Patents
Literature
Hiro is an intelligent assistant for R&D personnel, combined with Patent DNA, to facilitate innovative research.
Hiro

197 results about "Alarm correlation" patented technology

Alarm correlation in a large communications network

A system and method of correlating alarms from a plurality of network elements (NEs) in a large communications network. A plurality of uncorrelated alarms are collected by an alarm collector from alarm reporters. An alarm correlator then partitions the alarms into correlated alarm clusters such that alarms of one cluster have a high probability that they are caused by one network fault. The partitioning of the alarms is performed by creating alarm sets, expanding the alarm sets into alarm domains, and merging the alarm domains into alarm clusters if predefined conditions are met. The sets are formed by selecting an alarmed NE at the highest network hierarchy level which is not tagged, finding all of its contained NEs, and finding NEs that are peer-related to those contained NEs that are in an alarmed state. The sets are expanded into domains by finding NEs that are not in an alarmed state which contain the highest level alarmed NE in each alarm set. The domains are merged into one alarm cluster if the two domains have at least one common NE, at least one of the common NEs is not tagged, and the majority of the NEs contained by the non-tagged common NE are in an alarmed state.
Owner:TELEFON AB LM ERICSSON (PUBL)

System and method for fault diagnosis using distributed alarm correlation

A system and method for diagnosing faults in a communication network using a distributed alarm correlation system. The alarm correlation system may include node-level alarm correlation tools (ACTs) located at nodes in the network to provide node-level alarm correlation producing node-level correlation results. The node-level ACTs may share diagnostic knowledge with other node-level alarm correlation tools at other nodes. Each of the node-level ACTs may also share the diagnostic knowledge and the node-level correlation results with a higher-level ACT. The higher-level ACT may provide higher-level alarm correlation to produce higher-level correlation results.
Owner:SUBCOM LLC

Alarm correlation system

An alarm correlation method with rules and model is disclosed for suppression of alarms which will clear when another alarm clears. The alarm correlation method with rules and model includes a list of objects which alarms may be raised, and a list of correlation rules for each of the objects which associates objects which have correlated alarms, and a method of traversing the lists so that correlated alarms may be suppressed. The alarm correlation method with rules and model is particularly useful for overcoming operator overload due to the presence of multiple correlated alarms.
Owner:RPX CORP

Intelligent alarm monitoring method of neural network

ActiveCN102130783AImplementation of association analysisImprove accuracyData switching networksPositional TechniquePositioning system
The invention provides an intelligent alarm monitoring method of a neural network. A brand-new intelligent communication network comprehensive monitoring analysis and fault locating system is built by adopting an alarm correlation analysis and locating technology based on an expert system of the neural network. The system guarantees effective monitoring of repeated alarming, alarm oscillation, alarm flash and alarm storm by collecting the alarm data of each piece of equipment of each network element system of each major, and filters out a storm alarm, a flash alarm, an invalid alarm and a secondary alarm correctly; and the system can pick out an important alarm event which is really required to be processed from the collected mass alarms based on a deep correlation rule analysis and neural network technology, and can locate and remove a network fault quickly and correctly. The correction rate of network alarm analysis and fault diagnosis can be improved obviously, customer satisfaction is improved, and operating cost and maintenance cost are reduced greatly, so that the aims of reducing the work load of an operator and a maintainer and improving the efficiency of fault management are fulfilled.
Owner:INSPUR TIANYUAN COMM INFORMATION SYST CO LTD

Method and system for analyzing multiple-network relation

ActiveCN103178991ARealize dynamic association supervisionQuality improvementData switching networksSignaling networkComputer science
The invention discloses a method and system for analyzing multiple-network relation. Firstly, a routing protocol is acquired through a virtual router so as to find a network device, real-time monitoring and diagnostic analysis of a protocol state of the network device is performed, and an alarm is given when anomalous change occurs. Interdisciplinary alarm correlation analysis of a bearing network, a signaling network and a transmission network is performed. When the network device shuts down, a network device associated with the network device in a network is subjected to resource analysis and positioning, impact level is judged, and impact result state information is shown in a topological interface. By adopting the technical scheme, powerful support is provided for quick fault position and repair, an impact range of the whole network can be comprehensively and accurately mastered, customer perception is effectively improved, and the network is ensured to operate in high-stability, high-quality and high-efficiency mode.
Owner:CHINA MOBILE GRP HEILONGJIANG CO LTD

