Failure site identification device and failure site identification method

The fault location identification device in multi-layer networks addresses the challenge of slow failure location identification by analyzing network configurations and historical data to rapidly pinpoint fault locations and affected ranges, reducing maintenance effort.

WO2026053378A1PCT designated stage Publication Date: 2026-03-12NT T INC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-06
Publication Date
2026-03-12

AI Technical Summary

Technical Problem

Existing network management technologies are unable to quickly identify the failure location in large-scale multi-layer networks, requiring manual analysis and significant maintenance effort when network failures occur, as they only grasp the impact of failures without pinpointing the fault location.

Method used

A fault location identification device that collects network configuration, log, and alarm information, analyzes current and historical data to identify a suspected failure location, and uses network resource management technology to determine the affected range, thereby reducing the time and effort required to pinpoint faults.

Benefits of technology

The device accelerates the identification of suspected failure locations and reduces maintenance workload by analyzing network configurations and historical data to quickly pinpoint fault locations and affected ranges in multi-layer networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024032060_12032026_PF_FP_ABST
    Figure JP2024032060_12032026_PF_FP_ABST
Patent Text Reader

Abstract

A failure site identification device (1) comprises: a network configuration information collection unit (111) that collects network connection information (110) which includes physical connection information, logical connection information, and layer-to-layer management information, device configuration information (120), and failure history information (130); a log / alarm information acquisition unit (112) that acquires log information and alarm information; and a suspected site identification unit (113) that acquires error information and alarm information as current failure detection information, that extracts, as a suspected section, a common section among sections in failure, that retrieves past failure detection information and a failure occurrence section which are common to the current failure detection information and the extracted suspected section with reference to failure history information (130), and that identifies the retrieved failure occurrence section as a current suspected site.
Need to check novelty before this filing date? Find Prior Art

Description

Fault location identification device and fault location identification method

[0001] The present invention relates to a failure location identification device and a failure location identification method for identifying a suspected location when a failure occurs in a network made up of multiple devices.

[0002] Telecommunications carriers' network services are provided by multi-layer networks that combine different communication protocols, such as optical transport networks and IP networks. Conventionally, these networks have been managed by individual systems, so the impact of a network failure in one layer on network services in other layers had to be analyzed manually.

[0003] In response to this, a technology has been developed that allows for the rapid understanding of service impacts caused by communication failures in a multi-network that combines a number of communication technologies by centrally managing multiple networks (see Non-Patent Document 1).

[0004] Kazuaki Akashi et al., "Early Understanding of Network Status in the Event of a Large-Scale System Failure," NTT Technical Journal, October 2023, pp. 11-12, Internet <URL: https: / / journal.ntt.co.jp / article / 23442>

[0005] The network resource management technology described in Non-Patent Document 1 expresses network information, such as information transfer termination points and paths, in a layer-independent, general-purpose data format, enabling centralized management of complex multi-layer networks that combine multiple communication protocols and rapid understanding of the impact on services caused by failures.

[0006] However, the above-mentioned network resource management technology is only capable of grasping the extent of the impact on communication services based on the identified failure location (for example, a communication building or cable damaged by an earthquake, etc.), and is not capable of identifying the failure location itself. When a failure occurs in a large-scale network, alarms and the like are issued from many devices, and it takes time to identify the location where the failure (failure) is suspected (hereinafter referred to as the "suspect location"), requiring a lot of work from maintenance personnel.

[0007] The present invention was made in consideration of these points, and aims to shorten the time it takes to identify suspected faults even when a failure occurs in a large-scale network, and to reduce the workload of maintenance personnel.

