNodeB (eNB), and gNodeB (gNB).
[0110] Server 402 can be a server or server cluster deployed in the cloud that can provide basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks, and big data or artificial intelligence platforms.
[0111] In one possible implementation, server 402 may run a CEM platform, which enables data processing operations such as data statistics, data analysis, and data storage for documents. The probe device 401 supports document subscription to the CEM platform and can report documents to the CEM platform.
[0112] In this embodiment, the probe device 401 is used to acquire communication service documents and report them to the server 402. The server 402 receives the communication service documents from the probe device and, based on the communication service documents, acquires the user plane documents and signaling plane documents of the target network object from the probe device.
[0113] In one example of this application, a schematic diagram of the hardware structure of a server or probe device is shown in Figure 5. Figure 5 is a schematic diagram of the hardware structure of a server or probe device provided in an embodiment of this application.
[0114] Referring to Figure 5, the server or probe device shown in Figure 5 may include: a processor 501, a memory 502, a communication interface 503, and a bus 504. The processor 501, the memory 502, and the communication interface 503 can be connected via the bus 504.
[0115] The processor 501 is the control center of the server or probe device, and can be a general-purpose central processing unit (CPU) or other general-purpose processors. The general-purpose processor can be a microprocessor or any conventional processor. In this embodiment, the processor 501 in the server or probe device can be used to execute the data acquisition method.
[0116] As an example, processor 501 may include one or more CPUs, such as CPU 0 and CPU 1 shown in Figure 5.
[0117] The memory 502 can be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, or other type of dynamic storage device capable of storing information and instructions. It can also be an electrically erasable programmable read-only memory (EEPROM), a disk storage medium, or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. In this embodiment, the memory 502 in a server or probe device can be used to store documents, etc.
[0118] In one possible implementation, the memory 502 may exist independently of the processor 501. The memory 502 can be connected to the processor 501 via a bus 504 and is used to store data, instructions, or program code. When the processor 501 calls and executes the instructions or program code stored in the memory 502, it can implement the data acquisition method provided in the embodiments of this application.
[0119] In another possible implementation, the memory 502 can also be integrated with the processor 501.
[0120] Communication interface 503 is used for connecting the server or probe device to other devices via a communication network, such as Ethernet, radio access network (RAN), wireless local area network (WLAN), etc. Communication interface 503 may include a receiving unit for receiving data and a transmitting unit for transmitting data.
[0121] Bus 504 can be an industry standard architecture (ISA) bus, a peripheral component interconnect (PCI) bus, or an extended industry standard architecture (EISA) bus. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, only one thick line is used in Figure 5, but this does not indicate that there is only one bus or one type of bus.
[0122] It should be noted that the structure shown in Figure 5 does not constitute a limitation on the server or probe device. In addition to the components shown in Figure 5, the server or probe device may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0123] For ease of understanding, the data acquisition method provided in this application embodiment is described below with reference to the above system architecture and accompanying drawings. It should be noted that the names of each parameter or each piece of information in the following embodiments of this application are merely examples, and may be other names in other embodiments. The data acquisition method provided in this application is not specifically limited in this regard.
[0124] It is understood that in the embodiments of this application, the server / probe device may execute some or all of the steps in the embodiments of this application. These steps or operations are merely examples, and the embodiments of this application may also perform other operations or variations thereof. Furthermore, the various steps may be executed in different orders as presented in the embodiments of this application, and it is not necessarily necessary to execute all the operations in the embodiments of this application.
[0125] Figure 6 is a flowchart illustrating a data acquisition method provided in an embodiment of this application. In one possible implementation, the data acquisition method can be completed by the server and probe device shown in the system architecture of Figure 4 above. Referring to Figure 6, the method includes the following steps S601-S604.
[0126] S601, Probe device acquires communication service documents.
[0127] In this embodiment of the application, the communication service document includes a time slice document. The time slice document is a document obtained by statistically analyzing user plane documents and signaling plane documents using a first time period as the statistical unit.
[0128] The first time period refers to the time period for statistical documents. In one possible implementation, the first time period can be a pre-set fixed time period, such as 2 minutes. It is understood that time slices are time segments obtained by dividing time periods based on the aforementioned fixed time period; for example, 2 minutes can be a time slice. It is worth noting that in other possible implementations, the first time period can also be set to other time periods, such as 5 minutes; this application does not limit this. It should be understood that the larger the value of the first time period, the fewer documents are collected within a given time period.
[0129] Time-slice documents can include user plane time-slice documents and signaling plane time-slice documents. It is understood that after collecting user plane and signaling plane documents, the probe device performs statistical analysis on these documents using the first time period as the statistical unit, thus obtaining time-slice documents with a reduced document volume.
[0130] In one possible implementation, the process of the probe device acquiring time-slice documents can be as follows: At each first time interval, the probe device statistically analyzes the user plane documents and signaling plane documents within that first time period. This involves organizing, analyzing, and merging the user plane documents and signaling plane documents to obtain the time-slice documents corresponding to that first time period. This allows for the acquisition of multiple time-slice documents corresponding to multiple first time periods. For example, assuming the entire time period is one hour, using 2 minutes as the first time period would yield 30 time-slice documents.
[0131] In this embodiment, the communication service document also includes a signaling plane exception document, which is a signaling plane document indicating communication failure. For example, the signaling plane exception document can be a signaling plane transaction failure document, that is, a transaction document generated separately when a signaling plane transaction fails. Here, signaling plane transaction failure refers to response failure, i.e., communication failure. It is understood that after collecting the signaling plane document, the probe device also obtains the signaling plane exception document indicating communication failure from the signaling plane document, increasing the amount of information contained in the communication service document and providing a data foundation for the subsequent server to determine abnormal network objects.
[0132] In one possible implementation, the process of the probe device acquiring signaling plane exception documents may be as follows: For each communication event, the probe device acquires the cause identifier code defined by the communication protocol of this communication event, and detects whether the communication event was successful based on the cause identifier code. For example, a cause identifier code of 128 indicates successful communication, and a cause identifier code other than 128 indicates communication failure. It is worth noting that in some other possible implementations, the probe device may also use other methods to acquire signaling plane exception documents, and this application embodiment does not limit this.
