Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

47 results about "Alarm correlation" patented technology

Equipment fault processing method and system

The invention relates to the technical field of operation and maintenance, and discloses an equipment fault processing method and system. The method comprises the following steps: acquiring alarm messages of a plurality of devices in real time, identifying associated alarm messages caused by the same fault according to an alarm association rule, and compressing the associated alarm messages and an existing fault group to obtain new alarm messages; determining the work order type and the circulation process of the new work order according to the alarm type of the newly sent alarm message, and carrying out order dispatching priority configuration on each process link based on the alarm level of the newly sent alarm message and the pre-configured authority information of each process link; and calling a corresponding work order template based on the work order type, configuring the work order template to generate a new work order, monitoring the full life cycle of the new work order, and synchronously updating the processing state of the new work order. According to the method, the fault processing efficiency of the machine room intelligent connection equipment is effectively improved, resource configuration is optimized through real-time monitoring and data analysis, and the method can meet the fault troubleshooting requirements of equipment of different scales and types.
Owner:CHINA TOWER CO LTD

Multi-source heterogeneous system and method based on liquid air energy storage plant-level monitoring

The invention relates to the technical field of plant-level monitoring systems, in particular to a multi-source heterogeneous system and method for plant-level monitoring based on liquid air energy storage. According to the technical scheme, the method comprises the following steps of S1, collecting and preprocessing multi-source heterogeneous data in real time; s2, constructing a cross-system equipment graph; s3, formulating a hierarchical response intelligent strategy; s31, making a topological graph; s32, according to a hierarchical response strategy, dynamic adjustment is carried out according to the severity degree and the propagation range of the alarm; s33, calculating a weight; and S34, dividing response levels according to the weights. Multi-source heterogeneous data real-time acquisition and preprocessing can align millisecond-level and second-level data streams and eliminate time sequence errors, so that the system alarm association accuracy is improved, six system data formats are unified through JSON structured conversion, the analysis error rate can be reduced, and a basis is provided for large-scale monitoring; a three-flow topology model is established, a key equipment network is constructed, the root cause positioning time is shortened, and the false alarm rate is reduced through a topology weight optimization mechanism.
Owner:ZHONGLU ZHONGKE ENERGY STORAGE TECH CO LTD

Security alarm processing method and device, equipment and storage medium

The invention discloses a security alarm processing method and device, equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: carrying out the data preprocessing of multi-source heterogeneous data, and obtaining security alarm data; identifying the security alarm data through an alarm identification model, and determining an alarm type and a threat level; performing graph construction on the security alarm data through a graph database to generate a security knowledge graph; performing association analysis on the security knowledge graph to obtain attack chain information; and carrying out risk research and judgment on the attack chain information according to the alarm type and the threat level to obtain a comprehensive risk level. According to the method, the security alarm data is identified through the alarm identification model, so that the detection capability of novel attacks can be improved; and meanwhile, alarm correlation analysis is carried out in combination with the constructed security knowledge graph, and potential attack chains and complex attack behaviors are effectively identified, so that the alarm can be deeply analyzed, and the hazard degree of the alarm can be accurately judged.
Owner:STATE GRID HUBEI ELECTRIC POWER INFORMATION & TELECOMMUNICATION COMPANY +1

Fault positioning method, system and device and storage medium

The invention discloses a fault positioning method, system and device and a storage medium, and relates to the technical field of data processing, and the method comprises the steps: collecting alarm data, carrying out the entity relation extraction and link traceability tracking of the alarm data, and obtaining a corresponding text entity relation triple and a potential fault propagation path; performing multi-dimensional alarm association aggregation on the alarm data to generate a corresponding alarm clustering set; and in combination with variable information and multi-dimensional feature values in the text entity relationship triple, performing deep aggregation and association degree evaluation on the alarm clustering set to obtain a target fault set and a corresponding association degree score, and in combination with the association degree score and a potential fault propagation path, positioning a target root cause fault. According to the method, identification and convergence of alarm storm are realized through multi-dimensional alarm association aggregation, and root cause faults are quickly positioned in combination with a fault propagation path and a text entity relationship triple.
Owner:CHINA MERCHANTS BANK

