CN101883375B - Network monitoring method and system thereof - Google Patents

Network monitoring method and system thereof Download PDF

Info

Publication number
CN101883375B
CN101883375B CN 200910083877 CN200910083877A CN101883375B CN 101883375 B CN101883375 B CN 101883375B CN 200910083877 CN200910083877 CN 200910083877 CN 200910083877 A CN200910083877 A CN 200910083877A CN 101883375 B CN101883375 B CN 101883375B
Authority
CN
China
Prior art keywords
terminal
information
session
network side
network
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN 200910083877
Other languages
Chinese (zh)
Other versions
CN101883375A (en
Inventor
杨晓范
王文明
吴晓梅
曹秦峰
盛凌志
杜建凤
赵鑫
李智伟
赵新宁
姜欣
乔琳
高羽
马志良
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Mobile Group Beijing Co Ltd
Original Assignee
China Mobile Group Beijing Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Mobile Group Beijing Co Ltd filed Critical China Mobile Group Beijing Co Ltd
Priority to CN 200910083877 priority Critical patent/CN101883375B/en
Publication of CN101883375A publication Critical patent/CN101883375A/en
Application granted granted Critical
Publication of CN101883375B publication Critical patent/CN101883375B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention discloses a network monitoring method and a network monitoring system to solve the problems that the processes for performing analysis and fault elimination in the current network optimization and fault treatment flows have low real-time, poor accuracy and low efficiency. The network monitoring method provided by the invention comprises the following steps that: a network side receives session information reported by each terminal when sessions performed by the terminals respectively have abnormal events; according to the session information reported by a first terminal in the terminals, the network side acquires network side signaling information, which is received and transmitted during the time when the session information reported by the first terminal happens and belongs to corresponding sessions of the terminal, from acquired signaling information received and transmitted by a network side network element; and the network side performs fault analysis according to the session information reported by the first terminal and the acquired network side signaling information.