Master station system monitoring model based on power dispatching automation

The invention discloses a master station system monitoring model based on power dispatching automation. The master station system monitoring model comprises function modules including a monitoring and acquisition module, an alarm correlation analysis module and a monitoring visualization module. According to the invention, the health conditions of host computer servers are analyzed on the basis of operation states and operating performance index data of the host computer servers of an automatic master station system; the business relationship between the master station system and each component of each host computer server, each database server and each WEB application server can be displayed with levels in a visual graphics way according to the business relationship of the preset master station system and each host computer server, each database server and each WEB application server; and therefore, abnormal information of each server and affected master station systems can be displayed in real time, and a rapid alarm check way and a fault source locating inlet can be provided.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD SHAOXING POWER SUPPLY CO +1

Method and system for analyzing alarm correlation based on network and time

InactiveCN102136949AAlarm correlation analysis is accurateAlarm correlation analysis is efficientData switching networksData miningAlarm correlation
The invention provides a method and system for analyzing alarm correlation based on network and time. The method comprises the following steps: normalizing and converting all alarms in a unified format; and grouping the alarms in accordance with network correlation and on the basis of network configuration information; performing window inspection on each alarm group in accordance with time correlation and analyzing the alarm groups exceeding a time widow; and carrying out pattern matching analysis on alarms with an improved event tree model, and releasing root alarms. According to the invention, the problem that an existing system cannot perform comprehensive analysis can be solved, and the exact and efficient alarm correlation analysis is realized.
Owner:STATE GRID ELECTRIC POWER RES INST +2

Tracing analysis method for network attacks

PendingCN111490970ATraceability analysis is effectiveEasy to handleData switching networksComputer networkAttack
The invention discloses a tracing analysis method for network attacks, which comprises the following steps: acquiring threat intelligence of a specified type, and caching the threat intelligence to alocal threat intelligence database; acquiring current alarm information and the local threat information, and judging the attack source of the alarm; respectively carrying out alarm association according to the attack source and / or the equipment identifier of the attack target, determining the attack stage of the equipment, and judging the equipment collapse level according to the attack stage; and obtaining asset information of the equipment, and determining the influence range of the attack according to the alarm association result. Effective traceability analysis of network attacks is achieved, various traceability results are obtained, traceability data can be updated every time traceability is conducted, and a basis is provided for network operation and maintenance personnel to handleproblems and strengthen security policies.
Owner:西安交大捷普网络科技有限公司

Alarm correlation analysis method, device, equipment and medium

ActiveCN108156037ADeduplication is reasonableReasonable compressionData switching networksRule miningRoot cause
The embodiment of the invention discloses an alarm correlation analysis method, device, equipment and medium. The method comprises the following steps of: acquiring alarm data, and carrying out line segment deduplication and standardization on the alarm data to obtain standardized alarm data; corresponding each alarm data according to the standardized alarm data and the characteristic field; excavating an alarm association rule according to a preset alarm rule mining parameter based on an alarm family spectrum so as to obtain an alarm association rule after mining; obtaining a preset alarm social network according to the mining alarm association rules; presetting to carry out alarm analysis on the real time alarm data, according to the alarm family spectrum, the minded alarm association rule, and the alarm social network. The invention can effectively de-emphasize the massive alarm data, improve the calculation efficiency through association rule mining, and quickly grasp the main features of the alarm storm, and the complex relationship between the alarms, in particular to the root cause alarm the chain alarm occurs. Derived alarms have a more in-depth analysis.
Owner:CHINA MOBILE GROUP JIANGSU +2

Processing method for alarm correlation of monitoring system based on business rules

The invention discloses a processing method for alarm correlation of a monitoring system based on business rules. The processing method comprises following steps of: a), coding all capital equipment in a unified mode according to business rules; b), acquiring original alarm information, where each piece of business rules comprises a capital code through which a business system ID is founded out and finding out all related capital equipment corresponding to the business system by means of the business system ID; c), reading occurrence time of original alarm information and calculating the related warning time range; and d), matching all related original alarm information in a related manner in order to find out original alarm information and result alarm information if original alarm information of related capital equipment within the related alarm time range is present and carrying out early warning operation if otherwise. The processing method for alarm correlation of the monitoring system based on business rules has following beneficial effects: with business requirements of a client as objects of management, root causes of failure based on business rules can be precisely positioned and non-perceptible failure of the client can be pre-processed in order to avoid occurrences of perception failures.
Owner:SHANGHAI SNC NET INFORMATION TECH CO LTD

