| DC Field | Value | Language |
| dc.contributor.author | RAMLA, YAssine | - |
| dc.date.accessioned | 2026-10-08T07:41:26Z | - |
| dc.date.available | 2026-10-08T07:41:26Z | - |
| dc.date.issued | 2026 | - |
| dc.identifier.uri | https://repository.esi-sba.dz/jspui/handle/123456789/999 | - |
| dc.description | Encadreur :Dr. KHALDI Belkacem | en_US |
| dc.description.abstract | The fault management of a mobile network produces a large flow of alarms. One fault
is often reported by many alarms on several elements, and the engineers of the network
operations center must find which alarms belong together and where the fault lies. This
work, carried out at Ooredoo Algeria, studies three tasks on one export of the operator’s
alarm log: next-alarm prediction, alarm correlation and root-cause identification. The
topology of the network links the three tasks.
We first present the background of these tasks: mobile networks and alarms, the
data mining methods used for correlation, and the sequence and graph models used for
prediction. We then build two network graphs from the alarms themselves, one between
managed elements and one between sites. For prediction, we train sequence models of
the next alarm code and add graph information to them in three forms: static graph
embeddings, dynamic graph features, and attention over the active alarms of neighbouring
elements, all under the same leakage controls. Predicting the next element instead was
tried and paused after a negative result. For correlation, we mine a catalogue of statistically
tested rules between alarm codes at several topological distances and use it in a correlator
that groups the alarm stream into incidents. For root cause, we name the root site and
the root alarm of each incident.
The export covers about 11 hours: 99% of its alarms fall on one day. On this data,
no graph model beat the sequence model by more than the measured noise floor of 0.015
macro F1, and diagnostics trace this negative result to the small number of examples per
alarm code, not to the models. The graph is useful instead for grouping and locating
alarms. On the test period, the correlator reduces the number of items to handle by a
factor of 9.0 and keeps 89.1% of the vendor’s root–child links inside one incident. The
root-cause method names the right site in 18 of 19 labelled incidents, against 13 for the
site of the earliest alarm. We also design the application that would run these methods in
the network operations center. | en_US |
| dc.language.iso | en | en_US |
| dc.subject | Fault Management | en_US |
| dc.subject | Alarm Correlation | en_US |
| dc.subject | Root-cause Analysis | en_US |
| dc.subject | Alarm Prediction | en_US |
| dc.subject | Graph Neural Networks | en_US |
| dc.subject | Association Rules | en_US |
| dc.subject | Mobile Networks | en_US |
| dc.title | Intelligent Alarm Management for Telecom Networks: Real-Time Correlation, Root Cause Identification, and Cascade Prediction Using Graph Neural Networks | en_US |
| dc.type | Thesis | en_US |
| Appears in Collections: | Ingenieur
|