Automatic fault monitoring method and system for operation and maintenance of base station

PendingCN121814544ATransmissionWireless communicationAlarm correlationMonitoring methods
The invention relates to the technical field of mobile communication network operation and maintenance, and discloses an automatic fault monitoring method and system for base station operation and maintenance. The method comprises the following steps: acquiring operation indexes of a base station and performing time sequence analysis to obtain a drift vector; according to the drift vector, track clustering is carried out by adopting a K-means algorithm, and an initial performance baseline is determined to construct a baseline model; deviation is calculated and filtering processing is carried out to obtain a pure residual error sequence; micro degradation modes in the pure residual sequence are identified and aggregated, and an early signal list is obtained; constructing a correlation graph in combination with historical alarm logs, and mining a dependency relationship to obtain a correlation alarm cluster; performing root cause positioning rule fusion and feature aggregation on the cluster to obtain a labeled fault description; and finally, matching the early warning template and determining the priority to obtain final early warning output. According to the method, tiny hidden dangers of base station performance can be effectively identified, the problem that massive alarms are difficult to associate is solved, and early-stage accurate early warning and root cause positioning of faults are achieved.
Owner:GUANGDONG HUIDE TECH DEV CO LTD

An online maintenance and overload control method for a vehicle-mounted multi-source IDS alarm correlation tracking graph

PendingCN122339939AArea networkIn vehicle
This invention discloses an online maintenance and overload control method for multi-source IDS alarm correlation tracing graphs in vehicles. Rule-based intrusion detection systems (IDS) are deployed in the vehicle host domain, vehicle Ethernet domain, and Controller Area Network (CAN) to generate alarms. At the vehicle gateway electronic control unit (ECU) side, multi-source alarms undergo event standardization, sliding time window buffering and waterline out-of-order tolerance, deduplication aggregation, and indexed candidate retrieval. Under the condition of satisfying alarm correlation judgment rules, a directed alarm tracing graph is incrementally constructed. By suppressing forks and overloads through in / out-degree limits, node / edge budgets, and priority pruning, combined with two-stage expiration recycling and tracking record solidification, stable alarm correlation and tracing are achieved under resource-constrained conditions. This method can be used for real-time tracing and offline forensic analysis on the vehicle side.
Owner:ZHEJIANG UNIV +1

Alarm correlation analysis method and device, equipment and storage medium

The invention discloses an alarm correlation analysis method, device and equipment and a storage medium, and relates to the technical field of data processing, and the method comprises the steps: carrying out the feature extraction of target alarm data, and obtaining the multi-mode alarm feature information in the target alarm data; performing alarm data association analysis based on the target alarm data and the multi-modal alarm feature information through a preset alarm association model to generate alarm data association representation; performing clustering analysis on the alarm data association representation, and generating an alarm association group and an alarm attack chain identification result according to a clustering analysis result; and generating an alarm association analysis result based on the alarm association group and the alarm attack chain identification result. According to the technical scheme, the technical problem that in the prior art, a rule-based alarm correlation analysis method depends on manual definition and maintenance of rules, and consequently the efficiency and flexibility of alarm analysis are not high is solved.
Owner:STATE GRID HUBEI ELECTRIC POWER CO LTD

A method, apparatus and device for correlation analysis of alarm events

The application discloses a kind of correlation analysis methods, device and equipment of warning event, the method includes: based on the matching of the obtained warning label in the preset warning correlation analysis rule to warning label group, obtain matching result;According to the matching result, determine warning label set;Based on the warning label set, generate the prompt warning event corresponding to the warning label group of the warning label group.It can be seen that, in the method, a variety of warning events are generated into uniform warning labels, and the warning correlation analysis rules suitable for the uniform format of the warning labels are set to realize the correlation analysis of the warning events generated by various security protection products, output the prompt warning events that have an impact on network security, effectively reduce the number of alarms, improve the accuracy of alarm, and provide reliable basis for the analysis and research of network security by staff.
Owner:QI AN XIN TECHNOLOGY GROUP INC +1