Description

A kind of method for monitoring network and system thereof
Technical field
The present invention relates to the communications field, relate in particular to a kind of method for monitoring network and network monitoring system.
Background technology
Development along with mobile communication technology; Particularly the third generation (3G) mobile communication is in the large-scale commercialization of China; How when guaranteeing networking; Promote network quality rapidly, satisfy growing professional diversity of user and high reliability demand, become the problem that mobile communications network must solve.
In order to promote service quality, the network optimization and the troubleshooting process of mobile communication carrier are as shown in Figure 1.Can find out through flow process shown in Figure 1; After receiving customer complaint; Network operation carries relevant drive test terminal with the optimization personnel or tester carries out the analog service testing; Complain on-the-spot call information with analog subscriber, through external equipment end side testing data are derived then, to obtain the call information and relevant terminal and the radio signal quality and the network information; Simultaneously; The attendant of network side is through loading signaling tracing appearance and relevant monitoring equipment; According to testing time and testing scope, read measurement report (MR), A/Abi mouth or Iu mouth relevant information or signaling, the data of obtaining with the terminal drive test are again carried out the manual work comparison; Find the mistake of call exception or certain network entity, thereby be that the network optimization and incident investigation, customer complaint solution provide foundation.
Can find out, analyze in the existing network optimization and the troubleshooting process, there is following defective in the process of malfunction elimination:
(1) promptness is poor.Analyze with the malfunction elimination process in; Be the data that read through terminal data that drive test is collected and relevant interface for according to analyzing from network element; Because complain and carry out drive test on the spot receiving the terminal use, to analyzing and malfunction elimination through manual type, required time is longer again; Be unfavorable for dealing with problems fast, thereby influence the customer service impression.
(2) poor accuracy.Analyze with the malfunction elimination process in, on the one hand, that sight real-time constantly takes place is poor because the terminal data that obtains of drive test is because of being difficult to reproduce fault, causes with this as according to the accuracy reduction of analyzing resulting result; On the other hand and since analyze with the malfunction elimination process through the manual work realization, it is bigger influenced by human factor, accuracy that also can the impact analysis result.
(3) terminal data that collects is poor with the data dependence that reads from the relevant interface of network element device.Because the acquisition terminal data are to carry out respectively with process from the relevant interface reading of data of network element device; Promptly monitor respectively; Thereby the terminal data that causes collecting is poor with synchronization of data property and correlation that relevant interface from network element device reads, and then the accuracy of increase accident analysis difficulty, impact analysis.
(4) efficient is low.Undertaken by manual type owing to analyze, so the efficient that causes analyzing with malfunction elimination is lower with malfunction elimination.
Summary of the invention
The embodiment of the invention provides a kind of method for monitoring network and system thereof, analyzes in order to solve in existing network optimization and the troubleshooting process, the existing real-time of process of malfunction elimination is low, poor accuracy and inefficient problem.
The method for monitoring network that the embodiment of the invention provides comprises:
The session information that network side reports when receiving the session generation anomalous event of carrying out separately at each terminal;
Network side is according to the session information of first terminal to report in the said terminal, from the signaling information that the network side network element that collects is received and dispatched, obtains network side signaling information that received and dispatched, that belong to this corresponding session in terminal in the time that the session information at first terminal to report takes place;
Network side is with the session information of first terminal to report and the network side signaling information that gets access to; Signaling according in the standard signaling process of time sequencing that takes place and corresponding session is compared one by one; If the session information of first terminal to report and standard signaling process not exclusively mate, then confirm to cause the main cause that said anomalous event takes place to be first terminal; If network side signaling information that gets access to and standard signaling process not exclusively mate, then confirm to cause the main cause that said anomalous event takes place to be network side.
The network monitoring system that the embodiment of the invention provides comprises:
Receiver module, the session information that reports when being used to receive the session generation anomalous event of carrying out separately at each terminal;
Acquisition module; Be used for session information, from the signaling information that the network side network element that collects is received and dispatched, obtain network side signaling information that received and dispatched, that belong to this corresponding session in terminal in the time that the session information of first terminal to report takes place according to first terminal to report at said terminal;
Analysis module; Be used for the session information of first terminal to report and the network side signaling information that gets access to; Signaling according in the standard signaling process of time sequencing that takes place and corresponding session is compared one by one; If the session information of first terminal to report and standard signaling process not exclusively mate, then confirm to cause the main cause that said anomalous event takes place to be first terminal; If network side signaling information that gets access to and standard signaling process not exclusively mate, then confirm to cause the main cause that said anomalous event takes place to be network side.