[0133] S602, The probe device sends the communication service document to the server.
[0134] S603. The server receives communication service documents from the probe device.
[0135] In some embodiments, after obtaining communication service documents, the server can perform data processing based on the communication service documents. This data processing may include operations such as data statistics, data analysis, and data storage.
[0136] S604. Based on the communication service document, the server obtains the user plane document and signaling plane document of the target network object from the probe device.
[0137] The target network object is the network object to be processed. In some embodiments, the target network object can be an abnormal network object, also known as a poor-quality network object. Alternatively, in other embodiments, the target network object can be other types of network objects, such as pre-defined network objects that require special attention, etc., and this application does not limit this.
[0138] The technical solution provided in this application embodiment involves a server receiving time-slice data from a probe device. Since the time-slice data is obtained by statistically analyzing user plane data and signaling plane data using a first time period as the statistical unit, the time-slice data received by the server is a concise version of the original data obtained by the probe device after preprocessing. This significantly reduces the amount of data to be processed, thereby reducing the number of hardware devices deployed on the CEM platform and ultimately reducing costs for internet companies. Furthermore, for the target network object to be processed, the full amount of user plane data and signaling plane data can be obtained, providing a rich data foundation for subsequent data processing of the target network object and improving the reliability of data processing.
[0139] Figure 7 is a flowchart illustrating another data acquisition method provided in an embodiment of this application. Figure 7 uses the interaction flow between a server and a probe device as an example to illustrate the data acquisition process between the server and the probe device. Referring to Figure 7, the method includes the following steps S701-S707:
[0140] S701, Probe device acquires communication service documents.
[0141] The content of S701 is the same as that shown in S601 above, and will not be repeated here.
[0142] S702, The probe device sends the communication service document to the server.
[0143] S703, The server receives communication service documents from the probe device.
[0144] S704. The server performs anomaly detection on network objects during the communication process based on the communication service document, and obtains abnormal network objects.
[0145] Abnormal network objects, also known as poor-quality network objects, refer to network objects exhibiting poor network quality during communication. For example, network objects can be cells or network elements. Regional types can include cities, districts, etc., and network element types can include SGW, PGW, AMF, UPF, eNB, gNB, etc.
[0146] In one possible implementation, the process by which the server performs anomaly detection on network objects during the communication process based on the communication service document may include the following steps one to four.
[0147] Step 1: Based on the communication service documents, the server determines the growth rate of each network object under different network metrics.
[0148] Network metrics can include user plane metrics and signaling plane metrics. User plane metrics refer to network metrics pre-defined for user plane time slice documents in communication service documents. For example, user plane metrics may include, but are not limited to, packet loss rate, round trip time (RTT), retransmission rate, and traffic. Signaling plane metrics refer to network metrics pre-defined for signaling plane time slice documents and signaling plane anomaly documents in communication service documents. Signaling plane metrics may include, but are not limited to, attach success rate, call drop rate, latency, and number of call requests. It is worth noting that in some possible implementations, other types of network metrics can also be set, which are not limited in this embodiment.
[0149] In one possible implementation, the server can determine the growth rate of each network object under different user plane indicators based on the user plane time slice data in the communication service documents, and can determine the growth rate of each network object under different signaling plane indicators based on the signaling plane time slice data and signaling plane anomaly data in the communication service documents.
[0150] The indicator growth rate is used to characterize the growth of network indicator values in the current time period compared to network indicator values in past time periods. In one possible implementation, the indicator growth rate can be at least one of year-on-year growth rate and month-on-month growth rate.
[0151] Year-on-year growth rate refers to the growth rate compared with the same period of the previous year / quarter / month / week. In other words, it's the growth rate of a specific period in the current period compared to a specific period of the previous year / quarter / month / week. Simply put, year-on-year growth means comparing data from the same period.
[0152] In one possible implementation, for each network object, the process by which the server determines the year-on-year growth rate of the network object under different network indicators may be as follows: for each network indicator, determine the network indicator value of the network object for the target time period of the current period, and determine the year-on-year growth rate of the network object under the network indicator based on the network indicator value of the target time period of the current period, the network indicator value of the network object for the same time period of the previous year / quarter / month / week, and the following formula (1) for calculating the year-on-year growth rate.
[0153] In the formula, m i p represents the year-over-year growth rate of network objects under network metric i; i This represents the value of network metric i for the target time period of the network object in the current period; This represents the value of network metric i for the same time period of the previous year / quarter / month / week for a network object.
[0154] For example, taking year-on-year comparison with the same period of the previous week as an example, the network indicator value of a certain period of the current period (such as 12:00 to 12:15) can be compared with the network indicator value of the same period of the previous week (seven days ago) (such as 12:00 to 12:15), and then the year-on-year growth rate can be determined by using the above calculation formula (1).
[0155] The month-on-month growth rate refers to the growth rate compared to the previous adjacent period; that is, the growth rate of a certain period in the current period compared to a certain period in the adjacent previous period. In other words, month-on-month growth is essentially comparing data from adjacent periods.
[0156] In one possible implementation, for each network object, the process by which the server determines the month-on-month growth rate of the network object under different network indicators may be as follows: for each network indicator, determine the network indicator value of the network object in the target time period of the current period, and determine the month-on-month growth rate of the network object under the network indicator based on the network indicator value of the target time period of the current period, the network indicator value of the network object in the same time period of the previous adjacent period, and the following formula (2) for calculating the month-on-month growth rate.
[0157] In the formula, n i p represents the month-over-month growth rate of a network object under network metric i; i This represents the value of network metric i for the target time period of the network object in the current period; This represents the value of network indicator i in the same time period of the previous period adjacent to the network object.
[0158] For example, taking the month-on-month comparison as an example of comparing with the same period of the adjacent previous day, the network indicator value of a certain period of the current period (such as 12:00 to 12:15) can be compared with the network indicator value of the same period of the previous day (such as 12:00 to 12:15), and then the month-on-month growth rate can be determined by using the above calculation formula (2).
