Information processing device and method

WO2026176601A1PCT designated stage Publication Date: 2026-08-27NT T INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/005930
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2026-08-27

Smart Images

  • Figure JP2025005930_27082026_PF_FP_ABST
    Figure JP2025005930_27082026_PF_FP_ABST
Patent Text Reader

Abstract

An information processing device according to one embodiment of the present invention comprises: a creation unit that creates information that is a combination of alarm information already generated within a prescribed period in a communication network and alarm information generated at a location adjacent to a location related to the generation of the abovementioned alarm information; and an unknown inference unit that infers that an unknown alarm has been generated from the communication network when information, in which alarm information newly generated in the communication network has been associated with the alarm information generated at a location having an adjacent relationship with the location related to the generation of the abovementioned alarm information, is not included in the information created by the creation unit.
Need to check novelty before this filing date? Find Prior Art

Description

Information Processing Apparatus and Method

[0001] Embodiments of the present invention relate to an information processing apparatus and method.

[0002] In recent years, as the social importance of network services provided by telecommunications carriers has increased, the number of major accidents has tended to increase along with the sophistication and complexity of communication technologies and equipment due to service diversification. The maintenance and management of networks by telecommunications carriers has become increasingly important.

[0003] When servers and transmission devices on the network necessary for providing services become unavailable due to a failure, alarms indicating abnormalities are issued from various locations such as network devices and servers providing the services.

[0004] The generated alarms are collected by a monitoring system, and maintenance workers need to analyze where and what kind of failure has occurred using the collected alarms and the network configuration, etc., and perform recovery measures for the failure.

[0005] However, various alarms are generated depending on the cause of the failure and the type of the failed device, and the number of devices generating alarms and the types of alarms also change depending on the network configuration. To grasp such characteristics of alarm generation and identify the failure location and cause, a vast amount of know-how is required. Even for an expert, it is difficult to instantly identify the cause of the failure, etc. when a relatively large number of alarms are occurring. Therefore, it is effective to regularize the alarms generated by a failure and instantly identify the cause of the failure and the failure location when a new alarm occurs.

[0006] There is a technique for estimating the cause of a failure and the failure location, etc. from messages such as alarms generated due to the occurrence of a failure on the network. For example, as disclosed in Patent Document 1, rules with If conditions are learned from alarms generated in the time periods before and after the occurrence of a failure, and the ratio of the If conditions of the rules being satisfied for each suspected failure location, etc. is presented to an operator as an evaluation value to support the identification of the failure location and cause.

[0007] Japanese Patent No. 6637854

[0008] However, with the method described above, the fault location and cause for a newly occurring alarm are estimated based on the similarity of faults learned from previously occurring alarms. Therefore, it can be difficult to determine from the estimation results whether the fault is known or unknown. Furthermore, because the system is designed to operate under the assumption that a fault has occurred, even when it is unclear whether a fault has occurred, it outputs the closest known fault from the learned faults. This can lead to the problem of incorrectly concluding that a fault has occurred if the newly occurring alarm includes alarms common to both faulty and non-faulty situations.

[0009] In actual operation, if it is estimated that no failure has occurred, it is necessary to estimate that "no failure has occurred," and if there is a possibility that the failure that has occurred is not a known failure, it is necessary to estimate that "it is an unknown failure."

[0010] This invention was made in view of the above circumstances, and its purpose is to provide an information processing device and method that can appropriately estimate information related to alarms that occur in a communication network.

[0011] An information processing device according to one aspect of the present invention includes a creation unit that creates information which is a combination of alarm information that has already occurred in a communication network within a predetermined period and alarm information that has occurred in a location adjacent to the location where the alarm information occurred, and an unknown estimation unit that estimates that an unknown alarm has occurred in the communication network when information which is linked to newly occurred alarm information in the communication network and alarm information that has occurred in a location adjacent to the location where the alarm information occurred is not included in the information created by the creation unit.

[0012] An information processing method according to one aspect of the present invention is a method performed by an information processing device, comprising: a creation unit of the information processing device creating information which is a combination of alarm information that has already occurred in a communication network within a predetermined period and alarm information that has occurred at a location adjacent to the location where the alarm information occurred; and an unknown estimation unit of the information processing device estimating that an unknown alarm has occurred in the communication network when information linking newly occurred alarm information in the communication network and alarm information that has occurred at a location adjacent to the location where the alarm information occurred is not included in the information created by the creation unit.

[0013] According to the present invention, information related to alarms generated in a communication network can be appropriately estimated.