In the above embodiment of the present invention; Network side is through receiving the session information that each terminal reports when the session generation anomalous event; And with this as foundation; From the signaling information that the network side network element that collects is received and dispatched, obtain signaling information that received and dispatched, that belong to this corresponding session in terminal in the time that the session information of terminal to report takes place, the session information according to terminal to report carries out accident analysis with the signaling information that gets access to then.Can find out; Because network side carries out the session information that the foundation of accident analysis comprises the terminal real-time report; And the signaling information of the network side corresponding session that network element is received and dispatched in corresponding time of collecting; And correlativity between them and data sync property are higher, thereby the precision of analysis that obtains is higher; In addition, network side carries out accident analysis and carries out through network side with investigation, thereby has reduced the influence of human factor to the analysis result accuracy, and has improved the efficient of accident analysis and investigation; In addition, since network side acquisition terminal data, the process of carrying out accident analysis and investigation do not need artificial the participation, thereby improved the promptness of accident analysis and investigation.Have, network side can receive the session information that each terminal reports when session is unusual again, thereby can comparatively comprehensively obtain fault message, thereby can more comprehensively foundation be provided for the network optimization, makes the network optimization reach better effect.
Description of drawings
Fig. 1 is the network optimization of the prior art and troubleshooting process sketch map;
Fig. 2 is the related network architecture sketch map of the embodiment of the invention;
The structural representation of the network monitoring system that Fig. 3 provides for the embodiment of the invention;
Fig. 4 carries out the schematic flow sheet of monitoring analysis according to the information of terminal to report for the network monitoring system that the embodiment of the invention provided;
Fig. 5 is the related relevant signaling process sketch map of the session information of terminal to report in the embodiment of the invention;
The schematic flow sheet of reporting information when unusual takes place in the terminal that Fig. 6 provides for the embodiment of the invention;
Fig. 7 is the event monitoring schematic flow sheet at the terminal in the embodiment of the invention.
Embodiment
In the embodiment of the invention; Network side is provided with network monitoring system; This system can receive the session information of each terminal to report; And carry out network monitoring and analysis according to the relevant information that belongs to this terminal that the respective network elements that the session information and the signal collecting equipment of terminal to report collects from each network element of network side is received and dispatched, with locating network fault, phase-split network performance and service quality etc., thereby foundation is provided for the network optimization.Network monitoring system can be arranged in the existing network management system equipment, also can be independent of existing network management system equipment.
Below in conjunction with accompanying drawing the embodiment of the invention is described in detail.
Referring to Fig. 2, be the related network architecture of the embodiment of the invention, this framework comprises: network monitoring system place equipment, mobile communications network 1, and terminal (1,2 ... N).Wherein, but the speech and the data service of mobile communications network 1 support terminal; In mobile communications network 1, be provided with signal collecting equipment; This signal collecting equipment mainly is responsible for the ruuning situation of the various network elements in the mobile communications network 1 is monitored; Obtain key network element; Like RNC (Radio Network Controller, radio network controller) or/and MSC the signaling information of each network element interfaces such as (Mobile Switch Center moves letter in the exchange) and core net; There are communication interface in this signal collecting equipment and network monitoring system, can the signaling information that collect be provided to network monitoring system through this interface., the terminal can report relevant session information to network monitoring device when monitoring the anomalous event in the session through mobile communications network 1; After network monitoring system equipment receives the session information of terminal to report; The signal collecting equipment that can from mobile communications network 1, be provided with obtains relevant signaling information, and compares analysis with the session information of terminal to report.If mobile communications network 2 is also supported at the terminal; Then the terminal can be at the needs reporting information but mobile communications network 1 when unavailable, and the session information that needs is reported through mobile communications network 2 sends to network monitoring system place equipment (data transfer path shown in dotted line among the figure).
Referring to Fig. 3, the structural representation of the network monitoring system that provides for the embodiment of the invention, this network monitoring system can comprise receiver module 301, acquisition module 302, analysis module 303, also can comprise output module 304, wherein:
Receiver module 301, the main session information of being responsible for receiving each terminal to report;
Acquisition module 302, the main session information of being responsible for according to terminal to report, the signaling that the related network elements that collects from signal collecting equipment is received and dispatched, obtain with this terminal and with the information of this terminal to report under the relevant signaling information of session;
Analysis module 303, main being responsible for according to the session information of terminal to report and the signaling information that gets access to from signal collecting equipment compares analysis with the standard signaling process of corresponding session, obtains analysis result, to get rid of as fault or the foundation of the network optimization;
Output module 304, main being responsible for outputs to output equipment with the analysis result of analysis module 303, as outputs to screen display device and carry out screen display, perhaps outputs to PRN device and prints output etc., so that display analysis result more intuitively.