[0159] Step 2: For the positive network metrics of a network object, the server determines whether the growth rate of the positive network metric is less than or equal to a first preset growth rate. If the growth rate of the positive network metric is less than or equal to the first preset growth rate, then the network object is determined to be abnormal.
[0160] Among them, positive network metrics refer to network metrics where a higher value is better, such as attach success rate. The first preset growth rate is a pre-set growth rate threshold, such as 5%. This application embodiment does not limit the value of the first preset growth rate.
[0161] Understandably, if the growth rate of the positive network indicator of a network object is less than or equal to the first preset growth rate, it means that the growth rate of the positive network indicator value of the network object is small, indicating that its network quality is poor, and thus it is determined that the network object has become abnormal.
[0162] It is worth noting that in some other possible implementations, if the growth rate of the positive network indicator of a network object is greater than the first preset growth rate, it means that the growth rate of the positive network indicator of the network object is relatively large, indicating that its network quality is better, and thus it is determined that the network object has not experienced any abnormalities.
[0163] For example, taking the indicator growth rate as including year-on-year growth rate and month-on-month growth rate, step two above can be replaced as follows: For the positive network indicator of the network object, the server determines whether the year-on-year growth rate and month-on-month growth rate of the positive network indicator are less than or equal to a first preset growth rate. If either the year-on-year growth rate or the month-on-month growth rate of the positive network indicator is less than or equal to the first preset growth rate, then the network object is determined to be abnormal. If both the year-on-year growth rate and the month-on-month growth rate of the positive network indicator are greater than the first preset growth rate, then the network object is determined not to be abnormal.
[0164] Step 3: For negative network metrics of a network object, the server determines whether the growth rate of the negative network metric is greater than the second preset growth rate. If the growth rate of the negative network metric is greater than the second preset growth rate, then the network object is determined to be abnormal.
[0165] Among them, negative network metrics refer to network metrics where a smaller value is better, such as packet loss rate and latency. The second preset growth rate is a pre-set growth rate threshold, such as 5%. This application does not limit the value of the second preset growth rate in its embodiments.
[0166] Understandably, if the growth rate of a network object's negative network metric is greater than the second preset growth rate, it means that the growth rate of the negative network metric value of the network object is relatively large, indicating that its network quality is poor, and thus it is determined that the network object has become abnormal.
[0167] It is worth noting that in some other possible implementations, if the growth rate of the negative network indicator of a network object is less than or equal to the second preset growth rate, it means that the growth rate of the negative network indicator of the network object is small, indicating that its network quality is better, and thus it is determined that the network object has not experienced any abnormalities.
[0168] For example, taking the indicator growth rate as including year-on-year growth rate and month-on-month growth rate, step three above can be replaced as follows: For negative network indicators of a network object, the server determines whether the year-on-year growth rate and month-on-month growth rate of the network object under the negative network indicator are greater than a second preset growth rate. If either the year-on-year growth rate or the month-on-month growth rate of the network object under the negative network indicator is greater than the second preset growth rate, then the network object is determined to be abnormal. If both the year-on-year growth rate and the month-on-month growth rate of the network object under the negative network indicator are less than or equal to the second preset growth rate, then the network object is determined not to be abnormal.
[0169] The first preset growth rate used in step two and the second preset growth rate used in step three can be the same or different. This application does not limit this.
[0170] In some embodiments, the server may first execute the process of determining positive network indicators in step two above, and then execute the process of determining negative network indicators in step three; alternatively, the server may first execute the process of determining negative network indicators in step three above, and then execute the process of determining positive network indicators in step two; or, the server may execute the process of determining positive network indicators in step two and the process of determining negative network indicators in step three simultaneously. This application embodiment does not limit the execution order of steps two and three above.
[0171] Step 4: Determine if either the positive or negative network metrics of the network object indicate that the network object is abnormal. If either the positive or negative network metrics of the network object indicate that the network object is abnormal, the server determines that the network object is the abnormal network object.
[0172] In other words, if a network object's positive network indicator suggests it is abnormal, while its negative network indicator suggests it is not abnormal, or if its positive network indicator suggests it is not abnormal, while its negative network indicator suggests it is abnormal, then the network object is ultimately determined to be abnormal. It is worth noting that in some possible implementations, if both the positive and negative network indicators of a network object suggest it is not abnormal, then the network object is determined not to be an abnormal network object.
[0173] It is understandable that for a network object that includes multiple network metrics (such as both user plane and signaling plane metrics, and both positive and negative network metrics), if any one network metric indicates that the network object is abnormal, then the network object is ultimately determined to be an abnormal network object. Furthermore, in one possible implementation, when traversing multiple network metrics of a network object, if one network metric indicates that the network object is abnormal, then it is unnecessary to traverse the remaining network metrics; the network object can be directly determined to be an abnormal network object.
[0174] Regarding the anomaly detection process in steps one through four above, in one possible implementation, the server can perform anomaly detection on network objects during the communication process every second time period, based on the communication service documents within the second time period, to obtain the abnormal network objects within that second time period. That is, S704 can be executed once every second time period.
[0175] The second time period refers to the time period of the statistical indicators, which can also be understood as the granularity of the statistical indicators. In one possible implementation, the second time period can be a pre-set fixed time period, such as 15 minutes (granularity), meaning that statistical indicators are collected in batches every 15 minutes, so a day can include 96 periods. This provides a periodic anomaly detection method, which can quickly and efficiently identify abnormal network objects within different time periods, thereby successfully completing data collection within different time periods.
[0176] For example, taking communication service documents including user plane time slice documents, signaling plane time slice documents, and signaling plane anomaly documents as examples, after the probe device reports these documents to the server, the CEM platform running on the server can perform anomaly detection on different network objects (e.g., areas or network elements) during the communication process at a 15-minute granularity. Taking user plane indicators as an example, firstly, the user plane indicators can be compared with the statistical results of the previous week. For example, the statistical results of indicators from 12:00 to 12:15 on the current day can be compared with the statistical results of indicators from 12:00 to 12:15 seven days ago, the statistical results of indicators from 12:15 to 12:30 on the current day can be compared with the statistical results of indicators from 12:15 to 12:30 seven days ago, and so on, to obtain the year-on-year growth rate of user plane indicators. Then, the user plane metrics can be compared with the previous day's metric statistics. For example, the metric statistics from 12:00 to 12:15 on the current day can be compared with those from 12:00 to 12:15 one day prior, and so on. This yields the month-on-month growth rate of the user plane metrics. Furthermore, by distinguishing between positive and negative network metrics, we can determine whether the year-on-year growth rate and month-on-month growth rate under positive network metrics are less than or equal to a first preset growth rate, and whether the year-on-year growth rate and month-on-month growth rate under negative network metrics are greater than a second preset growth rate, to identify abnormal network objects (such as abnormal areas or abnormal network elements). Similarly, taking signaling plane metrics as an example, firstly, the signaling plane metrics can be compared with the previous week's metric statistics to obtain the year-on-year growth rate. Then, the signaling plane metrics can be compared with the previous day's metric statistics to obtain the month-on-month growth rate. Furthermore, by distinguishing between positive and negative network indicators, it is determined whether the year-on-year growth rate and month-on-month growth rate under the positive network indicator are less than or equal to the first preset growth rate, and whether the year-on-year growth rate and month-on-month growth rate under the negative network indicator are greater than the second preset growth rate, in order to identify abnormal network objects.
[0177] The above embodiments provide an anomaly detection method that can quickly and efficiently identify anomalous network objects. Anomaly detection is achieved by referencing the growth rates (year-on-year growth rate and / or month-on-month growth rate) of various network objects under different network metrics, increasing the amount of information referenced and thus improving the accuracy of anomaly detection. Furthermore, by distinguishing between positive and negative network metrics, and determining whether the growth rate of positive network metrics is less than or equal to a first preset growth rate, and whether the growth rate of negative network metrics is greater than a second preset growth rate, anomalous network objects are identified. This allows for more targeted anomaly detection of various network objects under different network metrics, further improving the accuracy of anomaly detection.
[0178] S705. The server obtains the user face document and signaling face document of the abnormal network object from the probe device.
[0179] In one possible implementation, the process of the server obtaining the user plane document and signaling plane document of the abnormal network object from the probe device may include: the server sending a document retrieval request for the abnormal network object to the probe device; the probe device, in response to the document retrieval request sent by the server, sending the user plane document and signaling plane document of the abnormal network object to the server; and the server receiving the user plane document and signaling plane document of the abnormal network object sent by the probe device in response to the document retrieval request.
[0180] The document retrieval request is used to request the user plane documents and signaling plane documents of the abnormal network object. For example, the document retrieval request can be a document subscription request, used to request the subscription of the user plane documents and signaling plane documents of the abnormal network object.
[0181] In one possible implementation, the document retrieval request may carry a type identifier and an identity identifier for the abnormal network object, such as using an identity document (ID) to represent the identifier.
[0182] For example, taking an abnormal network object as an SGW (e.g., the SGW's type ID is 10 and the SGW's identity ID is 1), the server can generate a document retrieval request for the abnormal network object based on the SGW's type ID and identity ID (the request parameters include: type ID is "10" and identity ID is "1"), and send the document retrieval request for the abnormal network object to the probe device to request the retrieval of the user plane document and signaling plane document of the abnormal network object.
[0183] In the above embodiments, for abnormal network objects, since the cause of the abnormality of the abnormal network object will be located later, considering that user face documents can be used to support the demarcation of network elements or service providers, and signaling face documents can be used to support the specific location of network elements, the server performs anomaly detection on network objects in the communication process and subscribes to the user face documents and signaling face documents of abnormal network objects from the probe device to ensure that the server can obtain the full set of documents of abnormal network objects, thereby providing a data foundation for the subsequent processing of abnormal network objects and improving the reliability of data processing.
[0184] In one possible implementation, taking a document retrieval request as a document subscription request as an example, after the server sends a document subscription request to the probe device, the probe device can also send a subscription response message to the server. Correspondingly, the server also receives a subscription response message sent by the probe device in response to the document subscription request. This subscription response message indicates whether user-plane documents and signaling-plane documents for abnormal network objects have been subscribed to.
[0185] In some embodiments, after obtaining the communication service documents and the user plane documents and signaling plane documents of the abnormal network objects, the server can perform data processing based on the communication service documents and the user plane documents and signaling plane documents of the abnormal network objects, such as data statistics, data analysis and data storage operations.
[0186] The embodiments shown in S704 to S705 above, taking the target network object as an abnormal network object as an example, exemplify the process by which the server, as shown in S604 of Figure 6, obtains the user plane document and signaling plane document of the target network object from the probe device based on the communication service document. It is worth noting that in other embodiments, the target network object can also be other types of network objects, such as pre-defined network objects that require special attention.
[0187] Furthermore, for abnormal network objects, a recovery test can be performed on the abnormal network object. Once it is determined that the abnormal network object has returned to normal, the acquisition of user face documents and signaling face documents for the abnormal network object from the probe device is stopped. This process is explained below based on S706 to S707.
[0188] S706. The server determines whether the abnormal network object has returned to normal. If the abnormal network object has returned to normal, then execute S707.
[0189] In one possible implementation, the server determines whether the growth rate of the positive network indicator of the abnormal network object is greater than a first preset growth rate within a preset time period, and whether the growth rate of the negative network indicator of the abnormal network object is less than or equal to a second preset growth rate within the preset time period. If the growth rate of the positive network indicator of the abnormal network object is greater than the first preset growth rate within the preset time period, and the growth rate of the negative network indicator of the abnormal network object is less than or equal to the second preset growth rate within the preset time period, then it is determined that the abnormal network object has returned to normal.