[0014] Figure 1 is a diagram showing an application example of an information processing device according to one embodiment of the present invention. Figure 2 is a diagram illustrating an example of the function of each part of the information processing device. Figure 3 is a diagram illustrating an example of the procedure for storing information in an existing occurrence pattern DB. Figure 4 is a diagram illustrating an example of the operation related to the estimation of the fault location. Figure 5 is a diagram showing a specific example of registering information in an existing occurrence pattern DB. Figure 6 is a diagram showing a modified example of the registered contents of the existing occurrence pattern DB. Figure 7 is a diagram showing a first example of estimating the fault location and alarms with unknown potential. Figure 8 is a diagram showing a second example of estimating the fault location and alarms with unknown potential. Figure 9 is a diagram showing a third example of estimating the fault location and alarms with unknown potential. Figure 10 is a block diagram showing an example of the hardware configuration of an information processing device according to one embodiment of the present invention.

[0015] Embodiments relating to this invention will be described below. Figure 1 is a diagram showing an example of application of an information processing device according to one embodiment of the present invention. As shown in Figure 1, the information processing device 100 according to one embodiment of the present invention has an existing occurrence pattern creation unit 10, a rule learning unit 20, an unknown failure probability estimation unit 30, a failure location estimation unit 40, and a storage unit 50.

[0016] The storage unit 50 includes an alarm DB (Database) 51, a network configuration DB 52, an existing occurrence pattern DB 53, and a rule DB 54.

[0017] Figure 2 is a diagram illustrating an example of the functions of each part of the information processing device. In this embodiment, in addition to learning rules used to estimate the nature of a failure, in this case the nature of a malfunction, the device also learns alarms that appear during normal operation separately from the learning of the said rules to respond to the detection of unknown malfunctions.

[0018] In this embodiment, alarms, including steady-state alarms, are managed by type, location, and combinations of simultaneously occurring alarms. This managed information is utilized during rule learning and fault estimation to appropriately output information regarding unlearned alarms or failures.

[0019] Alarm DB 51 stores a group of alarms that occur regularly from external sources, while Network Information DB 52 stores network configuration information of the monitored network from external sources.

[0020] The alarm group includes the device or system that generated the alarm, the content of the alarm, and the time the alarm occurred. Only the necessary alarms may be filtered from the alarm group and stored in the alarm DB 51, or the alarm group data may be exported from other monitoring equipment and stored in the alarm DB 51. The alarm group may also be actively acquired by an agent or other means. Furthermore, the information processing device 100 may be equipped with a server function (such as an SNMP server) that receives alarms.

[0021] The network configuration information stored in the network configuration DB 52 includes information such as adjacency, which is the relationship between each device that makes up the communication network, and includes information at both the logical and physical layers. Note that the network information DB 52 may not be necessary when the monitored device or system is not a communication network but a system such as an application or server.

[0022] The existing occurrence pattern creation unit 10 extracts groups of alarms from the alarm DB 51 within a certain period and organizes the relationships between each alarm. This function includes a function to aggregate information for the same equipment and the same alarm for each alarm, and a function to create known alarms and alarm combination information considering the adjacency of each alarm, and register them in the existing occurrence pattern DB 53.

[0023] The existing occurrence pattern creation unit 10 may, when organizing the relationships between alarms, use the network configuration information stored in the network configuration DB 52 as needed, for example, when a large-scale network is involved.

[0024] The existing occurrence pattern DB53 stores information on known alarms and alarm combinations. This stored information may be corrected by the user. This correction includes setting alarms that do not require consideration.

[0025] When the first failure of a certain type occurs in the network, the rule learning unit 20 generates rules used to estimate the nature of the failure, in this case the nature of the malfunction, based on a group of alarms that characterize the nature of the failure, and stores these rules in the rule DB 54.

[0026] The generated rules above define required alarms, related alarms, and fault descriptions in an associated manner. Required alarms are alarms that always occur in the associated fault description, and related alarms are alarms that occur in devices adjacent to the device that generated the required alarm, i.e., the device involved in the generation of the required alarm. Fault descriptions may include the suspected faulty part, the cause of the fault, or both.

[0027] The fault location estimation unit 40 compares newly generated alarms with rules already stored in the rule DB 54. If at least one of the newly generated alarms matches any of the alarms in the group characterized by the rule, it performs a confidence estimation process to indicate the likelihood that the above-mentioned fault occurred.

[0028] The unknown fault estimation unit 30 compares the alarms stored in the alarm DB 51 for a specified period with the information stored in the existing occurrence pattern DB 53 for a period prior to or during the specified period. If there are alarms or combinations of alarms in the alarm DB 51 for a specified period that do not match the information stored in the existing occurrence pattern DB 53, the unit outputs this information as an unknown fault.

[0029] Furthermore, the unknown fault estimation unit 30 receives information such as the confidence level output from the fault location estimation unit 40, and has a function to change this confidence level depending on the alarm situation that does not match the information stored in the existing occurrence pattern DB 53.