Referring to Fig. 4, carry out the schematic flow sheet of monitoring analysis according to the session information of terminal to report for the network monitoring system that the embodiment of the invention provided.In the present embodiment, the terminal reports the session information relevant with anomalous event in the time of can in the session implementation, anomalous event taking place.The associated session signaling that can comprise terminal iidentification, session identification, anomalous event in the session information of terminal to report also can comprise other information such as positional information or geographical location information of the place network at terminal.As; Session to the calling procedure at terminal; Reporting information can comprise MSISDN (Mobile Station Integrated Services Digital Number; Mobile site integrated service digital coding), IMSI (International Mobile SubscriberIdentifier; International mobile subscriber identifier), call out the cell ID (cell ID) that takes place, LAC ID (the Location Area Code that calls out generation; Location Area Code), the URNTI of this calling (UTRAN Radio Network Temporary Identity; UMTS grounding wireless access network Radio Network Temporary Identifier, this parameter is applicable to 3G network), the signaling of conversation time started, end of conversation time, terminal GPS (Global Positioning System, global position determination system) geographical location information and communication process.Network monitoring system carries out the flow process of monitoring analysis according to the information of terminal to report, mainly comprises:
The session information that step 401, network monitoring system receiving terminal report, and start the network monitoring handling process according to the session information of terminal to report.
In this step, after the receiver module 301 of network monitoring system receives the information of terminal to report, can trigger corresponding network monitoring handling process.Because network monitoring system can receive the information of each terminal to report, therefore, in order to improve analyzing and processing efficient, receiver module 301 can adopt corresponding network monitoring treatment progress to carry out the network monitoring processing by corresponding different terminals, so that realize parallel processing.
Step 402, network monitoring system retrieve relevant network side signaling information according to the session information of terminal to report from the signaling information that signal collecting equipment is collected.
In this step; The terminal iidentification that the acquisition module 302 of network monitoring system carries in can the session information according to terminal to report; Like MSISDN or/and IMSI; And, from the signaling that signal collecting equipment collects, retrieve the signaling of the corresponding session that belongs to this terminal of each network element in this time period (like RNC or/and MSC) transmitting-receiving according to the time that each session signaling in the session information of terminal to report takes place the earliest and the latest.Further; If in the session information of terminal to report, carry the positional information of this place, terminal network; Like CELL ID or/and LAC ID; Then acquisition module 302 can be at first according to CELL ID or/and LAC ID orients to the RNC of this terminal service MSC so that from a plurality of RNC of signal collecting equipment collection or/and orient relevant RNC the MSC or/and MSC, thereby dwindle range of search, improve recall precision.If the terminal can report GPS information, the GPS information that network monitoring system can be through terminal to report and the map navigation system of configuration, the RNC that navigates to this terminal more accurately and belonged to is or/and MSC.
The session identification that acquisition module 302 carries in also can the session information according to terminal to report; Like URNTI; From the signaling information that signal collecting equipment collects, orient corresponding session; This mode is applicable to 3G network, because therefore the unique respective session of URNTI in the 3G network can retrieve the session signaling corresponding with the session information of terminal to report as foundation with URNTI from the signaling information that collecting device collects.Acquisition module 302 can also be initiated the time and the concluding time is located corresponding session according to session; This mode is applicable to the 2G network; Because in the 2G network; The conversation start time can identify a session, therefore can from the signaling information that collecting device collects, retrieve the session signaling corresponding with the session information of terminal to report as foundation with the conversation start time.
Through this step; The terminal iidentification that carries in the session information of network monitoring system according to terminal to report, time, the session identification that session signaling took place retrieve the corresponding conversation procedure pairing signaling of this terminal in the corresponding time period from the signaling information of signal collecting equipment collection.
Step 403, network monitoring system compare according to the session information of terminal to report and the network side signaling information that is retrieved from signal collecting equipment, thereby obtain analysis result, with the foundation as the network optimization or fault eliminating.
In this step, the analysis module 303 of network monitoring system can confirm that through compare of analysis reporting information by terminal is to cover unusually or from other cause specifics from wireless network, thereby realizes the fault location and the analysis of causes.In analytic process; But the geographical location information that carries in the information that reference terminal reports (like the GPS geographical location information) analysis reports the distribution of terminal on the geographical position of anomalous event; Thereby foundation is provided for the fault location and the analysis of causes; As, if great amount of terminals generation anomalous event and reporting information in certain geographical regional extent, then can tentatively judge the network equipment failure of this geographic area.
This process can be: analysis module 303 is reference with the standard signaling of the pairing session flow process of the session signaling of terminal to report; The relevant signaling of the session signaling of terminal to report and the network side that retrieves and this are carried out 1 pair 1 compare of analysis with reference to signaling process; Be equivalent to the relevant signaling with the network side that retrieves of session signaling of terminal to report is arranged according to the time sequencing of signaling, and every signaling in the signaling flow that will obtain after will arranging and every signaling in the standard signaling flow are compared one by one.The result of comparison possibly comprise with corresponding fault: the signaling of terminal to report has disappearance, or, in the signaling of terminal to report failure response is arranged, then specification exception occurs in end side probably; The relevant signaling that retrieves has and lacks, or, in the relevant signaling that retrieves failure response is arranged, then specification exception occurs in network side probably; Further, can determine according to comparison result and Heuristics and possibly cause unusual reason.