[0190] For example, taking the indicator growth rate as including year-on-year growth rate and month-on-month growth rate, the above judgment on whether the abnormal network object has returned to normal can be replaced by: judging whether the year-on-year growth rate and month-on-month growth rate of the positive network indicator are both greater than the first preset growth rate within a preset time period, and judging whether the year-on-year growth rate and month-on-month growth rate of the negative network indicator are both less than or equal to the second preset growth rate within a preset time period. If the year-on-year growth rate and month-on-month growth rate of the positive network indicator are both greater than the first preset growth rate within the preset time period, and the year-on-year growth rate and month-on-month growth rate of the negative network indicator are both less than or equal to the second preset growth rate within the preset time period, then it is determined that the abnormal network object has returned to normal.
[0191] The preset duration can be a pre-set fixed duration. In one possible implementation, the preset duration can be determined based on a first time period or a second time period, such as setting the preset duration to a preset number of first time periods or a preset number of second time periods. This application does not limit the setting of the preset duration.
[0192] Regarding the aforementioned recovery detection process, in one possible implementation, the server can perform a recovery detection on the network objects during the communication process every second time period, based on the communication service documents within the second time period, to determine whether the abnormal network objects have returned to normal. That is, S706 can be executed once every second time period.
[0193] For example, taking a second time period of 15 minutes as an example, and a preset duration of 3 second time periods (i.e., 45 minutes), the CEM platform running on the server can perform recovery detection on abnormal network objects (such as abnormal areas or abnormal network elements) during the communication process at a 15-minute granularity. Taking user plane indicators as an example, firstly, the user plane indicators can be compared with the statistical results of the previous week to obtain the year-on-year growth rate of user plane indicators. Then, the user plane indicators can be compared with the statistical results of the previous day to obtain the month-on-month growth rate of user plane indicators. Furthermore, by distinguishing between positive and negative network indicators, it is determined whether the year-on-year growth rate and month-on-month growth rate under positive network indicators are greater than the first preset growth rate for 3 consecutive second time periods, and whether the year-on-year growth rate and month-on-month growth rate under negative network indicators are less than or equal to the second preset growth rate for 3 consecutive second time periods, in order to determine whether the abnormal network objects have returned to normal. Similarly, taking the signaling surface indicator as an example, firstly, the signaling surface indicator can be compared with the statistical results of the previous week to obtain the year-on-year growth rate. Then, the signaling surface indicator can be compared with the statistical results of the previous day to obtain the month-on-month growth rate. Furthermore, by distinguishing between positive and negative network indicators, it is determined whether the year-on-year growth rate and month-on-month growth rate under the positive network indicator are both greater than the first preset growth rate within three consecutive second time periods, and whether the year-on-year growth rate and month-on-month growth rate under the negative network indicator are both less than or equal to the second preset growth rate within three consecutive second time periods, in order to determine whether the abnormal network object has returned to normal.
[0194] Understandably, for an abnormal network object that includes multiple network metrics (such as both user plane and signaling plane metrics, or both positive and negative network metrics), it is necessary to ensure that all network metrics indicate that the abnormal network object has not experienced any anomalies within a preset time period before finally determining that the abnormal network object has recovered. In other words, if any network metric indicates that the abnormal network object has experienced anomalies within a preset time period, then it is ultimately determined that the abnormal network object has not recovered.
[0195] In the above embodiments, after the server successfully subscribes to the user face document and signaling face document of the abnormal network object, it also provides a recovery detection method for the abnormal network object to determine whether the abnormal network object has returned to normal.
[0196] S707. The server responds that the abnormal network object has been restored to normal and stops obtaining user face documents and signaling face documents of the abnormal network object from the probe device.
[0197] In one possible implementation, taking a document retrieval request as a document subscription request as an example, if the abnormal network object has recovered, the server can send a document unsubscription request for the abnormal network object to the probe device. The probe device receives the document unsubscription request for the abnormal network object sent by the server. In response to the document unsubscription request, the probe device sends a unsubscription response message to the server. The server receives the unsubscription response message sent by the probe device in response to the document unsubscription request.
[0198] The document unsubscribe request is used to request the unsubscribe from user plane documents and signaling plane documents of abnormal network objects. The unsubscribe response message indicates that the user plane documents and signaling plane documents of abnormal network objects have been unsubscribed.
[0199] For example, taking an abnormal network object as an SGW (e.g., SGW type ID is 10, SGW identity ID is 1), the server can generate a document unsubscribe request for the abnormal network object based on the SGW type ID and identity ID (request parameters include: type ID is "10", identity ID is "1"), and send the document unsubscribe request to the probe device to request the unsubscription of the user plane document and signaling plane document for the abnormal network object. It should be understood that after successful unsubscription, the probe device will no longer report the corresponding network object's user plane document or signaling plane document.
[0200] In the above embodiments, after the abnormal network object has returned to normal, a method is provided to unsubscribe from the user plane documents and signaling plane documents of the abnormal network object. Specifically, a document unsubscription request is triggered for the abnormal network object to request the unsubscription of its user plane documents and signaling plane documents. Then, upon receiving a unsubscription response message from the probe device in response to the document unsubscription request, it indicates that the unsubscription of the user plane documents and signaling plane documents of the abnormal network object has been successfully completed. Thus, for network objects that have returned to normal, it is unnecessary to continue acquiring the full data of the network object, avoiding the problem of an excessive number of documents pending server processing.
[0201] Figure 7 above illustrates the solution using the interaction process between the probe device and the server as an example. In other embodiments, the above process can also be completed by the probe device and the CEM platform running on the server. In one example, Figure 8 is a schematic diagram of the interaction process between a probe device and a CEM platform provided in an embodiment of this application. Referring to Figure 8, the interaction process between the probe device and the CEM platform can include: 1. The probe device reports time slice documents and signaling plane anomaly documents to the CEM platform; 2. The CEM platform adaptively identifies abnormal network objects and subscribes to the user plane documents and signaling plane documents of the abnormal network objects; 3. The CEM platform requests the probe device to subscribe to the user plane documents and signaling plane documents of the abnormal network objects; 4. The probe device responds to the CEM platform with a successful subscription; 5. The probe device reports the user plane documents and signaling plane documents of the abnormal network objects to the CEM platform; 6. The CEM platform adaptively identifies whether the abnormal network objects have recovered and unsubscribes from the user plane documents and signaling plane documents of the recovered network objects; 7. The CEM platform requests the probe device to unsubscribe from the user plane documents and signaling plane documents of the recovered network objects; 8. The probe device responds to the CEM platform with a successful unsubscription. After successful unsubscription, the probe device will no longer report the user plane documents or signaling plane documents of the corresponding network objects.