[0030] When the unknown fault estimation unit 30 outputs an unknown fault, the rule learning unit 20 generates a rule to be used for the nature of the fault, based on a new group of alarms preceding this output, and stores it in the rule DB 54 as a rule related to the estimation of the nature of the fault.

[0031] This method of implementation allows us to assume that there is "no malfunction" if it is presumed that there is no malfunction, and to assume that there is "a possibility of an unknown malfunction" if there is a possibility that it is not a known malfunction.

[0032] Figure 3 illustrates an example of the procedure for storing information in the existing occurrence pattern DB. The alarm occurrence time, generating device, and content are recorded in the alarm DB 51 (S11), and the existing occurrence pattern creation unit 10 retrieves all alarms with content within a specific time range (indicated as a in Figure 3) from the alarm DB 51 (S12).

[0033] The existing occurrence pattern creation unit 10 aggregates alarms of the same type for each extracted alarm and creates a set that includes alarms for adjacent logical and physical layers (S13).

[0034] The existing occurrence pattern creation unit 10 organizes the created set by grouping identical alarms, etc., by frequency or degree (S14). If the information of this organized set is not registered in the existing occurrence pattern DB 53, the existing occurrence pattern creation unit 10 registers this information in the existing occurrence pattern DB 53, including the registration date and time, and taking into account network topology information as necessary (S15).

[0035] The existing occurrence pattern creation unit 10 sets a new time range (indicated by b in Figure 3) by shifting the aforementioned specific time range so as to partially overlap with the original time range (S16), and returns to S12. Note that it is not necessary to check whether the information registered in the existing occurrence pattern DB 53 has been registered in the rule DB 54, which simplifies implementation.

[0036] Figure 4 illustrates an example of the operation related to estimating the location of a fault. The fault location estimation unit 40 retrieves information on multiple alarms within the time range to be inferred (indicated by the numeral a in Figure 4) from the alarm DB 51 and outputs the accuracy P (0 to 1) between the alarm and the rule stored in the rule DB 54 (S21).

[0037] The unknown fault estimation unit 30 searches whether each alarm within a time range a certain period past from the time range extracted in S11, or within a specified time range past from the extracted time range, exists in the existing pattern DB 53 (S22).

[0038] If, as a result of the processing in S22, an alarm that does not exist in the existing occurrence pattern DB53, i.e., an unknown alarm, is found, it is evaluated whether the location where this unknown alarm occurred is the same as or adjacent to the location where the aforementioned precision P exceeds 0, i.e., an alarm with a non-zero probability of failure occurred.

[0039] If, as a result of the processing in S23, the target locations are not the same or adjacent, the unknown fault estimation unit 30 adds the type of unknown alarm, the location of occurrence, and the time of occurrence of the existing unknown alarm as unknown fault details to the unknown fault list, which manages the type of unknown alarm, the location of occurrence, and the time of occurrence of the alarm. On the other hand, if, as a result of the processing in S23, the target locations are the same or adjacent, the type of alarm, the location of occurrence, and the location of occurrence of the alarm are added to the unknown fault list as unknown fault details, linked to the precision rate P related to the target alarm (S23).

[0040] However, in the case of adjacent cases, the likelihood of them being linked to this fault is unknown, so linking them to the precision rate P is optional. The process in S23 is performed for each unknown alarm.

[0041] Next, we will explain the search for whether or not there are any unknown combinations of alarms that appeared during the period under consideration. The unknown fault estimation unit 30 performs the sorting process described in S13 and S14 above for each alarm that appeared during the period under consideration, and determines whether the result of this process matches the existing occurrence pattern DB 53 (S24). In S24, for each alarm, the search range is expanded to include the time before and after the alarm (indicated by b in Figure 4).

[0042] If, as a result of this determination, the occurrence locations of each alarm combination that appeared during the period under consideration are not the same or adjacent to any combination of alarm occurrence locations in the existing occurrence pattern DB53, then the combination of alarms that appeared during the search period, their occurrence locations, and the time of the alarms will be added to the unknown failure list as an unknown failure.

[0043] On the other hand, if the result of the S24 determination shows that the occurrence locations of each alarm combination that appeared during the period under consideration are the same as or adjacent to the occurrence locations of alarms in the existing occurrence pattern DB53, then the combination of alarm types, occurrence locations, and occurrence times of each alarm that appeared during the search period are added to the unknown failure list as unknown failure details, linked to the precision P related to this alarm.

[0044] Next, the failure location estimation unit 40 outputs related unknown failure details indicated by the unknown failure list in addition to the information such as the estimated failure location, confidence level, and failure cause related to the generated alarm described above (S25).

[0045] In S24, when the estimated failure location related to the generated alarm and the occurrence location of the alarm that occurred during the search target period indicated by the unknown failure list are the same or adjacent, the failure location estimation unit 40 outputs the related unknown failure details indicated by the unknown failure list by superimposing on the information such as the estimated failure location, confidence level, and failure cause related to the generated alarm described above, and displays the possibility of relevance between the alarms on an external display device (reference c in FIG. 4).

[0046] On the other hand, in S24, when the estimated failure location related to the generated alarm and the occurrence location of the alarm that occurred during the search target period indicated by the unknown failure list are not the same or adjacent, the related unknown failure details indicated by the unknown failure list are output, and an alarm with unknown failure is displayed on the display device (reference d in FIG. 4).

[0047] In the present embodiment, in registering information in the existing occurrence pattern DB53, as a countermeasure against an increase in the number of combinations, instead of simply storing the number of alarm occurrences as the number of times, it is stored as once or multiple times within a period.

[0048] Also, by setting an alarm for which there is no need to consider unknown failure on the user side, the corresponding alarm is excluded from the registration target. Here, for alarms that are constantly output, etc., it is considered that there is no need to consider unknown failure, and they are excluded from the registration content of the existing occurrence pattern DB53. For example, if an alarm is associated with any combination of alarms after registration in the existing occurrence pattern DB53 within a certain period, this is automatically excluded from the registration content of the existing occurrence pattern DB53.

[0049] Furthermore, in this embodiment, combination rules are created that take into account the configuration and type of equipment. For example, in cases where alerts are generated from all adjacent equipment on the logical or physical layer, or when alerts are generated from a specific type of equipment or adjacent equipment, such as a switch from "xxx company," the alarm content and alarm combinations are registered in the unknown fault list for each equipment type, and inferences are made based on this registration. In this case, if the network equipment is changed and that equipment is removed, the corresponding alarm or alarm combination can be deleted from the registration.

[0050] Furthermore, in this embodiment, during inference, in addition to superimposing the determination result of unknown fault properties onto the inference result based on existing alarms, the confidence value can be adjusted. As a first example of this adjustment, even if the confidence level is 100% in the existing rules, if the new alarm includes an unknown alarm, the confidence level will not be displayed as 100%, but rather as, for example, 50%.

[0051] As a second example of the adjustments mentioned above, the display content for unknown faults will be changed depending on the nature of the unknown fault. For example, for a single unknown alarm, the occurrence of that alarm will be displayed, while combinations of alarms other than single unknown alarms and differences in alarm occurrence frequency will only be displayed for reference purposes.

[0052] Assuming that it is combined with existing fault estimation and classification technologies, the devices to which this embodiment can be applied are not limited to network devices; for example, it can also be applied to monitoring servers or application programs. In this case, there is no need to consider the proximity of alarm occurrence locations, and the devices can simply be registered and inferred based on combinations of alarms.

[0053] Furthermore, in this embodiment, in a carrier's large-scale network, there are cases where simple alerts and associated faults are automatically recovered, i.e., cases where it is not necessary to detect them as faults. Even in these cases, it is sufficient to evaluate only the likelihood of previous occurrences without any special consideration. For example, the fault location estimation unit 40 can determine whether or not to define it as a fault in its fault classification.

[0054] Figure 5 shows a specific example of registering information to an existing occurrence pattern database. In the network shown in Figure 5, the relationships between each device, such as an IP device, and its neighboring devices are as follows: Device K: Devices L, M Device L: Devices K, O Device M: Devices K, N, P, Q Device N: Devices M, O, Q Device O: Devices L, N, Q Device P: Devices M, Q, R Device Q: Devices M, N, O, P, R, T Device R: Devices P, Q, S Device S: Devices R, T Device T: Devices Q, S

[0055] In the example shown in Figure 5, alarms are generated from devices K, L, M, and T. The relationship between the device that generates an alarm and the type of alarm generated for that device is as follows: Device K: Alarm A Device L: Alarm B Device M: Alarm C Device T: Alarm A

[0056] Next, the existing occurrence pattern creation unit 10 extracts candidate combinations of the generated alarms. In the example shown in Figure 5, "Alarm A", "Alarm A, B, C", "Alarm A, B", and "Alarm A, C" are extracted as candidate combinations.

[0057] The existing occurrence pattern creation unit 10 compares the extracted combination candidates with the current registered contents of the existing occurrence pattern DB 53. If there are any combination candidates among the extracted candidates that are not currently registered, it adds these combination candidates to the registered contents of the existing occurrence pattern DB 53.