Setting up flow process with RRC is example; The signaling process (comprising the signaling shown in the dotted line) as shown in Figure 5 that the RRC of standard sets up; But with the session signaling of terminal to report and the network side signaling that retrieves from signal collecting equipment according to time sequencing, one by one with signaling process shown in Figure 5 signaling compare after; The signaling of finding terminal to report lacks the signaling shown in the dotted line, therefore can confirm that possibly there is fault in this terminal.If being this terminal access 3G network process, this RRC related procedure of terminal to report takes place; Then because this 3G network is not also successfully inserted at this terminal; Its session information report flow carries out through other networks, as reporting this session signaling through the 2G network.If this moment, the 2G/3G network was all unavailable, but then report in arbitrary network time spent.
This network monitoring system also can be exported analysis result after obtaining analysis result.
Need to prove; The network monitoring system that the embodiment of the invention provided can mainly be realized by software; Its functional module dividing mode is not limited to each above-mentioned functional module, and any network monitoring system with above-mentioned functions all should be within protection scope of the present invention.
Owing to relate to the process that reports related session information when the terminal in the session implementation anomalous event takes place in the embodiment of the invention, below provide a kind of mode of terminal to report session information.
Referring to Fig. 6, the schematic flow sheet of reporting information when unusual takes place in the terminal that provides for the embodiment of the invention, when the terminal makes a call or carries out specific transactions when connecting, carries out following steps:
The session that step 601, terminal monitoring are initiated, recording conversation information is also preserved.
In this step, to a certain session that initiate at the terminal, the terminal is according to the signalling interactive process in this session of session identification record, and content recorded can comprise the time of session identification, signaling sign and signaling content and generation.
Step 602, terminal are analyzed the session information of preserving, and judge whether anomalous event to be directed against the session of being monitored, if take place unusually, then execution in step 603 if taking place; Otherwise, continue the session that initiate at the terminal is monitored.
In this step,, do not send the connection interrupting information, then be judged as the improper situation of appearance, need carry out information reporting like terminal in call flow if the current ongoing professional improper situation that occurs is judged at the terminal.In 3G standard; (RRC connects Release complete to RNC loopback RRC Connection Release Complete message at the terminal; Be equivalent to aforesaid connection interrupting information) discharge to confirm that RRC connects; Show that session normally hangs up, and if the terminal does not have loopback Connection Release Complete message, show that then session is unusual.For another example, the terminal receives because of network side causes returning the response message that terminal traffic is busy or fail unusually, also can think professional the appearance unusually.
Step 603, terminal generate reporting information according to the generation of anomalous event.
In this step, after anomalous event that trigger message reports judge to take place according to the session information of record at the terminal, extracted the information of preserving at the terminal, forms reporting information.
Step 604, terminal report the reporting information of generation to network side.
In this step, information reporting can be carried out according to the information reporting cycle that is provided with in advance in the terminal, also can after generating reporting information, report immediately.According to the information reporting periodic report that is provided with in advance the time, if arrive the information reporting cycle, and information reporting is then carried out when having generated the information that need report in this terminal; When if the currently used access network in terminal is because of reasons such as network is unusual unavailable (as do not connect or network signal intensity is lower than setting threshold) when the information reporting cycle arrives; Can keep in the information that need report, wait until that next report cycle carries out information reporting again when arriving; In the time of also can supporting other access networks, switch to other access networks and upload information at this terminal.During the mode that after adopt generating reporting information, reports immediately,, can keep in the information that need report, but wait until that the currently used access network time spent carries out information reporting again if the currently used access network in terminal is unavailable because of reasons such as network are unusual; In the time of also can supporting other access networks, switch to other access networks and upload information at this terminal.
When carrying out information uploading, terminal and network side server are set up and reliably are connected, and the information uploading that can need be reported through PS (packet domain) or INTERNET (the Internet) is to network side.Behind reporting information, the relevant information of preservation can be removed in the terminal, preferably, after receiving the affirmation information that network side is replied, carries out clear operation again.
In the above-mentioned flow process, the terminal can adopt following mode to generate and reporting information:
Mode one: the terminal to report anomalous event takes place to rise constantly to push ahead sets the session information that is write down in the duration, specifically can realize through following process:
Corresponding event monitoring flow process is set up at first in business in the terminal, through this event monitoring flow process the various information of business processing flow is preserved and is extracted.As shown in Figure 7, T0 is the conversation zero hour constantly, and then the event monitoring flow process is in the T1 various mutual signaling that rises constantly of the T0 of opening entry current business session constantly.When TT takes place constantly, (should send RRCConnection Release Complete message constantly and actual not transmission at TT like the terminal) when anomalous event, the event monitoring flow process writes down TT session information constantly constantly at TT1.Then; The service conversation information that the event monitoring flow process is write down T1 to TT1 constantly (being the session information that the terminal current business is taken place at T0 to TT constantly, part shown in the figure bend), the information such as terminal iidentification, terminal location of adding generate reporting information; But detect the network PS field time spent constantly at T2; The reporting information that generates is uploaded to network side, then can remove, to save the storage overhead at terminal for the session information that need not report.Further,, can the information that needs report be divided into multiple messages and report, to reduce influence network performance if the amount of information that reports is bigger.Delay the mode of preserving session information through the event monitoring flow process; Can make session information that the terminal preserves by taking place constantly detecting anomalous event; Because the session flow process after usually anomalous event takes place is little to the meaning of analysing terminal or network failure, performance, service quality etc.; Thereby there is not the necessity of preserving; Therefore can save the storage overhead at terminal, also can guarantee that network side carries out the accuracy that fault, performance, service quality etc. are analyzed with this form the basis simultaneously to a certain extent.
Further; T1 is to Chang Du ⊿ of the time between TT1 T! ⊿ T=TT1-T1) can be made as fixed value; This just means; If conversation is played anomalous event constantly from T0 the time span Da Yu ⊿ T of TT constantly taking place, then only gets from TT1 and report Xiang the session information that Qian Tui Jin ⊿ T time span is preserved constantly.Like this; If the time that talk business is carried out is when longer, the information that is reported only is that anomalous event takes place for the previous period! ⊿ T) session information, rather than all session informations when session begins; Thereby reduce the amount of information that reports, reduce expense Internet resources.
If the disposal ability at terminal allows; This terminal also can be analyzed and screen according to the session information that is write down in the filtering rule Dui ⊿ T time span that is provided with in advance, therefrom selects the key message that perhaps extracts in the session information with the closely-related session information of anomalous event and reports.Wherein, Filtering rule can be according to the correlation setting of anomalous event and session information; And the correlation of anomalous event and session information can define according to concrete session flow process and fault, method for analyzing performance in advance; For example, the failure response message that the network side that the terminal receives sends can be used as and the closely-related message of anomalous event, and failure cause code wherein can be used as the key message of this message.Like this, can one side accurate foundation be provided, can reduce reporting information on the one hand again, thereby reduce system resource overhead for the analysis that network side carries out fault, performance etc.
Mode two: the session signaling of getting setting quantity forward takes place to rise constantly and reports in the terminal to report anomalous event, if the session information of this setting quantity is 10 signalings, then this mode specifically can realize through following process:
Corresponding event monitoring flow process is set up at first in business in the terminal, and is as shown in Figure 7, and T0 is the conversation zero hour constantly, then the various mutual signaling that rises constantly at the T0 of T1 opening entry current business session constantly of event monitoring flow process.When anomalous event when TT takes place constantly, the event monitoring flow process writes down TT session information constantly constantly at TT1.Then, the event monitoring flow process is with 10 nearest signalings that TT1 was write down constantly, and the information such as terminal iidentification, terminal location of adding generate reporting information, upload to network side constantly at T2, then can remove for the session information that need not report.Further, if the amount of information that reports is bigger, can the information that needs report be divided into multiple messages and reports.
In like manner, if the disposal ability at terminal allows, this terminal also can be analyzed and screen the session information that TT1 write down constantly according to the filtering rule that is provided with in advance, any session information after the screening is reported.
Mode three, terminal to report anomalous event take place to play the session signaling of getting the setting data amount forward constantly and report; The data volume of for example setting is the 10K data volume, and its implementation and mode two are similar, and difference is; In mode two; Be 10 signalings of going bail for forward constantly and depositing, and be some the signalings of going bail for forward constantly and depositing in the mode three, but the total amount of data of signaling is no more than the 10K size from TT1 from TT1.
In the step 601 of above-mentioned flow process; The conversation type that needs to detect and write down can comprise the session that is triggered the related procedure of execution by the terminal use; As the call flow when starting shooting, also can be the session that does not need the related procedure that the terminal use triggers, like the network switching flow.Need detecting and the session of record can be all types session that the terminal is supported, also can be specific certain or certain several types session.
Need to prove that the information content of terminal to report comprises the related session information of session identification, terminal iidentification and anomalous event at least, also can comprise one of following information or combination in any:
The information of relevant physical layer is like measurement report (MR);
The information of related network layer, like CELL ID, LAC ID, adjacent cell relation information etc.;
The information of relevant application layer like Traffic type, comprises note, multimedia message etc., can be used for locating and analyzing the Traffic type that breaks down;
Other information are like the GPS geographical location information at terminal etc.
If carry MR in the information of terminal to report; The network monitoring system that then embodiment of the invention provided also can obtain network performance and other statisticss that network element device generated in the corresponding time from signal collecting equipment; And compare analysis with the MR of terminal to report, with foundation as the network failure analysis or the network optimization.
Obviously, those skilled in the art can carry out various changes and modification to the present invention and not break away from the spirit and scope of the present invention.Like this, belong within the scope of claim of the present invention and equivalent technologies thereof if of the present invention these are revised with modification, then the present invention also is intended to comprise these changes and modification interior.