Alarm association method, device, equipment and computer storage medium

The application discloses an alarm correlation method, device and equipment and a computer storage medium, the alarm correlation method comprises the following steps: constructing a training set according to obtained original data, and determining characteristic data of alarm data pairs in the training set; determining all network elements according to the characteristic data, and constructing a network topology graph according to the network elements; determining all network element sequences in the network topology graph, and constructing an alarm correlation model according to network element vectors corresponding to the network element sequences; if an input test alarm data pair is received, performing alarm correlation prediction on the test alarm data pair according to the alarm correlation model, so as to determine an alarm correlation relationship of the test alarm data pair. The application realizes deep mining of alarm data, and improves the correlation effect between correlated alarm data.
Owner:CHINA MOBILE COMM GRP CO LTD +1

A power system multi-modal graph attention attack tracing blocking method and device

The application relates to a power system multimodal graph attention attack tracing and blocking method and device. The method uses alarm data and traffic data to cooperatively match and screen abnormal traffic data. Then, based on an aggregation and clustering mechanism, real attack traffic data is screened out through a non-directional abnormal flow graph, and the accuracy of screening is improved through an attention mechanism. Then, a directional alarm graph associated with alarms is constructed, an initial attack chain is generated based on the directional alarm graph, and the correlation and tracing of fine-grained multi-step attack behaviors are realized. Based on negative causal correlation, nodes in the initial attack chain are pruned to obtain a final attack chain, so that attack blocking is realized. Through multimodal cooperative analysis between the non-directional abnormal flow graph and the directional alarm graph, fine-grained attack behavior tracing is realized, attack chain analysis is performed using a non-causal reasoning method, the causal correlation of alarm types can be ensured, and the dependence on expert knowledge, attack markers and simulation work can be maximally reduced.
Owner:WUQIANG XISHUI POWER PLANT OF WULING ELECTRIC POWER CO LTD

Power grid penetration level coupling alarm association method, system, equipment and medium

The invention belongs to the technical field of power system network security and intelligent power grid operation monitoring, and discloses a power grid penetration level coupling alarm association method, system and device and a medium, and the method comprises the steps: obtaining a suspicious range of an alarm log based on a monitoring host and a time label; constructing an alarm association graph, and performing extraction processing in a local adjacent sub-graph mode to obtain an attack path; constructing a natural language processing mechanism in a classified manner to obtain an attack database; matching and identifying by using a graph matching algorithm with label classification to obtain a network information layer attack event; carrying out delay sampling on abnormal data, carrying out state aggregation by utilizing a prior fault knowledge base, constructing an initial state sequence, and carrying out compression and merging to obtain a target state sequence; and carrying out hierarchical coupling analysis on the network information layer attack event and the target state sequence to obtain an attack event sequence after alarm association. According to the invention, cross-level and multi-stage abnormal alarm association of power grid penetration attacks is realized, and a complete link can be identified and tracked.
Owner:ELECTRIC POWER RESEARCH INSTITUTE OF STATE GRID SHANDONG ELECTRIC POWER COMPANY +2

Security alarm processing method, device, equipment and storage medium

This application discloses a security alarm processing method, apparatus, device, and storage medium, relating to the field of network security technology. The method includes: preprocessing multi-source heterogeneous data to obtain security alarm data; identifying the security alarm data using an alarm identification model to determine the alarm type and threat level; constructing a security knowledge graph from the security alarm data using a graph database; performing correlation analysis on the security knowledge graph to obtain attack chain information; and assessing the risk of the attack chain information based on the alarm type and threat level to obtain a comprehensive risk level. Because this application identifies security alarm data using an alarm identification model, it can improve the detection capability of new attacks; simultaneously, by combining the constructed security knowledge graph with alarm correlation analysis, it effectively identifies potential attack chains and complex attack behaviors, thereby enabling in-depth analysis of alarms and accurate judgment of their severity.
Owner:STATE GRID HUBEI ELECTRIC POWER INFORMATION & TELECOMMUNICATION COMPANY +1