[0058] In the example shown in Figure 5, the current registered contents of the existing occurrence pattern DB 53 include a first registered contents that associates combination number "1", key alarm "A", and registration time, and a second registered contents that associates combination number "2", key alarm "A", adjacent alarm "B", and registration time.

[0059] This adjacent alarm is an alarm that occurs at locations adjacent to the location where the corresponding key alarm occurred. Furthermore, the registration time is not the time the alarm occurred, but the median value of a predetermined time range that has been extracted.

[0060] In this registration, since "Alarm A, C" and "Alarm A, B, C" are not present in the current registrations of the existing occurrence pattern DB 53 among the extracted combination candidates, the existing occurrence pattern creation unit 10 registers the corresponding combination candidates in the existing occurrence pattern DB 53 along with the registration time.

[0061] As a result of this registration, the registered contents of the existing occurrence pattern DB53 will include the following third, fourth, and fifth registered contents, in addition to the first and second registered contents described above. The combination numbers of the fourth and fifth registered contents are the same, and these are the registered contents related to each alarm that occurred simultaneously. • Third registered contents consisting of combination number "3", key alarm "A", and adjacent alarm "C", along with the associated registration time. • Fourth registered contents consisting of combination number "4", key alarm "A", and adjacent alarm "B", along with the associated registration time. • Fifth registered contents consisting of combination number "4", key alarm "A", and adjacent alarm "C", along with the associated registration time.

[0062] Figure 6 shows a modified example of the registered contents of the existing occurrence pattern DB. In the example shown in Figure 6(a), the registered contents of the existing occurrence pattern DB 53 differ from the example shown in Figure 5 and include the following seventh, eighth, and ninth registered contents: • Seventh registered contents consisting of combination number "1", key alarm "A", and registration time; • Eighth registered contents consisting of combination number "2", key alarm "A", and adjacent alarm "B", and registration time; • Ninth registered contents consisting of combination number "3", key alarm "A", and adjacent alarm "C", and registration time.

[0063] In this embodiment, in order to quickly search for alarm combinations from key alarm information using real-time search or the like, the registered contents of the existing occurrence pattern DB 53 may be modified to include combinations to be used as key alarms for all types of alarms.

[0064] When this change is made, in the example shown in Figure 6(b), the registered contents of the existing occurrence pattern DB53 are modified to include the following tenth and eleventh registered contents in addition to the seventh, eighth, and ninth registered contents described above.

[0065] - A 10th registration item consisting of combination number "4", key alarm "B", and adjacent alarm "A", and linked to the registration time. - A 11th registration item consisting of combination number "5", key alarm "C", and adjacent alarm "B", and linked to the registration time.

[0066] By making these changes, when searching for a combination of alarms "B" and "C" during prediction, it becomes possible to refer to only the key alarms.

[0067] Next, we will describe an example of estimating the location of a failure and the possibility of an unknown alarm. The following example describes an estimation using the registered contents of Rule DB 54 and Existing Occurrence Pattern DB 53 for a network with the configuration shown in Figure 5. However, estimation is not limited to this configuration, and it is also possible to use the same registered contents of Rule DB 54 and Existing Occurrence Pattern DB 53 for estimations of other networks with the same or similar configuration, for example, where the relationship between each alarm and the failure content, as registered in Rule DB 54, and the relationship between key alarms and adjacent alarms, as registered in Existing Occurrence Pattern DB 53, can be applied.

[0068] Figure 7 shows a first example of estimating the location of a failure and the possibility of an alarm being unknown. In this example, in a network with the configuration shown in Figure 5, an alarm occurs within the failure estimation period, and the failure rule is that alarm "D" occurs, and when alarm "C" occurs at the device adjacent to the device that caused alarm "D", the failure is "power supply failure". This rule has already been learned in rule DB 54, and either "Case 1" or "Case 2", described below, is already registered in the existing occurrence pattern DB 53 as an existing occurrence pattern.

[0069] In the example shown in Figure 7, "Case 1" of the existing occurrence patterns registered in the existing occurrence pattern DB53 consists of the following five registration contents: • A first registration contents consisting of combination number "1", key alarm "A", and registration time. • A second registration contents consisting of combination number "2", key alarm "C", and registration time. • A third registration contents consisting of combination number "3", key alarm "C", and adjacent alarm "C", and registration time. • A fourth registration contents consisting of combination number "4", key alarm "C", and adjacent alarm "D", and registration time. • A fifth registration contents consisting of combination number "5", key alarm "D", and adjacent alarm "C", and registration time.