Claims (12)

1. a method for monitoring network is characterized in that, may further comprise the steps:
The session information that network side reports when receiving the session generation anomalous event of carrying out separately at each terminal;
Network side is according to the session information of first terminal to report in the said terminal, from the signaling information that the network side network element that collects is received and dispatched, obtains network side signaling information that received and dispatched, that belong to this corresponding session in terminal in the time that the session information at first terminal to report takes place;
Network side is with the session information of first terminal to report and the network side signaling information that gets access to; Signaling according in the standard signaling process of time sequencing that takes place and corresponding session is compared one by one; If the session information of first terminal to report and standard signaling process not exclusively mate, then confirm to cause the main cause that said anomalous event takes place to be first terminal; If network side signaling information that gets access to and standard signaling process not exclusively mate, then confirm to cause the main cause that said anomalous event takes place to be network side.
2. the method for claim 1 is characterized in that, saidly from the signaling information that the network side network element that collects is received and dispatched, obtains corresponding network side signaling information, is specially:
If carry the sign at first terminal and the session identification of unique identification session in the session information of said first terminal to report; Then, from the signaling information that the network side network element that collects is received and dispatched, obtain corresponding with the sign at said first terminal, corresponding with said session identification network side signaling information according to said first terminal iidentification and session identification.
3. the method for claim 1; It is characterized in that; Carry terminal iidentification and conversation start temporal information in the session information of said first terminal to report, from the signaling information that the network side network element that collects is received and dispatched, obtain corresponding network side signaling information, be specially:
According to said first terminal iidentification and conversation start temporal information, from the signaling information that the network side network element that collects is received and dispatched, obtain corresponding with said first terminal iidentification, with corresponding network side signaling information of said conversation start time.
4. like claim 2 or 3 described methods; It is characterized in that; Also carry the positional information of the place network at this terminal in the session information of said first terminal to report, from the signaling information that the network side network element that collects is received and dispatched, obtain corresponding network side signaling information, be specially:
At first orient corresponding network side network element, from the signaling information that this network element that collects is received and dispatched, obtain the corresponding network side signaling information again according to the positional information of the place network at first terminal.
5. like claim 1,2 or 3 described methods, it is characterized in that first terminal reports session information when the session generation anomalous event that it carries out, comprising:
The information of this ongoing session in terminal is preserved at first terminal;
When in the said session implementation anomalous event taking place, first terminal generates information to be reported, and reports said information to be reported according to the session information that this anomalous event generation rises constantly, preserves before this.
6. method as claimed in claim 5 is characterized in that, the session information that said anomalous event generation rises constantly, preserves before this is specially:
Said anomalous event takes place to rise constantly, the interior session information of being preserved of setting duration before this; Perhaps
The session information of the setting quantity that said anomalous event generation rises constantly, preserved before this; Perhaps
The session information of the setting data amount that said anomalous event generation rises constantly, preserved before this.
7. method as claimed in claim 5; It is characterized in that; Generate before the information to be reported, also comprise:, from the session information that anomalous event takes place constantly, preserves before this, filter out and the closely-related session information of said anomalous event according to the filtering rule of setting;
Said generation information to be reported is specially: generate information to be reported according to the session information that filters out.
8. method as claimed in claim 5 is characterized in that, said terminal begins to preserve the session information that said session rises the zero hour after said session postpones a period of time zero hour.
9. a network monitoring system is characterized in that, comprising:
Receiver module, the session information that reports when being used to receive the session generation anomalous event of carrying out separately at each terminal;
Acquisition module; Be used for session information, from the signaling information that the network side network element that collects is received and dispatched, obtain network side signaling information that received and dispatched, that belong to this corresponding session in terminal in the time that the session information of first terminal to report takes place according to first terminal to report at said terminal;
Analysis module; Be used for the session information of first terminal to report and the network side signaling information that gets access to; Signaling according in the standard signaling process of time sequencing that takes place and corresponding session is compared one by one; If the session information of first terminal to report and standard signaling process not exclusively mate, then confirm to cause the main cause that said anomalous event takes place to be first terminal; If network side signaling information that gets access to and standard signaling process not exclusively mate, then confirm to cause the main cause that said anomalous event takes place to be network side.
10. system as claimed in claim 9; It is characterized in that; When if said acquisition module obtains signaling information; If carry the sign at first terminal and the session identification of unique identification session in the session information of said first terminal to report; The sign and the session identification at first terminal of then carrying in the session information according to said first terminal to report obtain corresponding with the sign at said first terminal, corresponding with said session identification network side signaling information from the signaling information that the network side network element that collects is received and dispatched.
11. system as claimed in claim 9; It is characterized in that; When said acquisition module obtains signaling information; The sign at first terminal of carrying in the session information according to said first terminal to report and conversation start temporal information, from the signaling information that the network side network element that collects is received and dispatched, obtain corresponding with the sign at said first terminal, with corresponding network side signaling information of said conversation start time.
12. like claim 10 or 11 described systems; It is characterized in that; When said acquisition module obtains signaling information; First location information of terminals of at first carrying in the session information according to said first terminal to report is oriented corresponding network side network element, from the signaling information that this network element that collects is received and dispatched, obtains the corresponding network side signaling information again.
CN 200910083877 2009-05-07 2009-05-07 Network monitoring method and system thereof Active CN101883375B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN 200910083877 CN101883375B (en) 2009-05-07 2009-05-07 Network monitoring method and system thereof