Optical cable network natural language operation and maintenance method and system

The application provides an optical cable network natural language operation and maintenance method and system, belongs to the technical field of optical cable communication, is applied to an optical cable network natural language operation and maintenance system, collects multi-dimensional data including optical cable vibration, temperature, environment, optical power and OTDR link attenuation through an enhanced optical fiber distribution robot of a physical perception layer, encapsulates into a multi-sensing data package MSDP, reports after data alignment relying on clock synchronization, carries out unified semantic modeling, fusion storage and semantic reasoning on the MSDP data package and network resource data, GIS geographic information and service data through a data fusion layer, constructs an optical cable operation and maintenance knowledge graph, receives natural language instructions of operation and maintenance personnel through an application interaction layer, completes intention understanding, knowledge retrieval, task planning and execution scheduling by the intelligent decision layer through multi-agent collaboration, simultaneously carries out alarm correlation analysis and health degree scoring, generates a preventive maintenance work order, and thus reduces the operation and maintenance threshold, improves the fault early warning and emergency recovery efficiency.
Owner:BEIJING RUIQI HAODI TECH CO LTD

Chain attack structure mining method and system based on alarm graph community division and related device

The invention provides a chain attack structure mining method and system based on alarm graph community division and a related device. The method comprises the following steps: step 1, constructing an alarm association graph based on an obtained network alarm log; step 2, performing clustering analysis on the obtained alarm association diagram to obtain an alarm community set; 3, constructing an initial chain attack structure based on the alarm community set; step 4, performing time sequence verification on the initial chain type attack structure to obtain a final chain type attack structure; according to the method, the hidden and multi-step chain attack topological structure can be accurately discovered, the complexity of security analysis is greatly reduced, and the advanced threat discovery capability is improved.
Owner:XI AN JIAOTONG UNIV

Method and device for tracing abnormal change of asset security fingerprint

PendingCN121560699AHardware monitoringFile system administrationAbnormal fingerprintsData mining
The invention provides an asset security fingerprint abnormal change tracing method and device. The asset security fingerprint abnormal change tracing efficiency and accuracy can be effectively improved. The method comprises the steps of collecting at least one fingerprint of a target asset; if the at least one fingerprint collected this time is changed compared with the at least one fingerprint of the target asset collected last time, generating a snapshot according to the at least one fingerprint collected this time, the snapshot being used for recording each changed fingerprint; if the snapshot triggers at least one abnormal change alarm for asset security, a log set associated with the target asset is acquired according to a time period corresponding to an alarm fingerprint associated with each abnormal change alarm, and the log set comprises at least one log; based on the content of the logs in each log set, source information corresponding to each alarm fingerprint is determined, and the source information comprises the account name of the operation body.
Owner:ULTRAPOWER SOFTWARE +1

Attack chain restoration method and device for network end aggregation, and storage medium

The invention discloses a network end aggregation attack chain restoration method and device and a storage medium, and relates to the technical field of data processing. According to the method, the end-side behavior data is matched with the preset attack behavior rule base, the high-probability behavior data conforming to the attack characteristics are screened out, and normal service noise is eliminated from the source; associating the successfully matched end-side behavior with a network-side alarm based on a preset association condition, and excluding an invalid attack attempt which is detected only by the network side but does not fall on the end side by using bidirectional verification that the network side has attack traffic as an evidence and the end side has attack falling empirical evidence; and finally, according to the successfully associated effective alarm events, the attack chain is restored according to the real landing time sequence of the end-side behavior data, so that each node of the attack chain is ensured to be a real attack link which is mutually authenticated by a network end, and the accuracy of attack chain restoration is improved.
Owner:INFORMATION & TELECOMM COMPANY SICHUAN ELECTRIC POWER

