A SYSTEM THAT ENABLES AUTOMATION OF ANOMALY SCANNING IN NETWORK ALARMS USING THE BINARY CLUSTERING BAYES-GAUSS MIXTURE MODEL METHOD.
Patent Information
- Authority / Receiving Office
- TR · TR
- Patent Type
- Applications
- Current Assignee / Owner
- TURKCELL TEKNOLOJI ARASTIRMA & GELISTIRME AS
- Filing Date
- 2024-11-04
- Publication Date
- 2026-06-22
Smart Images

Figure 00000013_0000
Abstract
Description
1 TARIFF BINARY CLUSTERING USING THE BAYES-GAUSS MIXTURE MODEL METHOD ANOMALY SCANNING IN NETWORK ALARMS A SYSTEM THAT ENABLES AUTOMATION Technical Area This invention uses the binary clustering Bayesian Gaussian mixture model method for network alarms. Automating anomaly scanning in cases of increased density to improve anomaly detection. and enables its management to be carried out in a more precise and effective manner. It is related to the system. Previous Technique Today, 15 commonly used methods for anomaly detection in network alarms. Among the methods are Gaussian Mixture Models (GMM), Bayesian Gaussian Mixture Models (BGMM), Density-Based Spatial Clustering of Noisy Applications Based Spatial Clustering of Applications with Noise-DBSCAN) and K- There is the K-Means Clustering method. These methods, 20 It detects anomalies by clustering data points. However, the current These methods are unable to adequately detect small and dynamic anomalies. GMM and BGMM, in particular, tend to overreact to small deviations, resulting in high false positive rates. This leads to positive rates. Differentiation according to the degree of importance of anomalies. Failure to do so leads to critical issues being overlooked. Static 25 These methods struggle to handle dynamic and complex data structures. Therefore, considering the studies and shortcomings in the current technique... when considered, binary clustering using the Bayesian Gaussian mixture model method By automating anomaly scanning during increases in network alarm intensity, 30 2 more precise and effective anomaly detection and management It appears that a system is needed to enable its implementation. United States Regulation US11848843B2, which is included in the known state of the art. The patent document states that anomalies in network traffic can be detected using machine learning. The text refers to a system that enables detection using this method. The subject of the invention is the networking of an MPLS (Multi-Protocol Label Switching) network. there are anomalies in the traffic that could affect the performance of devices on the network. Multiple machine learning models are used to determine if it is not. The first The machine learning model analyzes 10 network tunnels from multiple routers on the network. It is trained on the network traffic that passes through. The second machine learning model is a specific Router-specific networking for a subset of network tunnels associated with the router. It is trained on router-specific network traffic that passes through the first machine's traffic. The learning model is used to identify a network anomaly, and the second machine The learning model is used to identify anomalies specific to a router. 15 When both a network anomaly and a router-specific anomaly are identified A router error is identified. An indication of a router error is a piece of information. It is transmitted to the processing device. Brief Description of the Invention 20 The purpose of this invention is to create a binary clustering Bayesian Gaussian mixture model (Bi-Clustering). Network alarm using the Bayesian Gaussian Mixture Model (Bi-BGMM) method. Automating anomaly scanning in cases of increased density to improve anomaly detection. and to ensure that its management is carried out in a more precise and effective manner. 25 The goal is to implement a system developed for this purpose. Another aim of this invention is to use hierarchical clustering techniques. Detecting and automatically correcting anomalies in network alarms. 30 to ensure network performance optimization through mechanisms It is about implementing a developed system. 3 Another aim of this invention is to enable more precise anomaly detection and lower accuracy with Bi-BGMM. The goal is to implement a system designed to minimize the false positive rate. Another aim of this invention is to classify anomalies according to their severity into 5 categories. making resource allocation more efficient and improving network performance increasing customer satisfaction and operational efficiency, reducing costs developed with the aim of reducing the number of jobs and creating new job opportunities. The goal is to implement the system. Detailed Description of the Invention The "Bayesian Binary Clustering" method was used to achieve the purpose of this invention. Anomaly Scanning in Network Alarms Using Mixture Modeling Method A system that provides automation is shown in the attached figure; this figure is 15. Figure 1 shows a schematic view of the system that is the subject of the invention. The parts shown in the figure are individually numbered, and these numbers correspond to... The corresponding answers are given below. 