[0070] In the example shown in Figure 7, "Case 2" of the existing occurrence pattern registered in the existing occurrence pattern DB53 includes the following five registration contents: • A second registration contents consisting of combination number "1", key alarm "C", and registration time. • A third registration contents consisting of combination number "2", key alarm "C", and adjacent alarm "C", and registration time. • A fourth registration contents consisting of combination number "3", key alarm "C", and adjacent alarm "D", and registration time. • A fifth registration contents consisting of combination number "4", key alarm "D", and adjacent alarm "C", and registration time.

[0071] In the example shown in Figure 7, alarms are generated from devices M, N, O, Q, and S. The relationship between the device that generates an alarm and the type of alarm generated for that device is as follows: Device M: Alarm C Device N: Alarm D Device O: Alarm C Device Q: Alarm C Device S: Alarm A

[0072] By comparing these alarms with the fault rules registered in the rule DB 54, the fault type is determined to be a "power supply system failure," and the fault location estimation unit 40 estimates "device N," which is the device involved in the generation of the mandatory alarm "Alarm D," as the suspected fault location. Furthermore, among the devices related to the network shown in Figure 5, the fault location estimation unit 40 may estimate that devices other than "device N" are not suspect fault locations.

[0073] Then, when the combination of alarms that occurred in a time period a certain amount prior to the failure estimation period is compared with the existing occurrence pattern "Case 1", all of the combinations of alarms that occurred in the example shown in Figure 7 are included in the registered contents of "Case 1" described above, and therefore the unknown failure estimation unit 30 estimates that there are "no" unknown failures.

[0074] As a result, the estimated output indicates that "Device N" is the suspected location of the "power supply system failure," and that there are "no" unknown faults. Based on this estimated result, when displaying information plotting the fault location using a GUI (Graphical User Interface), the information plotting the fault location will be displayed for Device N.

[0075] Furthermore, when the combination of alarms that occurred in a certain period prior to the failure estimation period is compared with the existing occurrence pattern "Case 2", the unknown failure estimation unit 30 estimates that "Alarm A", one of the combinations of alarms that occurred in the example shown in Figure 7, is not included in the registration contents of "Case 2" described above, and therefore an unknown failure, "Alarm A", has been detected from the device S.

[0076] As a result, the estimated output indicates that "device N" is the suspected location of a "power supply system failure" and that "alarm A," which indicates an unknown fault, has been detected from device S. Furthermore, among the devices related to the network shown in Figure 5, the failure location estimation unit 40 may estimate that devices other than "device N" and "device S" are not suspected locations of failure, and the above estimation result may include the fact that devices other than "device N" and "device S" are not suspected locations of failure.

[0077] Based on these estimation results, when displaying information plotting the fault locations using a GUI or similar interface, the fault locations will be displayed on both device N and device S.

[0078] Figure 8 shows a second example of estimating the location of a failure and the possibility of an alarm being unknown. In this example, in a network with the configuration shown in Figure 5, an alarm occurs within the failure estimation period, and as a failure rule, alarm "D" occurs, the same as in the example shown in Figure 6, and the failure content when alarm "C" occurs from a device adjacent to the device that caused alarm "D" is already learned in rule DB 54 as "power supply failure". Furthermore, "Case 3", described below, is already registered in the existing occurrence pattern DB 53 as an existing occurrence pattern.

[0079] In the example shown in Figure 8, "Case 3" of the existing occurrence pattern registered in the existing occurrence pattern DB53 is the same as "Case 1" in the example shown in Figure 7, consisting of the following five registration contents: • A first registration contents consisting of combination number "1", key alarm "A", and registration time. • A second registration contents consisting of combination number "2", key alarm "C", and registration time. • A third registration contents consisting of combination number "3", key alarm "C", and adjacent alarm "C", and registration time. • A fourth registration contents consisting of combination number "4", key alarm "C", and adjacent alarm "D", and registration time. • A fifth registration contents consisting of combination number "5", key alarm "D", and adjacent alarm "C", and registration time.

[0080] In the example shown in Figure 8, alarms are generated from devices M, N, O, Q, and S. The relationship between the device that generates an alarm and the type of alarm generated for that device is as follows. This differs from the example shown in Figure 7 in that the first alarm E is generated from device N. Device M: Alarm C Device N: Alarm D, Alarm E Device O: Alarm C Device Q: Alarm C Device S: Alarm A

[0081] By comparing these generated alarms with the fault rules registered in rule DB54, the fault type is determined to be "power supply system failure," as in the example shown in Figure 7, and "device N," which is the source of the mandatory alarm "Alarm D," is estimated by the fault location estimation unit 40 as the suspected fault location.

[0082] Then, when the combination of alarms that occurred in a certain period prior to the estimated failure period is compared with the existing occurrence pattern "Case 3," the unknown failure estimation unit 30 estimates that "Alarm E," which is not included in the registered contents of "Case 3" as described above, has been detected from device N, indicating an unknown failure. As a result, the estimated result is output that "device N" is the suspected location of a "power supply system failure," and that "Alarm E," which is an unknown failure, has been detected from the same device N as this suspected location of failure.