[0008] The fault location estimation device according to the present invention is a fault location identification device for identifying a fault location in a multi-layer network, and includes a network configuration information collection unit that collects network connection information including physical connection information indicating connection information between devices as physical resources, logical connection information indicating connection information between devices for each layer as logical resources, and inter-layer management information indicating connection relationships between layers of network resources, device configuration information indicating the device configuration of each device constituting the multi-layer network, and fault detection information indicating the state of past fault detection, and fault location information indicating the fault section and the fault content; The network is characterized by comprising a log / alarm information acquisition unit that acquires log information from each device and acquires alarm information from a device in which a failure has been detected, and a suspected location identification unit that, when a failure occurs in the multi-layer network, acquires the error information and alarm information obtained by analyzing the log information as current failure detection information, extracts a common section among the sections affected by the failure indicated in the current failure detection information as a suspected section, searches for past failure detection information and failure-occurring sections that are common to the current failure detection information and the extracted suspected section by referring to the failure history information, and identifies the searched failure-occurring section and failure content as the suspected section of the current failure.

[0009] According to the present invention, even when a failure occurs in a large-scale network, it is possible to shorten the time required to identify a suspected location and reduce the workload of maintenance personnel.

[0010] FIG. 1 is a diagram showing the overall configuration of a communication network system including a failure point locating device according to an embodiment of the present invention. FIG. 2 is a functional block diagram showing the configuration of the failure point locating device according to an embodiment of the present invention. FIG. 3 is a diagram showing a specific example of suspected point locating processing by a suspected point locating unit of the failure point locating device according to an embodiment of the present invention. FIG. 4 is a diagram for explaining failure history information according to an embodiment of the present invention. FIG. 5 is a diagram for explaining network resource management technology in multi-layer. FIG. 6 is a flowchart showing the flow of processing executed by the failure point locating device according to an embodiment of the present invention. FIG. 7 is a hardware configuration diagram showing an example of a computer that realizes the functions of the failure point locating device according to an embodiment of the present invention.

[0011] Next, an embodiment of the present invention (hereinafter referred to as "the present embodiment") will be described. Fig. 1 is a diagram showing the overall configuration of a communication network system 1000 including a fault location identification device 1 according to the present embodiment.

[0012] 1, the communication network system 1000 includes a communication network (multi-layer network 500) configured with multiple layers, and a fault location identification device 1 that monitors the multi-layer network 500 and identifies a suspected location of a fault. The multi-layer network 500 is configured, for example, with a transmission layer 520 consisting of multiple transmission devices 20 and an IP layer 530 consisting of multiple IP devices (IP routers) 30. However, as long as it is multi-layer, an Ether layer or the like consisting of multiple L2SWs (Layer 2 switches) or the like may be present between the transmission layer 520 and the IP layer 530, and a service layer or the like may be present as a layer above the IP layer 530.

[0013] The fault location identification device 1 is communicatively connected to each transmission device 20 constituting the transmission layer 520 and each IP device 30 constituting the IP layer 530, collects log information 50 from all devices, and acquires alarm information 55 when each device detects a fault (malfunction). The fault location identification device 1 also collects in advance connection information (hereinafter referred to as "NW connection information 110") of the multi-layer network 500, device configuration information 120, and fault history information 130. The NW connection information 110 stores connection information between devices in each layer, as well as the relationship between the lower layer (transmission layer 520) and the upper layer (IP layer 530). The device configuration information 120 stores information such as the package (PKG) and IF accommodation (opposing device) installed in each device. The fault history information 130 stores events identified as the cause of a fault based on past log information 50 and alarm information 55 from the devices, and the location of the fault. When the fault location identification device 1 acquires log information 50 indicating the occurrence of a fault or alarm information 55 from the devices in each layer, it quickly identifies the suspected location of the fault using previously collected NW connection information (network connection information) 110, device configuration information 120, and fault history information 130. Furthermore, the fault location identification device 1 makes it possible to accurately identify the "fault range" affected by the fault based on the identified suspected location.

[0014] The fault location identification device 1 according to this embodiment simplifies the identification of a suspected section by extracting errors from a multi-layer network configuration (physical layer, transmission layer, IP layer, etc.) including a physical layer configured with physical resources, as described below. Furthermore, even if, for example, no alarm information 55 is detected in a transmission device 20 in a suspected section, the fault location identification device 1 can identify the section from which an error was extracted as a suspected section and identify the suspected section based on fault history information 130 that stores past similar events. Therefore, even when a failure occurs in a large-scale network, the time required to identify the suspected section can be shortened and the workload of maintenance personnel can be reduced. The fault location identification device 1 will be described in detail below.

[0015] 2 is a functional block diagram showing the configuration of the failure point identification device 1 according to this embodiment. As shown in FIG. 2, the failure point identification device 1 includes a control unit 11, an input / output unit 12, and a storage unit 13.

[0016] The input / output unit 12 inputs and outputs information to and from each of the plurality of transmission devices 20 and the plurality of IP devices 30, which are devices that make up the multi-layer network 500, and to and from other external devices (for example, a management device that manages the entire communication network system 1000). The input / output unit 12 is composed of a communication interface that transmits and receives information via a communication line, and an input / output interface that inputs and outputs information to and from an input device such as a keyboard and an output device such as a monitor, both of which are not shown.

[0017] The storage unit 13 is configured by a hard disk, a flash memory, a RAM (Random Access Memory), etc. The storage unit 13 stores the above-mentioned NW connection information 110, device configuration information 120, failure history information 130, etc. The NW connection information 110, device configuration information 120, and failure history information 130 may be collectively referred to as "NW configuration information 100."

[0018] The NW connection information (network connection information) 110 is composed of physical connection information, which is connection information for physical resources (physical resources), and logical connection information, which is connection information for logical resources (logical resources). The physical connection information stores connection information between devices (transmission devices 20, IP devices 30, etc.) as physical resources in the physical layer. Specifically, information on adjacent devices (adjacent device information) is stored along with information on connection interfaces. The logical connection information stores connection information between logical resources (transmission device 20 in the transmission layer 520, IP device 30 in the IP layer 530) for each layer (transmission layer 520, IP layer 530). Specifically, information (adjacent connection information) on adjacent logical resources (transmission devices 20, IP devices 30) in each layer is stored along with information on connection protocols and connection logical interfaces. In addition, this NW connection information 110 stores information for centrally managing network resources such as the hierarchical relationships between layers in physical resources and logical resources and the termination points of transfer paths, as shown in the network resource management technology described in the above-mentioned non-patent document 1 (hereinafter referred to as "inter-layer management information") (details will be described later).

[0019] The device configuration information 120 stores physical device configuration information and logical / physical interface information that indicate the device configuration of each device (transmission device 20, IP device 30, etc.) that constitutes the network. The physical device configuration information includes information such as the model, installed package, interface type, etc., as well as information on the OS used, firmware, etc. The logical / physical interface information includes information on the interface number of the interface provided in the physical resource (physical device), logical interface physical accommodation location information that indicates the accommodation location of the logical interface, etc.

[0020] The fault history information 130 stores fault detection information, which indicates the state of past fault detection, and information on the location of the fault (the section where the fault occurred and the details of the fault) identified as a result of the fault detection. The fault detection information includes error information (e.g., routing protocol down, interface down) in each layer detected from the log information 50, etc., at the time a fault occurred in the past, and alarm information issued from each device (transmission device 20, IP device 30, etc.).

[0021] The control unit 11 is responsible for all the processing performed by the fault location identification device 1, and is composed of a network configuration information collection unit (network configuration information collection unit) 111, a log / alarm information acquisition unit 112, a suspected location identification unit 113, and a fault range identification unit 114.

[0022] The NW configuration information collection unit 111 collects NW configuration information 100 about the network to be monitored (the multi-layer network 500) from an external device (such as a management device that manages the entire communication network system 1000), and stores the collected information in the storage unit 13. Specifically, the NW configuration information collection unit 111 collects NW connection information 110, device configuration information 120, and failure history information 130.

[0023] The NW configuration information collector 111 acquires the above-mentioned NW connection information 110, device configuration information 120, and failure history information 130 as the NW configuration information 100 before starting the process of identifying a suspected failure location.

[0024] The log / alarm information acquisition unit 112 acquires log information 50 from devices (such as transmission devices 20 and IP devices 30) in each layer that constitute the network, and also acquires alarm information 55 issued by the devices in each layer. The log / alarm information acquisition unit 112 may acquire the log information 50 and alarm information 55 directly from each device, or may acquire them via a management device (not shown) for the entire network. Furthermore, when acquiring the log information 50, the log / alarm information acquisition unit 112 may extract error information by analyzing the acquired log itself, or may receive error information obtained as a result of analyzing the logs acquired from each device by a log analysis device (not shown) or the like. In this embodiment, the log / alarm information acquisition unit 112 acquires log information 50 from each device and extracts error information by analyzing it itself.

[0025] The suspected portion identification unit 113 acquires, as fault detection information indicating the current state of fault detection, error information obtained by analyzing the log information 50 obtained from the devices in each layer and alarm information 55 from the devices in each layer, etc. Based on the fault detection information, the suspected portion identification unit 113 extracts, as a suspected portion, a common section from among sections affected by faults indicated by the error information and alarm information 55. Then, based on the current fault detection information and information on the suspected portion, the suspected portion identification unit 113 references fault history information 130 in the storage unit 13 and searches for history information common to the fault detection information and fault-occurrence sections in past events, thereby identifying the fault occurrence location (fault occurrence section and fault details) indicated in the past fault history information 130 as the suspected portion of the current fault (suspected section and fault details).

[0026] FIG. 3 is a diagram showing a specific example of the suspected part identification process performed by the suspected part identification unit 113. Here, as shown in FIG. 3, it is assumed that, in the IP layer 530 (FIG. 1), the occurrence of a routing protocol down error (hereinafter referred to as "protocol down") has been detected based on log information 50 or the like between IP devices "A" and "B" and between IP devices "C" and "D." Furthermore, alarm information 55 such as interface down from each IP device 30 has not been detected. Meanwhile, in the transmission layer 520 (FIG. 1), it is assumed that no error information has been extracted from the log information 50 of each transmission device 20, and no alarm information 55 has been detected. The above is the current fault detection information.

[0027] Based on this current failure detection information, the suspected section identification unit 113 extracts as a suspected section the section where the failure was detected, that is, the section between transmission devices "2" and "3", which is a common section between IP devices "A" and "B" and between IP devices "C" and "D" (symbol a in FIG. 3).The suspected section identification unit 113 then references the failure history information 130 to identify the suspected section (suspected section and failure details).

[0028] Here, as an example, it is assumed that the failure history information 130 stores the history information shown in Fig. 4. In the case of a network configuration similar to that shown in Fig. 3, that is, in the case where IP devices "A" to "D" and transmission devices "1" to "10" are arranged in the network, the following failure history information 130 is stored as information indicating past failure detection information and the location of the failure (the section where the failure occurred and the details of the failure).

[0029] <History information 1> Protocol down was detected between IP devices "A" and "B" and between IP devices "C" and "D". <History information 2-1> No alarms (alarm information 55) were detected simultaneously from the devices in each section [a] to [e] on the route between IP devices "A" and "B". <History information 2-2> No alarms (alarm information 55) were detected simultaneously from the devices in each section [f] to [h] on the route between IP devices "C" and "D". <History information 3> A repair history exists when a protocol down was detected in an IP device and no alarms (alarm information 55) were detected on each section. At this time, the failure was resolved by performing a "PKG (package) replacement" on transmission device 20 in the common transmission section "2"-"3".

[0030] Based on the acquired current failure detection information and information on the suspected section, the suspected section identification unit 113 checks each item of the history information in order to determine whether the information matches the contents of the above-mentioned failure history information 130. The suspected section identification unit 113 then detects matching history information in the past failure history information 130, namely, that a failure occurred in a similar location (the failure-occurring section) and that the failure content at that time was a "PKG (package) replacement" of the transmission device 20. As a result, the suspected section identification unit 113 identifies the current failure as a similar location, designating transmission section "2"-"3" as the suspected section, and identifying a failure in the containing PKG (package) of the transmission device 20 (transmission device "2" and / or "3") as the failure content. In this way, the suspected section identification unit 113 can identify the suspected section (suspected section and failure content) by referring to the failure history information 130 using the acquired current failure detection information and suspected section.