[0202] For example, Figure 9 is a data acquisition schematic diagram of a CEM platform provided in an embodiment of this application. Referring to Figure 9, the probe device can collect user plane time slice data, signaling plane time slice data, and signaling plane anomaly data through code stream parsing and periodic statistics. The collected user plane time slice data, signaling plane time slice data, and signaling plane anomaly data are then sent to the CEM platform for data processing operations such as data statistics, data analysis, and data storage. Furthermore, the CEM platform also provides a dynamic adaptive identification function, specifically, dynamically adaptively identifying abnormal network objects, and thus enabling a dynamic adaptive subscription function, specifically dynamically adaptively subscribing to the user plane data and signaling plane data of abnormal network objects.
[0203] It can be observed that, compared with the data acquisition methods of related CEM platforms, the data acquisition method provided in this application embodiment changes from the traditional default processing of all user face documents and signaling face documents to default processing of time slice documents, and dynamically and adaptively identifies abnormal network objects and dynamically and adaptively subscribes to user face documents and signaling face documents, which can significantly reduce the amount of documents processed by the platform. For example, in this application embodiment, reporting time slice documents can reduce the amount of documents processed by the platform by 30%. Moreover, considering that the number of abnormal network objects is usually small (generally not exceeding 5%), it means that the subscribed user face documents and signaling face documents will not exceed 5% of the total collection. In summary, the amount of documents processed by the CEM platform is 65% of the amount of documents to be processed in related technologies. Thus, due to the significant reduction in the amount of documents on the CEM platform, the server resource consumption of the CEM platform is also reduced proportionally, achieving the goal of reducing the server resource consumption of the CEM platform. In this embodiment, the document volume and traffic of the CEM platform are decoupled. The document volume no longer increases linearly with the traffic, so the CEM platform does not need to continuously expand the server as the traffic increases. This optimizes the hard expansion mode in related technologies and realizes soft expansion at the technical level.
[0204] The technical solution provided in this application embodiment involves a server receiving time-slice data from a probe device. Since the time-slice data is obtained by statistically analyzing user plane data and signaling plane data using a first time period as the statistical unit, the time-slice data received by the server is a concise version of the original data obtained by the probe device after preprocessing. This significantly reduces the amount of data to be processed, thereby reducing the number of hardware devices deployed on the CEM platform and ultimately reducing costs for internet companies. Furthermore, for the target network object to be processed, the full amount of user plane data and signaling plane data can be obtained, providing a rich data foundation for subsequent data processing of the target network object and improving the reliability of data processing.
[0205] It should be noted that the above description is for the purpose of more clearly explaining the data acquisition method described in the embodiments of this disclosure, and should not be construed as limiting the specific implementation of this application.
[0206] The above mainly describes the solutions provided by the embodiments of this application from the perspective of data acquisition process. Correspondingly, the embodiments of this application also provide a data acquisition device for implementing the various methods described above. This data acquisition device can be one of the devices described in the above method embodiments, or it can include the aforementioned devices, or it can be a component that can be used. It is understood that, in order to achieve the above functions, the data acquisition device includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, in conjunction with the units and algorithm steps of the various examples described in the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed by hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0207] This application embodiment can divide the data acquisition device into functional modules according to the above method embodiment. For example, each function can be divided into its own functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be understood that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods.
[0208] For example, Figure 10 is a schematic diagram of a data acquisition device provided in an embodiment of this application. Referring to Figure 10, the data acquisition device includes a receiving module 1001 and an acquisition module 1002. Wherein:
[0209] The receiving module 1001 is used to execute S603 shown in FIG6 or S703 shown in FIG7.
[0210] The acquisition module 1002 is used to execute S604 shown in Figure 6 above.
[0211] In one possible implementation, the acquisition module 1002 includes: a detection submodule for executing S704 shown in FIG7 above; and an acquisition submodule for executing S705 shown in FIG7 above.
[0212] In one possible implementation, the detection submodule is used to execute the anomaly detection process shown in steps one to four of S704 in Figure 7.
[0213] In one possible implementation, the acquisition submodule is used to execute the process shown in Figure 7 above, S705, of acquiring the user face document and signaling face document of the abnormal network object by sending a document acquisition request.
[0214] In one possible implementation, the device further includes an execution module for executing the process of stopping the acquisition of user face documents and signaling face documents of abnormal network objects in S707 shown in FIG7.
[0215] In one possible implementation, the detection submodule is also used to perform the process of determining whether the abnormal network object has returned to normal in S706 shown in FIG7.
[0216] In one possible implementation, the detection submodule is also used to perform the periodic anomaly detection process shown in S704 of FIG7 above.
[0217] For example, Figure 11 is a schematic diagram of another data acquisition device provided in an embodiment of this application. Referring to Figure 11, the data acquisition device includes an acquisition module 1101 and a transmission module 1102. Wherein:
[0218] The acquisition module 1101 is used to execute S601 shown in Figure 6 or S701 shown in Figure 7.
[0219] The sending module 1102 is used to execute S602 shown in FIG6 or S702 shown in FIG7.
[0220] In one possible implementation, the sending module 1102 is also used to perform the process of sending user face documents and signaling face documents of abnormal network objects in S705 shown in FIG7.
[0221] For a detailed description of the above-mentioned optional methods, please refer to the foregoing method embodiments, which will not be repeated here. Furthermore, the explanation of any of the data acquisition devices provided above and the description of their beneficial effects can be found in the corresponding method embodiments described above, and will not be repeated here.
