节点文献

基于事件关联的网络故障管理研究

Research on Event Correlation Based Network Fault Management

【作者】 李鹏

【导师】 李杰;

【作者基本信息】 中南大学 , 计算机软件与理论, 2008, 硕士

【摘要】 随着计算机网络的规模越来越大,在网络运行过程中产生了大量的事件,有效的网络管理的重要性已经日益突出。从某种角度来说,故障管理的主要任务就是监视、分析和处理网络事件。网络管理人员必须能够从观察到的众多事件中找出产生这些事件的问题。事件管理操作目前仍主要通过人工来完成。人工处理不能满足网络在速度、复杂性和规模等方面日益增长的需求,网络管理人员的人工处理速度跟不上网络事件的生成速度。本文立足于网络故障管理的核心技术即事件关联技术的研究,通过分析目前事件关联技术的研究现状,在日志分析和代码本优化的基础上,提出了一个基于事件关联技术的网络故障管理模型,该模型的关键技术是预处理技术和代码本与数据挖掘结合的关联引擎。本文研究了下面几个方面的内容:首先是因果图化简算法,针对因果图中的症状环和其他冗余信息,分别利用拓扑排序算法和图的广度优先遍历算法提出了相应的化简算法,提高了处理的自动化程度;其次根据日志文件的特点,利用计数字典和过滤提出了一种改进的日志行模式生成算法,给出了关键的步骤、算法流程和简单的分析,提高了处理的速度;然后阐述了代码本优化技术,使用动态权值和计数矩阵提高模型的自适应性,利用数据挖掘发现频繁故障集和故障模式,进一步提高处理速度和预测功能,使用海明码解码器处理噪声环境下的故障匹配,利用代码本技术上的时序关系降低噪声和解决变长编码的问题;最后阐述了事件关联技术在网络故障管理中的应用,提出了一个基于事件关联技术故障管理模型,描述的各个功能模块的作用以及系统的部署方式。

【Abstract】 With the scale-growing computer networks, large numbers of events are produced and effective management of the importance of the network has become increasingly prominent. In some ways, network management is the main task of monitoring, analyzing and processing network events. Network managers must be able to observe from the many events to identify the problems of these events. Event management operation is still mainly through artificial to complete. Manual processing in the network can not meet the speed, complexity and size of the areas growing demand, network management staff failed to keep pace with the speed of the network events generated.In this paper, it bases on the network fault management’s the core technology that is event correlation technology research, through analysis of current events related technology, on the base of the log analysis and optimization of the code proposing a event correlation based network fault management model.The model’s key technology is preprocessing technology and the engine based on data mining and codebook. This paper studies the following aspects: firstly, for causal map of symptoms cycle and other symptoms of redundant information, the reduction algorithm of the causal map utilizes topology sorting algorithm and the breadth-first traversal algorithm to reduce the causal map, which is able to handle the degree of automation; secondly in accordance with the characteristics of the log file, it uses dictionary with counting and filtering and presents an improved algorithm of the log line pattern, including key steps, the algorithm processes and simple analysis, improving the speed of processing; then on the code optimization technology, it uses dynamic weight and counting matrix to improve the model’s adaptability, finding that frequent set and mode using, furtherly improving the processing speed and forecasting functions; the use of Hamming code decoders deal with noise fault under the match, the technical use of the code to reduce noise and timing relations to resolve the issue of variable length encoding; finally it states the event correlation technology in the network fault management of applications, and proposes a event correlation based fault management model, describing in the role of the various functionalmodules and systems deployment.

【关键词】 事件关联代码本网络故障行模式
【Key words】 Event CorrelationCodebookFault ManagementLine Pattern
  • 【网络出版投稿人】 中南大学
  • 【网络出版年期】2009年 01期
  • 【分类号】TP393.07
  • 【被引频次】11
  • 【下载频次】225
节点文献中: 

本文链接的文献网络图示:

本文的引文网络