WO2025100725A1 - 이상 상태를 식별하기 위한 전자 장치 및 방법 - Google Patents
이상 상태를 식별하기 위한 전자 장치 및 방법 Download PDFInfo
- Publication number
- WO2025100725A1 WO2025100725A1 PCT/KR2024/013947 KR2024013947W WO2025100725A1 WO 2025100725 A1 WO2025100725 A1 WO 2025100725A1 KR 2024013947 W KR2024013947 W KR 2024013947W WO 2025100725 A1 WO2025100725 A1 WO 2025100725A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- state information
- state
- log
- identifying
- model
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F18/00—Pattern recognition
- G06F18/10—Pre-processing; Data cleansing
- G06F18/15—Statistical pre-processing, e.g. techniques for normalisation or restoring missing data
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F18/00—Pattern recognition
- G06F18/20—Analysing
- G06F18/26—Discovering frequent patterns
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/448—Execution paradigms, e.g. implementations of programming paradigms
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06N—COMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
- G06N3/00—Computing arrangements based on biological models
- G06N3/02—Neural networks
- G06N3/04—Architecture, e.g. interconnection topology
- G06N3/044—Recurrent networks, e.g. Hopfield networks
- G06N3/0442—Recurrent networks, e.g. Hopfield networks characterised by memory or gating, e.g. long short-term memory [LSTM] or gated recurrent units [GRU]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/0695—Management of faults, events, alarms or notifications the faulty arrangement being the maintenance, administration or management system
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/14—Network analysis or design
- H04L41/147—Network analysis or design for predicting network behaviour
Definitions
- the present disclosure relates to electronic devices and methods for identifying anomalies.
- KPIs Key performance indicators
- a wireless communication system can determine whether an anomaly has occurred in the network through the values of the KPIs. As the values of the KPIs are managed in the wireless communication system, the quality of the network can be improved.
- an electronic device may include a memory storing instructions , including one or more storage media, and at least one processor including a processing circuit.
- the instructions when individually or collectively executed by the at least one processor, may cause the electronic device to obtain log data regarding operation of the at least one NE (network element).
- the instructions when individually or collectively executed by the at least one processor, may cause the electronic device to obtain a log pattern through a designated algorithm based on the log data.
- the instructions, when individually or collectively executed by the at least one processor may cause the electronic device to identify first state information and second state information based on the log pattern.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to identify that the second state information is distinct from state information identified via the at least one model using the first state information.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to identify an abnormal state of the at least one NE based on identifying that the second state information is distinct from state information identified via the at least one model.
- a method performed by an electronic device may include an operation of obtaining log data regarding an operation of at least one network element (NE) from the at least one NE.
- the method may include an operation of obtaining a log pattern through a specified algorithm based on the log data.
- the method may include an operation of identifying first state information and second state information based on the log pattern.
- the method may include an operation of identifying that the second state information is distinct from state information identified through at least one model using the first state information.
- the method may include an operation of identifying an abnormal state of the at least one NE based on identifying that the second state information is distinct from state information identified through the at least one model.
- Figure 1 illustrates a wireless communication system
- FIG. 2 illustrates a system including an electronic device for obtaining log data regarding the operation of a network element (NE).
- NE network element
- FIG. 3 illustrates an example of a software defined network (SDN) architecture.
- SDN software defined network
- Figure 4 illustrates the configuration of an anomaly detector.
- Figure 5 illustrates a flow chart regarding the operation of the abnormal state detector.
- Figure 6 illustrates an example of the operation of the log parser.
- Figure 7 illustrates an example of the operation of the state model.
- Figure 8 illustrates an example of the operation of the prediction model.
- Figure 9 illustrates a flow chart regarding the operation of the abnormal state detector.
- Figure 10 illustrates an example of a functional configuration of an electronic device.
- signals e.g., signal, information, symbol, message, signaling, RS (reference signal), data
- terms referring to resources e.g., symbol, slot, subframe, radio frame, subcarrier, RE (resource element), RB (resource block), BWP (bandwidth part), occasion
- terms for operational states e.g., step, operation, procedure
- terms referring to data e.g., packet, user stream, information, bit, symbol, codeword
- terms referring to channels e.g., packet, user stream, information, bit, symbol, codeword
- the expression “more than” or “less than” may be used, but this is only a description for expressing an example and does not exclude the description of more than or less than.
- a condition described as “more than” may be replaced with “more than”
- a condition described as “less than” may be replaced with “less than”
- a condition described as “more than and less than” may be replaced with “more than and less than.”
- A” to “B” mean at least one of the elements from A to (inclusive of A) and from (inclusive of B).
- “C” and/or “D” mean at least one of "C” or “D,” that is, including ⁇ "C", “D", “C” and “D” ⁇ .
- Figure 1 illustrates a wireless communication system
- FIG. 1 illustrates a base station (110) and a terminal (120) as some of the nodes that utilize a wireless channel in a wireless communication system.
- FIG. 1 illustrates only one base station, but the wireless communication system may further include other base stations that are identical or similar to the base station (110).
- the base station (110) is a network infrastructure that provides wireless access to the terminal (120).
- the base station (110) has coverage defined based on the distance at which a signal can be transmitted.
- the base station (110) may be referred to as an 'access point (AP)', 'eNodeB (eNB)', '5th generation node', 'next generation nodeB (gNB)', 'wireless point', 'transmission/reception point (TRP)' or other terms having equivalent technical meanings.
- the terminal (120) is a device used by a user and performs communication with the base station (110) through a wireless channel.
- the link from the base station (110) to the terminal (120) is referred to as a downlink (DL), and the link from the terminal (120) to the base station (110) is referred to as an uplink (UL).
- the terminal (120) and another terminal may perform communication with each other through a wireless channel.
- the link between the terminal (120) and another terminal (device-to-device link, D2D) is referred to as a sidelink, and the sidelink may be used interchangeably with the PC5 interface.
- the terminal (120) may be operated without the involvement of the user.
- the terminal (120) is a device that performs machine type communication (MTC) and may not be carried by the user. Additionally, according to one embodiment, the terminal (120) may be an NB (narrowband)-IoT (internet of things) device.
- MTC machine type communication
- the terminal (120) may be an NB (narrowband)-IoT (internet of things) device.
- the terminal (120) may be referred to as a terminal, or other terms having equivalent technical meanings, such as 'user equipment (UE)', 'customer premises equipment (CPE)', 'mobile station', 'subscriber station', 'remote terminal', 'wireless terminal', 'electronic device', or 'user device'.
- UE user equipment
- CPE customer premises equipment
- NEs network elements
- network equipment network equipment
- the network status In order to identify anomalies for NEs, the network status must be monitored in real time based on at least one of resource usage of NEs and systems related to NEs, status information of NEs and systems related to NEs, network traffic information, and/or log data. Monitoring the network status and/or the status of NEs in real time may require a lot of human and material resources. Therefore, in the following specification, technical features for identifying anomalies in the operations of NEs based on log data output from NEs (or log data acquired from NEs) will be described.
- the log data may indicate the status of the NE (or network equipment).
- the log data may be composed of text data in a different format depending on the manufacturer (or developer) of the NE (or network equipment).
- the log data may be composed of unstructured data. Therefore, the operation of an electronic device for analyzing the log data using natural language processing (NLP) based on artificial intelligence will be described below.
- NLP natural language processing
- FIG. 2 illustrates a system including an electronic device for obtaining log data regarding the operation of a network element (NE).
- NE network element
- the electronic device (210) can be used to obtain log data regarding the operation of a plurality of network elements (NEs) (230).
- the plurality of NEs (230) can include NE (230-1) and NE (230-2).
- the plurality of NEs (230) can include a router, a distributed unit (DU), and/or a radio unit (RU).
- the NE can be referred to as a network device.
- Each of the plurality of NEs (230) can generate log data for the operation.
- Each of the plurality of NEs (230) can transmit the log data for the operation to the electronic device (210).
- the electronic device (210) can receive the log data generated based on various formats.
- the electronic device (210) can monitor the log data.
- the electronic device (210) can identify (or determine) an anomaly for the plurality of NEs (230) based on monitoring the log data.
- an anomaly may be referred to as an abnormal state.
- identifying an abnormal state of an NE may be referred to as identifying an NE in an abnormal state.
- the electronic device (210) may acquire data collected through a sensor of an NE (e.g., NE (230-1), NE (230-2)) or data output from the NE or the electronic device (210).
- the acquired data may be configured in a format of a specific value.
- Information on normal ranges and abnormal ranges of the acquired data may be stored in the memory of the electronic device (210).
- the electronic device (210) may identify or determine whether the NE is in an abnormal state based on the acquired data.
- the electronic device (210) can obtain unstructured data regarding the operation of the NE.
- the unstructured data may not be in a format of a specific value.
- the electronic device (210) can process the obtained unstructured data.
- the electronic device (210) can identify (or determine) an abnormal state of the NE based on the processed data.
- the electronic device (210) can identify the abnormal state of the NE based on the unstructured data using at least one of two techniques.
- the electronic device (210) can identify the abnormal state of the NE based on the result of a specific task (or operation) of the NE.
- the electronic device (210) can identify the abnormal state of the NE based on log data regarding the operation of the NE.
- the second technique can operate in a rule-based manner.
- an alarm can be generated based on the occurrence of a specific log.
- the electronic device (210) can identify an abnormal state of the NE based on a result of a specific task (or operation) of the NE.
- the result of the specific task (or operation) of the NE can be classified into one of a plurality of categories. Therefore, the electronic device (210) can determine an abnormal state of the NE based on determining whether the result of the specific task (or operation) of the NE is included in one of the plurality of categories.
- the electronic device (210) can determine an abnormal state of the NE based on determining whether the result of the tasks (or operations) that are sequentially performed is included in one of the plurality of categories.
- the electronic device (210) can identify an abnormal state of the NE based on log data regarding the operation of the NE.
- the log data can be composed of non-standard data.
- the log data can include text representing information that a manufacturer (or developer, user) of the NE determines is necessary to be output.
- the log data can be composed in different formats depending on the manufacturer (or developer, user) or the type of the NE. Accordingly, the electronic device (210) can identify that the NE is in an abnormal state (or an anomaly of the NE) when the log data indicating an error includes specified content. According to an embodiment, the electronic device (210) can identify (or extract) a common part in the log data as a log key.
- the electronic device (210) can analyze the meaning of the log data based on the log key.
- the electronic device (210) can determine whether the NE is in an abnormal state based on the meaning of the log data.
- the electronic device (210) can train a designated model (e.g., an artificial intelligence model) through a normal log pattern identified by using log data sorted in chronological order.
- the electronic device (210) can set the log data as input data of the designated model.
- the electronic device (210) can determine whether the NE is in an abnormal state based on the output data of the designated model.
- the second technique since repeated words are set as log keys, the meaning of the repeated words may not be considered. Therefore, the content of the actual log data may not be reflected.
- FIG. 3 illustrates an example of a software defined network (SDN) architecture.
- SDN software defined network
- SDN (300) may include an application layer (310), a control plane layer (320), and/or a data plane layer (330).
- the application layer (310) may include one or more applications used for control operations including routing and/or load balancing.
- An application may have exclusive control over a set of resources exposed by the SDN controller.
- An application may invoke or collaborate with other applications.
- the control plane layer (320) may include an SDN controller (321).
- the SDN controller (321) may be used to control the entire network resources.
- the SDN controller (321) may obtain network information and provide the obtained information to an application.
- the data play layer (330) may include at least one NE (331). At least one NE (331) may include at least one physical switch and/or at least one virtual switch.
- the interface between the control plane layer (320) and the application layer (310) may be referred to as a northbound API (application programming interface).
- the interface between the control plane layer (320) and the data plane layer (330) may be referred to as a southbound API.
- the openflow protocol or the OpFlex protocol may be used between the control plane layer (320) and the data plane layer (330).
- SDN While existing NEs (or network equipment) operate independently based on a data plane and a control plane, in SDN (300), the data plane and the control plane of the NE can be separated.
- the SDN controller (321) can perform the operation of the control plane of the NE.
- the SDN (300) can operate based on an algorithm for network control. Therefore, in the SDN (300), the network can be managed and controlled based on a specified algorithm without the intervention of an administrator.
- at least one NE (331) constituting the network can be managed through the SDN controller (321).
- At least one NE (331) can support at least one of REST (representational state transfer protocol), NETCONF (network configuration protocol), or RESTCONF (representational state transfer configuration protocol) in order to operate in conjunction with the SDN controller (321).
- the SDN controller (321) can control at least one NE (331) using at least one of REST, NETCONF, or RESTCONF.
- the network can be analyzed using an artificial intelligence model, and if a problem occurs, the problem can be resolved using the artificial intelligence model.
- network information e.g., log data
- the network controller 321
- the SDN controller 321
- an abnormal state of an NE can be monitored using an artificial intelligence model. If an abnormal state of an NE is found, the SDN controller (321) can isolate the NE and control the network traffic to be transmitted through another NE.
- Figure 4 illustrates the configuration of an anomaly detector.
- the terms '... unit', '... unit', etc. used hereinafter mean a unit that processes at least one function or operation, and this can be implemented by hardware, software, or a combination of hardware and software.
- At least one NE (410) can transmit log data to a network controller (420).
- the network controller (420) can receive log data from at least one NE (410).
- the network controller (420) can correspond to the SDN controller (321) of FIG. 3.
- the network controller (420) may include a log collection unit (421) and a network configuration unit (422).
- the log collection unit (421) may be configured to receive log data from at least one NE (410) and transmit the received log data to an abnormality detector (450).
- the network configuration unit (422) may be configured to change the settings of at least one NE (410) or control the operation of at least one NE (410).
- the abnormal condition detector (450) may include a log parser (460) and an analyzer (470). Log data collected from at least one NE (410) may be transmitted to the log parser (460) via the network controller (420).
- the log parser (460) may include at least one of a preprocessing unit (461), a pattern analysis unit (462), and/or a state information identification unit (463).
- the preprocessing unit (461) may be used to preprocess log data.
- the pattern analysis unit (462) may be used to obtain (or identify) a log pattern based on the log data.
- the state information identification unit (463) may be used to identify state information based on the log pattern.
- the state information may include an event number regarding the log data.
- the state information identification unit (463) may be referred to as an event classification unit. The specific operation of the log parser (460) will be described later with reference to FIG. 6.
- the analyzer (470) can receive status information from the log parser (460).
- the analyzer (470) can identify an abnormal status of at least one NE (410) based on the status information.
- the analyzer (470) can include at least one of a status model (471) and/or a prediction model (472).
- the state model (471) can be used to identify an abnormal state of at least one NE (410) based on a state change for a log pattern.
- the state model (471) can be configured based on a finite state automata. The specific operation of the state model (471) will be described later in FIG. 7.
- the prediction model (472) can be used to identify an abnormal state of at least one NE (410) based on a predicted state for a log pattern.
- the prediction model (472) can be configured based on a long short term memory (LSTM). The specific operation of the prediction model (472) will be described later in FIG. 8.
- the anomaly detector (450) can identify an anomaly of at least one NE (410) through three steps.
- the abnormal state detector (450) can identify whether at least one NE (410) is in an abnormal state based on identifying whether a log pattern obtained based on log data corresponds to one of a plurality of log patterns indicating a normal state by using a log parser (460).
- the abnormal state detector (450) (or network controller (420)) can provide a notification (or alarm) based on identifying the abnormal state of at least one NE (410) through the first step.
- the abnormal state detector (450) can perform the second step based on identifying that at least one NE (410) is not in an abnormal state through the first step.
- the abnormal state detector (450) can identify whether at least one NE (410) is in an abnormal state based on identifying whether the state information acquired using the log parser (460) corresponds to the state information acquired using the state model (471).
- the abnormal state detector (450) (or the network controller (420)) can provide a notification (or alarm) based on identifying the abnormal state of at least one NE (410) through the second step.
- the abnormal state detector (450) can perform the third step based on identifying that at least one NE (410) is not in an abnormal state through the second step.
- the abnormal state detector (450) can identify whether at least one NE (410) is in an abnormal state based on identifying whether the state information acquired using the log parser (460) corresponds to the state information acquired using the prediction model (472).
- the abnormal state detector (450) (or network controller (420)) can provide a notification (or alarm) based on identifying the abnormal state of at least one NE (410) through the third step.
- the network controller (420) may change the path of data traffic to bypass the NE in which the abnormal state has occurred based on identifying the abnormal state of at least one NE (410).
- Figure 5 illustrates a flow chart regarding the operation of the abnormal state detector.
- the abnormal state detector (450) (or an electronic device for the abnormal state detector (450)) can obtain log data regarding the operation of at least one NE (410).
- the abnormal state detector (450) can obtain log data regarding the operation of at least one NE (410) through the network controller (420).
- the abnormal state detector (450) can monitor log data regarding the operation of at least one NE (410).
- the abnormal state detector (450) can obtain a log pattern through a specified algorithm.
- the abnormal state detector (450) can obtain a log pattern through a specified algorithm based on log data.
- the abnormal state detector (450) can obtain a log pattern using a log parser (460).
- the abnormal state detector (450) can normalize the log data based on a specified algorithm.
- the abnormal state detector (450) can normalize the log data to identify status information through the log data.
- the abnormal state detector (450) can remove unnecessary information from the log data through a specified algorithm.
- the abnormal state detector (450) can normalize the log data by removing unnecessary information from the log data.
- the abnormal state detector (450) can obtain a log pattern based on normalizing the log data.
- the abnormal state detector (450) can obtain a log pattern to identify status information.
- the abnormal state detector (450) can identify the first state information and the second state information.
- the abnormal state detector (450) can identify the first state information and the second state information based on a log pattern.
- the log data can include log messages (texts) acquired within a specified time interval.
- the first state information can indicate a state of at least one NE (410) at a first time point.
- the second state information can indicate a state of at least one NE (410) at a second time point after the first time point.
- the first state information can indicate a past state of at least one NE (410).
- the second state information can indicate a current state of at least one NE (410).
- the first state information can include a first event number.
- the second state information can include a second event number. Each of the first event number and the second event number can be a value for indicating a state of at least one NE (410).
- the abnormal state detector (450) can identify whether the log pattern corresponds to one of a plurality of log patterns stored in the memory.
- the plurality of log patterns stored in the memory can indicate a normal state. If the log pattern corresponds to one of the plurality of log patterns stored in the memory, the abnormal state detector (450) can identify the first state information and the second state information based on the log pattern. If the log pattern does not correspond to one of the plurality of log patterns stored in the memory, the abnormal state detector (450) can identify the abnormal state of at least one NE (410).
- the abnormal state detector (450) can identify that the second state information is distinct from the state information identified through at least one model using the first state information.
- the abnormal state detector (450) can identify an abnormal state of at least one NE (410). For example, the abnormal state detector (450) can identify an abnormal state of at least one NE (410) based on identifying that the second state information is distinct from state information identified through at least one model using the first state information.
- the abnormal state detector (450) can identify state information through at least one model using the first state information.
- the abnormal state detector (450) can identify state information through at least one model using the first state information representing a past state.
- the abnormal state detector (450) can identify the abnormal state of at least one NE (410) based on identifying that the identified state information is distinct from the second state information.
- At least one model may include a state model (471) and a predictive model (472).
- the abnormal state detector (450) can identify the third state information through the state model (471).
- the abnormal state detector (450) can input the first state information into the state model (471).
- the abnormal state detector (450) can set the input data of the state model (471) as the first state information.
- the abnormal state detector (450) can obtain the third state information based on the output of the state model (471).
- the state model (471) can identify the state information that can be changed (or transitioned) from the first state information in a normal state as the third state information.
- the abnormal state detector (450) can identify the abnormal state of at least one NE (410) based on identifying that the second state information is not the state information that can be changed from the first state information.
- the abnormal state detector (450) can identify the fourth state information through the prediction model (472).
- the abnormal state detector (450) can input the first state information into the prediction model (472).
- the abnormal state detector (450) can set the input data of the prediction model (472) as the first state information.
- the abnormal state detector (450) can obtain the fourth state information based on the output of the prediction model (472).
- the prediction model (472) can identify state information that is predicted to change from the first state information in a normal state as the fourth state information.
- the abnormal state detector (450) can identify probability data for each of a plurality of states based on the output of the prediction model (472).
- the abnormal state detector (450) can obtain the fourth state information based on a state having the highest probability among the plurality of states.
- the abnormal state detector (450) can identify an abnormal state of at least one NE (410) based on identifying that the second state information is not the fourth state information representing a predicted state.
- Figure 6 illustrates an example of the operation of the log parser.
- the abnormal state detector (450) can process log data acquired from at least one NE (410) using a log parser (460).
- the log parser (460) can include at least one of a preprocessing unit (461), a pattern analysis unit (462), and/or a state information identification unit (463).
- the abnormal state detector (450) can perform a preprocessing operation, a pattern analysis operation, and a state information identification operation using the log parser (460).
- the abnormal state detector (450) can change log data into a log pattern through the log parser (460).
- the abnormal state detector (450) can identify whether the log pattern corresponds to one of a plurality of log patterns stored in a memory.
- the plurality of log patterns stored in the memory can indicate a normal state.
- the abnormal condition detector (450) can provide a notification (or alarm) based on identifying that the log pattern does not correspond to one of a plurality of log patterns stored in memory.
- the abnormal state detector (450) can perform a preprocessing operation using the preprocessing unit (461) of the log parser (460).
- the abnormal state detector (450) can normalize log data using the preprocessing unit (461).
- the preprocessing unit (461) can change the uppercase letters of the log contents according to the log data to lowercase letters.
- the preprocessing unit (461) can remove at least one of numbers, dates, file paths, region names, interface names, and/or symbols from the log contents according to a specified rule. Some of the words removed can be replaced with tokens that have meaning. For example, some of the words included in the log contents can be changed as shown in the table below.
- some of the words included in the log content can be replaced with tokens based on the rules in Table 1.
- numbers (or Eastern Arabic numerals) included in the log content can be replaced with the [number] token.
- the value of radix n can be converted based on a regular expression, and the converted number can be replaced with the [number] token.
- Dates and local names can be removed through a dictionary obtained through training data. For example, a date can be replaced with a [date] token.
- a local name can be replaced with a [loc] token. Since a Linux-based file path starts with '/', a word starting with '/' can be replaced with a [path] token. Since an interface is followed by the word 'interface' and the name of the interface, the word immediately following the word 'interface' can be changed to an [interface] token.
- the preprocessing operation through the preprocessing unit (461) of the log parser (460) can be completed by removing all symbols that have not been changed into tokens.
- the preprocessing operation can be performed based on specified rules as shown in Table 1. Therefore, a user (or administrator) can change the preprocessing operation by changing the rules according to actual log data.
- the abnormal state detector (450) can perform a pattern analysis operation using the pattern analysis unit (462) of the log parser (460). After the preprocessing operation is performed, the abnormal state detector (450) can perform a pattern analysis operation through the pattern analysis unit (462) of the log parser (460).
- the pattern analysis unit (462) can identify (or analyze) a log pattern based on a word dictionary.
- the word dictionary can be generated in advance through log data in a normal state.
- the word dictionary can be generated with words that appear more than a specified number of times (e.g., 3 times) in the learning data (e.g., log data) after the preprocessing operation is performed. Since the word dictionary is generated with words that appear more than a specified number of times (e.g., 3 times), words that are temporarily generated, such as process IDs (identifiers), can be removed.
- the specified number of times can be changed according to the setting information for the pattern analysis unit (462).
- words not in the word dictionary among the acquired log contents may be changed to the [UNK] (unknown) token.
- the log data may be changed (or compressed) into a log pattern of substantially the same form. If the log contents (or log message) are configured as ‘Interface HundGi0/3, changed state to FREQ_LOCK’, it may be changed to a log pattern configured as ‘interface [interface] changed state to freq lock’ after the preprocessing operation and the pattern analysis operation are performed. At this time, only the interface name may be changed to the [interface] token. According to the above example, even if the interfaces are different, the log contents (or log messages) regarding the same operation may be expressed as one log pattern.
- the abnormal state detector (450) can perform a state information identification operation using the state information identification unit (463) of the log parser (460). After pattern analysis is performed, the abnormal state detector (450) can perform a state information identification operation through the state information identification unit (463) of the log parser (460).
- the status information identification unit (463) can identify (or obtain) status information based on a log pattern.
- the status information can include an event number.
- the event number can be a value for indicating the status of at least one NE (410). Since the event number is identified (or obtained) through the status information identification unit (463), the status information identification unit (463) can be referred to as an event classification unit.
- the status information identification unit (463) can identify status information (e.g., event number) based on a log pattern. Based on the status information identification operation, identical or similar log patterns can be identified (or classified) with the same status information (e.g., event number). Log patterns acquired based on learning data can be registered in a status dictionary through the status information identification operation. A list of log patterns according to each status information can be stored in memory.
- status information e.g., event number
- the operation for constructing the above state dictionary can be performed based on a minimum edit distance algorithm.
- the minimum edit distance algorithm can be an algorithm for measuring the similarity between two sentences.
- the 'word removal' operation, the 'word addition' operation, and the 'word conversion' operation can each be defined as one modification.
- the similarity between two sentences can be measured through the minimum number of modifications for the two sentences to become the same.
- a cost can be defined. For example, using a dictionary of synonyms and antonyms, if the relationship between an existing word and a word to be converted is a synonym according to the 'word conversion' operation, the cost can be set to the first cost (e.g., '0'). Using a dictionary of synonyms and antonyms, if the relationship between an existing word and a word to be converted is an antonym according to the 'word conversion' operation, the cost can be set to the second cost (e.g., '6'). Depending on the embodiment, the first cost and the second cost can be changed. For example, the first cost and the second cost can be changed by an administrator (or a user).
- an antonym dictionary can be used to further increase the cost of the 'word conversion' operation.
- the meanings of two log patterns are opposite, such as 'interface up' and 'interface down', the minimum edit distance is small but the actual meanings are opposite, so the two log patterns should be identified with different state information. Therefore, the state information identification unit (463) can identify two log patterns with opposite meanings as different state information by increasing the cost of the 'word conversion' operation using an antonym dictionary.
- a public antonym dictionary such as WordNet can be utilized as the antonym dictionary.
- the two log patterns can become identical if less than half of the two log patterns are modified. Therefore, the two log patterns can be identified (or classified) with the same state information (e.g., event number).
- state information e.g., event number.
- each of the plurality of log patterns obtained (or extracted) from the learning data can be changed into state information (e.g., event number).
- state information e.g., event number
- log patterns with different costs can be changed (or identified) into different state information.
- log patterns with the same cost can be changed (or identified) into the same state information.
- the abnormal state detector (450) can identify the state information based on whether the log pattern identified based on the log data corresponds to one of the plurality of log patterns stored in the memory.
- the abnormal state detector (450) can identify the abnormal state of at least one NE (410) based on whether the log pattern identified based on the log data does not correspond to one of the plurality of log patterns stored in the memory.
- Log data can represent information about operations over time. Accordingly, first state information and second state information can be identified based on log data.
- the first state information may indicate a state of at least one NE (410) at a first time point.
- the second state information may indicate a state of at least one NE (410) at a second time point after the first time point.
- the first state information may indicate a past state of at least one NE (410).
- the second state information may indicate a current state of at least one NE (410).
- the first state information may include a first event number.
- the second state information may include a second event number. Each of the first event number and the second event number may be a value for indicating a state of at least one NE (410).
- Figure 7 illustrates an example of the operation of the state model.
- the abnormal state detector (450) can identify state information (e.g., event number) based on the log parser (460).
- the abnormal state detector (450) can sequentially identify (or output) state information using the log parser (460).
- the abnormal state detector (450) can identify whether a state change is a normal change based on the sequentially identified state information using the state model (471).
- the abnormal state detector (450) can identify first state information and second state information using the log parser (460).
- the abnormal state detector (450) can input the first state information into the state model (471).
- the abnormal state detector (450) can obtain third state information based on the output of the state model (471).
- the abnormal state detector (450) can identify an abnormal state of at least one NE (410) based on identifying that the second state information is distinct from the third state information.
- the abnormal state detector (450) can identify a normal state of at least one NE (410) based on identifying that the second state information corresponds to the third state information.
- the state model (471) may be configured based on a finite state automata.
- the state model (471) is a machine having finite states, and the state model (471) may have one state at a time. Each state may transition (or change) to another state according to a specific event.
- the state model (471) may be configured with a set of transition states and conditions causing the transition states.
- the state model (471) may include a set of state changes. For example, if at least one NE (410) operates normally, the q1 state is likely to change to the q139 state. The q139 state is likely to change to the q175 state. After the q1 state is identified, based on the log data, the abnormal state detector (450) can identify that at least one NE (410) is in a normal state. After the q139 state is identified, based on the log data, the abnormal state detector (450) can identify that at least one NE (410) is in an abnormal state. On the other hand, after the q139 state is identified, based on the log data, the q190 state is identified, the abnormal state detector (450) can identify that at least one NE (410) is in an abnormal state.
- At least one NE (410) can be identified as a normal state. For example, if a transition from the q2 state to the q19 state is not included in the state model (471), but a transition from the q2 state to the q19 state and a transition from the q19 state to the q150 state are possible, at least one NE (410) can be identified as a normal state.
- Figure 8 illustrates an example of the operation of the prediction model.
- the abnormal state detector (450) can identify state information (e.g., event number) based on the log parser (460).
- the abnormal state detector (450) can sequentially identify (or output) state information using the log parser (460).
- the abnormal state detector (450) can identify predicted state information using the prediction model (472) based on the sequentially identified state information.
- the abnormal state detector (450) can identify the abnormal state of at least one NE (410) based on the predicted state information.
- the abnormal state detector (450) can identify first state information and second state information using the log parser (460).
- the abnormal state detector (450) can input the first state information into the prediction model (472).
- the abnormal state detector (450) can obtain the fourth state information based on the output of the prediction model (472).
- the abnormal state detector (450) can identify the abnormal state of at least one NE (410) based on identifying that the second state information is distinct from the fourth state information.
- the abnormal state detector (450) can identify the normal state of at least one NE (410) based on identifying that the second state information corresponds to the fourth state information.
- the prediction model (472) may be configured based on LSTM (long short term memory).
- the prediction model (472) may include a first layer (801), a second layer (802), and a third layer (803).
- the input of the first layer (801) may consist of n states.
- the abnormal state detector (450) may input n consecutive states to the prediction model (472). n may be changed by the administrator (or user).
- the first layer (801) may be referred to as an LSTM layer.
- LSTM may be one of the machine learning algorithms known to be most suitable for time series data analysis. LSTM may have high performance for predicting the next result (or flow) when data is input sequentially.
- a second layer (802) may be configured at the output end of the first layer (801).
- the second layer (802) may be referred to as a FC (fully connected) layer.
- the number of outputs of the second layer (802) may be set to k.
- K may correspond to the number of state information identified by the log parser (460).
- a k-dimensional vector may be generated as the output of the second layer (802).
- the output of the second layer (802) may represent the probability that each of the k states will occur.
- a third layer (803) may be configured at the output end of the second layer (802).
- the third layer (803) may be referred to as a softmax layer.
- the abnormal state detector (450) may obtain predicted state information based on the state with the highest probability by using the prediction model (472).
- the abnormal state detector (450) can identify a normal state of at least one NE (410) based on identifying that the state information identified based on the log data corresponds to the state information predicted through the prediction model (472).
- the abnormal state detector (450) can identify an abnormal state of at least one NE (410) based on identifying that the state information identified based on the log data is distinct from the state information predicted through the prediction model (472).
- the anomaly detector (450) may provide a notification (or alarm) based on the prediction model (472) identifying the anomaly a specified number of consecutive times (e.g., 7 times).
- Figure 9 illustrates a flow chart regarding the operation of the abnormal state detector.
- the abnormal state detector (450) (or an electronic device for the abnormal state detector (450)) may obtain log data.
- the abnormal state detector (450) may obtain log data from at least one NE (410).
- the anomaly detector (450) can identify a log pattern. For example, the anomaly detector (450) can identify a log pattern based on log data. The anomaly detector (450) can normalize the log data based on a specified algorithm (or a specified rule). The anomaly detector (450) can obtain a log pattern based on normalizing the log data.
- the abnormal state detector (450) can identify whether the log pattern corresponds to one of the plurality of log patterns stored in the memory.
- the abnormal state detector (450) can identify whether the log pattern identified based on the log data corresponds to one of the plurality of log patterns stored in the memory.
- Each of the plurality of log patterns stored in the memory can indicate a normal state.
- the abnormal state detector (450) can identify the first state information and the second state information. Based on identifying that the log pattern corresponds to one of the plurality of log patterns stored in the memory, the abnormal state detector (450) can identify the first state information and the second state information.
- the log data may include log messages (texts) acquired within a specified time interval.
- the first state information may indicate a state regarding at least one NE (410) at a first point in time.
- the second state information may indicate a state regarding at least one NE (410) at a second point in time after the first point in time.
- the first state information may indicate a past state of at least one NE (410).
- the second state information may indicate a current state of at least one NE (410).
- the abnormal condition detector (450) can perform operations 902 to 904 using the log parser (460) described in FIG. 6.
- the abnormal state detector (450) can identify whether the second state information corresponds to the third state information identified through the state model (471) using the first state information.
- the abnormal state detector (450) can identify the third state information through the state model (471) using the first state information.
- the abnormal state detector (450) can identify whether the second state information corresponds to the third state information.
- the state model (471) can be configured based on a finite state automata.
- the third state information can mean state information transitioned from the first state information.
- the abnormal condition detector (450) can perform operation 905 using the state model (471) described in FIG. 7.
- the abnormal state detector (450) can identify whether the second state information corresponds to the fourth state information identified through the prediction model (472) using the first state information. For example, based on identifying that the second state information corresponds to the third state information, the abnormal state detector (450) can identify whether the second state information corresponds to the fourth state information identified through the prediction model (472) using the first state information. The abnormal state detector (450) can identify the fourth state information through the prediction model (472) using the first state information. The abnormal state detector (450) can identify whether the second state information corresponds to the fourth state information.
- the prediction model (472) can be configured based on an LSTM (long short term memory).
- the fourth state information can mean state information predicted based on the first state information.
- Operation 907 can identify that at least one NE (410) is in a normal state if the second state information corresponds to the fourth state information.
- the abnormal state detector (450) can identify that at least one NE (410) is in a normal state based on identifying that the second state information corresponds to the fourth state information.
- the abnormal state detector (450) can identify that at least one NE (410) is in a normal state based on identifying that the condition of operation 903, the condition of operation 905, and the condition of operation 906 are all satisfied.
- Operation 908 is such that if at least one of the conditions of operation 903, operation 905, and operation 906 is not satisfied, the anomaly detector (450) can identify that at least one NE (410) is in an abnormal state (or an anomaly of at least one NE (410)). The anomaly detector (450) can identify that at least one NE (410) is in an abnormal state based on identifying that at least one of the conditions of operation 903, operation 905, and operation 906 is not satisfied.
- the abnormal state detector (450) may provide a notification (or alarm) based on identifying that at least one NE (410) is in an abnormal state. According to an embodiment, the abnormal state detector (450) may provide a notification to the network controller (420). The network controller (420) may change the path of data traffic to bypass at least one NE (410) in which the abnormal state occurred.
- Figure 10 illustrates an example of a functional configuration of an electronic device.
- the electronic device (1000) may correspond to the abnormal state detector (450) of FIGS. 4 to 9.
- the electronic device (1000) may include a transceiver (1001), a processor (1003), and a memory (1005).
- the transceiver (1001) can perform functions for transmitting and receiving signals in a wired communication environment.
- the transceiver (1001) can include a wired interface for controlling direct connection between devices through a transmission medium (e.g., copper wire, optical fiber).
- a transmission medium e.g., copper wire, optical fiber
- the transceiver (1001) can transmit an electrical signal to another device through a copper wire, or perform conversion between an electrical signal and an optical signal.
- the transceiver (1001) may perform functions for transmitting and receiving signals in a wireless communication environment.
- the transceiver (1001) may perform a conversion function between a baseband signal and a bit stream according to a physical layer specification of the system.
- the transceiver (1001) encodes and modulates a transmission bit stream to generate complex-valued symbols.
- the transceiver (1001) restores a reception bit stream by demodulating and decoding a baseband signal.
- the transceiver (1001) may include a plurality of transmission and reception paths.
- the transceiver (1001) transmits and receives signals as described above. Accordingly, all or part of the transceiver (1001) may be referred to as a 'communication unit', a 'transmitter', a 'receiver' or a 'transmitter-receiver'.
- transmission and reception performed through a wireless channel are used to mean that processing as described above is performed by the transceiver (1001).
- the processor (1003) controls the overall operations of the electronic device (1000).
- the processor (1003) may be referred to as a control unit.
- the processor (1003) transmits and receives signals through the transceiver (1001).
- the processor (1003) records and reads data in the memory (1005).
- the processor (1003) may perform functions of a protocol stack required by a communication standard. Although only the processor (1003) is illustrated in FIG. 10, the electronic device (1000) may include two or more processors according to another implementation example.
- the operations of the processor (1003) may be executed by software, or may mean controlling hardware components such as a Field Programmable Gate Array (FPGA) or an Application-specific Integrated Circuit (ASIC).
- the processor (1003) may include at least one of components such as software components, object-oriented software components, class components, and task components, and processes, functions, properties, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables.
- the processor (1003) may include at least one module, and the term "module" includes a unit composed of hardware, software, or firmware.
- a module may be used interchangeably with terms such as logic, a logic block, a component, or a circuit.
- a module may be an integrally configured component or a minimum unit or a part thereof that performs one or more functions.
- a module may be composed of an ASIC.
- the processor (1003) may include at least some or all of the blocks (e.g., the blocks illustrated in FIG. 4) according to the embodiments described above.
- the processor (1003) may perform the functions of at least some or all of the blocks (e.g., the blocks illustrated in FIG. 4) according to the embodiments described above.
- the memory (1005) stores data such as basic programs, application programs, and setting information for the operation of the electronic device (1000).
- the memory (1005) may be referred to as a storage unit.
- the memory (1005) may be composed of volatile memory, nonvolatile memory, or a combination of volatile memory and nonvolatile memory.
- the memory (1005) provides stored data according to a request from the processor (1003).
- an electronic device may include a memory storing instructions , including one or more storage media, and at least one processor including a processing circuit.
- the instructions when individually or collectively executed by the at least one processor, may cause the electronic device to obtain log data regarding operation of the at least one NE (network element).
- the instructions when individually or collectively executed by the at least one processor, may cause the electronic device to obtain a log pattern through a designated algorithm based on the log data.
- the instructions, when individually or collectively executed by the at least one processor may cause the electronic device to identify first state information and second state information based on the log pattern.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to identify that the second state information is distinct from state information identified via the at least one model using the first state information.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to identify an abnormal state of the at least one NE based on identifying that the second state information is distinct from state information identified via the at least one model.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to normalize the log data based on the specified algorithm.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to obtain the log pattern based on normalizing the log data.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to identify whether the log pattern corresponds to one of a plurality of log patterns stored in the memory.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to identify, based on the log pattern, the first state information and the second state information, if the log pattern corresponds to one of the plurality of log patterns.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to identify the abnormal state of the at least one NE, if the log pattern does not correspond to one of the plurality of log patterns.
- the at least one model may include a state model and a predictive model.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to identify that the second state information is distinct from third state information identified via the state model.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to identify the abnormal state of the at least one NE based on identifying that the second state information is distinct from the third state information.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to input the first state information into the state model.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to obtain the third state information based on an output of the state model.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to identify that the second state information corresponds to the third state information, based on which the electronic device identifies that the second state information is distinct from fourth state information identified via the predictive model.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to identify the abnormal state of the at least one NE, based on which the electronic device identifies that the second state information is distinct from the fourth state information.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to input the first state information into the predictive model.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to obtain the fourth state information based on an output of the predictive model.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to identify probability data for each of the plurality of states based on an output of the predictive model.
- the instructions when executed individually or collectively by the at least one processor, may cause the electronic device to obtain the fourth state information based on a state having a highest probability among the plurality of states.
- the state model can be constructed based on a finite state automata.
- the prediction model can be constructed based on a long short term memory (LSTM).
- a method performed by an electronic device may include an operation of obtaining log data regarding an operation of at least one network element (NE) from the at least one NE.
- the method may include an operation of obtaining a log pattern through a specified algorithm based on the log data.
- the method may include an operation of identifying first state information and second state information based on the log pattern.
- the method may include an operation of identifying that the second state information is distinct from state information identified through at least one model using the first state information.
- the method may include an operation of identifying an abnormal state of the at least one NE based on identifying that the second state information is distinct from state information identified through the at least one model.
- the method may include an operation of normalizing the log data based on the specified algorithm.
- the method may include an operation of obtaining the log pattern based on normalizing the log data.
- the method may include an operation of identifying whether the log pattern corresponds to one of a plurality of log patterns stored in the memory.
- the method may include an operation of identifying the first state information and the second state information based on the log pattern if the log pattern corresponds to one of the plurality of log patterns.
- the method may include an operation of identifying the abnormal state of the at least one NE if the log pattern does not correspond to one of the plurality of log patterns.
- the at least one model may include a state model and a predictive model.
- the method may include an operation of identifying that the second state information is distinct from third state information identified through the state model.
- the method may include an operation of identifying the abnormal state of the at least one NE based on identifying that the second state information is distinct from the third state information.
- the method may include an operation of inputting the first state information into the state model.
- the method may include an operation of obtaining the third state information based on an output of the state model.
- the method may include an operation of identifying, based on identifying that the second state information corresponds to the third state information, that the second state information is distinct from fourth state information identified through the prediction model.
- the method may include an operation of identifying, based on identifying that the second state information is distinct from the fourth state information, that the abnormal state of the at least one NE.
- the method may include an operation of inputting the first state information into the prediction model.
- the method may include an operation of obtaining the fourth state information based on an output of the prediction model.
- the method may include an operation of identifying probability data for each of the plurality of states based on an output of the prediction model.
- the method may include an operation of obtaining the fourth state information based on a state having a highest probability among the plurality of states.
- the state model can be constructed based on a finite state automata.
- the prediction model can be constructed based on a long short term memory (LSTM).
- an abnormal state can be identified (or detected) in real time through the network equipment (or NE). For example, based on the log data, similar log patterns can be analyzed, so that the log data can be effectively compressed. By learning the log pattern while the network equipment is in a normal state, abnormal logs of the network equipment can be determined in real time. When an abnormal state of the network equipment is identified, a notification can be provided to the network manager so that the actual abnormality can be confirmed. Accordingly, since a notification of the abnormal state is provided first, the occurrence of a critical problem can be prevented.
- a computer-readable storage medium storing one or more programs (software modules) may be provided.
- the one or more programs stored in the computer-readable storage medium are configured for execution by one or more processors in an electronic device.
- the one or more programs include instructions that cause the electronic device to execute methods according to embodiments described in the claims or specification of the present disclosure.
- the one or more programs may be provided as included in a computer program product.
- the computer program product may be traded between a seller and a buyer as a commodity.
- the computer program product may be distributed in the form of a machine-readable storage medium (e.g., compact disc read only memory (CD-ROM)), or may be distributed online (e.g., downloaded or uploaded) via an application store (e.g., Play StoreTM) or directly between two user devices (e.g., smart phones).
- a machine-readable storage medium e.g., compact disc read only memory (CD-ROM)
- an application store e.g., Play StoreTM
- at least a portion of the computer program product may be temporarily stored or temporarily created in a machine-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or an intermediary server.
- These programs may be stored in a random access memory, a non-volatile memory including flash memory, a read only memory (ROM), an electrically erasable programmable read only memory (EEPROM), a magnetic disc storage device, a compact disc-ROM (CD-ROM), digital versatile discs (DVDs) or other forms of optical storage devices, a magnetic cassette. Or, they may be stored in a memory composed of a combination of some or all of these. In addition, each configuration memory may be included in multiple numbers.
- ROM read only memory
- EEPROM electrically erasable programmable read only memory
- CD-ROM compact disc-ROM
- DVDs digital versatile discs
- each configuration memory may be included in multiple numbers.
- the program may be stored in an attachable storage device that is accessible via a communications network, such as the Internet, an Intranet, a local area network (LAN), a wide area network (WAN), or a storage area network (SAN), or a combination thereof.
- the storage device may be connected to the device performing an embodiment of the present disclosure via an external port. Additionally, a separate storage device on the communications network may be connected to the device performing an embodiment of the present disclosure.
- the components included in the disclosure are expressed in the singular or plural form according to the specific embodiments presented.
- the singular or plural expressions are selected to suit the presented situation for the convenience of explanation, and the present disclosure is not limited to the singular or plural components, and even if a component is expressed in the plural form, it may be composed of the singular form, or even if a component is expressed in the singular form, it may be composed of the plural form.
- one or more of the components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added.
- a plurality of components e.g., modules or programs
- the integrated component may perform one or more functions of each of the plurality of components identically or similarly to those performed by the corresponding component of the plurality of components prior to the integration.
- the operations performed by a module, program or other component may be executed sequentially, in parallel, repeatedly, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- Data Mining & Analysis (AREA)
- Software Systems (AREA)
- General Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- Artificial Intelligence (AREA)
- Evolutionary Computation (AREA)
- Life Sciences & Earth Sciences (AREA)
- Signal Processing (AREA)
- Evolutionary Biology (AREA)
- Computer Vision & Pattern Recognition (AREA)
- Bioinformatics & Computational Biology (AREA)
- Bioinformatics & Cheminformatics (AREA)
- Computer Networks & Wireless Communication (AREA)
- General Health & Medical Sciences (AREA)
- Mathematical Physics (AREA)
- Health & Medical Sciences (AREA)
- Computing Systems (AREA)
- Molecular Biology (AREA)
- Biophysics (AREA)
- Biomedical Technology (AREA)
- Computational Linguistics (AREA)
- Probability & Statistics with Applications (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
일 실시 예에 따르면, 전자 장치는, 인스트럭션들을 저장하는 메모리 및 프로세서를 포함할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 적어도 하나의 NE의 동작에 관한 로그 데이터를 획득하고, 로그 패턴을 획득하고, 제1 상태 정보 및 제2 상태 정보를 식별하고, 상기 적어도 하나의 NE의 이상 상태를 식별하도록, 야기할 수 있다.
Description
본 개시(disclosure)는 이상 상태(anomaly)를 식별하기 위한 전자 장치 및 방법에 관한 것이다.
네트워크의 품질을 나타내기 위해 KPI(key performance indicator)가 정의될 수 있다. 무선 통신 시스템은, KPI에 관한 값을 통해 네트워크의 이상(anomaly)이 발생하였는지 여부를 판단할 수 있다. 무선 통신 시스템에서 KPI에 관한 값이 관리됨에 따라, 네트워크의 품질이 향상될 수 있다.
상술한 정보는 본 개시에 대한 이해를 돕기 위한 목적으로 하는 배경 기술(related art)로 제공될 수 있다. 상술한 내용 중 어느 것도 본 개시와 관련된 종래 기술(prior art)로서 적용될 수 있는지에 대하여 어떠한 주장이나 결정이 제기되지 않는다.
일 실시 예에 따르면, 전자 장치는, 인스트럭션들을 저장하고, 하나 이상의 저장 매체들을 포함하는 메모리, 및 처리 회로를 포함하는 적어도 하나의 프로세서를 포함할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 적어도 하나의 NE(network element)로부터, 상기 적어도 하나의 NE의 동작에 관한 로그 데이터를 획득하도록 야기할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 로그 데이터에 기반하여, 지정된 알고리즘을 통해 로그 패턴을 획득하도록 야기할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 로그 패턴에 기반하여, 제1 상태 정보 및 제2 상태 정보를 식별하도록 야기할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 제2 상태 정보가, 상기 제1 상태 정보를 이용하여 적어도 하나의 모델을 통해 식별된 상태 정보와 구별됨을 식별하도록 야기할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 제2 상태 정보가 상기 적어도 하나의 모델을 통해 식별된 상태 정보와 구별됨을 식별하는 것에 기반하여, 상기 적어도 하나의 NE의 이상 상태를 식별하도록, 야기할 수 있다.
일 실시 예에 따르면, 전자 장치에 의해 수행되는 방법은, 적어도 하나의 NE(network element)로부터, 상기 적어도 하나의 NE의 동작에 관한 로그 데이터를 획득하는 동작을 포함할 수 있다. 상기 방법은, 상기 로그 데이터에 기반하여, 지정된 알고리즘을 통해 로그 패턴을 획득하는 동작을 포함할 수 있다. 상기 방법은, 상기 로그 패턴에 기반하여, 제1 상태 정보 및 제2 상태 정보를 식별하는 동작을 포함할 수 있다. 상기 방법은, 상기 제2 상태 정보가, 상기 제1 상태 정보를 이용하여 적어도 하나의 모델을 통해 식별된 상태 정보와 구별됨을 식별하는 동작을 포함할 수 있다. 상기 방법은, 상기 제2 상태 정보가 상기 적어도 하나의 모델을 통해 식별된 상태 정보와 구별됨을 식별하는 것에 기반하여, 상기 적어도 하나의 NE의 이상 상태를 식별하는 동작을 포함할 수 있다.
도 1은 무선 통신 시스템을 도시한다.
도 2는 NE(network element)의 동작에 관한 로그 데이터를 획득하기 위한 전자 장치를 포함하는 시스템을 도시한다.
도 3은 SDN(software defined network) 아키텍처의 예를 도시한다.
도 4는, 이상 상태 감지기(anomaly detector)의 구성을 도시한다.
도 5는 이상 상태 감지기의 동작에 관한 흐름도를 도시한다.
도 6은 로그 파서의 동작의 예를 도시한다.
도 7은 상태 모델의 동작의 예를 도시한다.
도 8은 예측 모델의 동작의 예를 도시한다.
도 9는 이상 상태 감지기의 동작에 관한 흐름도를 도시한다.
도 10은 전자 장치의 기능적 구성의 예를 도시한다.
본 개시에서 사용되는 용어들은 단지 특정한 실시 예를 설명하기 위해 사용된 것으로, 다른 실시 예의 범위를 한정하려는 의도가 아닐 수 있다. 단수의 표현은 문맥상 명백하게 다르게 뜻하지 않는 한, 복수의 표현을 포함할 수 있다. 기술적이거나 과학적인 용어를 포함해서 여기서 사용되는 용어들은 본 개시에 기재된 기술 분야에서 통상의 지식을 가진 자에 의해 일반적으로 이해되는 것과 동일한 의미를 가질 수 있다. 본 개시에 사용된 용어들 중 일반적인 사전에 정의된 용어들은, 관련 기술의 문맥상 가지는 의미와 동일 또는 유사한 의미로 해석될 수 있으며, 본 개시에서 명백하게 정의되지 않는 한, 이상적이거나 과도하게 형식적인 의미로 해석되지 않는다. 경우에 따라서, 본 개시에서 정의된 용어일지라도 본 개시의 실시 예들을 배제하도록 해석될 수 없다.
이하에서 설명되는 본 개시의 다양한 실시 예들에서는 하드웨어적인 접근 방법을 예시로서 설명한다. 하지만, 본 개시의 다양한 실시 예들에서는 하드웨어와 소프트웨어를 모두 사용하는 기술을 포함하고 있으므로, 본 개시의 다양한 실시 예들이 소프트웨어 기반의 접근 방법을 제외하는 것은 아니다.
이하 설명에서 사용되는 신호를 지칭하는 용어(예: 신호, 정보, 심볼, 메시지, 시그널링, RS(reference signal), 데이터(data))), 자원을 지칭하는 용어(예: 심볼(symbol), 슬롯(slot), 서브프레임(subframe), 무선 프레임(radio frame), 서브캐리어(subcarrier), RE(resource element), RB(resource block), BWP(bandwidth part), 기회(occasion)), 연산 상태를 위한 용어(예: 단계(step), 동작(operation), 절차(procedure)), 데이터를 지칭하는 용어(예: 패킷, 사용자 스트림, 정보(information), 비트(bit), 심볼(symbol), 코드워드(codeword)), 채널을 지칭하는 용어, 네트워크 객체(network entity)들을 지칭하는 용어, 장치의 구성 요소를 지칭하는 용어 등은 설명의 편의를 위해 예시된 것이다. 따라서, 본 개시가 후술되는 용어들에 한정되는 것은 아니며, 동등한 기술적 의미를 가지는 다른 용어가 사용될 수 있다.
또한, 본 개시에서, 특정 조건의 만족(satisfied), 충족(fulfilled) 여부를 판단하기 위해, 초과 또는 미만의 표현이 사용될 수 있으나, 이는 일 예를 표현하기 위한 기재일 뿐 이상 또는 이하의 기재를 배제하는 것이 아니다. '이상'으로 기재된 조건은 '초과', '이하'로 기재된 조건은 '미만', '이상 및 미만'으로 기재된 조건은 '초과 및 이하'로 대체될 수 있다. 또한, 이하, 'A' 내지 'B'는 A부터(A 포함) B까지의(B 포함) 요소들 중 적어도 하나를 의미한다. 이하, 'C' 및/또는 'D'는 'C' 또는 'D' 중 적어도 하나, 즉, {'C', 'D', 'C'와 'D'}를 포함하는 것을 의미한다.
본 개시는, 일부 통신 규격(예: 3GPP(3rd Generation Partnership Project), xRAN(extensible radio access network), O-RAN(open-radio access network)에서 사용되는 용어들을 이용하여 다양한 실시 예들을 설명하지만, 이는 설명을 위한 예시일 뿐이다. 본 개시의 다양한 실시 예들은, 다른 통신 시스템에서도, 용이하게 변형되어 적용될 수 있다.
도 1은 무선 통신 시스템을 도시한다.
도 1을 참고하면, 도 1은 무선 통신 시스템에서 무선 채널을 이용하는 노드(node)들의 일부로서, 기지국(110) 및 단말(120)을 예시한다. 도 1은 하나의 기지국만을 도시하나, 무선 통신 시스템은 기지국(110)과 동일 또는 유사한 다른 기지국을 더 포함할 수 있다.
기지국(110)은 단말(120)에게 무선 접속을 제공하는 네트워크 인프라스트럭쳐(infrastructure)이다. 기지국(110)은 신호를 송신할 수 있는 거리에 기초하여 정의되는 커버리지(coverage)를 가진다. 기지국(110)은 기지국(base station) 외에 '액세스 포인트(access point, AP)', '이노드비(eNodeB, eNB)', '5G 노드(5th generation node)', '지노드비(next generation nodeB, gNB)', '무선 포인트(wireless point)', '송수신 포인트(transmission/reception point, TRP)' 또는 이와 동등한 기술적 의미를 가지는 다른 용어로 지칭될 수 있다.
단말(120)은 사용자에 의해 사용되는 장치로서, 기지국(110)과 무선 채널을 통해 통신을 수행한다. 기지국(110)에서 단말(120)을 향하는 링크는 하향링크(downlink, DL), 단말(120)에서 기지국(110)을 향하는 링크는 상향링크(uplink, UL)라 지칭된다. 또한, 도 1에 도시되지 않았으나, 단말(120)과 다른 단말은 상호 간 무선 채널을 통해 통신을 수행할 수 있다. 이때, 단말(120) 및 다른 단말 간 링크(device-to-device link, D2D)는 사이드링크(sidelink)라 지칭되며, 사이드링크는 PC5 인터페이스와 혼용될 수 있다. 다른 일부 실시 예들에서, 단말(120)은 사용자의 관여 없이 운영될 수 있다. 일 실시 예에 따라, 단말(120)은 기계 타입 통신(machine type communication, MTC)을 수행하는 장치로서, 사용자에 의해 휴대되지 아니할 수 있다. 또한, 일 실시 예에 따라, 단말(120)은 NB(narrowband)-IoT(internet of things) 기기일 수 있다.
단말(120)은 단말(terminal) 외 '사용자 장비(user equipment, UE)', '고객 댁내 장치'(customer premises equipment, CPE), '이동국(mobile station)', '가입자국(subscriber station)', '원격 단말(remote terminal)', '무선 단말(wireless terminal)', 전자 장치(electronic device)', 또는 '사용자 장치(user device)' 또는 이와 동등한 기술적 의미를 가지는 다른 용어로 지칭될 수 있다.
웹 기반의 서비스가 증가함에 따라, 네트워크의 규모가 커지고, 네트워크 구성의 복잡도가 증가할 수 있다. 네트워크 구성의 복잡도가 증가함에 따라, 장애, 고장, 패킷 손실, 및/또는 지연(latency) 증가를 포함하는 다양한 문제들이 발생할 수 있다. 이러한 문제들을 해결하기 위해, 네트워크를 구성하는 NE(network element)(또는 네트워크 장비)들에 대한 심각한 고장이 발생하기 전, NE들에 대한 이상 상태(anomaly)를 식별하기 위한 방안이 요구될 수 있다.
NE들에 대한 이상 상태(anomaly)를 식별하기 위해서는, NE들 및 NE들과 관련된 시스템들의 자원 사용량, NE들 및 NE들과 관련된 시스템들의 상태 정보, 네트워크 트래픽 정보, 및/또는 로그 데이터 중 적어도 하나에 기반하여 네트워크의 상태가 실시간으로 모니터링되어야 한다. 네트워크 상태 및/또는 NE들의 상태를 실시간으로 모니터링하는 것은 많은 인적 자원 및 물적 자원이 필요할 수 있다. 따라서, 이하 명세서에서는, NE들에서 출력되는 로그 데이터(또는 NE들로부터 획득된 로그 데이터)에 기반하여, NE들의 동작에 관한 이상 상태를 식별하기 위한 기술적 특징이 설명될 것이다.
일 실시 예에 따르면, 로그 데이터는 NE(또는 네트워크 장비)의 상태를 나타낼 수 있다. 다만, 로그 데이터는 NE(또는 네트워크 장비)의 제조사(또는 개발자)에 따라 다른 형식의 텍스트 데이터로 구성될 수 있다. 예를 들어, 로그 데이터는 비정형 데이터로 구성될 수 있다. 따라서, 지능(artificial intelligence)에 기반한 자연 언어 처리(natural language processing, NLP)를 이용하여 로그 데이터를 분석하기 위한 전자 장치의 동작이 이하에서 설명될 것이다.
도 2는 NE(network element)의 동작에 관한 로그 데이터를 획득하기 위한 전자 장치를 포함하는 시스템을 도시한다.
도 2를 참고하면, 전자 장치(210)는 복수의 NE(network element)들(230)의 동작에 관한 로그 데이터를 획득하기 위해 사용될 수 있다. 예를 들어, 복수의 NE들(230)은 NE(230-1) 및 NE(230-2)를 포함할 수 있다. 예를 들어, 복수의 NE들(230)은 라우터(router), DU(distributed unit) 및/또는 RU(radio unit)를 포함할 수 있다. 예를 들어, NE는 네트워크 장치(network device)로 참조될 수 있다.
복수의 NE들(230) 각각은 동작에 대한 로그 데이터를 생성할 수 있다. 복수의 NE들(230) 각각은 동작에 대한 로그 데이터를 전자 장치(210)에게 전송할 수 있다. 예를 들어, 전자 장치(210)는 다양한 형식에 기반하여 생성된 로그 데이터를 수신할 수 있다. 전자 장치(210)는 로그 데이터를 모니터링 할 수 있다. 전자 장치(210)는 로그 데이터를 모니터링 하는 것에 기반하여, 복수의 NE들(230)에 대한 이상 상태(anomaly)를 식별(또는 결정)할 수 있다.
이하에서 이상 상태(anomaly)는 비정상 상태(abnormal state)로 참조될 수 있다. 예를 들어, NE의 이상 상태를 식별한다는 것은, 비정상 상태의 NE를 식별하는 것으로 참조될 수 있다.
일 실시 예에 따르면, 전자 장치(210)는 NE(예: NE(230-1), NE(230-2))의 센서를 통해 수집된 데이터 또는 NE 또는 전자 장치(210)에서 출력되는 데이터를 획득할 수 있다. 상기 획득된 데이터는 특정한 값의 형식으로 구성될 수 있다. 획득된 데이터의 정상 범위 및 비정상 범위에 대한 정보가 전자 장치(210)의 메모리에 저장된 상태일 수 있다. 전자 장치(210)는 획득된 데이터에 기반하여, NE가 이상 상태에 있는지 여부를 식별 또는 결정할 수 있다.
일 실시 예에 따르면, 전자 장치(210)는 NE의 동작에 관한 비정형 데이터(unstructured data)를 획득할 수 있다. 비정형 데이터는 특정한 값의 형식이 아닐 수 있다. 전자 장치(210)는 획득된 비정형 데이터를 프로세싱할 수 있다. 전자 장치(210)는 프로세싱된 데이터에 기반하여, NE의 이상 상태를 식별(또는 판단)할 수 있다. 예를 들어, 전자 장치(210)는 2 가지의 기법들 중 적어도 하나를 이용하여, 비정형 데이터에 기반하여 NE의 이상 상태를 식별할 수 있다. 제1 기법에 따르면, 전자 장치(210)는 NE의 특정 작업(또는 동작)에 대한 결과에 기반하여, NE의 이상 상태를 식별할 수 있다. 제2 기법에 따르면, 전자 장치(210)는 NE의 동작에 관한 로그 데이터에 기반하여, NE의 이상 상태를 식별할 수 있다. 제2 기법은, 규칙 기반(rule-based)으로 동작 할 수 있다. 제2 기법에 따르면, 특정 로그가 발생되는 것에 기반하여, 알람이 발생될 수 있다.
제1 기법에 따르면, 전자 장치(210)는 NE의 특정 작업(또는 동작)에 대한 결과에 기반하여, NE의 이상 상태를 식별할 수 있다. NE의 특정 작업(또는 동작)에 대한 결과는 복수의 카테고리들 중 하나로 구분될 수 있다. 따라서, 전자 장치(210)는 NE의 특정 작업(또는 동작)에 대한 결과가 복수의 카테고리들 중 하나에 포함되는지 여부를 판단하는 것에 기반하여, NE의 이상 상태를 판단할 수 있다. 전자 장치(210)는 순차적으로 수행되는 작업(또는 동작)들에 대한 결과가 복수의 카테고리들 중 하나에 포함되는지 여부를 판단하는 것에 기반하여, NE의 이상 상태를 판단할 수 있다.
제2 기법에 따르면, 전자 장치(210)는 NE의 동작에 관한 로그 데이터에 기반하여, NE의 이상 상태를 식별할 수 있다. 로그 데이터는 비정형 데이터로 구성될 수 있다. 로그 데이터는 NE에 대한 제조사(또는 개발자, 사용자)가 출력이 필요하다고 판단한 정보들을 나타내는 텍스트를 포함할 수 있다. 제조사(또는 개발자, 사용자) 또는 NE의 유형에 따라 로그 데이터는 다른 형식으로 구성될 수 있다. 따라서, 전자 장치(210)는 에러를 지시하는 로그 데이터가 지정된 내용을 포함하는 경우, NE가 비정상 상태임(또는 NE의 이상 상태(anomaly))을 식별할 수 있다. 실시 예에 따라, 전자 장치(210)는 로그 데이터 내에서 공통된 부분을 로그 키(log key)로 식별(또는 추출)할 수 있다. 전자 장치(210)는 로그 키에 기반하여, 로그 데이터의 의미를 분석할 수 있다. 전자 장치(210)는 로그 데이터의 의미에 따라, NE가 비정상 상태인지 여부를 판단할 수 있다. 실시 예에 따라, 전자 장치(210)는 시간 순으로 정렬된 로그 데이터를 이용하여 식별된 정상 로그 패턴을 통해 지정된 모델(예: 인공지능 모델)을 학습시킬 수 있다. 전자 장치(210)는 로그 데이터를 지정된 모델의 입력 데이터로 설정할 수 있다. 전자 장치(210)는 지정된 모델의 출력 데이터에 기반하여, NE가 비정상 상태인지 여부를 판단할 수 있다. 다만, 제2 기법에 따르면, 반복되는 단어가 로그 키로 설정되므로, 반복되는 단어에 대한 의미가 고려되지 않을 수 있다. 따라서, 실제 로그 데이터의 내용이 반영이 되지 않을 수도 있다.
이하에서는, SDN(software defined network)에 기반하여 구성된 네트워크에서, 적어도 하나의 모델(예: 인공 지능 모델)을 이용하여, NE의 이상 상태를 식별하기 위한 기술적 특징이 설명될 것이다. 먼저 도 3에서 SDN 아키텍처(architecture)가 설명될 것이다.
도 3은 SDN(software defined network) 아키텍처의 예를 도시한다.
도 3을 참고하면, SDN(300)는 애플리케이션 레이어(310), 제어 플레인 레이어(control plane layer)(320), 및/또는 데이터 플레인 레이어(data plane layer)(330)를 포함할 수 있다.
애플리케이션 레이어(310)는, 라우팅(routing) 및/또는 로드 밸런스(load balance)를 포함하는 제어 동작을 위해 사용되는 하나 이상의 애플리케이션들을 포함할 수 있다. 애플리케이션은 SDN 컨트롤러에 의해 노출되는(exposed) 자원 셋(resource set)을 독점적으로 제어할 수 있다. 애플리케이션은 다른 애플리케이션을 호출(invoke)하거나 다른 애플리케이션과 협력(collaborate)할 수 있다.
제어 플레인 레이어(320)는 SDN 컨트롤러(321)를 포함할 수 있다. SDN 컨트롤러(321)는 전체 네트워크 자원들에 대한 제어를 위해 사용될 수 있다. SDN 컨트롤러(321)는 네트워크 정보를 획득하고, 획득된 정보를 애플리케이션에게 제공할 수 있다.
데이터 플레이 레이어(330)는 적어도 하나의 NE(331)를 포함할 수 있다. 적어도 하나의 NE(331)는 적어도 하나의 물리 스위치(physical switch) 및/또는 적어도 하나의 가상 스위치(virtual switch)를 포함할 수 있다.
제어 플레인 레이어(320) 및 애플리케이션 레이어(310) 사이의 인터페이스는 northbound API(application programming interface)로 참조될 수 있다. 제어 플레인 레이어(320) 및 데이터 플레인 레이어(330) 사이의 인터페이스는 southbound API로 참조될 수 있다. 예를 들어, 제어 플레인 레이어(320) 및 데이터 플레인 레이어(330) 사이에서, 오픈 플로우 프로토콜(openflow protocol) 또는 OpFlex 프로토콜이 사용될 수 있다.
기존의 NE(또는 네트워크 장비)들은 데이터 플레인 및 제어 플레인에 기반하여, 독립적으로 동작하는 것에 반해, SDN(300)에서는 NE의 데이터 플레인 및 제어 플레인이 분리될 수 있다. SDN 컨트롤러(321)는 NE의 제어 플레인의 동작을 수행할 수 있다. SDN(300)은 네트워크 제어를 위한 알고리즘에 기반하여 동작할 수 있다. 따라서, SDN(300)에서, 관리자의 개입 없이도 네트워크가 지정된 알고리즘에 기반하여 관리 및 제어될 수 있다. 또한 네트워크를 구성하는 적어도 하나의 NE(331)이 SDN 컨트롤러(321)을 통해 관리될 수 있다. 적어도 하나의 NE(331)은 SDN 컨트롤러(321)와 연동하여 동작하기 위해, REST(representational state transfer protocol), NETCONF(network configuration protocol), 또는 RESTCONF(representational state transfer configuration protocol) 중 적어도 하나를 지원할 수 있다. SDN 컨트롤러(321)는 REST, NETCONF, 또는 RESTCONF 중 적어도 하나를 이용하여 적어도 하나의 NE(331)를 제어할 수 있다.
이하에서는, SDN(300)에서, 인공지능을 이용하여, 네트워크 관리를 수행하기 위한 기술적 특징이 설명될 것이다. 예를 들어, SDN 컨트롤러(321)을 통해 획득된 네트워크 정보(예: 로그 데이터)를 이용하여, 인공지능 모델을 통해 네트워크가 분석되고, 문제가 발생되는 경우, 인공지능 모델을 통해 발생된 문제를 해결할 수 있다. 예를 들어, SDN(300)에서, 인공지능 모델을 이용하여 NE의 이상 상태가 모니터링될 수 있다. SDN 컨트롤러(321)는 NE의 이상 상태가 발견되는 경우, 해당 NE를 격리하고, 네트워크 트래픽을 다른 NE를 통해서 전송하도록 제어할 수 있다.
도 4는, 이상 상태 감지기(anomaly detector)의 구성을 도시한다. 이하 사용되는 '...부', '...기' 등의 용어는 적어도 하나의 기능이나 동작을 처리하는 단위를 의미하며, 이는 하드웨어나 소프트웨어, 또는, 하드웨어 및 소프트웨어의 결합으로 구현될 수 있다.
도 4를 참고하면, 적어도 하나의 NE(410)은 로그 데이터를 네트워크 컨트롤러(420)에게 전송할 수 있다. 네트워크 컨트롤러(420)는 적어도 하나의 NE(410)로부터 로그 데이터를 수신할 수 있다. 예를 들어, 네트워크 컨트롤러(420)는 도 3의 SDN 컨트롤러(321)에 상응할 수 있다.
네트워크 컨트롤러(420)는 로그 수집부(421) 및 네트워크 구성부(422)를 포함할 수 있다. 로그 수집부(421)는 적어도 하나의 NE(410)로부터 로그 데이터를 수신하고, 수신된 로그 데이터를 이상 상태 감지기(450)에게 전송하도록 구성(configure)될 수 있다. 네트워크 구성부(422)는 적어도 하나의 NE(410)의 설정을 변경하거나, 적어도 하나의 NE(410)의 동작을 제어하도록 구성될 수 있다.
이상 상태 감지기(450)는 로그 파서(log parser)(460) 및 분석기(analyzer)(470)를 포함할 수 있다. 적어도 하나의 NE(410)로부터 수집된 로그 데이터는, 네트워크 컨트롤러(420)를 통해 로그 파서(460)로 전달될 수 있다.
로그 파서(460)은 전처리부(461), 패턴 분석부(462), 및/또는 상태 정보 식별부(463) 중 적어도 하나를 포함할 수 있다. 전처리부(461)는 로그 데이터를 전처리(preprocessing)하기 위해 사용될 수 있다. 패턴 분석부(462)는 로그 데이터에 기반하여, 로그 패턴을 획득(또는 식별)하기 위해 사용될 수 있다. 상태 정보 식별부(463)는 로그 패턴에 기반하여, 상태 정보를 식별하기 위해 사용될 수 있다. 예를 들어, 상태 정보는, 로그 데이터에 관한 이벤트 번호를 포함할 수 있다. 상태 정보 식별부(463)는 이벤트 분류부로 참조될 수 있다. 로그 파서(460)의 구체적인 동작은 도 6에서 후술될 것이다.
분석기(470)는 로그 파서(460)로부터 상태 정보를 수신할 수 있다. 분석기(470)는 상태 정보에 기반하여, 적어도 하나의 NE(410)의 이상 상태를 식별할 수 있다. 분석기(470)는 상태 모델(471) 및/또는 예측 모델(472) 중 적어도 하나를 포함할 수 있다.
상태 모델(471)은 로그 패턴에 대한 상태 변화에 기반하여, 적어도 하나의 NE(410)의 이상 상태를 식별하기 위해 사용될 수 있다. 상태 모델(471)은 유한 상태 기계(finite state automata)에 기반하여 구성될 수 있다. 상태 모델(471)의 구체적인 동작은 도 7에서 후술될 것이다.
예측 모델(472)은 로그 패턴에 대한 예측된 상태에 기반하여, 적어도 하나의 NE(410)의 이상 상태를 식별하기 위해 사용될 수 있다. 예측 모델(472)는 LSTM(long short term memory)에 기반하여 구성될 수 있다. 예측 모델(472)의 구체적인 동작은 도 8에서 후술될 것이다.
일 실시 예에 따르면, 이상 상태 감지기(450)는 3 단계들을 통해 적어도 하나의 NE(410)의 이상 상태(anomaly)를 식별할 수 있다.
첫 번째 단계에서, 이상 상태 감지기(450)는 로그 파서(460)을 이용하여, 로그 데이터에 기반하여 획득된 로그 패턴이, 정상 상태를 나타내는 복수의 로그 패턴들 중 하나에 상응하는지 여부를 식별하는 것에 기반하여, 적어도 하나의 NE(410)가 비정상 상태에 있는지 여부를 식별할 수 있다. 이상 상태 감지기(450) (또는 네트워크 컨트롤러(420))는 첫 번째 단계를 통해, 적어도 하나의 NE(410)의 이상 상태를 식별하는 것에 기반하여, 알림(notification)(또는 알람(alarm))을 제공할 수 있다. 이상 상태 감지기(450)는 첫 번째 단계를 통해, 적어도 하나의 NE(410)의 이상 상태가 아님을 식별하는 것에 기반하여, 두 번째 단계를 수행할 수 있다.
두 번째 단계에서, 이상 상태 감지기(450)는 로그 파서(460)를 이용하여 획득된 상태 정보가 상태 모델(471)을 이용하여 획득된 상태 정보에 상응하는지 여부를 식별하는 것에 기반하여, 적어도 하나의 NE(410)가 비정상 상태에 있는지 여부를 식별할 수 있다. 이상 상태 감지기(450)(또는 네트워크 컨트롤러(420))는 두 번째 단계를 통해, 적어도 하나의 NE(410)의 이상 상태를 식별하는 것에 기반하여, 알림(notification)(또는 알람(alarm))을 제공할 수 있다. 이상 상태 감지기(450)는 두 번째 단계를 통해, 적어도 하나의 NE(410)의 이상 상태가 아님을 식별하는 것에 기반하여, 세 번째 단계를 수행할 수 있다.
세 번째 단계에서, 이상 상태 감지기(450)는 로그 파서(460)를 이용하여 획득된 상태 정보가 예측 모델(472)을 이용하여 획득된 상태 정보에 상응하는지 여부를 식별하는 것에 기반하여, 적어도 하나의 NE(410) 비정상 상태에 있는지 여부를 식별할 수 있다. 이상 상태 감지기(450)(또는 네트워크 컨트롤러(420))는 세 번째 단계를 통해, 적어도 하나의 NE(410)의 이상 상태를 식별하는 것에 기반하여, 알림(notification)(또는 알람(alarm))을 제공할 수 있다.
일 실시 예에 따르면, 네트워크 컨트롤러(420)는 적어도 하나의 NE(410)의 이상 상태를 식별하는 것에 기반하여, 데이터 트래픽의 경로를 이상 상태가 발생한 NE를 우회하도록 변경할 수 있다.
도 5는 이상 상태 감지기의 동작에 관한 흐름도를 도시한다.
도 5를 참고하면, 동작 510에서, 이상 상태 감지기(450)(또는 이상 상태 감지기(450)를 위한 전자 장치)는 적어도 하나의 NE(410)의 동작에 관한 로그 데이터를 획득할 수 있다. 예를 들어, 이상 상태 감지기(450)는 네트워크 컨트롤러(420)를 통해, 적어도 하나의 NE(410)의 동작에 관한 로그 데이터를 획득할 수 있다. 이상 상태 감지기(450)는 적어도 하나의 NE(410)의 동작에 관한 로그 데이터를 모니터링할 수 있다.
동작 520에서, 이상 상태 감지기(450)는 지정된 알고리즘을 통해 로그 패턴을 획득할 수 있다. 예를 들어, 이상 상태 감지기(450)는 로그 데이터에 기반하여, 지정된 알고리즘을 통해 로그 패턴을 획득할 수 있다. 예를 들어, 이상 상태 감지기(450)는 로그 파서(460)를 이용하여 로그 패턴을 획득할 수 있다.
예를 들어, 이상 상태 감지기(450)는 지정된 알고리즘에 기반하여, 로그 데이터를 정규화(normalize)할 수 있다. 이상 상태 감지기(450)는 로그 데이터를 통해 상태 정보를 식별하기 위해, 로그 데이터를 정규화할 수 있다. 이상 상태 감지기(450)는 지정된 알고리즘을 통해 로그 데이터에서 불필요한 정보들을 제거할 수 있다. 이상 상태 감지기(450)는 로그 데이터에서 불필요한 정보들을 제거함으로써, 로그 데이터를 정규화할 수 있다. 이상 상태 감지기(450)는 로그 데이터를 정규화하는 것에 기반하여, 로그 패턴을 획득할 수 있다. 이상 상태 감지기(450)는 상태 정보를 식별하기 위해 로그 패턴을 획득할 수 있다.
동작 530에서, 이상 상태 감지기(450)는 제1 상태 정보 및 제2 상태 정보를 식별할 수 있다. 예를 들어, 이상 상태 감지기(450)는 로그 패턴에 기반하여, 제1 상태 정보 및 제2 상태 정보를 식별할 수 있다. 예를 들어, 로그 데이터는 지정된 시간 구간 내에서 획득된 로그 메시지(텍스트)들을 포함할 수 있다. 제1 상태 정보는 제1 시점에서의 적어도 하나의 NE(410)에 관한 상태를 나타낼 수 있다. 제2 상태 정보는 제1 시점 이후의 제2 시점에서의 적어도 하나의 NE(410)에 관한 상태를 나타낼 수 있다. 예를 들어, 제1 상태 정보는 적어도 하나의 NE(410)의 과거의 상태를 나타낼 수 있다. 제2 상태 정보는 적어도 하나의 NE(410)의 현재의 상태를 나타낼 수 있다. 예를 들어, 제1 상태 정보는 제1 이벤트 번호를 포함할 수 있다. 제2 상태 정보는 제2 이벤트 번호를 포함할 수 있다. 제1 이벤트 번호 및 제2 이벤트 번호 각각은 적어도 하나의 NE(410)의 상태를 지시하기 위한 값일 수 있다.
일 실시 예에 따르면, 이상 상태 감지기(450)는 로그 패턴이 메모리에 저장된 복수의 로그 패턴들 중 하나에 상응하는지 여부를 식별할 수 있다. 메모리에 저장된 복수의 로그 패턴들은 정상 상태를 나타낼 수 있다. 이상 상태 감지기(450)는 로그 패턴이 메모리에 저장된 복수의 로그 패턴들 중 하나에 상응하는 경우, 로그 패턴에 기반하여, 제1 상태 정보 및 제2 상태 정보를 식별할 수 있다. 이상 상태 감지기(450)는 로그 패턴이 메모리에 저장된 복수의 로그 패턴들 중 하나에 상응하지 않는 경우, 적어도 하나의 NE(410)의 이상 상태를 식별할 수 있다.
동작 540에서, 이상 상태 감지기(450)는 제2 상태 정보가 제1 상태 정보를 이용하여 적어도 하나의 모델을 통해 식별된 상태 정보와 구별됨을 식별할 수 있다.
동작 550에서, 이상 상태 감지기(450)는 적어도 하나의 NE(410)의 이상 상태를 식별할 수 있다. 예를 들어, 이상 상태 감지기(450)는 제2 상태 정보가 제1 상태 정보를 이용하여 적어도 하나의 모델을 통해 식별된 상태 정보와 구별됨을 식별하는 것에 기반하여, 적어도 하나의 NE(410)의 이상 상태를 식별할 수 있다.
예를 들어, 이상 상태 감지기(450)는 제1 상태 정보를 이용하여, 적어도 하나의 모델을 통해 상태 정보를 식별할 수 있다. 이상 상태 감지기(450)는 과거의 상태를 나타내는 제1 상태 정보를 이용하여, 적어도 하나의 모델을 통해 상태 정보를 식별할 수 있다. 이상 상태 감지기(450)는 식별된 상태 정보가 제2 상태 정보와 구별됨을 식별하는 것에 기반하여, 적어도 하나의 NE(410)의 이상 상태를 식별할 수 있다.
일 실시 예에 따르면, 적어도 하나의 모델은 상태 모델(471) 및 예측 모델(472)을 포함할 수 있다.
예를 들어, 이상 상태 감지기(450)는 상태 모델(471)을 통해 제3 상태 정보를 식별할 수 있다. 이상 상태 감지기(450)는 제1 상태 정보를 상태 모델(471)에 입력할 수 있다. 이상 상태 감지기(450)는 상태 모델(471)의 입력 데이터를 제1 상태 정보로 설정할 수 있다. 이상 상태 감지기(450)는 상태 모델(471)의 출력에 기반하여, 제3 상태 정보를 획득할 수 있다. 예를 들어, 상태 모델(471)은 정상 상태에서 제1 상태 정보로부터 변경(또는 전이) 가능한 상태 정보를, 제3 상태 정보로 식별할 수 있다. 이상 상태 감지기(450)는 제2 상태 정보가 제1 상태 정보로부터 변경 가능한 상태 정보가 아님을 식별하는 것에 기반하여, 적어도 하나의 NE(410)의 이상 상태를 식별할 수 있다.
예를 들어, 이상 상태 감지기(450)는 예측 모델(472)을 통해 제4 상태 정보를 식별할 수 있다. 이상 상태 감지기(450)는 제1 상태 정보를 예측 모델(472)에 입력할 수 있다. 이상 상태 감지기(450)는 예측 모델(472)의 입력 데이터를 제1 상태 정보로 설정할 수 있다. 이상 상태 감지기(450)는 예측 모델(472)의 출력에 기반하여, 제4 상태 정보를 획득할 수 있다. 예를 들어, 예측 모델(472)은 정상 상태에서 제1 상태 정보로부터 변경될 것으로 예측되는 상태 정보를, 제4 상태 정보로 식별할 수 있다. 일 예로, 이상 상태 감지기(450)는 예측 모델(472)의 출력에 기반하여, 복수의 상태들 각각에 대한 확률 데이터를 식별할 수 있다. 이상 상태 감지기(450)는 복수의 상태들 중 가장 높은 확률을 가지는 상태에 기반하여, 제4 상태 정보를 획득할 수 있다.
이상 상태 감지기(450)는 제2 상태 정보가 예측된 상태를 나타내는 제4 상태 정보가 아님을 식별하는 것에 기반하여, 적어도 하나의 NE(410)의 이상 상태를 식별할 수 있다.
도 6은 로그 파서의 동작의 예를 도시한다.
도 6을 참고하면, 이상 상태 감지기(450)는 로그 파서(460)를 이용하여, 적어도 하나의 NE(410)로부터 획득된 로그 데이터를 가공할 수 있다. 예를 들어, 로그 파서(460)은 전처리부(461), 패턴 분석부(462), 및/또는 상태 정보 식별부(463) 중 적어도 하나를 포함할 수 있다. 이상 상태 감지기(450)는 로그 파서(460)를 이용하여, 전처리 동작, 패턴 분석 동작, 및 상태 정보 식별 동작을 수행할 수 있다. 이상 상태 감지기(450)는 로그 파서(460)를 통해 로그 데이터를 로그 패턴으로 변경할 수 있다. 이상 상태 감지기(450)는 상기 로그 패턴이 메모리에 저장된 복수의 로그 패턴들 중 하나에 상응하는지 여부를 식별할 수 있다. 메모리에 저장된 복수의 로그 패턴들은 정상 상태를 나타낼 수 있다. 이상 상태 감지기(450)는 상기 로그 패턴이 메모리에 저장된 복수의 로그 패턴들 중 하나에 상응하지 않음을 식별하는 것에 기반하여, 알림(또는 알람)을 제공할 수 있다.
예를 들어, 이상 상태 감지기(450)는 로그 파서(460)의 전처리부(461)를 이용하여, 전처리 동작을 수행할 수 있다. 이상 상태 감지기(450)는 전처리부(461)를 이용하여, 로그 데이터의 정규화할 수 있다.
일 예로, 전처리부(461)는 로그 데이터에 따른 로그 내용의 대문자를 소문자로 변경할 수 있다. 전처리부(461)는 지정된 규칙(rule)에 따라 로그 내용 중 숫자, 날짜, 파일 경로, 지역 명, 인터페이스 명, 및/또는 기호 중 적어도 하나를 제거할 수 있다. 제거되는 단어 중 일부는 의미를 가지는 토큰(token)으로 대체될 수 있다. 예를 들어, 로그 내용에 포함된 단어 중 일부는 하기의 표와 같이 변경될 수 있다.
표 1을 참고하면, 로그 내용에 포함된 단어들 중 일부는 표 1과 같은 규칙에 기반하여 토큰으로 치환될 수 있다. 예를 들어, 로그 내용에 포함된 숫자(number)(또는 아라비아 숫자(East Arabic numerals))는 [number] 토큰으로 치환될 수 있다. n 진법(radix n)의 값은 정규 표현식(regular expression)에 기반하여 변환되고, 변환된 숫자는 [number] 토큰으로 치환될 수 있다. 날짜 및 지역명은 학습용 데이터를 통해 획득된 사전을 통해 제거될 수 있다. 일 예로, 날짜는 [date] 토큰으로 치환될 수 있다. 지역명은 [loc] 토큰으로 치환될 수 있다. 파일 경로는 리눅스 기반의 파일 경로가 '/'로 시작하므로, '/'로 시작하는 단어를 [path] 토큰으로 치환될 수 있다. 인터페이스는 'interface' 단어 다음에 인터페이스의 이름이 따라오므로, ‘interface' 단어 바로 뒤에 따라오는 단어는 [interface] 토큰으로 변경될 수 있다.
로그 파서(460)의 전처리부(461)를 통한 전처리 동작은 토큰으로 변경되지 않은 모든 기호를 제거함으로써 완료될 수 있다. 전처리 동작은 표 1과 같은 지정된 규칙에 기반하여 수행될 수 있다. 따라서, 사용자(또는 관리자)는 실제 로그 데이터에 따라 규칙을 변경함으로써, 전처리 동작을 변경할 수 있다.
예를 들어, 이상 상태 감지기(450)는 로그 파서(460)의 패턴 분석부(462)를 이용하여, 패턴 분석 동작을 수행할 수 있다. 이상 상태 감지기(450)는 전처리 동작이 수행된 후, 로그 파서(460)의 패턴 분석부(462)를 통해 패턴 분석 동작을 수행할 수 있다.
일 예로, 패턴 분석부(462)는 단어 사전에 기반하여, 로그 패턴을 식별(또는 분석)할 수 있다. 단어 사전은 정상 상태의 로그 데이터를 통해서 미리 생성될 수 있다. 전처리 동작이 수행된 후의 학습용 데이터(예: 로그 데이터)에서 지정된 횟수(예: 3회) 이상 나타난 단어들로 단어 사전이 생성될 수 있다. 지정된 횟수(예: 3회) 이상 나타난 단어들로 단어 사전이 생성되므로, 프로세스 ID(identifier)와 같은 일시적으로 생성되는 단어들이 제거될 수 있다. 상기 지정된 횟수는 패턴 분석부(462)에 대한 설정 정보에 따라 변경될 수 있다.
전처리 동작이 수행된 후 획득된 로그 내용 중 단어 사전에 없는 단어는 [UNK](unknown) 토큰으로 변경될 수 있다. 패턴 분석 동작이 수행된 후 로그 데이터는 실질적으로 동일한 형태의 로그 패턴으로 변경(또는 압축)될 수 있다. 로그 내용(또는 로그 메시지)가 ‘Interface HundGi0/3, changed state to FREQ_LOCK'와 같이 구성된 경우, 전처리 동작 및 패턴 분석 동작이 수행된 후, 'interface [interface] changed state to freq lock'와 같이 구성된 로그 패턴으로 변경될 수 있다. 이 때, 인터페이스 이름만이 [interface] 토큰으로 변경될 수 있다. 상술한 예에 따르면, 인터페이스가 다른 경우에도 동일한 동작에 관한 로그 내용(또는 로그 메시지)는 하나의 로그 패턴으로 표현될 수 있다.
예를 들어, 이상 상태 감지기(450)는 로그 파서(460)의 상태 정보 식별부(463)를 이용하여, 상태 정보 식별 동작을 수행할 수 있다. 이상 상태 감지기(450)는 패턴 분석이 수행된 후, 로그 파서(460)의 상태 정보 식별부(463)를 통해 상태 정보 식별 동작을 수행할 수 있다.
상태 정보 식별부(463)는 로그 패턴에 기반하여, 상태 정보를 식별(또는 획득)할 수 있다. 상태 정보는 이벤트 번호(event number)를 포함할 수 있다. 이벤트 번호는 적어도 하나의 NE(410)의 상태를 지시하기 위한 값일 수 있다. 상태 정보 식별부(463)을 통해 이벤트 번호가 식별(또는 획득)된 다는 점에서, 상태 정보 식별부(463)은 이벤트 분류부(event classification unit)으로 참조될 수 있다.
상태 정보 식별부(463)는 로그 패턴에 기반하여, 상태 정보(예: 이벤트 번호)를 식별할 수 있다. 상태 정보 식별 동작에 기반하여, 동일 또는 유사한 로그 패턴들은 동일한 상태 정보(예: 이벤트 번호)로 식별(또는 분류)될 수 있다. 학습용 데이터에 기반하여 획득된 로그 패턴들은 상태 정보 식별 동작을 통해 상태 사전에 등록될 수 있다. 각 상태 정보에 따른 로그 패턴 목록이 메모리에 저장될 수 있다.
상기 상태 사전을 구성하기 위한 동작은 최소 편집 거리(minimum edit distance) 알고리즘에 기반하여 수행될 수 있다. 최소 편집 거리 알고리즘은 두 문장의 유사도를 측정하기 위한 알고리즘일 수 있다. '단어 제거' 동작, '단어 추가' 동작, 및 '단어 변환' 동작을 각각 한 번의 수정으로 정의될 수 있다. 두 문장이 같아지기 위한 최소 수정 횟수를 통해 두 문장의 유사도가 측정될 수 있다.
최소 편집 거리 알고리즘에 따르면, 코스트(cost)가 정의될 수 있다. 예를 들어, 유의어 및 반의어 사전을 이용하여, '단어 변환' 동작에 따라 기존 단어와 변환되는 단어의 관계가 유의어인 경우, 코스트가 제1 코스트(예: '0')으로 설정될 수 있다. 유의어 및 반의어 사전을 이용하여, '단어 변환' 동작에 따라 기존 단어와 변환되는 단어의 관계가 반의어인 경우, 코스트가 제2 코스트(예: '6')으로 설정될 수 있다. 실시 예에 따라, 제1 코스트 및 제2 코스트는 변경될 수 있다. 예를 들어, 제1 코스트 및 제2 코스트는 관리자(또는 사용자)에 의해 변경될 수 있다.
두 로그 패턴들이 서로 반대되는 의미를 가지는 경우, '단어 변환' 동작에 대한 코스트를 더 증가시키기 위해, 반의어 사전이 사용될 수 있다. 'interface up' 및 'interface down'과 같이 두 로그 패턴들의 의미가 서로 반대되는 경우, 최소 편집 거리는 작으나 실제 의미는 반대이므로, 두 로그 패턴들은 서로 다른 상태 정보로 식별되어야 한다. 따라서, 상태 정보 식별부(463)는 반의어 사전을 이용하여, '단어 변환' 동작에 대한 코스트를 증가시킴으로써 반대의 의미를 가지는 두 로그 패턴들을 서로 다른 상태 정보로 식별할 수 있다. 실시 예에 따라, 반의어 사전은 WordNet과 같은 공개된 반의어 사전이 활용될 수 있다.
상술한 최소 편집 거리 알고리즘에 기반하여, 두 로그 패턴들이 동일해지기 위한 코스트가 두 로그 패턴 길이의 평균의 절반보다 작은 경우, 두 로그 패턴의 절반 이하가 수정됨에 따라, 두 로그 패턴이 서로 같아질 수 있다. 따라서, 두 로그 패턴들은 동일한 상태 정보(예: 이벤트 번호)로 식별(또는 분류)될 수 있다. 상술한 예와 같이 두 로그 패턴 길이의 평균의 절반이 기준으로 설정된 이유는, 일정한 임계 값이 기준으로 설정되는 경우, 짧은 로그 패턴들은 의미와 관계없이 항상 같은 상태 정보로 식별될 수 있는 문제를 방지하기 위한 것이다.
상술한 예를 통해, 최소 편집 거리 알고리즘에 기반하여, 학습용 데이터로부터 획득(또는 추출)된 복수의 로그 패턴들 각각이 상태 정보(예: 이벤트 번호)로 변경될 수 있다. 예를 들어, 코스트가 서로 다른 로그 패턴들은 서로 다른 상태 정보로 변경(도는 식별)될 수 있다. 예를 들어, 코스트가 서로 같은 로그 패턴들은 동일한 상태 정보로 변경(또는 식별)될 수 있다.
상술한 복수의 로그 패턴들 각각은 메모리에 저장될 수 있다. 따라서, 이상 상태 감지기(450)는 로그 데이터에 기반하여 식별된 로그 패턴이 메모리에 저장된 복수의 로그 패턴들 중 하나에 상응하는 것에 기반하여, 상태 정보를 식별할 수 있다. 이상 상태 감지기(450)는 로그 데이터에 기반하여 식별된 로그 패턴이 메모리에 저장된 복수의 로그 패턴들 중 하나에 상응하지 않는 것에 기반하여, 적어도 하나의 NE(410)의 이상 상태를 식별할 수 있다.
상술한 실시 예에서는, 로그 데이터에 기반하여 상태 정보가 식별되는 예가 도시되었으나 이에 한정되는 것은 아니다. 로그 데이터는 시간에 따른 동작들에 대한 정보를 나타낼 수 있다. 따라서, 로그 데이터에 기반하여, 제1 상태 정보 및 제2 상태 정보가 식별될 수 있다.
일 예로, 제1 상태 정보는 제1 시점에서의 적어도 하나의 NE(410)에 관한 상태를 나타낼 수 있다. 제2 상태 정보는 제1 시점 이후의 제2 시점에서의 적어도 하나의 NE(410)에 관한 상태를 나타낼 수 있다. 예를 들어, 제1 상태 정보는 적어도 하나의 NE(410)의 과거의 상태를 나타낼 수 있다. 제2 상태 정보는 적어도 하나의 NE(410)의 현재의 상태를 나타낼 수 있다. 예를 들어, 제1 상태 정보는 제1 이벤트 번호를 포함할 수 있다. 제2 상태 정보는 제2 이벤트 번호를 포함할 수 있다. 제1 이벤트 번호 및 제2 이벤트 번호 각각은 적어도 하나의 NE(410)의 상태를 지시하기 위한 값일 수 있다.
도 7은 상태 모델의 동작의 예를 도시한다.
도 7을 참고하면, 이상 상태 감지기(450)는 로그 파서(460)에 기반하여 상태 정보(예: 이벤트 번호)를 식별할 수 있다. 이상 상태 감지기(450)는 로그 파서(460)를 이용하여 상태 정보를 순차적으로 식별(또는 출력)할 수 있다. 이상 상태 감지기(450)는 상태 모델(471)을 이용하여, 순차적으로 식별되는 상태 정보에 기반하여, 상태 변화가 정상적인 변화인지 여부를 식별할 수 있다. 예를 들어, 이상 상태 감지기(450)는 로그 파서(460)를 이용하여 제1 상태 정보 및 제2 상태 정보를 식별할 수 있다. 이상 상태 감지기(450)는 제1 상태 정보를 상태 모델(471)에 입력할 수 있다. 이상 상태 감지기(450)는 상태 모델(471)의 출력에 기반하여, 제3 상태 정보를 획득할 수 있다. 이상 상태 감지기(450)는 제2 상태 정보가 제3 상태 정보와 구별됨을 식별하는 것에 기반하여, 적어도 하나의 NE(410)의 이상 상태를 식별할 수 있다. 이상 상태 감지기(450)는 제2 상태 정보가 제3 상태 정보에 상응함을 식별하는 것에 기반하여, 적어도 하나의 NE(410)의 정상 상태를 식별할 수 있다.
일 실시 예에 따르면, 상태 모델(471)은 유한 상태 기계(finite state automata)에 기반하여 구성될 수 있다. 상태 모델(471)은 유한한 상태를 가지는 기계이며, 상태 모델(471)은 한 번에 하나의 상태를 가질 수 있다. 각 상태는 특정 사건에 따라 다른 상태로 전이(또는 변경)될 수 있다. 상태 모델(471)은 전이 상태 및 전이 상태를 유발하는 조건의 집합으로 구성될 수 있다.
상태 모델(471)은 상태 변화에 대한 집합을 포함할 수 있다. 예를 들어, 적어도 하나의 NE(410)가 정상적으로 동작하는 경우, q1 상태는 q139 상태로 변경될 가능성이 있다. q139 상태는 q175 상태로 변경될 가능성이 있다. q1 상태가 식별된 후, 로그 데이터에 기반하여, q139 상태가 식별되는 것에 기반하여, 이상 상태 감지기(450)는 적어도 하나의 NE(410)가 정상 상태임을 식별할 수 있다. q139 상태가 식별된 후, 로그 데이터에 기반하여, q175 상태가 식별되는 것에 기반하여, 이상 상태 감지기(450)는 적어도 하나의 NE(410)가 비정상 상태임을 식별할 수 있다. 반면, q139 상태가 식별된 후, 로그 데이터에 기반하여, q190 상태가 식별되는 것에 기반하여, 이상 상태 감지기(450)는 적어도 하나의 NE(410)가 비정상 상태임을 식별할 수 있다.
일 실시 예에 따르면, 상태 모델(471)에 포함되지 않은 상태 변화가 발생되는 경우에도, 2 번 이내의 상태 전이가 가능하다면, 적어도 하나의 NE(410)가 정상 상태로 식별될 수 있다. 예를 들어, q2 상태로부터 q19 상태로 상태로의 전이는 상태 모델(471)에 포함되지 않으나, q2 상태로부터 q19 상래로의 전이 및 q19 상태로부터 q150 상태로의 전이가 가능한 경우, 적어도 하나의 NE(410)가 정상 상태로 식별될 수 있다.
도 8은 예측 모델의 동작의 예를 도시한다.
도 8을 참조하면, 이상 상태 감지기(450)는 로그 파서(460)에 기반하여 상태 정보(예: 이벤트 번호)를 식별할 수 있다. 이상 상태 감지기(450)는 로그 파서(460)를 이용하여 상태 정보를 순차적으로 식별(또는 출력)할 수 있다. 이상 상태 감지기(450)는 순차적으로 식별되는 상태 정보에 기반하여, 예측 모델(472)을 이용하여 예측되는 상태 정보를 식별할 수 있다. 이상 상태 감지기(450)는 예측되는 상태 정보에 기반하여, 적어도 하나의 NE(410)의 이상 상태를 식별할 수 있다. 예를 들어, 이상 상태 감지기(450)는 로그 파서(460)를 이용하여 제1 상태 정보 및 제2 상태 정보를 식별할 수 있다. 이상 상태 감지기(450)는 제1 상태 정보를 예측 모델(472)에 입력할 수 있다. 이상 상태 감지기(450)는 예측 모델(472)의 출력에 기반하여, 제4 상태 정보를 획득할 수 있다. 이상 상태 감지기(450)는 제2 상태 정보가 제4 상태 정보와 구별됨을 식별하는 것에 기반하여, 적어도 하나의 NE(410)의 이상 상태를 식별할 수 있다. 이상 상태 감지기(450)는 제2 상태 정보가 제4 상태 정보에 상응함을 식별하는 것에 기반하여, 적어도 하나의 NE(410)의 정상 상태를 식별할 수 있다.
일 실시 예에 따르면, 예측 모델(472)은 LSTM(long short term memory)에 기반하여 구성될 수 있다. 예측 모델(472)은 제1 레이어(801), 제2 레이어(802), 및 제3 레이어(803)을 포함할 수 있다.
제1 레이어(801)의 입력은 n개의 상태들로 구성될 수 있다. 이상 상태 감지기(450)는 예측 모델(472)에 연속된 n 개의 상태들을 입력할 수 있다. n은 관리자(또는 사용자)에 의해 변경될 수 있다. 제1 레이어(801)는 LSTM 레이어로 참조될 수 있다. LSTM은 시계열 데이터 분석에 가장 적합한 것으로 알려진 기계학습 알고리즘의 하나일 수 있다. LSTM은 데이터를 순차적으로 입력 받은 경우 다음 결과(또는 흐름)의 예측에 대한 높은 성능을 가질 수 있다.
제1 레이어(801)의 출력단에 제2 레이어(802)가 구성될 수 있다. 제2 레이어(802)는 FC(fully connected) 레이어로 참조될 수 있다. 복수의 상태들의 확률 데이터를 식별하기 위해, 제2 레이어(802)의 출력의 개수가 k개로 설정될 수 있다. k는 로그 파서(460)에서 식별된 상태 정보의 개수에 상응할 수 있다. 제2 레이어(802)의 출력으로 k 차원의 벡터가 생성될 수 있다. 제2 레이어(802)의 출력은 k 개의 상태들 각각이 발생될 확률을 나타낼 수 있다.
k 개의 상태들 각각이 발생될 확률의 전체 합을 1로 만들기 위해, 제3 레이어(803)가 제2 레이어(802)의 출력단에 구성될 수 있다. 제3 레이어(803)는 소프트맥스(softmax) 레이어로 참조될 수 있다. 이상 상태 감지기(450)는 예측 모델(472)를 이용하여, 가장 높은 확률을 가지는 상태에 기반하여, 예측되는 상태 정보를 획득할 수 있다.
이상 상태 감지기(450)는 로그 데이터에 기반하여 식별된 상태 정보가 예측 모델(472)을 통해 예측되는 상태 정보에 상응함을 식별하는 것에 기반하여, 적어도 하나의 NE(410)의 정상 상태를 식별할 수 있다. 이상 상태 감지기(450)는 로그 데이터에 기반하여 식별된 상태 정보가 예측 모델(472)을 통해 예측되는 상태 정보와 구별됨을 식별하는 것에 기반하여, 적어도 하나의 NE(410)의 이상 상태를 식별할 수 있다.
실시 예에 따라, 이상 상태 감지기(450)는 예측 모델(472)가 연속으로 지정된 횟수(예: 7회)만큼 이상 상태를 식별하는 것에 기반하여, 알림(또는 알람)을 제공할 수 있다.
도 9는 이상 상태 감지기의 동작에 관한 흐름도를 도시한다.
도 9를 참고하면, 동작 901에서, 이상 상태 감지기(450)(또는 이상 상태 감지기(450)를 위한 전자 장치)는 로그 데이터를 획득할 수 있다. 예를 들어, 이상 상태 감지기(450)는 적어도 하나의 NE(410)로부터 로그 데이터를 획득할 수 있다.
동작 902에서, 이상 상태 감지기(450)는 로그 패턴을 식별할 수 있다. 예를 들어, 이상 상태 감지기(450)는 로그 데이터에 기반하여 로그 패턴을 식별할 수 있다. 이상 상태 감지기(450)는 지정된 알고리즘(또는 지정된 규칙)에 기반하여 로그 데이터를 정규화(normalize)할 수 있다. 이상 상태 감지기(450)는 로그 데이터를 정규화하는 것에 기반하여, 로그 패턴을 획득할 수 있다.
동작 903에서, 이상 상태 감지기(450)는 로그 패턴이 메모리에 저장된 복수의 로그 패턴들 중 하나에 상응하는지 여부를 식별할 수 있다. 이상 상태 감지기(450)는 로그 데이터에 기반하여 식별된 로그 패턴이 메모리에 저장된 복수의 로그 패턴들 중 하나에 상응하는지 여부를 식별할 수 있다. 메모리에 저장된 복수의 로그 패턴들 각각은 정상 상태를 나타낼 수 있다.
동작 904에서, 로그 패턴이 메모리에 저장된 복수의 로그 패턴들 중 하나에 상응하는 경우, 이상 상태 감지기(450)는 제1 상태 정보 및 제2 상태 정보를 식별할 수 있다. 로그 패턴이 메모리에 저장된 복수의 로그 패턴들 중 하나에 상응함을 식별하는 것에 기반하여, 이상 상태 감지기(450)는 제1 상태 정보 및 제2 상태 정보를 식별할 수 있다.
예를 들어, 로그 데이터는 지정된 시간 구간 내에서 획득된 로그 메시지(텍스트)들을 포함할 수 있다. 제1 상태 정보는 제1 시점에서의 적어도 하나의 NE(410)에 관한 상태를 나타낼 수 있다. 제2 상태 정보는 제1 시점 이후의 제2 시점에서의 적어도 하나의 NE(410)에 관한 상태를 나타낼 수 있다. 예를 들어, 제1 상태 정보는 적어도 하나의 NE(410)의 과거의 상태를 나타낼 수 있다. 제2 상태 정보는 적어도 하나의 NE(410)의 현재의 상태를 나타낼 수 있다.
예를 들어, 이상 상태 감지기(450)는 도 6에서 설명된 로그 파서(460)를 이용하여, 동작 902 내지 동작 904를 수행할 수 있다.
동작 905에서, 이상 상태 감지기(450)는 제2 상태 정보가, 제1 상태 정보를 이용하여 상태 모델(471)을 통해 식별된 제3 상태 정보에 상응하는지 여부를 식별할 수 있다. 이상 상태 감지기(450)는 제1 상태 정보를 이용하여, 상태 모델(471)을 통해 제3 상태 정보를 식별할 수 있다. 이상 상태 감지기(450)는 제2 상태 정보가 제3 상태 정보에 상응하는지 여부를 식별할 수 있다. 예를 들어, 상태 모델(471)은 유한 상태 기계(finite state automata)에 기반하여 구성될 수 있다. 제3 상태 정보는 제1 상태 정보로부터 전이되는 상태 정보를 의미할 수 있다.
예를 들어, 이상 상태 감지기(450)는 도 7에서 설명된 상태 모델(471)을 이용하여, 동작 905를 수행할 수 있다.
동작 906에서, 제2 상태 정보가 제3 상태 정보에 상응하는 경우, 이상 상태 감지기(450)는 제2 상태 정보가, 제1 상태 정보를 이용하여 예측 모델(472)을 통해 식별된 제4 상태 정보에 상응하는지 여부를 식별할 수 있다. 예를 들어, 제2 상태 정보가 제3 상태 정보에 상응함을 식별하는 것에 기반하여, 이상 상태 감지기(450)는 제2 상태 정보가, 제1 상태 정보를 이용하여 예측 모델(472)을 통해 식별된 제4 상태 정보에 상응하는지 여부를 식별할 수 있다. 이상 상태 감지기(450)는 제1 상태 정보를 이용하여, 예측 모델(472)을 통해 제4 상태 정보를 식별할 수 있다. 이상 상태 감지기(450)는 제2 상태 정보가 제4 상태 정보에 상응하는지 여부를 식별할 수 있다. 예를 들어, 예측 모델(472)은 LSTM(long short term memory)에 기반하여 구성될 수 있다. 제4 상태 정보는 제1 상태 정보에 기반하여 예측되는 상태 정보를 의미할 수 있다.
동작 907은 제2 상태 정보가 제4 상태 정보에 상응하는 경우, 적어도 하나의 NE(410)가 정상 상태임을 식별할 수 있다. 예를 들어, 이상 상태 감지기(450)는 제2 상태 정보가 제4 상태 정보에 상응함을 식별하는 것에 기반하여, 적어도 하나의 NE(410)가 정상 상태임을 식별할 수 있다. 이상 상태 감지기(450)는 동작 903의 조건, 동작 905의 조건, 및 동작 906의 조건이 모두 만족됨을 식별하는 것에 기반하여, 적어도 하나의 NE(410)가 정상 상태임을 식별할 수 있다.
동작 908은, 동작 903의 조건, 동작 905의 조건, 및 동작 906의 조건 중 적어도 하나가 만족되지 않는 경우, 이상 상태 감지기(450)는 적어도 하나의 NE(410)가 비정상 상태(또는 적어도 하나의 NE(410)의 이상 상태(anomaly))임을 식별할 수 있다. 이상 상태 감지기(450)는 동작 903의 조건, 동작 905의 조건, 및 동작 906의 조건 중 적어도 하나가 만족되지 않음을 식별하는 것에 기반하여, 적어도 하나의 NE(410)가 비정상 상태임을 식별할 수 있다.
동작 909는, 이상 상태 감지기(450)는 적어도 하나의 NE(410)가 비정상 상태임을 식별하는 것에 기반하여, 알림(또는 알람)을 제공할 수 있다. 실시 예에 따라, 이상 상태 감지기(450)는 네트워크 컨트롤러(420)에게 알림을 제공할 수 있다. 네트워크 컨트롤러(420)는 데이터 트래픽의 경로를 비정상 상태가 발생한 적어도 하나의 NE(410)를 우회하도록 변경할 수 있다.
도 10은 전자 장치의 기능적 구성의 예를 도시한다.
도 10를 참고하면, 전자 장치(1000)는 도 4 내지 도 9의 이상 상태 감지기(450)에 상응할 수 있다. 일 실시 예에 따르면, 전자 장치(1000)는 송수신기(1001), 프로세서(1003), 및 메모리(1005)를 포함할 수 있다.
송수신기(1001)는, 유선 통신 환경에서, 신호를 송수신하기 위한 기능들을 수행할 수 있다. 송수신기(1001)는, 전송 매체(transmission medium)(예: 구리선, 광섬유)를 통해 장치와 장치 간의 직접적인 연결을 제어하기 위한, 유선 인터페이스를 포함할 수 있다. 예를 들어, 송수신기(1001)는 구리선을 통해 다른 장치에게 전기적 신호를 전달하거나, 전기적 신호와 광신호간 변환을 수행할 수 있다.
송수신기(1001)는 무선 통신 환경에서, 신호를 송수신하기 위한 기능들을 수행할 수도 있다. 예를 들어, 송수신기(1001)는 시스템의 물리 계층 규격에 따라 기저대역 신호 및 비트열 간 변환 기능을 수행할 수 있다. 예를 들어, 데이터 송신 시, 송수신기(1001)는 송신 비트열을 부호화 및 변조함으로써 복소 심볼들(complex-valued symbols)을 생성한다. 또한, 데이터 수신 시, 송수신기(1001)는 기저대역 신호를 복조 및 복호화를 통해 수신 비트열을 복원한다. 또한, 송수신기(1001)는 다수의 송수신 경로(path)들을 포함할 수 있다.
송수신기(1001)는 상술한 바와 같이 신호를 송신 및 수신한다. 이에 따라, 송수신기(1001)의 전부 또는 일부는 '통신부', '송신부', '수신부' 또는 '송수신부'로 지칭될 수 있다. 또한, 이하 설명에서, 무선 채널을 통해 수행되는 송신 및 수신은 송수신기(1001)에 의해 상술한 바와 같은 처리가 수행되는 것을 포함하는 의미로 사용된다.
프로세서(1003)는 전자 장치(1000)의 전반적인 동작들을 제어한다. 프로세서(1003)는 제어부로 지칭될 수 있다. 예를 들어, 프로세서(1003)는 송수신기(1001)를 통해 신호를 송신 및 수신한다. 또한, 프로세서(1003)는 메모리(1005)에 데이터를 기록하고, 읽는다. 그리고, 프로세서(1003)는 통신 규격에서 요구하는 프로토콜 스택(protocol stack)의 기능들을 수행할 수 있다. 도 10에는 프로세서(1003)만 도시되었으나, 다른 구현 예에 따라, 전자 장치(1000)는, 둘 이상의 프로세서들을 포함할 수 있다.
본 개시에서, 프로세서(1003)의 동작들은 소프트웨어에 의해 실행되거나, FPGA(Field Programmable Gate Array) 또는 ASIC(application-specific integrated circuit)과 같은 하드웨어 구성요소들을 제어하는 것을 의미할 수 있다. 또한, 프로세서(1003)는 소프트웨어 구성요소들, 객체지향 소프트웨어 구성요소들, 클래스 구성요소들 및 태스크 구성요소들과 같은 구성요소들과, 프로세스들, 함수들, 속성들, 프로시저들, 서브루틴들, 프로그램 코드의 세그먼트들, 드라이버들, 펌웨어, 마이크로코드, 회로, 데이터, 데이터베이스, 데이터 구조들, 테이블들, 어레이들, 및 변수들 중 적어도 하나를 포함할 수 있다. 프로세서(1003)는 적어도 하나의 모듈을 포함할 수 있으며, 용어 "모듈"은 하드웨어, 소프트웨어 또는 펌웨어로 구성된 유닛을 포함한다. 예를 들어, 모듈은 로직, 논리 블록, 부품, 또는 회로 등의 용어와 상호 호환적으로 사용될 수 있다. 모듈은, 일체로 구성된 부품 또는 하나 또는 그 이상의 기능을 수행하는 최소 단위 또는 그 일부가 될 수 있다. 예를 들면, 모듈은 ASIC으로 구성될 수 있다.
예를 들어, 프로세서(1003)는 상술한 실시 예들에 따른 블록들(예: 도 4에 도시된 블록들) 중 적어도 일부 또는 전부를 포함할 수 있다. 프로세서(1003)는 상술한 실시 예들에 따른 블록들(예: 도 4에 도시된 블록들) 중 적어도 일부 또는 전부의 기능을 수행할 수 있다.
메모리(1005)는 전자 장치(1000)의 동작을 위한 기본 프로그램, 응용 프로그램, 설정 정보 등의 데이터를 저장한다. 메모리(1005)는 저장부로 지칭될 수 있다. 메모리(1005)는 휘발성 메모리, 비휘발성 메모리 또는 휘발성 메모리와 비휘발성 메모리의 조합으로 구성될 수 있다. 그리고, 메모리(1005)는 프로세서(1003)의 요청에 따라 저장된 데이터를 제공한다.
일 실시 예에 따르면, 전자 장치는, 인스트럭션들을 저장하고, 하나 이상의 저장 매체들을 포함하는 메모리, 및 처리 회로를 포함하는 적어도 하나의 프로세서를 포함할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 적어도 하나의 NE(network element)로부터, 상기 적어도 하나의 NE의 동작에 관한 로그 데이터를 획득하도록 야기할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 로그 데이터에 기반하여, 지정된 알고리즘을 통해 로그 패턴을 획득하도록 야기할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 로그 패턴에 기반하여, 제1 상태 정보 및 제2 상태 정보를 식별하도록 야기할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 제2 상태 정보가, 상기 제1 상태 정보를 이용하여 적어도 하나의 모델을 통해 식별된 상태 정보와 구별됨을 식별하도록 야기할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 제2 상태 정보가 상기 적어도 하나의 모델을 통해 식별된 상태 정보와 구별됨을 식별하는 것에 기반하여, 상기 적어도 하나의 NE의 이상 상태를 식별하도록, 야기할 수 있다.
일 실시 예에 따르면, 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 지정된 알고리즘에 기반하여, 상기 로그 데이터를 정규화(normalize)하도록 야기할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 로그 데이터를 정규화 하는 것에 기반하여, 상기 로그 패턴을 획득하도록, 야기할 수 있다.
일 실시 예에 따르면, 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 로그 패턴이 상기 메모리에 저장된 복수의 로그 패턴들 중 하나에 상응하는지 여부를 식별하도록 야기할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 로그 패턴이 상기 복수의 로그 패턴들 중 하나에 상응하는 경우, 상기 로그 패턴에 기반하여, 상기 제1 상태 정보 및 상기 제2 상태 정보를 식별하도록 야기할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 로그 패턴이 상기 복수의 로그 패턴들 중 하나에 상응하지 않는 경우, 상기 적어도 하나의 NE의 상기 이상 상태를 식별하도록, 야기할 수 있다.
일 실시 예에 따르면, 상기 적어도 하나의 모델은, 상태 모델 및 예측 모델을 포함할 수 있다.
일 실시 예에 따르면, 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 제2 상태 정보가, 상기 상태 모델을 통해 식별된 제3 상태 정보와 구별됨을 식별하도록 야기할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 제2 상태 정보가 상기 제3 상태 정보와 구별됨을 식별하는 것에 기반하여, 상기 적어도 하나의 NE의 상기 이상 상태를 식별하도록, 야기할 수 있다.
일 실시 예에 따르면, 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 제1 상태 정보를, 상기 상태 모델에 입력하도록 야기할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 상태 모델의 출력에 기반하여, 상기 제3 상태 정보를 획득하도록, 야기할 수 있다.
일 실시 예에 따르면, 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 제2 상태 정보가 상기 제3 상태 정보에 상응함을 식별하는 것에 기반하여, 상기 제2 상태 정보가, 상기 예측 모델을 통해 식별된 제4 상태 정보와 구별됨을 식별하도록 야기할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 제2 상태 정보가 상기 제4 상태 정보와 구별됨을 식별하는 것에 기반하여, 상기 적어도 하나의 NE의 상기 이상 상태를 식별하도록, 야기할 수 있다.
일 실시 예에 따르면, 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 제1 상태 정보를, 상기 예측 모델에 입력하도록 야기할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 예측 모델의 출력에 기반하여, 상기 제4 상태 정보를 획득하도록, 야기할 수 있다.
일 실시 예에 따르면, 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 예측 모델의 출력에 기반하여, 복수의 상태들 각각에 대한 확률 데이터를 식별하도록 야기할 수 있다. 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가, 상기 복수의 상태들 중 가장 높은 확률을 가지는 상태에 기반하여, 상기 제4 상태 정보를 획득하도록, 야기할 수 있다.
일 실시 예에 따르면, 상기 상태 모델은, 유한 상태 기계(finite state automata)에 기반하여 구성될 수 있다. 상기 예측 모델은, LSTM (long short term memory)에 기반하여 구성될 수 있다.
일 실시 예에 따르면, 전자 장치에 의해 수행되는 방법은, 적어도 하나의 NE(network element)로부터, 상기 적어도 하나의 NE의 동작에 관한 로그 데이터를 획득하는 동작을 포함할 수 있다. 상기 방법은, 상기 로그 데이터에 기반하여, 지정된 알고리즘을 통해 로그 패턴을 획득하는 동작을 포함할 수 있다. 상기 방법은, 상기 로그 패턴에 기반하여, 제1 상태 정보 및 제2 상태 정보를 식별하는 동작을 포함할 수 있다. 상기 방법은, 상기 제2 상태 정보가, 상기 제1 상태 정보를 이용하여 적어도 하나의 모델을 통해 식별된 상태 정보와 구별됨을 식별하는 동작을 포함할 수 있다. 상기 방법은, 상기 제2 상태 정보가 상기 적어도 하나의 모델을 통해 식별된 상태 정보와 구별됨을 식별하는 것에 기반하여, 상기 적어도 하나의 NE의 이상 상태를 식별하는 동작을 포함할 수 있다.
일 실시 예에 따르면, 상기 방법은, 상기 지정된 알고리즘에 기반하여, 상기 로그 데이터를 정규화(normalize)하는 동작을 포함할 수 있다. 상기 방법은, 상기 로그 데이터를 정규화 하는 것에 기반하여, 상기 로그 패턴을 획득하는 동작을 포함할 수 있다.
일 실시 예에 따르면, 상기 방법은, 상기 로그 패턴이 상기 메모리에 저장된 복수의 로그 패턴들 중 하나에 상응하는지 여부를 식별하는 동작을 포함할 수 있다. 상기 방법은, 상기 로그 패턴이 상기 복수의 로그 패턴들 중 하나에 상응하는 경우, 상기 로그 패턴에 기반하여, 상기 제1 상태 정보 및 상기 제2 상태 정보를 식별하는 동작을 포함할 수 있다. 상기 방법은, 상기 로그 패턴이 상기 복수의 로그 패턴들 중 하나에 상응하지 않는 경우, 상기 적어도 하나의 NE의 상기 이상 상태를 식별하는 동작을 포함할 수 있다.
일 실시 예에 따르면, 상기 적어도 하나의 모델은, 상태 모델 및 예측 모델을 포함할 수 있다.
일 실시 예에 따르면, 상기 방법은, 상기 제2 상태 정보가, 상기 상태 모델을 통해 식별된 제3 상태 정보와 구별됨을 식별하는 동작을 포함할 수 있다. 상기 방법은, 상기 제2 상태 정보가 상기 제3 상태 정보와 구별됨을 식별하는 것에 기반하여, 상기 적어도 하나의 NE의 상기 이상 상태를 식별하는 동작을 포함할 수 있다.
일 실시 예에 따르면, 상기 방법은, 상기 제1 상태 정보를, 상기 상태 모델에 입력하는 동작을 포함할 수 있다. 상기 방법은, 상기 상태 모델의 출력에 기반하여, 상기 제3 상태 정보를 획득하는 동작을 포함할 수 있다.
일 실시 예에 따르면, 상기 방법은, 상기 제2 상태 정보가 상기 제3 상태 정보에 상응함을 식별하는 것에 기반하여, 상기 제2 상태 정보가, 상기 예측 모델을 통해 식별된 제4 상태 정보와 구별됨을 식별하는 동작을 포함할 수 있다. 상기 방법은, 상기 제2 상태 정보가 상기 제4 상태 정보와 구별됨을 식별하는 것에 기반하여, 상기 적어도 하나의 NE의 상기 이상 상태를 식별하는 동작을 포함할 수 있다.
일 실시 예에 따르면, 상기 방법은, 상기 제1 상태 정보를, 상기 예측 모델에 입력하는 동작을 포함할 수 있다. 상기 방법은, 상기 예측 모델의 출력에 기반하여, 상기 제4 상태 정보를 획득하는 동작을 포함할 수 있다.
일 실시 예에 따르면, 상기 방법은, 상기 예측 모델의 출력에 기반하여, 복수의 상태들 각각에 대한 확률 데이터를 식별하는 동작을 포함할 수 있다. 상기 방법은, 상기 복수의 상태들 중 가장 높은 확률을 가지는 상태에 기반하여, 상기 제4 상태 정보를 획득하는 동작을 포함할 수 있다.
일 실시 예에 따르면, 상기 상태 모델은, 유한 상태 기계(finite state automata)에 기반하여 구성될 수 있다. 상기 예측 모델은, LSTM (long short term memory)에 기반하여 구성될 수 있다.
상술한 실시 예에 따르면, 네트워크 장비(또는 NE)를 통해서 이상 상태가 실시간으로 식별(또는 탐지(detect))될 수 있다. 예를 들어, 로그 데이터에 기반하여, 유사한 로그 패턴이 분석됨으로써, 로그 데이터가 효과적으로 압축될 수 있다. 네트워크 장비가 정상 상태인 동안 로그 패턴을 학습시킴으로써, 네트워크 장비의 비정상 로그가 실시간으로 판단될 수 있다. 네트워크 장비의 이상 상태가 식별되는 경우, 네트워크 관리자에게 실제 이상 유무를 확인할 수 있도록 알림이 제공될 수 있다. 이에 따라, 이상 상태에 대한 알림이 먼저 제공되므로, 심각한 문제(critical problem)의 발생이 방지될 수 있다. 기존에는 네트워크 프로토콜에 대한 로그 내용 및 네트워크 장비의 특징이 반영된 로그 내용이 고려되지 않아 이상 상태가 식별되기 어려웠으나, 상술한 실시 예에 따르면, 네트워크 장비에서 출력되는 로그 데이터를 통해서 네트워크 장비의 상태가 학습되므로, 이상 상태가 정확히 탐지되는 효과가 있다.
본 개시의 청구항 또는 명세서에 기재된 실시예들에 따른 방법들은 하드웨어, 소프트웨어, 또는 하드웨어와 소프트웨어의 조합의 형태로 구현될(implemented) 수 있다.
소프트웨어로 구현하는 경우, 하나 이상의 프로그램들(소프트웨어 모듈들)을 저장하는 컴퓨터 판독 가능 저장 매체가 제공될 수 있다. 컴퓨터 판독 가능 저장 매체에 저장되는 하나 이상의 프로그램들은, 전자 장치(device) 내의 하나 이상의 프로세서들에 의해 실행 가능하도록 구성된다(configured for execution). 하나 이상의 프로그램들은, 전자 장치로 하여금 본 개시의 청구항 또는 명세서에 기재된 실시예들에 따른 방법들을 실행하게 하는 명령어(instructions)를 포함한다. 상기 하나 이상의 프로그램들은 컴퓨터 프로그램 제품(computer program product)에 포함되어 제공될 수 있다. 컴퓨터 프로그램 제품은 상품으로서 판매자 및 구매자 간에 거래될 수 있다. 컴퓨터 프로그램 제품은 기기로 읽을 수 있는 저장 매체(예: compact disc read only memory(CD-ROM))의 형태로 배포되거나, 또는 어플리케이션 스토어(예: 플레이 스토어™)를 통해 또는 두 개의 사용자 장치들(예: 스마트 폰들) 간에 직접, 온라인으로 배포(예: 다운로드 또는 업로드)될 수 있다. 온라인 배포의 경우에, 컴퓨터 프로그램 제품의 적어도 일부는 제조사의 서버, 어플리케이션 스토어의 서버, 또는 중계 서버의 메모리와 같은 기기로 읽을 수 있는 저장 매체에 적어도 일시 저장되거나, 임시적으로 생성될 수 있다.
이러한 프로그램(소프트웨어 모듈, 소프트웨어)은 랜덤 액세스 메모리 (random access memory), 플래시(flash) 메모리를 포함하는 불휘발성(non-volatile) 메모리, 롬(read only memory, ROM), 전기적 삭제가능 프로그램가능 롬(electrically erasable programmable read only memory, EEPROM), 자기 디스크 저장 장치(magnetic disc storage device), 컴팩트 디스크 롬(compact disc-ROM, CD-ROM), 디지털 다목적 디스크(digital versatile discs, DVDs) 또는 다른 형태의 광학 저장 장치, 마그네틱 카세트(magnetic cassette)에 저장될 수 있다. 또는, 이들의 일부 또는 전부의 조합으로 구성된 메모리에 저장될 수 있다. 또한, 각각의 구성 메모리는 다수 개 포함될 수도 있다.
또한, 프로그램은 인터넷(Internet), 인트라넷(Intranet), LAN(local area network), WAN(wide area network), 또는 SAN(storage area network)과 같은 통신 네트워크, 또는 이들의 조합으로 구성된 통신 네트워크를 통하여 접근(access)할 수 있는 부착 가능한(attachable) 저장 장치(storage device)에 저장될 수 있다. 이러한 저장 장치는 외부 포트를 통하여 본 개시의 실시예를 수행하는 장치에 접속할 수 있다. 또한, 통신 네트워크상의 별도의 저장장치가 본 개시의 실시예를 수행하는 장치에 접속할 수도 있다.
상술한 본 개시의 구체적인 실시예들에서, 개시에 포함되는 구성 요소는 제시된 구체적인 실시예에 따라 단수 또는 복수로 표현되었다. 그러나, 단수 또는 복수의 표현은 설명의 편의를 위해 제시한 상황에 적합하게 선택된 것으로서, 본 개시가 단수 또는 복수의 구성 요소에 제한되는 것은 아니며, 복수로 표현된 구성 요소라 하더라도 단수로 구성되거나, 단수로 표현된 구성 요소라 하더라도 복수로 구성될 수 있다.
실시예들에 따르면, 전술한 해당 구성요소들 중 하나 이상의 구성요소들 또는 동작들이 생략되거나, 또는 하나 이상의 다른 구성요소들 또는 동작들이 추가될 수 있다. 대체적으로 또는 추가적으로, 복수의 구성요소들(예: 모듈 또는 프로그램)은 하나의 구성요소로 통합될 수 있다. 이런 경우, 통합된 구성요소는 상기 복수의 구성요소들 각각의 구성요소의 하나 이상의 기능들을 상기 통합 이전에 상기 복수의 구성요소들 중 해당 구성요소에 의해 수행되는 것과 동일 또는 유사하게 수행할 수 있다. 실시예들에 따르면, 모듈, 프로그램 또는 다른 구성요소에 의해 수행되는 동작들은 순차적으로, 병렬적으로, 반복적으로, 또는 휴리스틱하게 실행되거나, 상기 동작들 중 하나 이상이 다른 순서로 실행되거나, 생략되거나, 또는 하나 이상의 다른 동작들이 추가될 수 있다.
한편 본 개시의 상세한 설명에서는 구체적인 실시예에 관해 설명하였으나, 본 개시의 범위에서 벗어나지 않는 한도 내에서 여러 가지 변형이 가능함은 물론이다.
Claims (15)
- 전자 장치에 있어서,인스트럭션들을 저장하고, 하나 이상의 저장 매체들을 포함하는 메모리; 및처리 회로를 포함하는 적어도 하나의 프로세서를 포함하고,상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가:적어도 하나의 NE(network element)로부터, 상기 적어도 하나의 NE의 동작에 관한 로그 데이터를 획득하고,상기 로그 데이터에 기반하여, 지정된 알고리즘을 통해 로그 패턴을 획득하고,상기 로그 패턴에 기반하여, 제1 상태 정보 및 제2 상태 정보를 식별하고,상기 제2 상태 정보가, 상기 제1 상태 정보를 이용하여 적어도 하나의 모델을 통해 식별된 상태 정보와 구별됨을 식별하고,상기 제2 상태 정보가 상기 적어도 하나의 모델을 통해 식별된 상태 정보와 구별됨을 식별하는 것에 기반하여, 상기 적어도 하나의 NE의 이상 상태를 식별하도록, 야기하는,전자 장치.
- 제1 항에 있어서, 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가:상기 지정된 알고리즘에 기반하여, 상기 로그 데이터를 정규화(normalize)하고,상기 로그 데이터를 정규화 하는 것에 기반하여, 상기 로그 패턴을 획득하도록, 더 야기하는,전자 장치.
- 제1 항에 있어서, 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가:상기 로그 패턴이 상기 메모리에 저장된 복수의 로그 패턴들 중 하나에 상응하는지 여부를 식별하고,상기 로그 패턴이 상기 복수의 로그 패턴들 중 하나에 상응하는 경우, 상기 로그 패턴에 기반하여, 상기 제1 상태 정보 및 상기 제2 상태 정보를 식별하고,상기 로그 패턴이 상기 복수의 로그 패턴들 중 하나에 상응하지 않는 경우, 상기 적어도 하나의 NE의 상기 이상 상태를 식별하도록, 더 야기하는,전자 장치.
- 제1 항에 있어서, 상기 적어도 하나의 모델은,상태 모델 및 예측 모델을 포함하는,전자 장치.
- 제4 항에 있어서, 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가:상기 제2 상태 정보가, 상기 상태 모델을 통해 식별된 제3 상태 정보와 구별됨을 식별하고,상기 제2 상태 정보가 상기 제3 상태 정보와 구별됨을 식별하는 것에 기반하여, 상기 적어도 하나의 NE의 상기 이상 상태를 식별하도록, 더 야기하는,전자 장치.
- 제5 항에 있어서, 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가:상기 제1 상태 정보를, 상기 상태 모델에 입력하고,상기 상태 모델의 출력에 기반하여, 상기 제3 상태 정보를 획득하도록, 더 야기하는,전자 장치.
- 제5 항에 있어서, 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가:상기 제2 상태 정보가 상기 제3 상태 정보에 상응함을 식별하는 것에 기반하여, 상기 제2 상태 정보가, 상기 예측 모델을 통해 식별된 제4 상태 정보와 구별됨을 식별하고,상기 제2 상태 정보가 상기 제4 상태 정보와 구별됨을 식별하는 것에 기반하여, 상기 적어도 하나의 NE의 상기 이상 상태를 식별하도록, 더 야기하는,전자 장치.
- 제7 항에 있어서, 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가:상기 제1 상태 정보를, 상기 예측 모델에 입력하고,상기 예측 모델의 출력에 기반하여, 상기 제4 상태 정보를 획득하도록, 더 야기하는,전자 장치.
- 제8 항에 있어서, 상기 인스트럭션들은, 상기 적어도 하나의 프로세서에 의해, 개별적으로 또는 집합적으로, 실행될 시, 상기 전자 장치가:상기 예측 모델의 출력에 기반하여, 복수의 상태들 각각에 대한 확률 데이터를 식별하고,상기 복수의 상태들 중 가장 높은 확률을 가지는 상태에 기반하여, 상기 제4 상태 정보를 획득하도록, 더 야기하는,전자 장치.
- 제4 항에 있어서, 상기 상태 모델은,유한 상태 기계(finite state automata)에 기반하여 구성되고,상기 예측 모델은,LSTM (long short term memory)에 기반하여 구성되는,전자 장치.
- 전자 장치에 의해 수행되는 방법에 있어서,적어도 하나의 NE(network element)로부터, 상기 적어도 하나의 NE의 동작에 관한 로그 데이터를 획득하는 동작;상기 로그 데이터에 기반하여, 지정된 알고리즘을 통해 로그 패턴을 획득하는 동작;상기 로그 패턴에 기반하여, 제1 상태 정보 및 제2 상태 정보를 식별하는 동작;상기 제2 상태 정보가, 상기 제1 상태 정보를 이용하여 적어도 하나의 모델을 통해 식별된 상태 정보와 구별됨을 식별하는 동작; 및상기 제2 상태 정보가 상기 적어도 하나의 모델을 통해 식별된 상태 정보와 구별됨을 식별하는 것에 기반하여, 상기 적어도 하나의 NE의 이상 상태를 식별하는 동작을 포함하는,방법.
- 제11 항에 있어서, 상기 방법은,상기 지정된 알고리즘에 기반하여, 상기 로그 데이터를 정규화(normalize)하는 동작; 및상기 로그 데이터를 정규화 하는 것에 기반하여, 상기 로그 패턴을 획득하는 동작을 더 포함하는,방법.
- 제11 항에 있어서, 상기 방법은,상기 로그 패턴이 상기 메모리에 저장된 복수의 로그 패턴들 중 하나에 상응하는지 여부를 식별하는 동작;상기 로그 패턴이 상기 복수의 로그 패턴들 중 하나에 상응하는 경우, 상기 로그 패턴에 기반하여, 상기 제1 상태 정보 및 상기 제2 상태 정보를 식별하는 동작; 및상기 로그 패턴이 상기 복수의 로그 패턴들 중 하나에 상응하지 않는 경우, 상기 적어도 하나의 NE의 상기 이상 상태를 식별하는 동작을 더 포함하는,방법.
- 제11 항에 있어서, 상기 적어도 하나의 모델은,상태 모델 및 예측 모델을 포함하는,방법.
- 제14 항에 있어서, 상기 방법은,상기 제2 상태 정보가, 상기 상태 모델을 통해 식별된 제3 상태 정보와 구별됨을 식별하는 동작; 및상기 제2 상태 정보가 상기 제3 상태 정보와 구별됨을 식별하는 것에 기반하여, 상기 적어도 하나의 NE의 상기 이상 상태를 식별하는 동작을 더 포함하는,방법.
Applications Claiming Priority (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR20230152228 | 2023-11-06 | ||
| KR10-2023-0152228 | 2023-11-06 | ||
| KR1020230175982A KR20250066350A (ko) | 2023-11-06 | 2023-12-06 | 이상 상태를 식별하기 위한 전자 장치 및 방법 |
| KR10-2023-0175982 | 2023-12-06 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025100725A1 true WO2025100725A1 (ko) | 2025-05-15 |
Family
ID=95696212
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/KR2024/013947 Pending WO2025100725A1 (ko) | 2023-11-06 | 2024-09-12 | 이상 상태를 식별하기 위한 전자 장치 및 방법 |
Country Status (1)
| Country | Link |
|---|---|
| WO (1) | WO2025100725A1 (ko) |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110224850A (zh) * | 2019-04-19 | 2019-09-10 | 北京亿阳信通科技有限公司 | 电信网络故障预警方法、装置及终端设备 |
| KR20200039295A (ko) * | 2018-10-05 | 2020-04-16 | 삼성전자주식회사 | 5g 이동 통신 시스템에서 네트워크 분석 정보를 활용한 효율적 mico 모드 관리 방법 |
| KR20200135867A (ko) * | 2018-03-27 | 2020-12-03 | 차이나 아카데미 오브 텔레커뮤니케이션즈 테크놀로지 | 네트워크 데이터의 모니터링 방법 및 장치 |
| US20210028973A1 (en) * | 2019-07-26 | 2021-01-28 | Ciena Corporation | Identifying and locating a root cause of issues in a network having a known topology |
-
2024
- 2024-09-12 WO PCT/KR2024/013947 patent/WO2025100725A1/ko active Pending
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR20200135867A (ko) * | 2018-03-27 | 2020-12-03 | 차이나 아카데미 오브 텔레커뮤니케이션즈 테크놀로지 | 네트워크 데이터의 모니터링 방법 및 장치 |
| KR20200039295A (ko) * | 2018-10-05 | 2020-04-16 | 삼성전자주식회사 | 5g 이동 통신 시스템에서 네트워크 분석 정보를 활용한 효율적 mico 모드 관리 방법 |
| CN110224850A (zh) * | 2019-04-19 | 2019-09-10 | 北京亿阳信通科技有限公司 | 电信网络故障预警方法、装置及终端设备 |
| US20210028973A1 (en) * | 2019-07-26 | 2021-01-28 | Ciena Corporation | Identifying and locating a root cause of issues in a network having a known topology |
Non-Patent Citations (1)
| Title |
|---|
| "3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Architecture enhancements for 5G System (5GS) to support network data analytics services (Release 18)", 3GPP STANDARD; 3GPP TS 23.288, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, no. V18.3.0, 19 September 2023 (2023-09-19), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France, pages 1 - 316, XP052512101 * |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2021080222A1 (en) | Method and apparatus for detecting physical downlink control channel based on predicted information | |
| CN114389940A (zh) | 故障恢复预案确定方法、装置及系统、计算机存储介质 | |
| WO2020242008A1 (en) | Method and device for managing multiple remote radio heads in communication network | |
| US20160283307A1 (en) | Monitoring system, monitoring device, and test device | |
| WO2020143297A1 (zh) | 呼叫中心的容灾方法、装置、设备及存储介质 | |
| WO2020138977A1 (en) | Apparatus and method for monitoring performance of network device in wireless communication system | |
| WO2012023657A1 (ko) | 가상 머신을 이용한 네트워크 기반 유해 프로그램 검출 방법 및 그 시스템 | |
| WO2024232470A1 (ko) | 머신 러닝 기반 가상 머신 고장 예측 방법 및 장치 | |
| WO2023003067A1 (ko) | 비정상 데이터 탐지 시스템 및 방법 | |
| WO2020235926A1 (en) | Methods and systems for recovery of network elements in a communication network | |
| WO2024085730A1 (en) | Method and apparatus for logging events in communication networks | |
| WO2024232462A1 (ko) | Api 게이트웨이 및 이의 동작 방법 | |
| CN111222547A (zh) | 一种面向移动应用的流量特征提取方法及系统 | |
| WO2024111887A1 (ko) | 데이터 이산화 및 결정 경계 데이터 포인트 분석을 통한 이상 탐지 시스템 및 방법과 이를 위한 컴퓨터 프로그램 | |
| WO2013129804A1 (ko) | 무선 네트워크 부하 저감 정책 분석 방법 및 시스템과 기록매체 | |
| WO2019035634A1 (ko) | 소프트웨어 정의 네트워크에서 네트워크 공격을 처리하기 위한 장치 및 방법 | |
| WO2013122362A1 (ko) | 무선 네트워크 부하 저감 정책 운영 방법 및 시스템과 기록매체 | |
| KR100964392B1 (ko) | 망 관리에서의 장애 관리 시스템 및 그 방법 | |
| CN115348161A (zh) | 日志告警信息生成方法、装置、电子设备及存储介质 | |
| WO2018044016A1 (ko) | 이동 통신망 장애 감시 시스템 및 방법 | |
| CN115225381B (zh) | 异步故障检测滤波器设计方法 | |
| KR20250066350A (ko) | 이상 상태를 식별하기 위한 전자 장치 및 방법 | |
| WO2024063498A1 (ko) | 제어평면 메시지를 사용한 imei 검증 및 미인증 단말 검출 방법 및 그 시스템 | |
| CN101009582A (zh) | 基于2m数据电路传输质量实时在线监测的方法与装置 | |
| WO2026049261A1 (ko) | 네트워크 이상을 식별하기 위한 관리 장치 및 방법 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24888921 Country of ref document: EP Kind code of ref document: A1 |