[0222] As an example, referring to FIG5, some or all of the functions implemented in the receiving module 1001 and the acquiring module 1002 in the data acquisition device shown in FIG10, and the acquiring module 1101 and the sending module 1102 in the data acquisition device shown in FIG11 can be implemented by the processor 501 in FIG5 executing the computer execution instructions in the memory 502 in FIG5.
[0223] In this embodiment, the data acquisition device is presented as an integrated set of functional modules. Here, "module" can refer to a specific ASIC, circuitry, a processor and memory executing one or more software or firmware programs, integrated logic circuitry, and / or other devices that can provide the aforementioned functions. In a simplified embodiment, those skilled in the art will recognize that the data acquisition device can take the form of a server or probe device as shown in Figure 5.
[0224] For example, the processor 501 in the server or probe device shown in Figure 5 can call the computer execution instructions stored in the memory 502 to cause the server or probe device to execute the data acquisition method in the above method embodiment.
[0225] Specifically, the functions / implementation processes of the receiving module 1001 and the acquisition module 1002 in the data acquisition device shown in Figure 10, and the acquisition module 1101 and the sending module 1102 in the data acquisition device shown in Figure 11, can be implemented by the processor 501 in the server or probe device shown in Figure 5 calling the computer execution instructions stored in the memory 502.
[0226] Since the data acquisition device provided in this application embodiment can execute the above data acquisition method, the technical effects it can obtain can be referred to the above method embodiment, and will not be repeated here.
[0227] It should be understood that one or more of the above modules or units can be implemented by software, hardware, or a combination of both. When any of the above modules or units are implemented by software, the software exists as computer program instructions and is stored in memory. The processor can be used to execute the program instructions and implement the above method flow. The processor can be built into a SoC (System-on-a-Chip) or ASIC, or it can be a separate semiconductor chip. In addition to the core that executes software instructions for computation or processing, the processor may further include necessary hardware accelerators, such as field-programmable gate arrays (FPGAs), PLDs (Programmable Logic Devices), or logic circuits that implement dedicated logic operations.
[0228] When the above modules or units are implemented in hardware, the hardware can be any one or any combination of a CPU, microprocessor, digital signal processing (DSP) chip, microcontroller unit (MCU), artificial intelligence processor, ASIC, SoC, FPGA, PLD, application-specific digital circuit, hardware accelerator, or non-integrated discrete device, which can run the necessary software or perform the above method flow independently of software.
[0229] Optionally, embodiments of this application also provide a server (e.g., the server may be a chip or a chip system), the server including a processor for implementing the methods executed by the server in any of the above method embodiments. In one possible design, the server further includes a memory. The memory is used to store necessary program instructions and data, and the processor can call the program code stored in the memory to instruct the server to execute the methods in any of the above method embodiments. Of course, the memory may not be present in the server. When the server is a chip system, it may be composed of chips or may include chips and other discrete devices; embodiments of this application do not specifically limit this.
[0230] Optionally, embodiments of this application also provide a probe device (e.g., the probe device may be a chip or a chip system), the probe device including a processor for implementing the method executed by the probe device in any of the above method embodiments. In one possible design, the probe device further includes a memory. The memory is used to store necessary program instructions and data, and the processor can call the program code stored in the memory to instruct the probe device to execute the method in any of the above method embodiments. Of course, the memory may not be present in the probe device. When the probe device is a chip system, it may be composed of chips or may include chips and other discrete devices; embodiments of this application do not specifically limit this.
[0231] This application also provides a computer-readable storage medium storing computer-executable instructions. When the computer-executable instructions are executed on a server, the server executes the method performed by any of the data acquisition devices provided above. When the computer-executable instructions are executed on a probe device, the probe device executes the method performed by any of the data acquisition devices provided above.
[0232] For explanations of the relevant content and descriptions of the beneficial effects in any of the computer-readable storage media provided above, please refer to the corresponding embodiments described above, which will not be repeated here.
[0233] This application also provides a chip. This chip integrates a control circuit for implementing the functions of the aforementioned data acquisition device and one or more ports. Optionally, the functions supported by this chip can be referred to above, and will not be repeated here. Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by a program instructing related hardware. This program can be stored in a computer-readable storage medium. The aforementioned storage medium can be a read-only memory, random access memory, etc. The aforementioned processing unit or processor can be a central processing unit, a general-purpose processor, an application-specific integrated circuit (ASIC), a microprocessor (digital signal processor, DSP), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof.
[0234] This application also provides a computer program product containing computer-executable instructions. When these computer-executable instructions are executed on a server, the server performs any of the methods described in the above embodiments. When these computer-executable instructions are executed on a probe device, the probe device performs any of the methods described in the above embodiments. The computer program product includes one or more computer-executable instructions. When the computer-executable instructions are loaded and executed on the server or probe device, all or part of the flow or function according to the embodiments of this application is generated. The server may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device.
[0235] Computer-executable instructions can be stored in or transmitted from one computer-readable storage medium to another. For example, computer-executable instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. A computer-readable storage medium can be any available medium that a server can access, or it can contain one or more data storage devices such as servers or data centers that can be integrated with media. Available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state disks (SSDs)).
[0236] It should be noted that the devices for storing computer instructions or computer programs provided in the embodiments of this application, such as but not limited to the memory, computer-readable storage medium and communication chip, are all non-transitory.
[0237] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software programs, implementation can be, in whole or in part, in the form of a computer program product.
[0238] Although this application has been described herein in conjunction with various embodiments, those skilled in the art, by reviewing the accompanying drawings, the disclosure, and the appended claims, will understand and implement other variations of the disclosed embodiments in carrying out the claimed application. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple instances. A single processor or other unit can implement several functions listed in the claims. While different dependent claims may recite certain measures, this does not mean that these measures cannot be combined to produce good results.
[0239] Although this application has been described in conjunction with specific features and embodiments, it is obvious that various modifications and combinations can be made thereto without departing from the spirit and scope of this application. Accordingly, this specification and drawings are merely exemplary illustrations of this application as defined by the appended claims, and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from the spirit and scope of this application. Thus, if such modifications and modifications of this application fall within the scope of the claims of this application and their equivalents, this application is also intended to include such modifications and modifications.