Power grid security alarm correlation analysis method based on fuzzy sequence mining

The invention discloses a power grid security alarm correlation analysis method based on fuzzy sequence mining, and belongs to the technical field of power grid alarm. The method is realized through six steps of data access and preprocessing, alarm semantics and structuring, alarm attribute fuzzification, fuzzy sequence pattern mining, association analysis and root cause inference, and situation assessment and alarm output. According to the method, the alarm attributes are fuzzified, a time-ordered fuzzy alarm sequence is constructed, multi-dimensional information such as event level, frequency, duration, disturbance degree and electrical distance is effectively reserved, and the expression ability and robustness of complex events are enhanced. Weighted fuzzy support and confidence are introduced, alarm risk levels, causal roles and time effects are comprehensively considered, accurate recognition of key modes is realized, and false association is reduced. And an alarm relation network is constructed by integrating the electrical distance, the topological structure and the power flow direction, so that causal inference between alarms better conforms to the physical reality of the power grid, and the accuracy of root cause identification is improved.
Owner:STATE GRID GANSU ELECTRIC POWER RESEARCH INSTITUTE

An alarm data correlation analysis method, system, device and medium

The application discloses a kind of correlation analysis methods, systems, devices and media of alarm data, wherein the method obtains several multi-source alarm data;All the multi-source alarm data is extracted to multidimensional feature, and several multidimensional feature vectors are obtained;All the multidimensional feature vectors are dynamically clustered and compressed, and several alarm compression clusters are obtained;The alarm compression cluster includes several alarm cluster points, and the alarm compression cluster records the space-time distribution characteristics of all the alarm cluster points;All the alarm compression clusters are analyzed by graph structure correlation, and the alarm correlation analysis result of the multi-source alarm data is obtained.The method can effectively improve the correlation analysis efficiency and effect of alarm data.The application relates to the technical field of communication network operation and maintenance.
Owner:E SURFING IOT CO LTD

Intelligent video plan generation method and system based on multi-dimensional data fusion

The invention relates to the field of intelligent monitoring, in particular to an intelligent video recording plan generation method and system based on multi-dimensional data fusion, and the method comprises the steps: obtaining historical alarm data of equipment from an Internet of Things platform, obtaining video point position viewing behavior data of a user from a video monitoring platform, obtaining pre-configured spatial association relationship data between the equipment and the video point location; calculating a risk probability that the specified equipment gives an alarm in a future set time period; calculating a user attention score of each video point location in a future set time period, and calculating an alarm association importance score of each video point location based on historical alarm data and the spatial association relationship; integrating the risk probability of the alarm, the attention score and the alarm association importance score, and generating a video recording value score of each video point location in each time period; dynamically generating an intelligent video recording plan by adopting a greedy algorithm based on the video recording value score and the system resource constraint; and the intelligent level of the whole monitoring system is improved.
Owner:INSPUR GENERSOFT CO LTD

Alarm data graph generation method and device and electronic equipment

PendingCN122001742AEffectively identify correlationsEffectively identify causal communication relationshipsTransmissionData graphEngineering
The invention provides an alarm data graph generation method and device, electronic equipment and a computer program product, and belongs to the field of cloud computing. The method comprises the following steps: preprocessing original alarm data; determining an alarm event according to the preprocessed alarm data and generating an alarm event sequence sorted according to time, obtaining a multi-time-granularity alarm sequence database according to the alarm event sequence, and determining a target alarm association pair from the alarm sequence database, performing causal judgment on the target alarm association pair based on a time sequence statistical rule to obtain an alarm propagation relation pair of a network element level; according to a preset generalization rule, mapping network element objects involved in the alarm propagation relationship pair into network element categories with common attributes, and obtaining a generalization alarm propagation relationship of category levels; and generating the alarm data graph according to the generalization alarm propagation relationship.
Owner:CHINA MOBILE GRP HEILONGJIANG CO LTD +1

Traceability analysis method and device for APT attack detection, equipment and medium

The invention provides a traceability analysis method and device for APT attack detection, equipment and a medium, and the method comprises the steps: obtaining an alarm log of an intrusion detection system, and generating an attack scene adjacency matrix based on the alarm log; identifying a causal relationship between different attack behaviors based on the attack scene adjacency matrix to generate a multi-step attack relationship graph; extracting a multi-step attack alarm sequence according to the multi-step attack relation graph; generating an attack target network according to the multi-step attack alarm sequence; and performing attack intention prediction according to the attack target network. Therefore, the attack scene graph is generated by associating isolated alarms, the key attack sequence is extracted by using causal inference, and the dynamically evolved attack target network is constructed, so that the intention of an attacker and a multi-step attack path can be accurately described, and the detection depth and prediction accuracy of a complex APT attack are remarkably improved; and conversion from passive alarm to active threat identification is realized.
Owner:CHINA MOBILE GROUP DESIGN INST +1

IT resource management method and device, storage medium and processor

The invention discloses an IT resource management method and device, a storage medium and a processor. In the scheme, collected multi-dimensional attribute information of enterprise IT resources is converted into a JSON character string, and a hash value corresponding to each resource attribute is calculated; comparing each hash value with a historical hash value to obtain a comparison result; if the comparison result indicates that the data corresponding to the resource attribute is changed, associating the changed data of the resource attribute with an alarm event to obtain alarm association information; calculating a PageRank value of a node related to the alarm associated information through an improved PageRank algorithm by using the resource attribute causal graph model, and determining an alarm root cause matched with the alarm event according to the PageRank value; and generating a corresponding alarm strategy according to the alarm root cause. According to the method, the operation and maintenance closed loop of the IT resources from abnormal perception to root cause repair is realized in an automatic manner, and the operation and maintenance management efficiency of the IT resources is remarkably improved.
Owner:AGRICULTURAL BANK OF CHINA

A repeated alarm analysis method based on a large language model and a knowledge graph

PendingCN122451155ASemantic vectorDatasheet
The application provides a repeated alarm analysis method based on a large language model and a knowledge graph, relates to the technical field of repeated alarm analysis, and comprises the following steps: alarm data preprocessing and entity structuring extraction, knowledge graph construction and semantic vector generation, vector matching retrieval and candidate alarm screening, double-model independent adjudication and conflict decision, and result storage and correlation network visualization. The application can first obtain target alarm original parameters and standardize them, extract entities by using a large language model, and associate the standardized entities with historical alarms; then, a knowledge graph is constructed and incrementally updated, and alarm semantic vectors are generated and stored in a vector library; candidate alarms are obtained through vector matching, and are preliminarily determined by a first semantic determination model; then, the candidate alarms are independently reviewed according to core correlation and strict investigation rules by a second model, and when conflicts occur, the second result is used as the criterion and logs are recorded; finally, the determination results are written into a special data table, and a visual alarm correlation network graph is generated based on the knowledge graph.
Owner:BEIJING RUIPING INFORMATION TECH CO LTD

Alarm data processing methods, devices, electronic equipment and storage media

ActiveCN118612041BTelevision systemsTransmissionData miningAlarm correlation
This invention provides a method, apparatus, electronic device, and storage medium for processing alarm data, relating to the field of data processing technology. The method includes: acquiring alarm data for Internet Protocol Television (IPTV); grouping the alarm data to obtain several alarm data groups; constructing frequent itemsets and corresponding alarm association rules based on the alarm data, and filtering the alarm association rules to obtain a first alarm association rule that meets certain conditions; counting the number of users with poor quality corresponding to the alarm data groups under the first alarm association rule, and performing critical processing on the first alarm association rule based on the number of users with poor quality to obtain a second alarm association rule for ITV. The second alarm association rule is the root cause of alarms for ITV anomalies, thereby improving the accuracy of the alarm association rule and providing effective support for subsequent fault location, so as to improve the efficiency and accuracy of fault location.
Owner:CHINA TELECOM CORP LTD

Optical transport network alarm prediction method and device

The application provides an optical transmission network alarm prediction method and device, and relates to the technical field of data processing. The method comprises the following steps: acquiring performance monitoring data of an optical transmission network device and reported alarm information; performing alarm correlation processing and alarm label extraction according to the alarm data to obtain an alarm label vector; and performing alarm prediction through a random forest after aligning the performance data and the alarm label vector.
Owner:BEIJING UNIV OF POSTS & TELECOMM

A communication network fault locating system and method based on big data analysis

ActiveCN118677759BTransmissionNetwork managementAlarm correlation
The application belongs to the technical field of communication network, and particularly relates to a communication network fault positioning system and method based on big data analysis, which comprises an offline training module and an online training module, wherein the offline training module and the online training module each comprise a data acquisition unit, a data cleaning unit, a modeling analysis unit, an optimization iteration unit and a model evaluation unit; the offline training module and the online training module are connected to a network management server and run relying on a network management system; each unit of each module is composed of atomized capabilities, realizing front-end and back-end separation, supporting high concurrency and atomized capability assembly; the alarm distinguishing and chaining mechanism of the fault root network element proposed in the scheme can realize the disclosure of part of alarms to after-sales service parties, realize intelligent alarm correlation compression and rapid fault positioning under a cloud network, and effectively solve the problems of insufficient manual operation and maintenance experience, difficult fault positioning, low processing efficiency and difficult customized service under a new cloud network.
Owner:湖南省通信网络保障中心

Network fault diagnosis method and device, electronic equipment and storage medium

The invention discloses a network fault diagnosis method and device, electronic equipment and a storage medium. The method comprises the steps of obtaining alarm data of a to-be-diagnosed network, topological structure information of equipment in the to-be-diagnosed network and an alarm-related product document of the equipment; based on the alarm data and the topological structure information, frequent alarm co-occurrence mode mining is carried out through a preset association rule mining algorithm, and an alarm association triple is obtained; determining an alarm pair set based on the topological structure information and the alarm data, and generating a first conduction relation triple through a pre-trained first large language model based on the alarm pair set and a first preset prompt word; based on the product document, carrying out knowledge graph mining, and determining a second conduction relation triple; and constructing a three-channel knowledge graph based on the alarm association triad, the first conduction relation triad and the second conduction relation triad, and performing network fault diagnosis based on the three-channel knowledge graph to obtain target fault diagnosis information.
Owner:CHINA MOBILE GROUP ZHEJIANG +2

Abnormal sensing method and system for APT threat

The invention discloses an anomaly perception method and system for APT threat, and belongs to the technical field of network information security, and the method comprises the steps: mining alarm associated information in a layered manner from the log data of machine room networking and a network flow, and constructing a traceability graph; performing virus sensing on all node layers of the traceability graph, and identifying suspicious nodes, abnormal nodes and healthy nodes; specifically, first-layer anomaly recognition based on static analysis is carried out on all nodes, abnormal nodes are preliminarily recognized, second-layer anomaly recognition based on dynamic analysis and atlas analysis is carried out on preliminarily recognized non-abnormal nodes, and potential risk nodes, healthy nodes and abnormal nodes are recognized; third-layer anomaly recognition based on a classification model is carried out on the potential risk nodes, and final classification of the potential risk nodes is output; and according to the identified node type, self-adaptively sending a response measure. According to the invention, the threat discovery capability can be improved, and the precision, stability and expandability of anomaly perception can be improved.
Owner:CHINA TELECOM DIGITAL INTELLIGENCE TECH CO LTD