Method and device for realizing associated alarm

The invention discloses a method and a device for realizing associated alarm. In the scheme of the invention, when it is determined that there is an alarm correlation rule matched with source alarm information, determining an alarm correlation object associated with the alarm source on an alarm object tree according to the matched alarm correlation rule and performing associated alarm treatment on an alarm of the alarm correlation object according to the matched alarm correlation rule. The associated alarm realizing scheme provided by the invention is simple, flexible and easy to implement, an alarm basic flow of the foreground alarm source is not need to be changed at all, and a stocking of an original alarm and a historical alarm export function of an original alarm are not affected; and the alarm management basic function that had been developed and realized are not affected and the existing structure is not relied on. By using the method, the alarm management function of a communication system is completed, the cost is lowered and the expansibility is strengthened.
Owner:ZTE CORP

Method and apparatus for SDH equipment alarm correlativity analysis

The invention relates to a method which is used for the alarm correlation analysis of SDH equipment, and a device thereof. The method and the device consider the order of severity of SDH business impact caused by different faults in terms of an SDH transmission system, and differentiate a business alarm and a non-business alarm; a reasonable alarm processing rule is provided so as to satisfy the complexity and flexibility of the maintenance of a signal processing by the SDH business alarm; the self-learning processing of an alarm controlling rule is introduced and diversities related to equipment alarm in different periods are compatible; an alarm correlation analysis algorithm works closely with SDH business operation and maintenance experience to lead to the partitioning operation of a algorithm control logic and operational data. High-efficiency date modeling is combined to improve the execution efficiency of an algorithm analysis, thereby being beneficial to the determination of a source alarm fast carried out by a user.
Owner:FENGHUO COMM SCI & TECH CO LTD

Communication network transmission type alarm uniform analysis device and method

The invention discloses a communication network transmission type alarm uniform analysis device and method and relates to the field of communications. The device comprises a display module, an adaptive module, an interface module, a preprocessing analysis module, a secondary analysis module and a static data read-only module, wherein the display module, the adaptive module, the interface module, the preprocessing analysis module, the secondary analysis module and the static data read-only module are sequentially connected, the adaptive module completes delivery and transition of the service path and alarm correlation analysis services and is communicated with the display module, the interface module provides data for the preprocessing analysis module, and outputs alarm correlation analysis results, the preprocessing analysis module conducts preprocessing analysis on the alarm correlation analysis, and the secondary analysis module conducts secondary analysis on the alarm correlation analysis. Software service technologies are adopted on the implementation forms of the modules, different service analysis modules are reused in a binary mode conveniently, the preprocessing and asynchronous parallel processing are adopted, the alarm analysis efficiency can be effectively improved, the secondary analysis mechanism is adopted, and interference possibly existing in the analysis results can be effectively avoided.
Owner:FENGHUO COMM SCI & TECH CO LTD

Root alarm positioning function implementation method and system based on alarm backtracking

The invention discloses a root alarm positioning function implementation method and system based on alarm backtracking and relates to the field of failure alarms in the network. The method comprises the first step of establishing an alarm association table and a branch count table, the second step of marking weighted values and branch metric measure values of all the alarms in the alarm association table, the third step of selecting and triggering the alarm A, and searching for and triggering a derivative alarm and a driving alarm B corresponding to the triggered alarm in the alarms of the alarm association table, the fourth step of acquiring the position information of the driving alarm B through calculation when the driving alarm B is a root alarm, and the fifth step of triggering a root alarm of the alarm A on feedback NE1 of a network management interface when the driving alarm B is found. According to the method, the rule-based correlation technology and the topology-based correlation technology are combined, the position types and different types of network hierarchical structures are introduced, the accurate positioning information of the correlation alarms can be acquired through the hierarchical representation method of line numbers in the alarm positioning information, and the alarm positioning efficiency and the alarm positioning accuracy are both higher.
Owner:FENGHUO COMM SCI & TECH CO LTD +1

Alarm transmission mode based alarm correlation analysis system and analysis method thereof

ActiveCN102938708ASolve the problem that the alarm correlation analysis cannot be carried out comprehensivelyImprove accuracyData switching networksDirected graphNetwork conditions
The invention relates to an alarm transmission mode based alarm correlation analysis system and an analysis method thereof. The method comprises the steps of conducting normalization processing and conversion on all alarms in a uniform format; combining network configuration information to establish a directed graph containing all logic and physical nodes and relations of an event management system (EMS) for a single EMS; positioning alarms on related nodes on the directed graph and judging correlations of alarms according to accessible relations of nodes; and conducting mode matching analysis on homologous alarms by using an improved event tree model to derive the source alarm. By the aid of the system and the method, the problem that the prior art can not conduct alarm correlation analysis comprehensively is effectively solved, the accuracy, the high efficiency and the adaptability of alarm correlation analysis are enhanced, operation and maintenance costs and the operation difficulty are reduced, the system and the method are convenient to popularize and implement, and the system and the method are particularly suitable for current network conditions of the growing complexity and using habits of users.
Owner:STATE GRID ELECTRIC POWER RES INST +2

Information security event automatic association and rapid response method and system based on big data analysis

The invention discloses an information security event automatic association and rapid response method and system based on big data analysis. The method and the system comprise an offline association module, an online association module, an element alarm comparison module, an element alarm priority module, an element alarm clustering module, an attack mode discovering module and an alarm response system / work order module. Through adoption of the method and the system, alarms reported by a security device are aggregated into element alarms for correlation analysis by using a big data technique, thus generating multiple element alarms. Element alarm priority analysis is carried out after alarm correlation analysis is carried out; alarm priorities corresponding to element alarms are distributed; an alarm response system informs related personnel and the delegates related personnel to check and repair faults according to the alarm level priorities; the alarm response time is remarkably shortened; and misinformation generated by information security devices such as IDS (Intrusion Detection Systems) is eliminated.
Owner:NANJING LIANCHENG TECH DEV

Method and device for determining alarm correlation matrix and analyzing alarm correlation

The invention discloses a method for determining an alarm correlation matrix, comprising the following steps of: determining the alarm correlation, wherein the correlation at least comprises derived alarm and the corresponding relationship of all direct root alarms and priority relationship between direct root alarms corresponding to the same derived alarm; generating a weighted layered directed graph of the alarm according to the alarm correlation; and generating the alarm correlation matrix according to the weighted alarm layered directed graph. The invention discloses a method for analyzing the alarm correlation simultaneously; based on the method, the analysis method also comprises the following steps of: as for the generated alarm, outputting the root alarm and the derived alarm in the generated alarms according to the matching situation between the generated alarm and the matrix element alarm of the line of the correlation matrix. The invention discloses a device for realizing the two methods simultaneously. The method and the device are more convenient and quicker to determine the root alarm and the derived alarm thereof.
Owner:ZTE CORP

Alarm processing method and alarm management system

The invention discloses an alarm processing method and an alarm management system. The method comprises the following steps of: pre-establishing a correlation relation among a plurality of alarms and a condition for the correlation relation in the alarm management system; after the alarm management system receives one of the alarms, shielding the alarm if the alarm is judged to be a sub-alarm of the other alarms received by the alarm management system according to the locally-stored correlation relation and if the condition for the correlation relation between the alarm and the other alarms is met, otherwise, not shielding. The system arranged in network element equipment comprises a storage unit, a receiving unit and a judging unit. In the invention, according to the characteristics of correlation and derivability of the respective alarms, an alarm correlation report decision device is implemented, a source alarm is reported preferentially, the correlation for a derivative alarm is shielded, the redundancy of alarm information can be reduced effectively and the quantity of the alarms can be reduced greatly; moreover, the source information of a fault is highlighted and the efficiency of problem positioning is improved.
Owner:ZTE CORP