Claims
1. A data acquisition method, characterized by, Applied to a server, comprising: receiving a communication service bill from a probe device, the communication service bill comprising a time slice bill, the time slice bill being a bill obtained by counting user plane bills and signaling plane bills in a first time period as a statistical unit; based on the communication service bill, obtaining user plane bills and signaling plane bills of a target network object from the probe device, the target network object being a network object to be processed.
2. The method of claim 1, wherein, The target network object is an abnormal network object; the communication service bill further comprises a signaling plane abnormal bill, the signaling plane abnormal bill being a signaling plane bill indicating communication failure; The method further comprises: based on the communication service bill, performing abnormal detection on network objects in a communication process to obtain the abnormal network object; obtaining user plane bills and signaling plane bills of the abnormal network object from the probe device.
3. The method of claim 2, wherein, The method further comprises: based on the communication service bill, determining the index growth rate of each network object under different network indexes, the index growth rate being used to represent the growth of the network index value in the current time period compared with the network index value in the past time period; for the positive network index of the network object, if the index growth rate of the positive network index is less than or equal to a first preset growth rate, it is determined that the network object is abnormal; for the negative network index of the network object, if the index growth rate of the negative network index is greater than a second preset growth rate, it is determined that the network object is abnormal; if any of the positive network index and the negative network index of the network object indicates that the network object is abnormal, the network object is determined to be the abnormal network object.
4. The method of claim 2, wherein, The method further comprises: sending a bill acquisition request of the abnormal network object to the probe device, the bill acquisition request being used to request to acquire user plane bills and signaling plane bills of the abnormal network object; receiving user plane bills and signaling plane bills of the abnormal network object sent by the probe device in response to the bill acquisition request.
5. The method according to claim 3 or 4, characterized in that, The method further comprises: in response to the abnormal network object having recovered to normal, stopping acquiring user plane bills and signaling plane bills of the abnormal network object from the probe device.
6. The method of claim 5, wherein, The method further comprises: if the index growth rate of the positive network index of the abnormal network object is greater than the first preset growth rate within a preset time length, and the index growth rate of the negative network index of the abnormal network object is less than or equal to the second preset growth rate within the preset time length, it is determined that the abnormal network object has recovered to normal.
7. The method according to any one of claims 2 to 6, characterized in that, The abnormal detection on the network object in the communication process based on the communication service bill is performed to obtain the abnormal network object, and the abnormal detection on the network object in the communication process based on the communication service bill is performed every second time period to obtain the abnormal network object in the second time period. The application is applied to a probe device, and comprises:
8. A data acquisition method characterized by, Obtaining a communication service bill, wherein the communication service bill comprises a time slice bill, and the time slice bill is obtained by counting user plane bills and signaling plane bills in a first time period; Sending the communication service bill to a server, wherein the communication service bill is used to obtain user plane bills and signaling plane bills of a target network object from the probe device, and the target network object is a network object to be processed. The target network object is an abnormal network object, and the communication service bill further comprises a signaling plane abnormal bill, and the signaling plane abnormal bill is a signaling plane bill indicating a communication failure.
9. The method of claim 8, wherein, After the communication service bill is sent to the server, the method further comprises: In response to a bill obtaining request of an abnormal network object returned by the server based on the communication service bill, sending the user plane bills and the signaling plane bills of the abnormal network object to the server, wherein the bill obtaining request is used to request to obtain the user plane bills and the signaling plane bills of the abnormal network object. The application is applied to a probe device and a server, wherein 10. A data acquisition system characterized by, The probe device is used to obtain a communication service bill, wherein the communication service bill comprises a time slice bill, and the time slice bill is obtained by counting user plane bills and signaling plane bills in a first time period; and the probe device is used to send the communication service bill to the server; The server is used to receive the communication service bill from the probe device; and based on the communication service bill, the server is used to obtain user plane bills and signaling plane bills of a target network object from the probe device, wherein the target network object is a network object to be processed. The application is applied to a server, and comprises:
11. A data acquisition device, characterized by A receiving module is used to receive a communication service bill from a probe device, wherein the communication service bill comprises a time slice bill, and the time slice bill is obtained by counting user plane bills and signaling plane bills in a first time period; An obtaining module is further used to obtain user plane bills and signaling plane bills of a target network object from the probe device based on the communication service bill, wherein the target network object is a network object to be processed. The application is applied to a probe device, and comprises:
12. A data acquisition device, characterized by An obtaining module is used to obtain a communication service bill, wherein the communication service bill comprises a time slice bill, and the time slice bill is obtained by counting user plane bills and signaling plane bills in a first time period; A sending module is used to send the communication service bill to a server, wherein the communication service bill is used to obtain user plane bills and signaling plane bills of a target network object from the probe device, and the target network object is a network object to be processed. 13. A server, characterized by A computer program product comprising a memory and a processor connected thereto; the memory for storing computer-executable instructions; the processor for invoking the computer-executable instructions to perform the method of any of claims 1-7.
14. A probe device, characterized by A computer program product comprising a memory and a processor connected thereto; the memory for storing computer-executable instructions; the processor for invoking the computer-executable instructions to perform the method of any of claims 8-9.
15. A computer-readable storage medium, characterized in that, A computer program product comprising computer-executable instructions that, when run on a server, cause the server to perform the method of any of claims 1-7, and that, when run on a probe device, cause the probe device to perform the method of any of claims 8-9.
16. A computer program product, characterised in that, A computer program product comprising computer-executable instructions that, when run on a server, cause the server to perform the method of any of claims 1-7, and that, when run on a probe device, cause the probe device to perform the method of any of claims 8-9.
Citation Information
Patent Citations
Network resource optimizing method and device
CN103731859A
Data management method and device and computer readable storage medium
CN110121190A
DPI data acquisition method and related device
CN114339719A
Service quality management method and device
CN118118946A
Method and system for time-sliced aggregation of data
US20080222653A1