[0031] The fault range identification unit 114 identifies a "fault range," which is a range that will affect the network if a failure occurs, based on the information about the suspected location identified by the suspected location identification unit 113. As an example, the fault range identification unit 114 will be described as identifying the fault range using the network resource management technology described in Non-Patent Document 1.

[0032] The network resource management technology described in Non-Patent Document 1 expresses network information, such as information transfer termination points and paths, in a layer-independent, general-purpose data format. Specifically, as shown in FIG. 5 , physical resources are composed of communication devices such as transmission devices 20 and IP devices 30, and optical fibers 4, and the connection relationships of each resource in the physical layer are defined. Furthermore, for logical resources, entities (entities) are defined to indicate the connection relationships of logical resources, such as information transfer termination points (TPEs) (circles indicated by symbols α and the like in FIG. 5 ), areas (transferable areas) in each layer where information transfer is possible (NFDs) (symbol β in FIG. 5 ), and information transfer paths (FREs) (symbol γ: forwarding paths in FIG. 5 ). These entities also hold information on the hierarchical relationships between layers, as shown in FIG. 5 . By using this network resource management technology, when the fault scope identification unit 114 identifies a suspected location, it is able to identify the scope of impact across layers from the suspected location by tracing the relationships between entities (termination points, forwarding paths, etc.) and their layers.

[0033] <<Processing of the Fault Location Locating Device>> Next, a description will be given of the processing executed by the fault location locating device 1. Fig. 6 is a flowchart showing the flow of processing executed by the fault location locating device 1 according to this embodiment.

[0034] First, the NW configuration information collection unit 111 of the fault point identification device 1 collects NW connection information 110, device configuration information 120, and fault history information 130 as NW configuration information 100 for the network to be monitored (step S1), and stores them in the memory unit 13.

[0035] Next, in step S2, the log / alarm information acquisition unit 112 of the fault point identification device 1 acquires and analyzes log information 50 from devices of each layer that make up the network (such as the transmission device 20 and the IP device 30), thereby extracting error information. The log / alarm information acquisition unit 112 also acquires alarm information 55 from the devices of each layer.

[0036] Next, the suspected part identifying unit 113 of the failure part identifying device 1 executes suspected part identifying processing using the error information and alarm information 55 obtained by analyzing the log information 50. The suspected part identifying unit 113 may be triggered to execute the suspected part identifying processing when a threshold or more of error information is extracted or alarm information 55 is acquired within a predetermined time period, or the suspected part identifying unit 113 may be configured to execute processing when a specific type of error information or a specific type of alarm information is extracted. Specifically, the suspected part identifying unit 113 executes the following processing.

[0037] The suspected part identification unit 113 acquires the error information and alarm information 55 as current fault detection information, and extracts common sections from the faulty sections based on the fault detection information as suspect sections (step S3).

[0038] Then, based on the fault detection information and the information on the suspected section, the suspected area identification unit 113 refers to the fault history information 130 and searches for history information common to the fault detection information and the suspected section in past events, thereby identifying the fault location (fault section and fault content) indicated in the past fault history information 130 as the suspected area (suspected section and fault content) for the current fault (step S4).

[0039] Next, the fault range identification unit 114 of the fault location identification device 1 uses existing network resource management technology (Non-Patent Document 1) based on the information on the suspected location identified by the suspected location identification unit 113 to identify the ``fault range,'' which is the range that will affect the network if a fault occurs (step S5).

[0040] In this way, the fault location identification device 1 simplifies the identification of suspected sections by using error information and alarm information 55 obtained from the network configuration of each layer (physical layer, transmission layer, IP layer, etc.) configured by each device. Furthermore, the fault location identification device 1 can identify suspected sections by referring to fault history information 130 that stores past similar events based on the current fault detection information and suspected sections. Therefore, even when a fault occurs in a large-scale network, the fault location identification device 1 can shorten the time it takes to identify suspected sections and reduce the workload of maintenance personnel.

[0041] <Hardware Configuration> The failure point identification device 1 according to this embodiment is realized by, for example, a computer 900 having a configuration as shown in Fig. 7. Fig. 7 is a hardware configuration diagram showing an example of the computer 900 that realizes the functions of the failure point identification device 1 according to this embodiment. The computer 900 has a CPU 901, a ROM (Read Only Memory) 902, a RAM 903, an HDD (Hard Disk Drive) 904, an input / output I / F (Interface) 905, a communication I / F 906, and a media I / F 907.

[0042] The CPU 901 operates based on a program stored in the ROM 902 or the HDD 904, and is controlled by the control unit 11 (FIG. 2). The ROM 902 stores a boot program executed by the CPU 901 when the computer 900 is started up, programs related to the hardware of the computer 900, and the like.

[0043] The CPU 901 controls an input device 910 such as a mouse or keyboard, and an output device 911 such as a display or printer, via an input / output I / F 905. The CPU 901 acquires data from the input device 910 via the input / output I / F 905, and outputs generated data to the output device 911. Note that a GPU (Graphics Processing Unit) or the like may be used as a processor together with the CPU 901.

[0044] The HDD 904 stores programs executed by the CPU 901 and data used by the programs. The communication I / F 906 receives data from other devices via a communication network (e.g., NW (Network) 920) and outputs the data to the CPU 901, and also transmits data generated by the CPU 901 to other devices via the communication network.

[0045] The media I / F 907 reads a program or data stored in the recording medium 912 and outputs it to the CPU 901 via the RAM 903. The CPU 901 loads a program related to a target process from the recording medium 912 onto the RAM 903 via the media I / F 907, and executes the loaded program. The recording medium 912 is an optical recording medium such as a DVD (Digital Versatile Disc) or a PD (Phase Change Rewritable Disc), a magneto-optical recording medium such as an MO (Magneto Optical Disc), a magnetic recording medium, a semiconductor memory, or the like.

[0046] For example, when the computer 900 functions as the fault location identification device 1 of the present invention, the CPU 901 of the computer 900 executes a program loaded onto the RAM 903 to realize the functions of the control unit 11 ( FIG. 2 ). Furthermore, the data in the RAM 903 is stored in the HDD 904. The CPU 901 reads and executes a program related to a target process from the recording medium 912. Alternatively, the CPU 901 may read a program related to a target process from another device via a communication network (NW 920).

[0047] <Effects> The effects of the fault location identification device etc. according to the present invention will be described below. The fault location identification device 1 according to the present invention is a fault location identification device 1 that identifies a fault occurrence location in a multi-layer network 500, and includes a network configuration information collection unit 111 that collects NW connection information 110 including physical connection information indicating connection information between devices as physical resources, logical connection information indicating connection information between devices for each layer as logical resources, and inter-layer management information indicating connection relationships between layers of network resources, device configuration information 120 indicating the device configuration of each device that constitutes the multi-layer network 500, and fault history information 130 that stores fault detection information indicating the state of past fault detection and fault occurrence locations indicating fault occurrence sections and fault contents, and a network configuration information collection unit 111 that collects the multi-layer network 500. The network is equipped with a log / alarm information acquisition unit (112) that acquires log information from each of the devices in each constituent layer and acquires alarm information from a device in which a fault has been detected, and a suspected part identification unit (113) that, when a fault occurs in the multi-layer network (500), acquires error information and alarm information (55) obtained by analyzing the log information (50) as current fault detection information, extracts a common section from the sections affected by the fault indicated in the current fault detection information as a suspected section, searches for past fault detection information and fault-occurring sections that are common to the current fault detection information and the extracted suspected section by referring to the fault history information (130), and identifies the searched fault-occurring section and fault content as the suspected part of the current fault.