[0083] Furthermore, among the devices related to the network shown in Figure 5, the fault location estimation unit 40 may estimate that devices other than "device N" are not suspected fault locations, and the estimation result described above may include that devices other than "device N" are not suspected fault locations. Based on this estimation result, when information plotting the fault location is displayed using a GUI or the like, the information plotting the fault location will be displayed for device N.

[0084] In the example shown in Figure 8, with the existing method that does not use the existing occurrence pattern, the rule matching degree for the failure of device N is 100%, so the confidence level is estimated to be 100%, but the fact that an unknown alert has been generated from the suspected faulty device itself is not output. In contrast, in this embodiment, by using the existing occurrence pattern, the fact that there is an unknown fault characteristic for the failure of device N, the suspected faulty device itself, is also output.

[0085] Figure 9 shows a third example of estimating the location of a failure and the possibility of an alarm being unknown. In this example, in the network configuration shown in Figure 5, an alarm occurs within the failure estimation period, and as a failure rule, alarm "D" occurs, the same as in the example shown in Figure 6. Rule DB 54 has already learned that the failure when alarm "D" occurs from a device adjacent to the device that generated alarm "D" is a "power supply failure," and as an existing occurrence pattern, "Case 3," the same as in the example shown in Figure 8, is registered in the existing occurrence pattern DB 53.

[0086] In the example shown in Figure 8, alarms are generated from devices M, N, O, Q, and S. The relationship between the device that generates an alarm and the type of alarm generated for that device is as follows. This differs from the example shown in Figure 7 in that the first alarm E is generated from device O. Device M: Alarm C Device N: Alarm D Device O: Alarm C, Alarm E Device Q: Alarm C Device S: Alarm A

[0087] By comparing these generated alarms with the fault rules registered in rule DB54, the fault type is determined to be "power supply system failure," as in the example shown in Figure 7, and "device N," which is the source of the mandatory alarm "Alarm D," is estimated by the fault location estimation unit 40 as the suspected fault location.

[0088] Then, when the combination of alarms that occurred in a certain period of time prior to the estimated failure period is compared with the existing occurrence pattern "Case 3," the unknown failure estimation unit 30 estimates that "Alarm E," which has the potential for an unknown failure, was detected from device O, because "Alarm E" is not included in the registered contents of "Case 3" as described above. As a result, the estimated result is output that "device N" is the suspected location of a "power supply system failure," and that "Alarm E," which has the potential for an unknown failure, was detected from device O adjacent to this suspected location of failure.

[0089] Furthermore, among the devices related to the network shown in Figure 5, the fault location estimation unit 40 may estimate that devices other than "device N" and "device O" are not suspected fault locations, and the estimation result described above may include that devices other than "device N" and "device O" are not suspected fault locations. Based on this estimation result, when information plotting the fault location is displayed using a GUI or the like, information plotting the fault location will be displayed for device N and device O.

[0090] In the example shown in Figure 9, with the existing method that does not use the existing occurrence pattern, the rule match degree for the failure of device N is 100%, so the confidence level is estimated to be 100%, but the fact that an unknown alert has been generated from an adjacent device to the suspected failure device is not output. In contrast, in this embodiment, by using the existing occurrence pattern, the possibility that there is a relationship between the suspected failure device N and an unknown failure in an adjacent device may also be output.

[0091] Figure 10 is a block diagram showing an example of the hardware configuration of an information processing device according to one embodiment of the present invention. In the example shown in Figure 10, the information processing device 100 according to the above embodiment is composed of, for example, a server computer or a personal computer, and has a hardware processor 111A such as a CPU (Central Processing Unit). A program memory 111B, a data memory 112, an input / output interface 113, and a communication interface 114 are connected to this hardware processor 111A via a bus 115.

[0092] The communication interface 114 includes, for example, one or more wireless communication interface units, enabling the transmission and reception of information with the communication network. As the wireless interface, for example, an interface employing a low-power wireless data communication standard such as a wireless LAN (Local Area Network) is used.

[0093] The input / output interface 113 is connected to an input device 200 and an output device 300, which are attached to the information processing device 100 and used by users or the like.

[0094] The input / output interface 113 can capture operation data entered by a user or the like through an input device 200 such as a keyboard, touch panel, or touchpad, and can also output output data to an output device 300, including a display device using liquid crystal or organic EL (electroluminescence), for display. The input device 200 and output device 300 may be devices built into the information processing device 100, or they may be input devices and output devices of other information terminals that can communicate with the information processing device 100 via a network.

