The Topologies Exploration on the Knowledge Graph of Alarm Correlation by a Community-based Link Prediction Model.

Shuo Cui,Yang Wen,Ke Dong,Bing An
DOI: https://doi.org/10.1145/3627341.3630375
2023-01-01
Abstract:Alarm correlation refers to identifying the correlation between alarms in the system through technical means, accurately categorizing alarms caused by the same problem, and realizing root cause location. Accurate and efficient alarm association identification technology is of great practical significance to accelerate system troubleshooting and ensure the safety of large systems. This paper innovatively proposes a link prediction model considering community similarity and resource allocation between nodes. Based on the application scenario of alarm association knowledge graph, the key innovative technologies and innovation paths in this field are mined and identified, and the potential technological development trends are predicted in the future. Based on the information of 431 invention patents related to alarm correlation in China from 2006 to 2022 and 535 papers from 1998 to 2023, the alarm correlation knowledge map is constructed, and key technologies are identified by topology analysis method. An improved link prediction method is proposed combining community discovery method and resource allocation index, and the potential innovation path of alarm association field is predicted based on the improved index, so as to comprehensively analyze the application status and development prospect of alarm association technology. It is found that technologies such as multilevel classification and causal knowledge will produce innovative results in the fields of alarm clustering and intrusion detection. The research will provide reference for technology prediction in the field of knowledge graph and scientific research innovation of network security personnel.
What problem does this paper attempt to address?