Alarm correlation analysis method and device

InactiveCN102142983AReduce the number of correlation analyzesData switching networksCorrelation analysisAnalysis method
The invention discloses an alarm correlation analysis method and an alarm correlation analysis device. The method comprises the following steps of: dividing cached alarms into different types according to alarm information; according to the alarm information of the alarms, searching an alarm correlation rule matched with the alarm information in predetermined alarm correlation rules; and according to constraint conditions, included in the searched alarm correlation rule, among the alarms, judging whether the alarms hitting the same alarm correlation rule are correlated. In the method, the cached alarms are divided into different types according to the alarm information; a rule matched with the alarm information in the alarm correlation rules is searched; and whether the alarms hitting the same alarm correlation rule are correlated is judged according to the constraint conditions, included in the searched alarm correlation rule, among the alarms. Because of the judgment of the alarms hitting the same alarm correlation rule, the times for performing correlation analysis can be reduced; therefore, the alarm correlation analysis efficiency is improved.
Owner:HUAWEI TECH CO LTD

Fault positioning method and device

The invention relates to a method for positioning accidence and relative device. Wherein, said method is characterized in that: first, setting alarm correlation data, according to the alarm analysis factor; then based on said alarm correlation data, processing correlation analysis on the alarm message, to find the source alarm; at least, positioning accidence, based on found source alarm. With said invention, the source alarm can be found from lots of alarm data quickly, to improve the alarm analysis speed and improve the accidence positioning accuracy. And the alarm analysis process is completed by software, to avoid mistake and miss most, therefore, the alarm analysis data is reliable, the accidence positioning is accurate and the labor density is reduced.
Owner:HUAWEI TECH CO LTD

Alarm processing method and device, NMS, OSS, and EMS

The invention provides an alarm processing method and device, an NMS, an OSS, and an EMS. The method comprises the steps: receiving the alarm information from a VNF (virtual network function) application layer and / or virtual resources of the network EMS (element management system), wherein the alarm information comprises the information which is used for determining the VNF and a VM (virtual machine) giving an alarm; determining the VNF and the VM (virtual machine) giving an alarm according to the alarm information; combining an obtained physical resource alarm from an NFVO (network function virtualized orchestrator) according to the determined VNF and VM, and carrying out alarm correlation analysis and processing. The invention solves a problem that the related technology cannot carry out the alarm correlation analysis and cannot determine the root cause of alarm, thereby achieving the alarm correlation analysis after network function virtualization, and determining the root cause of a fault.
Owner:ZTE CORP

Method and apparatus for aggregating alarms and faults of a communications network

A distributed method and system of controlling a communications network having a plurality of spans of interconnected network elements some of which include a network element processor distributes network topology information to respective span databases; stores original fault objects in the respective span databases; advertises fault objects to other network element processors in a local span when the original fault affects network elements other than a network element in which the fault occurred; advertises alarm objects to other network element processors that are respectively associated with a circuit affected by the original faults; stores the advertised fault and alarm objects in the respective span databases; and performs distributed processing of the advertised fault and alarm objects with the other network element processors and the respective span databases. Aggregation of other faults and alarms that may be occurring on the communications network due to other faults other than the received fault aids in determining causality of the fault. Causality may be determined by correlating other faults and alarms with the received fault. If not a root cause of another fault or alarm, the received fault is sympathetic to another fault or alarm. Sympathetic faults are suppressed while root cause faults are promoted to an alarm and reported to affected network elements. The number of alarms viewed by a network manager as well as the reporting of alarms and underlying faults are reduced by performing such distributed alarm correlation and fault reporting suppression.
Owner:CIENA

Method and apparatus for asynchronous alarm correlation

A method and apparatus for providing asynchronous alarm correlation in packet networks are disclosed. For example, the method receives a trigger, and performs an asynchronous correlation of at least one root cause alarm with at least one symptom alarm.
Owner:AT&T INTPROP I L P

Alarm correlation analysis method based on a graph data model

The invention discloses an alarm correlation analysis method based on a graph data model. The alarm correlation analysis method comprises the following steps: step 1, constructing the graph data model: converting a relational database model into the graph data model; Step 2,performing fault marking: when a network fault event or a user complaint event is received, marking a corresponding node inthe graph data model as a fault; Step 3, performing alarm pre-association: taking out the node with the lowest hierarchy from the graph data according to a fault time window, and storing the node in apre-association result set; Step 4, carrying out root alarm association judgment to determine a fault root source: in a pre-association result, when a further association relationship does not exist,determining the corresponding node as the fault root source; And when the further association relationship exists, the node involved in the association relationship is the fault source. According tothe method, the relation model is converted into the graph model, the processing efficiency is improved, the service request can be quickly responded, and the scene of real-time processing and analysis of the network data is effectively supported.
Owner:中电福富信息科技有限公司

Method and apparatus for providing alarm correlation for a gateway router

A method and an apparatus for providing alarm correlation for a gateway router are disclosed. For example, the method receives one or more alarms, wherein each of the one or more alarms having a message signature in accordance with a router redundancy signaling protocol. The method then identifies one or more root causes by correlating the one or more alarms in accordance with the message signatures.
Owner:AT&T INTPROP I L P

Incremental analysis method of optical synchronization transmission network alarm correlation

The invention discloses an incremental analysis method for alarm correlation of an optical synchronous transmission network, which includes the following steps: Step S102, when the path configuration changes or the alarm changes, the analysis data of this time is compared with the analysis data of the last time to obtain Obtaining incremental input data; and step S104 , analyzing and processing according to the incremental input data to determine the root cause alarm, and the derived relationship between the root cause alarm and the non-root cause alarm. The invention can automatically filter out the situation that the non-root alarm is not reported correctly, and further guarantees the accuracy of the analysis.
Owner:ZTE CORP

Method for filtering alarm between network management system and network element management system

A method for making filter alarm between network management system and network element management system includes setting alarm correlation rule including master alarm and auxiliary alarm for network element management system by network management system, judging whether alarm message required to be sent by network element management system is master alarm or auxiliary alarm according to alarm correlation rule, sending alarm message to network management system if it is master alarm or otherwise filtering off said alarm message and not sending it to network management system.
Owner:ZTE CORP

Regulation engine system and method for establishing alarm regulation association

The invention discloses a rule engine system used to set up alarming rule correlation, comprising a rule setting interface engine; a rule engine manager; a timer; and building up alarming correlation with an alarming rule pool. The invention also discloses a method for setting up the alarming rule correlation. In the invention, a novel alarming rule correlation method is provided; the rule engine can play a function in the alarms existing before the rule comes into effect; alarm reporting process and rule engine function process are mutually independent from each other, which improves the real time of alarm reporting and reduces the difficulty of development.
Owner:ZTE CORP

Alarm information reminding method based on wearable device

The invention provides an alarm information reminding method based on a wearable device. The method comprises the steps that communication connection between the wearable device and an automobile meter is established through a wireless mode; the automobile meter sends alarm correlation information to the wearable device after being connected with the wearable device in the wireless mode; according to a preset reminding mode, the wearable device gives an alarm to a user according to the corresponding reminding mode when the alarm correlation information accords with an alarm trigger condition. Compared with a traditional meter reminding mode, by means of the reminding mode, user identification is facilitated, distraction does not exist, and therefore the vehicle driving safety is improved.
Owner:大陆汽车车身电子系统(芜湖)有限公司

Intrusion detection and analysis system on basis of service data flow of virtual machines

InactiveCN104753952AApplicable security defenseImprove robustnessData switching networksService flowData stream
The invention provides an intrusion detection and analysis system on the basis of service data flow of virtual machines. The intrusion detection and analysis system comprises a data acquisition module, an intrusion detection module, a communication interface, an alarm response module and a safety management module. The data acquisition module is used for acquiring audit data when access request operation is started; the intrusion detection module is used for analyzing the acquired audit data and detecting the audit data to determine whether the audit data are intrusion events or not; the intrusion detection module and the data acquisition module are bidirectionally communicated with each other via the communication interface; an intrusion detection system can generate alarm information by the aid of the alarm response module when the intrusion events occur, and the alarm information is transmitted to the safety management module by the aid of the alarm response module, so that the alarm information can be visually displayed; the safety management module is used for combining and scheduling forecasting methods, transmitting access control strategies, the forecasting methods and alarm correlation information to the intrusion detection module, transmitting response strategies to the alarm response module and receiving safety update information transmitted by the alarm response module.
Owner:CHENGDU SHUANGAOYANG TECH
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Patsnap Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Patsnap Eureka Blog
Learn More
PatSnap group products