[0095] The program memory 111B is a non-temporary tangible storage medium in which a non-volatile memory that can be written to and read at any time, such as an HDD (Hard Disk Drive) or SSD (Solid State Drive), is used in combination with another non-volatile memory such as ROM (Read Only Memory), and can store programs necessary for executing various control processes, etc., according to one embodiment.

[0096] The data memory 112 is a tangible storage medium that, for example, uses a combination of the above-mentioned non-volatile memory and volatile memory such as RAM (Random Access Memory), and can be used to store various data or information acquired and created during the process of various operations.

[0097] An information processing device 100 according to one embodiment of the present invention may be configured as a data processing device having various parts of the information processing device 100, with the software-based processing function unit being the software-based processing unit.

[0098] The storage devices and storage units 50 used as work memories by each part of the information processing device 100 may be configured using the data memory 112 shown in Figure 10. However, the storage areas configured by these storage devices are not essential to the information processing device 100, and may be areas provided in external storage media such as USB (Universal Serial Bus) memory, or in storage devices such as database servers located in the cloud.

[0099] All of the above processing functions can be implemented by having the hardware processor 111A read and execute a program stored in the program memory 111B. Some or all of these processing functions may be implemented in various other forms, including application-specific integrated circuits (ASICs) or field-programmable gate arrays (FPGAs).

[0100] Furthermore, the methods described in each embodiment can be stored as programs (software means) that can be executed by a computer on recording media such as magnetic disks (floppy disks, hard disks, etc.), optical disks (CD-ROMs, DVDs, MOs, etc.), and semiconductor memories (ROMs, RAMs, flash memories, etc.), and can also be transmitted and distributed via communication media. The programs stored on the media also include configuration programs that configure the computer to run software means (including not only the execution program but also tables or data structures). The computer implementing this device reads the program recorded on the recording media and, if necessary, constructs the software means using the configuration program, and executes the above-described processes by controlling the operation of this software means. Note that the recording media referred to in this specification are not limited to those for distribution, but also include storage media such as magnetic disks or semiconductor memories provided inside the computer or in devices connected via a network.

[0101] It should be noted that the present invention is not limited to the embodiments described above, and can be modified in various ways during implementation without departing from its essence. Furthermore, each embodiment may be combined as appropriate, and in that case, the combined effects can be obtained. Moreover, the above embodiments include various inventions, and various inventions can be extracted by selecting combinations from the multiple constituent elements disclosed. For example, if the problem can be solved and effects obtained even if some constituent elements are deleted from all the constituent elements shown in the embodiment, then the configuration with these deleted constituent elements can be extracted as an invention.

[0102] 100... Information processing device 10... Existing occurrence pattern creation unit 20... Rule learning unit 30... Unknown failure probability estimation unit 40... Failure location estimation unit 50... Memory unit 51... Alarm DB 52... Network configuration DB 53... Existing occurrence pattern DB 54... Rule DB

Claims

1. An information processing device comprising: a creation unit that creates information which is a combination of alarm information that has already occurred in a communication network within a predetermined period and alarm information that has occurred in a location adjacent to the location where the alarm information occurred; and an unknown estimation unit that estimates that an unknown alarm has occurred in the communication network when information which is linked to alarm information that has newly occurred in the communication network and alarm information that has occurred in a location adjacent to the location where the alarm information occurred is not included in the information created by the creation unit.

2. The information processing apparatus according to claim 1, wherein the creation unit updates the information created by the creation unit to include a combination of multiple alarm information that occurred in the communication network within a predetermined period, and alarm information that occurred at a location adjacent to the location where the alarm information occurred.

3. The information processing apparatus according to claim 1, which is capable of accessing a storage device that stores a first alarm information generated in the communication network, a second alarm information generated at a location adjacent to the location where the first alarm information was generated, and rules that define the content of a failure in the communication network caused by the generation of the first and second alarm information, and further comprises a failure estimation unit that estimates the content of a failure in the communication network caused by the generation of newly generated alarm information by comparing newly generated alarm information in the communication network with information that links newly generated alarm information and alarm information generated at a location adjacent to the location where the alarm information was generated, and the rules, and outputs the result of estimation by the failure estimation unit and the result of estimation by the unknown estimation unit together.

4. An information processing method performed by an information processing device, comprising: creating information using a creation unit of the information processing device, which is a combination of alarm information that has already occurred in the communication network within a predetermined period and alarm information that has occurred in a location adjacent to the location where the alarm information occurred; and estimating that an unknown alarm has occurred in the communication network using an unknown estimation unit of the information processing device, when information linking newly occurred alarm information in the communication network and alarm information that has occurred in a location adjacent to the location where the alarm information occurred is not included in the information created by the creation unit.