[0048] In this way, the fault location identification device 1 can simplify and realize identification of the current suspected section by searching for current fault detection information obtained from the log information 50 and the alarm information 55, and past fault detection information and fault-occurring sections common to the suspected section, using the fault history information 130. For example, even if alarm information 55 is not detected in the transmission device 20 in the suspected section, the suspected section can be identified as a failure in the package containing the transmission device 20 in less time than before, based on the fault history information 130 that stores past similar events. Therefore, the fault location identification device 1 can reduce the workload of maintenance personnel.

[0049] In addition, the fault location identification device 1 further includes a fault range identification unit that identifies the fault range, which indicates the range affected by the fault, based on the identified current suspect location and using network connection information including inter-layer management information.

[0050] In this way, the failure point identification device 1 can easily and accurately identify the extent of the influence of the failure in the multi-layer network 500 based on the identified suspected point.

[0051] The present invention is not limited to the above-described embodiments, and many modifications can be made by a person having ordinary skill in the art within the technical concept of the present invention.

[0052] REFERENCE SIGNS LIST 1 Fault location identification device 11 Control unit 12 Input / output unit 13 Storage unit 50 Log information 55 Alarm information 100 NW configuration information (network configuration information) 110 NW connection information (network connection information) 111 NW configuration information collection unit (network configuration information collection unit) 112 Log / alarm information acquisition unit 113 Suspected location identification unit 114 Fault range identification unit 120 Device configuration information 130 Fault history information 500 Multi-layer network 520 Transmission layer 530 IP layer 1000 Communication network system

Claims

1. A fault location identification device for identifying the location of a fault in a multi-layer network, comprising: network connection information including physical connection information indicating connection information between devices as physical resources, logical connection information indicating connection information between devices for each layer as logical resources, and inter-layer management information indicating the connection relationships between layers of network resources; device configuration information indicating the device configuration of each device constituting the multi-layer network; and fault detection information indicating the state of past fault detection and fault location information indicating the section where the fault occurred and the type of fault; and a log / alarm information acquisition unit for acquiring log information from each device in each layer constituting the multi-layer network and acquiring alarm information from a device in which a fault has been detected. a suspected part identification unit that, when a failure occurs in the multi-layer network, acquires the error information and the alarm information obtained by analyzing the log information as current failure detection information, extracts a common section among the sections affected by the failure indicated in the current failure detection information as a suspected section, searches for past failure detection information and failed sections that are common to the current failure detection information and the extracted suspected section by referring to the failure history information, and identifies the searched failed section and failure details as a suspected part of the current failure.

2. The fault location identification device according to claim 1, further comprising a fault range identification unit that identifies a fault range indicating the range of the impact of the fault using network connection information including the inter-layer management information based on the identified current suspect location.

3. A fault location identification method of a fault location identification device that identifies a fault location in a multi-layer network, comprising the steps of: collecting network connection information including physical connection information indicating connection information between devices as physical resources, logical connection information indicating connection information between devices for each layer as logical resources, and inter-layer management information indicating connection relationships between layers of network resources; device configuration information indicating the device configuration of each device that constitutes the multi-layer network; and fault detection information indicating past fault detection states and fault location information that indicates the faulty section and the fault content; and acquiring log information from each device in each layer that constitutes the multi-layer network, and acquiring alarm information from a device in which a fault has been detected. When a failure occurs in the multi-layer network, the error information and the alarm information obtained by analyzing the log information are acquired as current failure detection information, a common section among the sections affected by the failure indicated in the current failure detection information is extracted as a suspected section, past failure detection information and a failure section that is common to the current failure detection information and the extracted suspected section are searched for by referring to the failure history information, and the searched failure section and failure content are identified as a suspected section of the current failure.

4. The fault location identification method described in claim 3, characterized in that the fault location identification device further executes a step of identifying a fault range indicating the range affected by the fault using network connection information including the inter-layer management information based on the identified current suspect location.

Citation Information

Patent Citations

  • Information providing system, information providing method, and program

    JP2023136144A

  • Network management device, method, and program

    WO2020080492A1