20 1. System 2. Database 3. Server 4. Alert Server 25 5. Processor A. Electronic Devices Network alarm density using binary clustering Bayesian Gaussian mixture model method. By automating anomaly screening in the increases, anomaly detection and 30 4 to ensure that its management is carried out in a more precise and effective manner The system in question, developed for the purpose of invention (1); - including device information, real-time speed, and geographical location. It records customer connection information and district-based network alarms. at least one database structured to keep under (2), 5 - using any communication protocol with electronic device (A) to establish a connection, access data on the database (2) and the database (2) recording data on it, device information, instantaneous speed and geographic location Customer connection information and district-based network alarms in this form at least one 10 configured to retrieve and transmit from database (2) server (3), - using any communication protocol with electronic device (A) establishing a connection, accessing values labeled as outliers, optimum speed The results of the speed test, which deviated from the value, are sent as a message to the queue structure. assigning and processing message contents in the queue structure to the relevant service 15 at least one configured to send SMS messages to provider personnel alert server (4), - executed on electronic device (A), transmitted via server (3) Customers' connection information includes device data, instantaneous speed, and geographical location. Accessing information and district-based network alarms and performing data analysis 20 to carry out, evaluating the data for each district as a separate set and performing data analysis on a district basis, Bayesian analysis of network alarm data. By applying Gaussian Mixture Models, data can be processed using multiple Gaussian distributions. modeling with, cluster each data point obtained from the BGMM model measuring the “Mahalanobis” distance to the centers and anomaly 25 to determine the degree, again with a second BGMM application clustering and creating new subsets, anomalies obtained from the second clustering through the scoring method Ranking the "Mahalanobis" distances by percentile allows for the identification of specific distances. Interfering with the network device using algorithms and commands 30 to provide and automatic correction processes on network devices to perform, alert server for values labeled as outliers (4) contains at least one processor (5) configured to transmit notifications. The invention involves establishing a connection between the database (2) and the server (3) in the system (1). It is structured as follows: The database (2) contains device information, instantaneous speed and 5 keeping records of customers' connection information in the form of geographical location It is structured as follows: The database (2) contains district-based network alarms. It is structured to keep records. The server (3) in the system (1) which is the subject of the invention, is located in the known state of the art. the field connects to electronic device (A) using any communication protocol to establish and run on electronic device (A) through this established connection The server (3) is configured to communicate with the processor (4). (2) to access the data on the database (2) and to record data on the database (2) It is configured. Server (3), device information, instantaneous speed and geographical location 15 This includes customer connection information and district-based network alarms in the form of data. It is configured to pull from the base (2) and transmit to the processor (4). The warning server (4) in the system in question (1) is known to the art. using any communication protocol included in the situation, electronic device 20 To establish a connection with (A) and through this connection, to use the electronic device (A) It is configured to communicate with the processor (5) that is running on it. The warning server (4) displays the values that are labeled as outliers via the processor (5). It is configured to access the alert server (4), from the optimum speed value. Assigning slingshot speed test results as a message to the queue structure and queue 25 The message content processed within its structure is sent via SMS (Short SMS) to the relevant service provider personnel. to transmit as Message Service (SMS). It is being structured. The processor (5) in the system (1) which is the subject of the invention, is 30 on the electronic device (A). It is configured to be executed. The processor (5) transmits through the server (3). 6 Customers' connection information includes device data, instantaneous speed, and geographical location. Accessing information and district-based network alarms and performing data analysis. to carry out, evaluate the data for each district as a separate set and the data It is structured to perform its analysis on a district basis. The processor (5) is at least three months old. Retrieving district-based network alarm data into data analysis software and performing this process on day 5 It is configured to repeat every hour on updated data. The processor (5) lists the number of hourly alarms for each day in the historical alarm data. It is configured to extract. The processor (5) extracts each data point, a specific network alarm data representing alarm events within a time period Bayesian Gaussian Mixture Models (BGMM), 10 By applying this method, we can model the data with multiple Gaussian distributions. Adding Bayesian approximations to the parameters, from the various Gaussian components of the data Assuming that it arrives, assign the data points to multiple Gaussian components, and each mean, covariance, mixing weights of the components By defining the parameters in the form of weights, it is possible to detect network alarms. to determine its normal distribution and to provide a basis for anomaly detection. It is structured. The processor (5) processes each data obtained from the BGMM model. Measuring the “Mahalanobis” distance of the point to the cluster centers and anomaly determining the degree of anomaly, thus determining the degree of anomaly for each data point. It is configured to obtain the distances. The processor (5) is configured to obtain the specified 20 Reclustering the “Mahalanobis” distances with a second BGMM implementation. to subject to and create new subsets thus the initial clustering results to make it more precise and accurate and to detect more precise and accurate anomalies The processor (5) is structured to obtain subsets that enable detection. Determining the degree to which a data point is an anomaly and the significance of anomalies 25 Anomaly scoring method used for classification according to degree Percentage of “Mahalanobis” distances obtained from the second clustering via Sorting into slices and assigning an anomaly score to each data point, the scores; classifying them according to high, medium, and low importance levels, thus to obtain the scores classified according to the severity of the anomalies and 30 It is configured to perform operational prioritization. Processor (5), 7 anomaly scores, the types of anomalies determined by these scores, and those detected According to the anomaly, using specific algorithms and commands, the network device to enable intervention and automatic correction in network devices It is configured to perform the operations. The processor (5), contrary to 5 to send notification to the alert server (4) for the tagged values It is being structured. Industrial application of the invention In the system of the invention, (1) binary clustering Bayes Gaussian mixture model method 10 By automating anomaly scanning during increases in network alarm intensity, more precise and effective anomaly detection and management This is ensured. Around these fundamental concepts, the subject of the invention is “Binary Clustering Bayes Gauss 15 Anomaly Scanning in Network Alarms Using Mixture Modeling Method A wide variety of applications related to "A System that Provides Automation (1)" It is possible to develop further, and the invention cannot be limited to the examples described here. It is essentially as stated in the requests.
Claims
8 REQUESTS 1. Network alarm using binary clustering Bayesian Gaussian mixture model method By automating anomaly scanning in cases of increased density, anomalies can be detected. detection and management in a more precise and effective way 5 developed to enable its realization; - including device information, real-time speed, and geographical location. It records customer connection information and district-based network alarms. at least one database structured to keep it under (2), - using any communication protocol with electronic device (A) 10 to establish a connection, access data on the database (2) and the database (2) recording data on it, device information, instantaneous speed and geographic location Customer connection information and district-based network alarms in this form at least one configured to retrieve and transmit from database (2) server (3), 15 - using any communication protocol with electronic device (A) establishing a connection, accessing values labeled as outliers, optimum speed The results of the speed test, which deviated from the value, are sent as a message to the queue structure. assigning and processing message contents in the queue structure to the relevant service. at least one 20 configured to send SMS messages to provider personnel including the warning server (4); - executed on electronic device (A), transmitted via server (3) Customers' connection information includes device data, instantaneous speed, and geographical location. Accessing information and district-based network alarms and performing data analysis. to carry out, evaluate the data for each district as a separate set 25 and performing data analysis on a district basis, Bayesian analysis of network alarm data. By applying Gaussian Mixture Models, data can be processed using multiple Gaussian distributions. modeling with, cluster each data point obtained from the BGMM model to measure the "Mahalanobis" distance to the centers and anomalies to determine the degree, again with a second BGMM application 30 clustering and creating new subsets, anomalies 9 obtained from the second clustering through the scoring method Ranking the "Mahalanobis" distances by percentile allows for the identification of specific distances. using algorithms and commands to interfere with the network device to provide and automatic correction processes on network devices To do this, send an alert to the server for values labeled as outliers. (4) with at least one processor (5) configured to transmit notifications a characterized system (1).
2. Database (2) configured to connect with Server (3) A system like the one in Claim 1, characterized (1). 10 3. Includes device information, real-time speed, and geographical location. configured to keep a record of customers' connection information a system like the one in Claim 1 or 2 characterized by a database (2) (1). 15 4. To keep a record of district-based network alarms. a structured database (2) as in Claim 3 system (1).
5. Using any communication protocol, connect to electronic device (A) to establish a connection and through this established connection electronic device (A) configured to communicate with the processor (4) running on it in any of the above requests characterized by the server (3) such a system (1). 25 6. To access data on database (2) and to add data to database (2) characterized by the server (3) configured to record a system like any of the above requests (1).
7. Customer connection information includes device details, real-time speed, and geographical location. information and district-based network alarms via the database (2) with server (3) configured to pull and transmit to processor (4) as in any of the above characterized claims system (1). 5 8. Using any communication protocol, connect to electronic device (A) to establish a connection and through this established connection electronic device (A) configured to communicate with the processor (5) running on it Any of the above requests characterized by the warning server (4) a system like one of them (1).
9. To access the values labeled as outliers via the processor (5). the above characterized by the configured alert server (4) a system like any of the requests (1). 15 10. Sending speed test results that deviate from the optimum speed value as a message in the queue. assigning the processed message content in the queue structure to the relevant service. Alert configured to be sent as an SMS to provider personnel. Any of the above requests characterized by server (4) 20 a system like one of them (1).
11. Processor (5) configured to run on electronic device (A) as in any of the above claims characterized by system (1). 25 12. Device information, instantaneous speed and geographical location transmitted via the server (3). customer connection information and district-based network alarms in this form to access and perform data analysis, data for each district is in a separate set to evaluate and analyze data on a district basis 30 11 from the above requests characterized by the configured processor (5) a system like any other (1).
13. Integrate at least three months' worth of district-based network alarm data into data analysis software. to obtain and repeat this process hourly throughout the day on updated data 5 The above is characterized by the processor (5) which is configured to do so. a system like any of the requests (1).
14. In the historical alarm data, list the number of hourly alarms for each day. The above 10 is characterized by the processor (5) configured to extract. a system like any of the requests (1).
15. Each data point represents alarm events within a specific time period. Bayesian-Gauss Mixture Models on Network Alarm Data, By applying this method, we can model the data with multiple Gaussian distributions, model 15 Adding Bayesian approximations to the parameters, various Gaussian approximations of the data Assuming that it comes from components, the data points are multiple Gaussian assigning to components and calculating the mean, covariance, and weights of each component. By determining the mixing parameters, the network To determine the normal distribution of alarms and the basic 20 for anomaly detection. characterized by the processor (5) configured to create a system like any of the above requests (1).
16. Each data point obtained from the BGMM model is assigned to the cluster centers. To measure the “Mahalanobis” distance and determine the degree of anomaly. 25 thus obtaining the distances that determine the degree of anomaly of each data point. The above is characterized by the processor (5) which is configured to do so. a system like any of the requests (1). 12 17. Determining the specified “Mahalanobis” distances with a second BGMM application. to re-cluster and create new subsets thus first To make clustering results more precise and accurate. and obtaining subsets that enable more sensitive and accurate anomaly detection The above 5 is characterized by the processor (5) configured to do so. a system like any of the requests (1).
18. Determining the degree of anomaly in each data point and identifying the anomalies. Anomaly scoring used for classification according to severity “Mahalanobis” 10 was obtained from the second clustering via the method. to rank the distances in percentiles and assign them to each data point Assigning anomaly scores, categorizing scores into high, medium, and low significance levels. to classify according to, thus according to the degree of importance of, anomalies obtaining classified scores and operational prioritization The above 15 is characterized by the processor (5) configured to do so. a system like any of the requests (1).
19. Anomaly scores, the types of anomalies determined by these scores, and those detected. According to the anomaly, the network uses specific algorithms and commands. to enable intervention in the device and automatic 20 in network devices with processor (5) configured to perform correction operations as in any of the above characterized claims system (1).
20. Notification to the alert server (4) for values labeled as outliers 25 The above is characterized by the processor (5) which is configured to transmit. a system like any of the requests (1).