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN 200910083877 CN101883375B (en) 2009-05-07 2009-05-07 Network monitoring method and system thereof

Publications (2)

Publication Number Publication Date
CN101883375A CN101883375A (en) 2010-11-10
CN101883375B true CN101883375B (en) 2012-11-07

Family

ID=43055223

Family Applications (1)

Application Number Title Priority Date Filing Date
CN 200910083877 Active CN101883375B (en) 2009-05-07 2009-05-07 Network monitoring method and system thereof

Country Status (1)

Country Link
CN (1) CN101883375B (en)

Families Citing this family (19)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102131226B (en) * 2011-03-23 2013-09-11 中国联合网络通信集团有限公司 Wireless network testing method, device and system
WO2012171168A1 (en) * 2011-06-13 2012-12-20 华为技术有限公司 Method, device and system for monitoring indoor overlay network
CN102917387B (en) * 2011-08-01 2016-06-22 中国移动通信集团公司 The method that plurality of wireless networks is monitored and mobile terminal
CN102984738B (en) * 2011-09-05 2016-07-06 中国移动通信集团北京有限公司 A kind of signaling report method, system and device
CN103095515B (en) * 2011-11-02 2017-03-29 中国移动通信集团上海有限公司 A kind of information gathering, analytic method, device and Information Acquisition System
CN103379525A (en) * 2012-04-18 2013-10-30 广州银禾网络通信有限公司 Method for association analysis of signaling data of user equipment side and wireless access network side in mobile communication network
CN103458453B (en) * 2012-05-30 2018-03-23 中国移动通信集团黑龙江有限公司 Network analysis method, apparatus and system
CN103517292B (en) * 2012-06-26 2017-05-03 中国移动通信集团公司 Mobile terminal information reporting method and apparatus
CN103826255A (en) * 2012-11-16 2014-05-28 中国电信股份有限公司 Wireless network coverage test method and wireless network coverage reporting platform
CN103222297A (en) * 2012-12-12 2013-07-24 华为技术有限公司 Data acquisition and processing application method, system and corresponding equipment thereof
CN105828367B (en) * 2015-01-04 2019-05-14 中国移动通信集团上海有限公司 A kind of determination method and device of network failure information
CN105120485B (en) * 2015-09-11 2018-10-12 中国联合网络通信集团有限公司 A kind of localization method and system of anomalous event
CN107155194B (en) * 2016-03-04 2020-02-21 中国移动通信集团山东有限公司 Signaling acquisition method and device
CN108156001B (en) * 2016-12-02 2022-05-13 中兴通讯股份有限公司 Intelligent network problem reporting method and device based on signaling analysis
CN108271195B (en) * 2016-12-31 2021-04-09 中国移动通信集团福建有限公司 Signaling association analysis method and device based on soft and hard acquisition
CN107579878B (en) * 2017-09-19 2020-08-21 浙江明讯网络技术有限公司 Signaling monitoring method and device
CN109639516B (en) * 2018-10-17 2022-05-17 平安科技(深圳)有限公司 Monitoring method, device, equipment and storage medium of distributed network system
CN113424505B (en) * 2019-02-12 2023-04-11 中兴通讯股份有限公司 Method for reporting performance information
CN116800826A (en) * 2022-03-18 2023-09-22 华为技术有限公司 Network data analysis method, readable medium and electronic device

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1878384A (en) * 2006-07-10 2006-12-13 华为技术有限公司 Network element failure detecting method
CN1963780A (en) * 2005-11-07 2007-05-16 富士通株式会社 Monotoring device, monotiring method, and monotoring system

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1963780A (en) * 2005-11-07 2007-05-16 富士通株式会社 Monotoring device, monotiring method, and monotoring system
CN1878384A (en) * 2006-07-10 2006-12-13 华为技术有限公司 Network element failure detecting method

Also Published As

Publication number Publication date
CN101883375A (en) 2010-11-10

Similar Documents

Publication Publication Date Title
CN101883375B (en) Network monitoring method and system thereof
CN101883374B (en) Method for reporting information by terminal, and terminal equipment
EP3214861B1 (en) Method, device and system for detecting fraudulent user
CN101925084B (en) Method for reporting and matching call log and device thereof
EP2393319A1 (en) Method for mobile network coverage experience analysis and monitoring
CN101925083A (en) Call process analysis system and method
GB2427795A (en) Providing an aggregated summary of correlated call detail records in a mobile network
CN101179809B (en) Method for catching clone SIM card
CN102917387A (en) Method for monitoring multiple wireless networks and a mobile terminal
CN103179594A (en) Method and device for optimizing wireless network on basis of road test data
CN105357699A (en) Wireless network quality monitoring system and method
CN103581976A (en) Cell identifying method and device
US7974635B2 (en) Method and system for automated collection of call routing performance data in a wireless network
CN101316430A (en) Communication information collecting method, test method and network side equipment
US20050287954A1 (en) System and method for monitoring a communications network
CN114124267B (en) Method and system for testing satellite communication system
US8805321B2 (en) Geolocation data acquisition system
US20120021718A1 (en) Method and arrangement for gathering data from a communication network
CN102123410A (en) Silence call positioning method based on A-interface signaling
EP2571314A1 (en) Method and apparatus for inter-system reselection frequency statistics
CN102984738B (en) A kind of signaling report method, system and device
CN113015080A (en) Pseudo base station identification and positioning method and device, electronic equipment and storage medium
CN110121190B (en) Data management method and device and computer readable storage medium
CN100525348C (en) System and method for collecting service information in communication system
CN103476052A (en) Fault detection method and device

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant