A system and method for performing an audit for parameters of core nodes in a network

The system addresses the challenges of evolving network auditing by employing a dynamic audit template and real-time analysis to ensure accurate, efficient, and adaptive network management, optimizing performance and compliance across diverse network technologies.

WO2025203104A1PCT designated stage Publication Date: 2025-10-02JIO PLATFORMS LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/IN2025/050485
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-26
Filing Date
2025-03-26
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Existing network auditing technologies struggle to keep pace with the rapid evolution of telecommunication networks, leading to discrepancies between audited and actual network states, inefficiencies, and a lack of real-time monitoring capabilities, particularly in complex architectures like 5G.

Method used

A system and method for performing audits on core nodes using a dynamic audit template, automated discrepancy identification, and real-time analysis, incorporating live and one-time audits, and a distributed event streaming platform to provide immediate alerts and corrective actions.

Benefits of technology

Enables flexible, adaptive, and comprehensive network management with real-time insights, rapid identification of discrepancies, and automated corrective actions, enhancing network performance and compliance monitoring across various network technologies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IN2025050485_02102025_PF_FP_ABST
    Figure IN2025050485_02102025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure provides a system (102) for performing an audit for parameters of core nodes in a network comprises a memory (204) and processors (202) configured to execute instructions. The instructions include receiving parameters with first values as parameters for auditing, populated in an audit template. The system (102) obtains second values of parameters from core nodes. The system (102) performs the audit by comparing second values with first values. The system (102) analyzes comparison results to identify discrepancies without manual intervention. The system (102) identifies one or more parameters of core nodes as having discrepancy when second values don't match first values. The system (102) stores second values of the one or more parameters, generates a report and displays the identified discrepancy on the user interface. This approach enables efficient, automated auditing of network configurations, identifying discrepancies between expected and actual parameter values across multiple core nodes.
Need to check novelty before this filing date? Find Prior Art

Description

A SYSTEM AND METHOD FOR PERFORMING AN AUDIT FOR PARAMETERS OF CORE NODES IN A NETWORKRESERVATION OF RIGHTS

[0001] A portion of the disclosure of this patent document contains material, which is subject to intellectual property rights such as, but are not limited to, copyright, design, trademark, Integrated Circuit (IC) layout design, and / or trade dress protection, belonging to Jio Platforms Limited (JPL) or its affiliates (hereinafter referred as owner). The owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent files or records, but otherwise reserves all rights whatsoever. All rights to such intellectual property are fully reserved by the owner.FIELD OF THE DISCLOSURE

[0002] The present disclosure relates generally to the field of communication systems. More particularly, the present disclosure relates to systems and methods for performing an audit on telecommunication networks.DEFINITION

[0003] As used in the present disclosure, the following terms are generally intended to have the meaning as set forth below, except to the extent that the context in which they are used to indicate otherwise.

[0004] Parameters refer to a subset of network configuration parameters of core nodes, designated as critical for network performance and compliance, including but not limited to quality of service (QoS) settings, network latency thresholds, packet loss rate limits, frequency band allocations, transmit power levels, or antenna configurations. The elevated parameter represents a parameter which is associated with each of the core nodes globally.

[0005] Core node, refer to term refers to the 5G Core Network (5GC), which is the central control and management component responsible for functions likeconnectivity, mobility, authentication, and data management, allowing for a seamless transition between wired and wireless services.

[0006] First values refer to the expected or desired configuration values of the parameters in the network during normal operations, which serve as a baseline for comparison during audits.

[0007] Second values refer to the actual, current values of parameters as configured on the core nodes at the time of audit, representing the real-time state of the network infrastructure.

[0008] Audit template refers to a dynamic, editable list of parameters and their values used to perform audits across multiple core nodes in a network.

[0009] Core nodes refer to central network elements such as Mobile Switching Centers (MSCs), Serving GPRS Support Nodes (SGSNs), Gateway GPRS Support Nodes (GGSNs), and their equivalents in newer network architectures like the Evolved Packet Core (EPC) in 4G or the 5G Core Network.

[0010] Live audit jobs refer to continuous monitoring and auditing of network parameters in real-time, providing immediate alerts for any discrepancies detected.

[0011] One-time audits refer to comprehensive audits of all specified parameters executed on-demand or as scheduled at a specific point in time.

[0012] Ad-hoc audits refer to unscheduled, event-triggered audits performed in response to specific modifications in network configuration or topology to ensure continued compliance.

[0013] Distributed event streaming platform refers to a system for real-time processing of audit events, capable of ingesting network parameter values and operational metrics from network nodes, analyzing Real-time data for anomalies, and triggering alerts or actions based on predefined conditions.

[0014] Coverage platform refers to a software system that performs audits of all parameters, capable of setting parameters or comparing them with extracted parameters and their values from network sites.

[0015] User interface portal refers to any interface system, including but not limited to web portals, desktop applications, mobile applications, command-line interfaces, or API-based interfaces, that provides access to the audit system's functionalities. \

[0016] Parameter discrepancy patterns refer to recurring or systematic deviations between expected and actual parameter values identified through analysis of historical audit data.BACKGROUND OF THE DISCLOSURE

[0017] The following description of related art is intended to provide background information pertaining to the field of the disclosure. This section may include certain aspects of the art that may be related to various features of the present disclosure. However, it should be appreciated that this section be used only to enhance the understanding of the reader with respect to the present disclosure, and not as admissions of prior art.

[0018] The present disclosure relates to the field of network management and optimization, specifically focusing on the auditing of network parameters in telecommunication networks. As networks grow in complexity and scale, the need for efficient and accurate auditing processes becomes increasingly critical to maintain optimal performance, ensure compliance, and maximize resource utilization.

[0019] Network auditing is a fundamental process in modem telecommunications infrastructure management. It involves collecting data on various network parameters and analyzing this data to derive meaningful insights. These insights are crucial for monitoring the overall health and status of thenetwork, particularly when compared against established benchmarks and compliance standards. Through network auditing, operators can assess existing Key Performance Indicators (KPIs), develop new KPIs, and continuously improve network management practices.

[0020] The dynamic nature of modem networks presents unique challenges for auditing processes. During network reconfigurations, which involve adding, removing, or changing network nodes, the associated network parameters also undergo modifications. This constant state of flux necessitates a robust and adaptable auditing system capable of handling dynamic network parameters. The ability to conduct timely and accurate audits is essential for determining discrepancies, optimizing radio network services, enhancing network performance, improving resource utilization, and striking an ideal balance among coverage, capacity, and quality.

[0021] Existing network auditing technologies often rely on static, predefined parameter sets and periodic manual audits. While these approaches have served the industry for years, they are increasingly inadequate in the face of rapidly evolving network technologies and configurations. Traditional auditing methods struggle to keep pace with the frequency of network changes, leading to potential discrepancies between the audited state and the actual network state.

[0022] Furthermore, conventional auditing systems typically require significant manual intervention, making them time-consuming and prone to human error. The process of updating audit parameters, executing audits, and analyzing results often involves multiple systems and manual data entry, which can lead to inconsistencies and delays in identifying and addressing network issues.

[0023] Another limitation of existing technologies is their inability to provide real-time or near-real-time auditing capabilities. In a landscape where network conditions can change rapidly, the delay between an audit and the availability of results can mean that critical issues go unnoticed for extended periods, potentially impacting network performance and user experience.

[0024] The increasing complexity of network architectures, particularly with the advent of 5G and beyond, exacerbates these challenges. Modem networks involve a multitude of parameters across various network elements, making comprehensive auditing a daunting task using traditional methods. The need for a more sophisticated, automated, and flexible auditing system has never been more pressing.

[0025] Conventional systems and methods face difficulty in efficiently monitoring, analyzing, and optimizing network performance, particularly in the context of rapidly evolving network configurations and the need for real-time insights. There is, therefore, a need in the art to provide a method and a system that can overcome the shortcomings of the existing prior arts by offering dynamic, automated, and comprehensive auditing capabilities for modem telecommunication networks.SUMMARY OF THE DISCLOSURE

[0026] In an exemplary embodiment, a system for performing an audit of core nodes in a network is described. The system comprises a user interface module configured for receiving a plurality of parameters along with first values for performing auditing, wherein the plurality of parameters along with corresponding first values are populated in an audit template. The system comprises an audit module configured for obtaining second values of the plurality of parameters from the core nodes in the network. The system comprises an audit execution module configured for comparing the second values of the plurality of parameters with the first values of the plurality of parameters. The system comprises an analysis module configured for analyzing results of the comparison to determine discrepancies associated with one or more parameters of the plurality of parameters. The system comprises a reporting module configured for generating an audit report based on the determined discrepancies.

[0027] In some embodiments, the parameters comprise a subset of network configuration parameters of the core nodes in the network including at least one ofquality of service (QoS) settings, network latency thresholds, packet loss rate limits, frequency band allocations, transmit power levels, antenna configurations, a bandwidth, a throughput, a carrier frequency, an allowable data transmission, a latency, a packet loss, a jitter, a signal strength, a bit error rate (BER), and a propagation delay.

[0028] In some embodiments, the audit template is a dynamic audit template. The user interface module is further configured for receiving updates to the audit template from an administrator. The audit execution module is further configured for modifying the audit template based on the received updates. The audit execution module is further configured for performing a subsequent audit using the modified audit template.

[0029] In some embodiments, obtaining the second values of the plurality of parameters comprises establishing, by a network module, secure network connections with the core nodes using at least one of: Simple Network Management Protocol (SNMP), Secure Shell (SSH) protocol, or a proprietary network management protocol. Obtaining the second values of the plurality of parameters further comprises authenticating, by the network module, the system with each core node. Obtaining the second values of the plurality of parameters further comprises executing, by the audit module, commands or queries on each core node to retrieve the second values of the plurality of parameters.

[0030] The system comprises a discrepancy identification module configured for identifying one or more parameters of the plurality of parameters as having discrepancy on determining that the second values of the one or more parameters do not match with the corresponding first values of the one or more parameters.

[0031] In some embodiments, the analysis module is further configured for analyzing historical audit data to identify parameter discrepancy patterns. The the analysis module is further configured for generating recommendations for parameter adjustments based on the identified patterns.

[0032] In some embodiments, a corrective action module is configured for initiating, by, corrective actions for parameters identified as having discrepancies or based on selecting one of the generated recommendations. The corrective actions comprise at least one of sending configuration update commands to the affected core nodes to align the second values with the first values, generating alerts for manual review by a network administrator for discrepancies exceeding a predefined threshold, or logging the discrepancies for future analysis and reporting.

[0033] In some embodiments, the audit execution module is configured to perform both live audit jobs and one-time audits. Live audit jobs continuously monitor and audit network parameters in real-time, providing immediate alerts for any discrepancies. One-time audits are executed on-demand or scheduled at configurable time intervals, performing a audit of one or more selected parameters at a given point in time.

[0034] In an aspect, the system further comprises a processing engine which classifies the at least one network discrepancy into at least one category including a Total Discrepancy category, a High-Impact Discrepancy category or a low -impact Discrepancy category.

[0035] In an embodiment, the user interface module (212) is configured to visualize the one or more discrepancies are visualized based on a selected geographic location.

[0036] In another exemplary embodiment, a method for performing an audit of core nodes in a network is described. The method comprises receiving, by a user interface module, a plurality of parameters along with first values for performing auditing, wherein the plurality of parameters along with corresponding first values are populated in an audit template. The method comprises obtaining, by an audit module, second values of the plurality of parameters from the core nodes. The method comprises performing, by an audit execution module, the audit by comparing the second values of the plurality of parameters with the first values of the plurality of parameters. The method comprises analyzing, by an analysismodule, results of the comparison to determine discrepancies associated with the plurality of parameters. The method further comprises generating, by a reporting module, an audit report based on the determined discrepancies.

[0037] In some embodiments, the parameters comprise a subset of core network configuration parameters designated as critical for network performance and compliance. The subset of core network configuration parameters includes at least one of: quality of service (QoS) settings, network latency thresholds, packet loss rate limits, frequency band allocations, transmit power levels, antenna configurations, a bandwidth, a throughput, a carrier frequency, an allowable data transmission, a latency, a packet loss, a jitter, a signal strength, a bit error rate (BER), and a propagation delay.

[0038] In some embodiments, the audit template is a dynamic audit template. The method further comprises receiving, by the user interface module, updates to the audit template from an administrator. The method further comprises modifying, by the audit execution module, the audit template based on the received updates. The method further comprises performing, by the audit execution module, a subsequent audit using the modified audit template.

[0039] In some embodiments, obtaining the second values of the plurality of parameters comprises establishing, by a network module, secure network connections with the core nodes using at least one of: Simple Network Management Protocol (SNMP), Secure Shell (SSH) protocol, or a proprietary network management protocol. Obtaining the second values of the plurality of parameters further comprises authenticating, by the network module, the system with each core node. Obtaining the second values of the plurality of parameters further comprises executing, by the audit module, commands or queries on each core node to retrieve the current values of the plurality of parameters.

[0040] In an embodiment, the method further comprises identifying, by a discrepancy identification module, one or more parameters of the plurality of parameters as having discrepancy on determining that the second values of the oneor more parameters do not match with the corresponding first values of the one or more parameters.

[0041] In some embodiments, the method further comprises analyzing, by the analysis module, historical audit data to identify parameter discrepancy patterns. The method further comprises generating, by the analysis module, recommendations for parameter adjustments based on the identified patterns.

[0042] In some embodiments, the method further comprises initiating, by a corrective action module, corrective actions for parameters identified as having discrepancies or based on selecting one of the generated recommendations. The corrective actions comprise at least one of sending configuration update commands to the affected core nodes to align the second values with the first values, generating alerts for manual review by a network administrator for discrepancies exceeding a predefined threshold, or logging the discrepancies for future analysis and reporting.

[0043] In some embodiments, the method further comprises performing, by the audit module, both live audit jobs and one-time audits. Live audit jobs continuously monitor and audit network parameters in real-time, providing alerts for the discrepancies. One-time audits are executed on-demand or scheduled or scheduled at configurable time intervals include performing an audit of one or more selected parameters at a given point in time.

[0044] In an embodiment, the user interface module is configured to visualize the one or more discrepancies are visualized based on a selected geographic location.

[0045] In an aspect, the method further comprises classifying, by the processing engine the at least one network discrepancy into at least one category including a Total Discrepancy category, a High-Impact Discrepancy category or a low-impact Discrepancy category.

[0046] In yet another exemplary embodiment, a User Equipment (UE) for facilitating an audit of core nodes in a network is described. The UE is configured to receive a notification comprising instructions for performing an audit and transmit the notification to a system. The system comprises a user interface module configured for receiving a plurality of parameters along with first values for performing auditing, wherein the plurality of parameters along with corresponding first values are populated in an audit template. The system comprises an audit module configured for obtaining second values of the plurality of parameters from the core nodes in the network. The system comprises an audit execution module configured for comparing the second values of the plurality of parameters with the first values of the plurality of parameters. The system comprises an analysis module configured for analyzing results of the comparison to determine discrepancies associated with one or more parameters of the plurality of parameters. The system comprises a reporting module configured for generating an audit report based on the determined discrepancies.

[0047] In yet another exemplary embodiment, a non-transitory computer- readable storage medium storing computer-executable instructions is described. When executed by one or more processors, the instructions cause the one or more processors to perform a method for performing an audit of core nodes in a network. The method comprises receiving, by a user interface module, a plurality of parameters along with first values for performing auditing, wherein the plurality of parameters along with corresponding first values are populated in an audit template . The method comprises obtaining, by an audit module, second values of the plurality of parameters from the core nodes. The method comprises performing, by an audit execution module, the audit by comparing the second values of the plurality of parameters with the first values of the plurality of parameters. The method comprises analyzing, by an analysis module, results of the comparison to determine discrepancies associated with the plurality of parameters. The method further comprises generating, by a reporting module, an audit report based on the determined discrepancies.

[0048] The foregoing general description of the illustrative embodiments and the following detailed description thereof are merely exemplary aspects of the teachings of this disclosure, and are not restrictive.OBJECTS OF THE DISCLOSURE

[0049] Some of the objects of the present disclosure, which at least one embodiment herein satisfies are as listed herein below.

[0050] An object of the present disclosure is to provide a system and a method for performing an audit of parameters of a plurality of core nodes in telecommunication networks, thereby enhancing network performance and compliance monitoring.

[0051] An object of the present disclosure is to perform an audit on a plurality of network core elements having dynamic parameters, thereby enabling flexible and adaptive network management.

[0052] An object of the present disclosure is to allow a dynamic audit template to perform auditing of the network parameters, which can be modified or updated at any time, thereby ensuring relevance and accuracy of audits in evolving network environments.

[0053] An object of the present disclosure is to perform an audit across the core nodes of a plurality of network technologies for the network parameters mentioned in the dynamic audit template in a recurring fashion, thereby providing comprehensive and up-to-date audit data to the end user.

[0054] An object of the present disclosure is to provide real-time analysis of audit results without manual intervention, thereby enabling rapid identification and response to network discrepancies.

[0055] An object of the present disclosure is to implement automated corrective actions for parameters identified as having discrepancies, thereby streamlining network optimization processes.

[0056] An object of the present disclosure is to integrate live audit jobs and one-time audits within a single system, thereby offering flexible auditing options to meet various operational needs.

[0057] An object of the present disclosure is to incorporate a distributed event streaming platform for real-time processing of audit events, thereby enhancing the system's ability to detect and respond to anomalies quickly.

[0058] An object of the present disclosure is to provide a user-friendly interface for inputting parameters and viewing audit results, thereby improving the accessibility and usability of the auditing system for network administrators.

[0059] An object of the present disclosure is to implement intelligent load balancing for audit requests, thereby ensuring efficient utilization of system resources and improving overall performance.

[0060] An object of the present disclosure is to offer both structured and unstructured data storage options for audit data, thereby enabling comprehensive data analysis and fast retrieval of audit information.

[0061] An object of the present disclosure is to facilitate ad-hoc audits in response to detected modifications in network configuration or topology, thereby ensuring the continuous relevance of audit parameters in dynamic network environments.

[0062] Another objective of the present disclosure is to provide a system and method that performs a real-time audit with a live dashboard through a user equipment (UE).

[0063] Another objective of the present disclosure is to provide a system and a method that evaluates the quality of service provided by one or more vendors (service provider or network operator) in a network.

[0064] Another objective of the present disclosure is to provide a system and a method to increase the overall efficiency and functionality of the network by providing a comprehensive and real-time view of the network.

[0065] Another objective of the present disclosure is to provide a system and a method that facilitates network administrators in identifying areas of the network that may be experiencing issues and taking corrective action before the occurrence of major problems.

[0066] Another objective of the present disclosure is to provide a system and a method for improving the performance and efficiency of the network by analyzing and visualizing data related to the network nodes.

[0067] Other objects and advantages of the present disclosure will be more apparent from the following description, which is not intended to limit the scope of the present disclosure.BRIEF DESCRIPTION OF DRAWINGS

[0068] The accompanying drawings, which are incorporated herein, and constitute a part of this disclosure, illustrate exemplary embodiments of the disclosed methods and systems in which like reference numerals refer to the same parts throughout the different drawings. Components in the drawings are not necessarily to scale, emphasis instead being placed upon clearly illustrating the principles of the present disclosure. Some drawings may indicate the components using block diagrams and may not represent the internal circuitry of each component. It will be appreciated by those skilled in the art that disclosure of such drawings includes the disclosure of electrical components, electronic components or circuitry commonly used to implement such components.

[0069] FIG. 1 illustrates an exemplary network architecture of a system for performing an audit for a plurality of parameters of core nodes in a network, in accordance with embodiments of the present disclosure.

[0070] FIG. 2 illustrates an exemplary micro service-based architecture of the system, in accordance with embodiments of the present disclosure.

[0071] FIG. 3 illustrates an exemplary system architecture for performing the audit for a plurality of parameters of the core nodes in the network, in accordance with an embodiment of the present disclosure.

[0072] FIG. 4 illustrates an exemplary flow diagram for performing an audit for a plurality of parameters of the core nodes in the network, in accordance with an embodiment of the present disclosure.

[0073] FIG. 5 illustrates an exemplary method for performing an audit for a plurality of parameters of core nodes in a network, in accordance with embodiments of the present disclosure.

[0074] FIG. 6 illustrates an exemplary block diagram of a computer system in which or with which embodiments of the present disclosure may be implemented.

[0075] FIG. 7 illustrates an exemplary flow diagram illustrating steps performed by the system for performing the configuration audit of the one or more network parameters, in accordance with an embodiment of the present disclosure.

[0076] FIG. 8 illustrates an exemplary user interface that enables a user (network administrator) to provide one or more inputs, in accordance with an embodiment of the present disclosure.

[0077] FIG. 9 illustrates an exemplary representation of the network discrepancies of multiple network operators (vendors) in a live dashboard status, in accordance with an embodiment of the present disclosure.

[0078] FIG. 10 illustrates another exemplary representation of various types of discrepancies related to the one or more network parameters, in accordance with an embodiment of the present disclosure.

[0079] FIG. 11 illustrates an exemplary graphical illustration showing types of discrepancies, in accordance with an embodiment of the present disclosure.

[0080] The foregoing shall be more apparent from the following more detailed description of the disclosure.LIST OF REFERENCE NUMERALS100 - Network architecture102 - System104 - Network108-1, 108-2... 108-N - User equipment110-1, 110-2... 110-N - Users112 - Servers114 - Core nodes202 - Processor(s)204 - Memory206 - Interfaces208 - Processing engine210 - Database212 - User interface module214 - audit module216 - Audit execution module218 - Analysis module220 - Discrepancy identification module222 - Data management module224 - Reporting module226 - Network module228 - Scheduling module230 - Corrective action module232 - Other module(s)300 - System architecture302 - User interface portal304 - Load balancer308 - Application gateway310 - Audit microservices312 - Reports spark job316 - Elastic search318 - Live audit jobs320 - One-time audits322 - Database management system324 - External system326 - Distributed event streaming platform400 - Flow diagram402, 404, 406, 408, 410, 412, 414, 416, 418, 420, 422, 424, 426, 428, 430, 432 -Steps of flow diagram 400500 - Method502, 504, 506, 508, 510, 512 - Steps of method 500600 - Computer system610 - External storage device620 - Bus630 - Main memory640 - Read-only memory650 - Mass storage device660 - Communication port(s)670 - Processor700- Flow chart800, 900, 1000, 1100 - DashboardDETAILED DESCRIPTION OF THE DISCLOSURE

[0081] In the following description, for the purposes of explanation, various specific details are set forth in order to provide a thorough understanding of embodiments of the present disclosure. It will be apparent, however, that embodiments of the present disclosure may be practiced without these specific details. Several features described hereafter can each be used independently of one another or with any combination of other features. An individual feature may not address all of the problems discussed above or might address only some of the problems discussed above. Some of the problems discussed above might not be fully addressed by any of the features described herein.

[0082] The ensuing description provides exemplary embodiments only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the ensuing description of the exemplary embodiments will provide those skilled in the art with an enabling description for implementing an exemplary embodiment. It should be understood that various changes may be made in the function and arrangement of elements without departing from the spirit and scope of the disclosure as set forth.

[0083] Specific details are given in the following description to provide a thorough understanding of the embodiments. However, it will be understood by one of ordinary skill in the art that the embodiments may be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not to obscure the embodiments in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail in order to avoid obscuring the embodiments.

[0084] Also, it is noted that individual embodiments may be described as a process which is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations can be performed inparallel or concurrently. In addition, the order of the operations may be re-arranged. A process is terminated when its operations are completed but could have additional steps not included in a figure. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination can correspond to a return of the function to the calling function or the main function.

[0085] The word “exemplary” and / or “demonstrative” is used herein to mean serving as an example, instance, or illustration. For the avoidance of doubt, the subject matter disclosed herein is not limited by such examples. In addition, any aspect or design described herein as “exemplary” and / or “demonstrative” is not necessarily to be constmed as preferred or advantageous over other aspects or designs, nor is it meant to preclude equivalent exemplary structures and techniques known to those of ordinary skill in the art. Furthermore, to the extent that the terms “includes,” “has,” “contains,” and other similar words are used in either the detailed description or the claims, such terms are intended to be inclusive in a manner similar to the term “comprising” as an open transition word without precluding any additional or other elements.

[0086] Reference throughout this specification to “one embodiment” or “an embodiment” or “an instance” or “one instance” means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present disclosure. Thus, the appearances of the phrases “in one embodiment” or “in an embodiment” in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0087] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the disclosure. As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be furtherunderstood that the terms “comprises” and / or “comprising,” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed items.

[0088] The aspects of the present disclosure are directed to a system and method for performing an audit for a plurality of parameters of core nodes in a network. Efficient auditing of network parameters is crucial in modem telecommunication networks to maintain optimal performance, ensure compliance, and maximize resource utilization.

[0089] Network auditing involves collecting data of various network parameters and analyzing these parameters for meaningful insights. These parameters include, but are not limited to, quality of service (QoS) settings, network latency thresholds, packet loss rate limits, frequency band allocations, transmit power levels, and antenna configurations. The insights derived from auditing can be used to monitor the health and general status of the network when compared to existing benchmarks and compliance standards.

[0090] The present disclosure relates to a system and method for performing an audit for a plurality of parameters of core nodes in a network based on parameters. These parameters are populated in a dynamic audit template, which can be modified or updated at any time to reflect changes in network configuration or compliance requirements. This flexibility allows for the auditing of dynamic network parameters, which is essential during network reconfigurations when nodes are added, removed, or changed.

[0091] The system and method described in this disclosure perform audits across a plurality of core nodes of various network technologies. The audit process involves obtaining current values of the parameters from the core nodes and comparing them with the expected values defined in the audit template. Thiscomparison is performed without manual intervention, allowing for rapid identification of discrepancies based on the comparison.

[0092] Furthermore, the system incorporates advanced features such as automated corrective actions, real-time processing of audit events through a distributed event streaming platform, and the ability to perform both live audit jobs and one-time audits. These features enhance the system's capability to detect and respond to network issues promptly, thereby optimizing radio network services, improving network performance and resource utilization, and achieving a balance among coverage, capacity, and quality.

[0093] The audit data generated by this system is used for various diagnosis and maintenance actions. By implementing this automated and flexible auditing system, network operators can save a significant amount of effort and time while obtaining more accurate and timely results across 2G, 3G, 4G, 5G, and future network technologies.

[0094] Real-time audit of network parameters offers numerous benefits. However, organizations may encounter several challenges and issues during implementation and operation. For example, 5G networks generate vast amounts of data due to the high number of connected devices and the increased throughput. Handling this data in real-time by the existing configuration audit systems is challenging, requiring scalable infrastructure and efficient data processing techniques to manage the volume and velocity of incoming data streams. Further, the existing configuration audit systems are unable to ensure the quality and consistency of the data collected from various network elements, especially in heterogeneous environments with equipment from different vendors. Therefore, inaccurate or inconsistent data can lead to false alarms or misinterpretation of network performance. Also, for a configuration audit system, it is required to correlate multiple parameters and identify meaningful patterns or anomalies in a real-time, that may be a cumbersome task.

[0095] In a traditional approach, the configuration audit is performed manually. The configuration audit is performed for various reasons, such as a security issue, a fault investigation, maintenance of organizational policies or regulatory requirements. The process of manually verifying each network parameter by the network administrator (user) to audit consumes more time and is complex for a large network. The manual process is error-prone and leads to misconfigurations in the network, which may raise a network failure. Also, the configuration auditing method and standards vary between the network administrators, resulting in inconsistencies in reports and findings. As networks grow, manual auditing of each network parameter for the user devices becomes increasingly unmanageable and inefficient.

[0096] Existing configuration audit systems have limited capabilities and may not provide real-time data. Therefore, there is a need for a system and a method that overcomes the limitations of the existing art.

[0097] The present disclosure discloses a system and method for performing a configuration audit of one or more network parameters. The system may allow an administrator to define at least one audit template having one or more network parameters and at least one configurable value corresponding to each of the one or more network parameters. The administrator defines the audit template to perform real-time audits with a live dashboard. The system may perform the configuration audit of the network parameters by collecting network values (current values) and comparing the current values with the configurable values (also known as Golden values) corresponding to the network parameters. The system may provide one or more audit reports (compliance reports) and initiate corrective measures. The live dashboard may be configured to present a discrepancy (if the current value and the golden value are not the same) and a compliance percentage across the network or selected geographies with node-level granularity. In an aspect, the discrepancy and compliance report may be sent to a user through the UE at a predetermined time on a daily basis.

[0098] Hereinafter, exemplary embodiments of the present disclosure will be described with reference to the accompanying drawings.

[0099] The various embodiments throughout the disclosure will be explained in more detail with reference to FIGS. 1-11.

[0100] FIG. 1 illustrates a network architecture (100) of a system (102) for performing an audit for a plurality of parameters of core nodes (114) in a network, in accordance with embodiments of the present disclosure.

[0101] In an embodiment, the system (102) is connected to a network (104), which is further connected to at least one computing devices 108-1, 108-2, . . . 108- N (collectively referred as computing device 108, herein) associated with one or more users 110-1, 110-2, . . . 110-N (collectively referred as user (110), herein). The computing device (108) may be personal computers, laptops, tablets, wristwatch, or any custom-built computing device integrated within a modem diagnostic machine that can connect to a network as an loT (Internet of Things) device. In an embodiment, the computing device (108) may also be referred to as User Equipment (UE) or user device. Accordingly, the terms “computing device” and “User Equipment” may be used interchangeably throughout the disclosure. In an aspect, the user (110) is a network operator or a field engineer. Further, the network (104) can be configured with a centralized server that stores compiled data.

[0102] In an embodiment, the system (102) may receive at least one input data from the user (110) via the at least one computing devices (108). In an aspect, the user (110) may be configured to initiate the process of performing an audit for a plurality of parameters of core nodes (114) in a network, through an application interface of a mobile application installed in the computing devices (108). The mobile application may be configured to communicate with a plurality of servers (112).

[0103] In some examples, the mobile application may be a software or a mobile application from an application distribution platform. Examples ofapplication distribution platforms include the App Store for iOS provided by Apple, Inc., Play Store for Android OS provided by Google Inc., and such application distribution platforms. In an embodiment, the computing device (108) may transmit the at least one captured data packet over a point-to-point or point-to-multipoint communication channel or network (104) to the system (102). In an embodiment, the computing device (108) may involve collection, analysis, and sharing of data received from the system (102) via the network (104).

[0104] In an exemplary embodiment, the network (104) may include, but not be limited to, at least a portion of one or more networks having one or more nodes that transmit, receive, forward, generate, buffer, store, route, switch, process, or a combination thereof, etc. one or more messages, packets, signals, waves, voltage or current levels, some combination thereof, or so forth. In an exemplary embodiment, the network (104) may include, but not be limited to, a wireless network, a wired network, an internet, an intranet, a public network, a private network, a packet-switched network, a circuit-switched network, an ad hoc network, an infrastructure network, a Public-Switched Telephone Network (PSTN), a cable network, a cellular network, a satellite network, a fiber optic network, or some combination thereof.

[0105] Although FIG. 1 shows exemplary components of the network architecture (100), in other embodiments, the network architecture (100) may include fewer components, different components, differently arranged components, or additional functional components than depicted in FIG. 1. Additionally, or alternatively, one or more components of the network architecture (100) may perform functions described as being performed by one or more other components of the network architecture (100).

[0106] FIG. 2 with reference to FIG. 1, illustrates an exemplary block diagram (200) of the system (102) for performing audit for the plurality of parameters of core nodes (114) in the network, in accordance with an embodiment of the present disclosure.

[0107] The system (102) includes one or more processor(s) (202), a memory (204), a processing engine (208), a database (210), and an interface(s) (206). In an exemplary embodiment, the processing engine (208) may include one or more modules / engines selected from any of a user interface module (212), an audit module (214), an audit execution module (216), an analysis module (218), a discrepancy identification module (220), a data management module (222), a reporting module (224), a network module (226), a scheduling module (228), a corrective action module (230), and other module(s) (232) having functions that may include but are not limited to receiving data, processing data, testing, storage, and peripheral functions, such as wireless communication unit for remote operation, audio unit for alerts and the like. The other module(s) (232) may be further configured for additional specialized tasks enhancing the audit process. These may include configuration management for maintaining audit templates, security measures for protected communications, data visualization for graphical result representation, real-time notifications, integration with external systems, compliance checking, version control for tracking configuration changes, performance optimization based on audit outcomes, fault tolerance to ensure uninterrupted operations, and the like.

[0108] The one or more processor(s) (202) is configured to initiate the processor of authentication and authorization of subscribers at edge of a network through an application interface of the User Equipment (UE) (108). In an embodiment, the application interface is configured to transmit one or more instructions to the one or more Processor(s) (202).

[0109] In an embodiment, the one or more processor(s) (202) may be implemented as one or more microprocessors, microcomputers, microcontrollers, edge or fog microcontrollers, digital signal processors, central processing units, logic circuitries, and / or any devices that process data based on operational instructions. Among other capabilities, the one or more processor(s) (202) may be configured to fetch and execute computer-readable instructions stored in the memory (204) of the system (102). The memory (204) may be configured to storeone or more computer-readable instructions or routines in a non-transitory computer readable storage medium, which may be fetched and executed to create or share data packets over a network service. The memory (204) may comprise any non-transitory storage device including, for example, volatile memory such as Random Access Memory (RAM), or non-volatile memory such as Erasable Programmable Read-Only Memory (EPROM), flash memory, and the like.

[0110] The interface(s) (206) is included within the system (102) to serve as a medium for data exchange, configured to facilitate user interaction with the mobile application. The interface(s) (206) may be composed of interfaces for data input and output devices, storage devices, and the like, providing a communication pathway for the various components of the system (102).

[0111] The interface(s) (206) may comprise a variety of interfaces, for example, interfaces for data input and output devices, referred to as RO devices, storage devices, and the like. The interface(s) (206) may facilitate communication to / from the system (102). The interface(s) (206) may also provide a communication pathway for one or more components of the system (102). Examples of such components include but are not limited to, the processing unitZengine(s) (208) and the database (210).

[0112] In an embodiment, the processing unitZengine(s) (208) may be implemented as a combination of hardware and programming (for example, programmable instructions) to implement one or more functionalities of the processing engine(s) (208). In examples described herein, such combinations of hardware and programming may be implemented in several different ways. For example, the programming for the processing engine(s) (208) may be processorexecutable instructions stored on a non-transitory machine -readable storage medium and the hardware for the processing engine(s) (208) may comprise a processing resource (for example, one or more processors), to execute such instructions. In the present examples, the machine-readable storage medium may store instructions that, when executed by the processing resource, implement theprocessing engine(s) (208). In such examples, the system (102) may comprise the machine-readable storage medium storing the instructions and the processing resource to execute the instructions, or the machine-readable storage medium may be separate but accessible to the system (102) and the processing resource. In other examples, the processing engine(s) (208) may be implemented by electronic circuitry.

[0113] Upon receiving at least one request, the processing unit (208) is configured to extract the audit template associated with the received request. In an aspect, the processing unit (208) fetches the one or more network parameters, along with the at least one configurable value, associated with the extracted audit template from the memory (204) or the database (210). Each network parameter is associated with the at least one configurable value predefined by the operator during the initial configuration of the audit template in the memory (204).

[0114] The processing unit (208) employs a parsing and extraction process to extract the configurable values corresponding to each network parameter associated with the extracted audit template. The parsing process systematically identifies configurable values linked to the specified audit template. For example, the audit template may encompass critical network parameters such as bandwidth and carrier frequency. For example, consider the audit template designated for bandwidth assessment. This template may include a network parameter labeled "Bandwidth" with a configurable value of 150 Mbps, indicating the minimum bandwidth threshold required for optimal network performance. Similarly, the carrier frequency parameter may be included with a configurable value set to 2.1 GHz, representing the operating frequency for the particular network segment being audited.

[0115] During the parsing process, the processing unit (208) categorizes these configurable values according to their respective network parameters. For instance, the configurable value of 150 Mbps for the bandwidth parameter is extracted and categorized under bandwidth. In contrast, the configurable value of2. 1 GHz for the carrier frequency is categorized under carrier frequency. Following the parsing and categorization, the extracted configurable values are then stored in the database (210) for future reference and utilization during the configuration auditing process.

[0116] Further, the processing unit (208) is configured to collect at least one network value corresponding to the at least one network parameter as defined by the audit template from at least one data source. In an example, the at least one data source may be the EMS, which serves as a centralized platform for monitoring and managing network elements. The the processing unit (208) establishes communication with the EMS to retrieve the required network values. The EMS manages individual network devices, including user equipment (UE) (104), routers, switches, and other components integral to the network infrastructure. By continuously tracking the performance and health of these network devices, the EMS can provide real-time status updates regarding various network parameters, such as bandwidth utilization, latency, packet loss, and signal strength.

[0117] For instance, if the audit template specifies the network parameters related to latency and bandwidth, the processing unit (208) will request current network values for these parameters from the EMS. The EMS, in turn, monitors the latency experienced by data packets and the bandwidth currently utilized across different network segments. It may report a latency value of 30 milliseconds and a bandwidth utilization of 120 Mbps at the time of the request.

[0118] In an aspect, the EMS is configured to periodically transmit these network values corresponding to the network parameters to the system (108). This periodic updating may occur at defined intervals, such as once every minute, once every hour, or once every day, depending on the operational requirements and the criticality of the monitored network parameters. By employing this systematic approach, the collecting module (210) ensures that the system (108) receives timely and accurate network values, facilitating effective auditing and management ofnetwork performance in alignment with the parameters defined in the audit template.

[0119] In an example, the processing unit (208) is configured to categorize one or more collected network values into defined headers as specified in the audit template. These headers may encompass various classifications, including the parameter type, the node type, and the network type.

[0120] For example, the collected network values may include metrics such as latency, bandwidth, carrier frequency, and throughput. The system (102) processes these values by categorizing them according to the headers outlined in the audit template.

[0121] Specifically, for network type 5G, the collected value for the carrier frequency may typically be within the range of 3 GHz to 4 GHz, reflecting the frequencies utilized for enhanced data transmission and lower latency. In contrast, for network type 6G, the carrier frequency may shift to a different range, such as 100 GHz or higher, as 6G technologies are designed to support more advanced applications and significantly increased data rates. This differentiation in frequency values is essential for accurately assessing and managing network performance across varying generations of technology. By categorizing these metrics under the appropriate network type headers, the system (108) ensures that the analysis aligns with the specific operational characteristics and requirements of each network generation.

[0122] In an exemplary aspect, the UE (108) is communicatively connected with the EMS through the network (106). The EMS continuously monitors and tracks the network value corresponding to the network parameters. For example, the EMS may specifically track the carrier frequency of the network (104) by receiving data from the UE (108). In this case, the carrier frequency could be monitored to ensure it remains within the designated operational range, such as 2. 1 GHz, which is critical for maintaining optimal network functionality. Once the processing unit (208) collects this network value, it categorizes the data accordingto the established headers, storing relevant information in the database (210). For example, the carrier frequency value of 2.1 GHz would be stored under the "Frequency" header, while associated metrics such as latency and bandwidth would be categorized accordingly. This structured data storage approach facilitates efficient retrieval and analysis of network parameters, ultimately supporting informed decision-making and enhanced network management within the system (102).

[0123] Upon collecting the collected network value, the processing unit (208) may be configured to compare the collected network value corresponding to each network parameter with the configurable value corresponding to each network parameter fetched from the database (210) to perform the configuration audit. In an aspect, the processing unit (208) may fetch the collected network value and the configurable value from the database (210). The the processing unit (208) may be configured to compare the collected network value with the configurable value. The processing unit (208) may perform a comparison mechanism on the values. The comparison mechanism involves checking whether the collected network value matches the configurable value. For example, if the collected network value is the same as the configurable value (golden value), then the processing unit (208) may consider the value as compliant (no discrepancy). Conversely, if the collected network value is not the same as the configurable value, then the processing unit (208) may consider the value as non-compliant (discrepancy). For example, if the collected network value for latency is measured at 25 milliseconds and the configurable value (golden value) is also set to 25 milliseconds, then the processing unit (208) may consider this value as compliant (no discrepancy). Conversely, if the collected network value for bandwidth is reported as 75 Mbps while the configurable value is 100 Mbps, then the processing unit (208) may consider this value as non-compliant (discrepancy). Another example might involve a collected signal strength value of -70 dBm, compared to a configurable value of -65 dBm; in this case, the processing unit (208) would classify the signal strength as non- compliant.

[0124] In an aspect, the processing unit (208) may be configured to determine at least one network discrepancy based on the performed configuration audit. The processing unit (208) may analyze the results of the configuration audit to identify at least one network discrepancy. If the collected network value does not match its associated configurable value, the processing unit (208) flags this as a discrepancy. For example, if the collected latency is found to be 35 milliseconds while the configurable value is set to 25 milliseconds, the processing unit (208) would identify this as a discrepancy, indicating that the network latency exceeds the acceptable threshold. Similarly, if the collected bandwidth is reported as 50 Mbps against a configurable value of 100 Mbps, this difference would also be recognized as a network discrepancy.

[0125] In an aspect, the processing unit (208) may be configured to classify the at least one determined network discrepancy into at least one category. The at least one category may comprise a total discrepancy category, a high-impact category, and a low-impact category. The categorization of the discrepancies is essential for prioritizing remediation efforts and effectively managing network performance. The categories may include a total discrepancy category, a high- impact category, and a low-impact category.

[0126] The total discrepancy category encompasses all identified discrepancies, regardless of their severity or impact on network performance. For example, if the processing unit (208) identifies discrepancies in latency, bandwidth, and signal strength, all of these would fall under the total discrepancy category, providing a comprehensive overview of compliance issues.

[0127] Within the high-impact category, the processing unit (208) classifies discrepancies that significantly affect network performance or user experience. For instance, if a collected latency value exceeds the configurable threshold by a substantial margin, such as a recorded latency of 100 milliseconds against a configurable value of 25 milliseconds, this discrepancy would be classified as high- impact due to its potential to degrade service quality. Similarly, if the collectedbandwidth is only 20 Mbps while the configurable value is set at 100 Mbps, this discrepancy would also be categorized as high-impact, as it could severely hinder data transmission capabilities.

[0128] Conversely, the low-impact category includes discrepancies that have minimal effects on overall network performance or user experience. For example, if the processing unit (208) identifies a minor deviation in signal strength, such as a collected value of -70 dBm against a configurable value of -65 dBm, this could be classified as low-impact. Although the discrepancy exists, it may not substantially affect service quality or user satisfaction.

[0129] By employing this classification scheme, the processing unit (208) facilitates targeted responses to network discrepancies, ensuring that high-impact issues are prioritized for immediate attention while allowing for more gradual remediation of lower-impact discrepancies.

[0130] In an example, the network discrepancy may be calculated as the difference between the collected value and the configurable value. The collected value may be “X”, and the configurable value may be “Y”. The network discrepancy may be calculated based on “X-Y= difference”. The difference may be used to determine the network discrepancy. In an exemplary aspect, the classification of network discrepancy may be based on a predefined range. The predefined range may be stored in the memory (204). The predefined range may be categorized as “A”, “B”, “C” and “D”. Suppose the difference between the configurable value and collected network value falls between “A” and “B”, then the processing unit (208) may categorize the network discrepancy as the low-impact category. If the difference falls between “B” and “C”, then the processing unit (208) may categorize the network discrepancy as the high-impact category. Otherwise, if the difference falls between the “C” and “D”, then the processing unit (208) may categorize the network discrepancy as the total discrepancy category.

[0131] For example, the processing unit (208) may compare the configurable value, and the collected network value associated with the latencynetwork parameter of a specific node type, such as the ODSC. In this scenario, the configurable value for latency for the ODSC is set at 30 milliseconds, reflecting the performance standard required for optimal operation. The collected network value, as measured during the audit process, is recorded at 20 milliseconds.

[0132] Upon conducting the comparison between the configurable value of 30 milliseconds and the collected network value of 20 milliseconds, the processing unit (208) generates audit output based on the configuration audit. Further the processing unit (208) identifies that the values are compliant, as the collected value does not exceed the configured threshold. Therefore, the processing unit (208) would conclude that there is no discrepancy in this instance.

[0133] However, if the collected network value were instead measured at 35 milliseconds, the processing unit (208) would then determine that this constitutes a non-compliance situation, as the collected value exceeds the established configurable value. In this case, the processing unit (208) would report the identified discrepancy to the the processing unit (208), indicating that the network performance is not in alignment with the required latency standard for the ODSC node type. This reporting mechanism enables timely communication of compliance issues, facilitating necessary corrective actions to ensure that network performance meets operational standards. By systematically comparing configurable and collected values, the processing unit (208) plays a crucial role in maintaining the integrity and performance of the network infrastructure.

[0134] In an aspect, the processing unit (208) may be configured to track changes in configuration discrepancies over time to provide insights into trends and patterns. For example, the processing unit (208) may track changes in configuration discrepancies based on the stored comparison results in the database (210). The comparison results may be the type of network discrepancy determined by comparing the configurable and collected network values. The processing unit (208) may provide insights by examining the comparison results for a selected time period. The selected time period may be a day, a week, a month, or a year. Forexample, the user (110) may select the time period through the application interface . The application interface may be the web application in the UE (108). Based on the selected time period, the processing unit (208) may compute a graph, a map, or a table using the comparison results. The computed graph or table may be displayed to the user (110) through the UE (108). The processing unit (208) may be configured to analyze data over a configured period of time to identify any recurring issues or areas of improvement. For example, the configured period of time may be every 15 days. The processing unit (208) may store all the compared results in the database (210) to identify the recurring issues. For example, a network discrepancy count may be used to identify the recurring issues. The network discrepancy count may represent a number of times the same kind of discrepancy has occurred. The network discrepancy count may be stored in the memory (204). Based on the network discrepancy count the recurring issue may be identified and communicated to the user (110) at the configured period. For example, the latency-related network discrepancy count may be 10, and the bandwidth-related network discrepancy count may be 5. The processing unit (208) may report the network discrepancy count to the UE (108) through the the processing unit (208).

[0135] In an aspect, the processing unit (208) may visualize the audit report. In some aspects, the processing unit (208) may visualize the determined network discrepancies for a selected geographic location, where the geographic location is provided by the user via the UE (108). The determined network discrepancies may be visualized using various formats, including graphs, maps, and tables. For example, the processing unit (208) may generate a graphical representation of the network trend over a 15 -day period based on the comparison results. This graphical representation may then be transmitted to the display unit of the UE (108) for user review, facilitating a clear understanding of network performance in the specified location.

[0136] In an aspect, the processing unit (208) may be configured to generate a compliance report based on the comparison. The compliance report may indicate the at least one network discrepancy category. The compliance report may representthe status of network adherence to security regulations and audits. For example, the compliance report may include a node type, a network status, a network discrepancy category, a network discrepancy count, and a network operator name. The compliance report may highlight the exact cause of discrepancies in the network. The user (110) may take corrective measures to resolve the discrepancies. In an aspect, the the processing unit (208) may be configured to alert the user in real-time whenever significant discrepancies or trends are detected, ensuring timely response and action to maintain network compliance and performance.

[0137] The the processing unit (208) may be configured to transmit the at least one determined network discrepancy and the compliance report towards the UE (108). The the processing unit (208) may transmit the at least one determined network discrepancy using a response to the UE (108). The response may be a data transmit message. The response may be an HTTP response. In the aspect, the UE (108) connected with the web application may receive the response from the the processing unit (208) using the network (106). For example, the response may include a node type, a network type, a network discrepancy category, and a network discrepancy count. The UE (108) may display the transmitted message using the user interface. The user (110) may take a corrective action based on the received the network discrepancy category. For example, corrective action may provide a solution to resolve the issue that disrupts normal network operations. The corrective action may be identifying misconfiguration and adjusting the configuration settings to align with the network.

[0138] The database (210) may be configured to store data that may be either stored or generated as a result of functionalities implemented by any of the components of the system (108). The database (210) may be configured to store pre-processed data.

[0139] In an embodiment, the system (102) may be embedded or associated with an Element Management System (EMS). In an aspect, the EMS plays a critical role in the management and oversight of various network functions, including theSession Management Function (SMF) and the Access Management Function (AMF). By establishing connections with these network functions, the EMS continuously collects real-time values associated with various network parameters, such as session states, user equipment (UE) connectivity statuses, and resource allocations. The EMS processes the collected data to provide insights into network health and performance. In an example, the EMS may transmit the collected data to the system (102) for further processing. The EMS monitors key performance indicators (KPIs), such as latency, throughput, and connection success rates, allowing network operators to proactively identify trends and potential issues.

[0140] Furthermore, in communication with the system (102), the EMS supports configuration management by allowing administrators to define and implement policy changes across the network functions. By utilizing real-time data, the EMS can facilitate automated adjustments to configurations, ensuring alignment with operational policies and industry best practices. This automation reduces the risk of human error and enhances the agility of network management, making it easier to adapt to evolving network demands and improve overall operational efficiency.

[0141] In an embodiment, the database (210) is configured for serving as a centralized repository for storing and retrieving various operational data. The database (210) is designed to interact seamlessly with other components of the system (102) to support the system's functionality effectively. The database (210) may store data that may be either stored or generated as a result of functionalities implemented by any of the components of the one or more processor(s) (202) or the processing engines (208). In an embodiment, the database (210) may be separate from the system (102).

[0142] In an embodiment, the user interface module (212) may be responsible for receiving the plurality of parameters along with first values to be considered as parameters for performing auditing. The user interface module (212) may present an intuitive interface where network administrators or other authorizedpersonnel may input these parameters and their corresponding expected values. The parameters, also referred to as golden parameters, are a subset of core network configuration parameters that have been specifically selected for auditing from among a larger set of parameters. These parameters are designated as 'elevated' or 'golden' due to their particular importance in the audit process. The selection of these parameters is typically based on their critical role in maintaining network performance, ensuring compliance, or their significance in diagnostic and maintenance activities. In an alternative embodiment, the network administrator is an automated system which either learns OR identifies these parameters and their first values with help of network conditions or user defined conditions and populate / modify the values to / in “Template” automatically and upload the same for audit. Examples of parameters may include:Quality of Service (QoS) settings: For instance, an administrator might set a QoS parameter for voice traffic with an expected value of "High Priority" to ensure clear voice calls.Network latency thresholds: An elevated parameter might be "Core Network Latency" with an expected value of "<50ms" to maintain responsive network performance.Packet loss rate limits: A parameter such as "Maximum Packet Loss Rate" might be set with an expected value of "<0.1%" to ensure reliable data transmission.Frequency band allocations: In a cellular network, a parameter like "5G Frequency Band" might be set to an expected value of "3.5 GHz" to ensure proper 5G coverage.Transmit power levels: A parameter for "Base Station Transmit Power" might have an expected value of "20W" to optimize coverage while complying with regulatory limits.Antenna configurations: An elevated parameter could be "Antenna Tilt Angle" with an expected value of "5 degrees" to optimize cell coverage.

[0143] In an embodiment, the user interface module (212) may populate these parameters and their corresponding first values into an audit template. The audit template refers to a structured document or data format that serves as a baseline for the auditing process. The audit template contains the list of parameters and their expected values (first values) against which the actual values of the parameters will be compared.

[0144] In an aspect of this embodiment, the user interface provided by the user interface module (212) is designed to offer functionalities that enable the user (110) to manage the input data effectively. Specifically, the interface may provide options for the user (110) to select, upload, delete, or update the at least one input. These functionalities facilitate the customization and flexibility necessary for users to tailor audit templates to meet specific needs, thereby enhancing the overall usability and efficiency of the configuration auditing process. In an embodiment, the user interface of the UE (108) is a touch screen or apointer device. For example, the user interface is a Web Browser (e.g., INTERNET EXPLORER, manufactured by Microsoft Corp, of Redmond, Wash, or SAFARI, manufactured by Apple Computer of Cupertino, Calif.).

[0145] In an aspect, the user (110) may send one or more requests to the network (104) using the mobile application installed on the UE (108). The user may provide the at least one input to perform the configuration audit of the network parameters associated with the network, through an application interface of the mobile application installed in the UE (108). The mobile application may be configured to communicate with the network (104). In some examples, the mobile application may be a software or a mobile application from an application distribution platform. Examples of application distribution platforms include the App Store for iOS provided by Apple, Inc., Play Store for Android OS provided by Google Inc., and such application distribution platforms. In an aspect, the UE (108) may send the at least one request to the system (102) through the application interface. The UE (108) may communicate with the application by establishing a connection by sending one or more connection requests. For example, the one ormore connection requests may be a hypertext transfer protocol (HTTP) request, a WebSocket request, and an application programming interface (API) request. For example, the HTTP request may include a POST request. The POST request may be used to send data, a form, and a fde. For example, the POST request may be used to send at least one input. The application may receive the at least one input from the user (110) using the UE (108). The application may further transmit the at least one input to the user interface module (212) using the network (104). For example, the application may include a web application, a mobile application, or a cloud application.

[0146] In an aspect, the user interface module (212) is configured to prompt the user (110) to select the at least one audit template from a plurality of audit templates. In an aspect, the plurality of audit templates may be stored in the database (210). Each audit template may include a set of one or more network parameters and the one or more headers. Each audit template is designed to encompass the one or more network parameters, along with one or more headers that categorize and detail these one or more network parameters. Each of the network parameters includes a configurable value (predefined value). The one or more network parameters may include a bandwidth, a throughput, a carrier frequency, an allowable data transmission, a latency, a packet loss, a jitter, a quality of service (QoS), a signal strength, a bit error rate (BER), and a propagation delay. The bandwidth is the maximum data transfer rate across a network, while throughput represents the actual rate of successful data transmission, often lower due to factors like congestion. The carrier frequency pertains to the frequency of the electromagnetic signal used for transmission, affecting range and penetration. The allowable data transmission defines the maximum data volume that can be sent without issues. The latency measures the time taken for data to travel from source to destination, with lower values preferred for real-time applications. The packet loss indicates the failure of data packets to reach their destination, impacting performance. The jitter measures variability in packet arrival times, affecting data consistency. The QoS ensures prioritized traffic management for criticalapplications. The signal strength assesses the received power level, influencing connection reliability. The BER measures the ratio of erroneous bits to total transmitted bits, indicating communication quality. The propagation delay accounts for the time taken for a signal to travel from sender to receiver, contributing to overall latency.

[0147] The one or more headers may be selected from a group of a network node, a parameter type, a parameter category, a type of network discrepancy, a network type, an operating system version and a cell identifier (ID). In an exemplary aspect, the parameter node may include an outdoor small cell (ODSC), an indoor small cell (ID SC), a dual -mode small cell, and a cloud RAN(C-RAN) small cell. These small cells are low-power cellular radio access nodes that improve coverage and capacity in the network (106). The ODSC may be used as a small cell for an outdoor environment such as a street, a park, a campus, or an open space. The IDSC may be used in an indoor environment such as a residence, an apartment, or an enclosed space.

[0148] In an exemplary aspect, the parameter type may include a tabular and a scalar. The tabular type may be data that are multi-dimensional data useful for analysis and reporting. For example, the tabular type may be a network performance metric. The network performance metric may include a latency, a bandwidth, and a packet loss. Here, the network performance metric is multidimensional data. Further, the scalar type may be individual data points used for real-time monitoring and quick assessments. The scalar type may be a throughput. The throughput may be a single value representing the data transfer rate at a given moment.

[0149] For example, an audit template designed to audit bandwidth may include the headers such as network node, parameter type, and operating system version. This template would allow the user (110) to evaluate whether the current bandwidth aligns with the predefined acceptable levels set within the template. Each header may be tailored to present a set of associated network parametersrelevant to the audit process . For example, an audit template specifically for latency may have headers such as network type and parameter node, allowing the user to focus on evaluating latency within specific network segments or configurations. In an example, the user (110) may choose the audit template labeled "Latency Assessment" when needing to perform the configuration audit related to latency metrics. This particular template may include parameters like maximum allowable latency, current latency, and threshold levels, along with headers that categorize the parameters based on network type (e.g., 4G or 5G or 6G), thus enabling precise assessments tailored to the user's operational requirements. By selecting the appropriate audit template, the user (110) effectively streamlines the auditing process, ensuring that the evaluation is comprehensive and relevant to the network parameters being scrutinized.

[0150] The user (110) may select the audit template based on the network parameter for which the configuration audit needs to be performed. For example, the plurality of templates may include “A”, “B” and “C” The template “A” relates to the latency network parameter. The template “B” relates to the bandwidth network parameter. The template “C” relates to the frequency network parameter. The template “A” may include the parameter node, the parameter type, the network type, and the operating system version. For example, to configure the latency of the network, the configuration audit is determined based on the network type and the parameter node. The template “A” has the headers network type and the parameter node. The user (110) selects the template “A” to configure the latency network parameter.

[0151] Further, the audit module (214) may be tasked with obtaining second values of the plurality of parameters from the core nodes (114). The core nodes (114) are the central, critical components of a network responsible for managing network resources, handling user authentication, and facilitating data traffic. The core nodes (114) may include Mobility Management Entities (MMEs) and Serving Gateways (S-GWs) in 4G LTE networks, and their 5G counterparts such as Access and Mobility Management Function (AMF), Session Management Function (SMF),and User Plane Function (UPF). Further, the second values are the actual, current values of the parameters as configured on these core nodes (114) at the time of the audit, representing the real-time state of the network's core components. These values are crucial for identifying any discrepancies from the expected configurations, enabling the system to effectively monitor and maintain the integrity of the core network infrastructure across different generations of cellular technology. The audit module (214) may establish secure connections with the core nodes (114) using protocols such as:Simple Network Management Protocol (SNMP): A standard protocol for collecting and organizing information about managed devices on IP networks.Secure Shell (SSH): A cryptographic network protocol for operating network services securely over an unsecured network.Proprietary network management protocols: Custom protocols developed by network equipment manufacturers for managing their specific devices.

[0152] In an embodiment, the audit module (214) might use SNMP to query a router for its current QoS settings, or SSH into a switch to retrieve its current packet loss statistics. The audit module (214) may authenticate itself with each core node (114) to ensure secure and authorized access. Once connected, the audit module (214) may execute commands or queries on each core node (114) to retrieve the current values of the plurality of parameters. For instance, the audit module (214) might send an SNMP GET request to retrieve the current transmit power level of a base station, or execute a CLI command over SSH to check the current frequency band allocation of a 5G node.

[0153] In an embodiment, the audit execution module (216) may be responsible for performing the actual audit by comparing the second values of the plurality of parameters, as obtained by the audit module (214), with the first values populated in the audit template. This comparison may involve complex algorithms to account for various data types, units of measurement, and acceptable ranges foreach parameter. For example, a numeric parameter like "Core Network Latency", the comparison might check if the second value is less than or equal to the first value. For a categorical parameter like QoS settings, the comparison might check for an exact match between the first and second values. For some parameters, the comparison might allow for a certain tolerance. For instance, if the expected transmit power (first value) is 20W, the audit might consider second values between 19.5W and 20.5W as acceptable.

[0154] The audit execution module (216) may also be capable of handling dynamic audit templates, allowing for updates to the audit criteria as network requirements evolve. The dynamic audit template refers to the ability of the audit template to be modified in real-time or near-real-time to reflect changing network conditions, new compliance requirements, or evolving best practices.

[0155] In an embodiment, when updates to the audit template are received from an administrator via the user interface module (212), the audit execution module (216) may modify the audit template accordingly and perform subsequent audits using the updated criteria. For example, if a new regulatory requirement mandates a lower maximum latency for packet processing in core network elements, an administrator could update this parameter in the audit template. This core network parameter 'Maximum Packet Processing Latency' is crucial for ensuring efficient data flow through the network's central components. It directly affects the performance of key core nodes such as the Serving Gateway (S-GW) in 4G or the User Plane Function (UPF) in 5G networks. Once updated, the audit execution module (216) would use this new, lower latency threshold value in all subsequent audits, ensuring that all relevant core network elements are checked against this updated performance standard.

[0156] In an embodiment, the analysis module (218) may analyze the results of the comparison performed by the audit execution module (216) to identify discrepancies without manual intervention. Discrepancies refer to instances where the actual network configuration (second values) does not match the expectedconfiguration (first values) as defined in the audit template. The analysis module (218) may employ advanced statistical techniques and machine learning algorithms to detect patterns, anomalies, and trends in the audit data. The analysis module (218) might use a machine learning algorithm to classify discrepancies based on their frequency. For instance, the analysis module (218) might categorize a persistent mismatch in QoS settings as a "critical" discrepancy, while a one-time slight deviation in transmit power might be classified as "minor".

[0157] The analysis module (218) may also be capable of analyzing historical audit data to identify long-term parameter discrepancy patterns. For example, by analyzing six months of historical data, the analysis module (218) might detect that a particular core node (114), such as a Serving Gateway (S-GW) in a 4G network or a User Plane Function (UPF) in a 5G network, consistently shows discrepancies in its packet processing latency during peak traffic hours, suggesting a potential capacity issue. Based on this analysis, the analysis module (218) may generate recommendations for parameter adjustments. Recommendations for parameter adjustments are suggested changes to core network configurations aimed at optimizing performance, enhancing reliability, or ensuring compliance with service level agreements. For instance, if the analysis reveals that a group of core routers consistently operate near their maximum session capacity during peak hours, the analysis module (218) might recommend increasing the 'Maximum Concurrent Sessions' parameter for these nodes or suggest implementing more advanced load balancing strategies. These recommendations provide valuable insights for network optimization, allowing administrators to proactively address potential bottlenecks or performance issues in the core network infrastructure before they impact service quality.

[0158] In an embodiment, the discrepancy identification module (220) may work closely with the analysis module (218) to identify the one or more parameters as having discrepancy when it is determined that the second values of the one or more parameters do not match with the corresponding first values of the one or more parameters. The discrepancy identification module (220) may implementsophisticated logic to determine the severity of discrepancies, potentially categorizing them based on their impact on network performance or compliance. Example of discrepancy severity categorization may include:Critical: Discrepancies that severely impact network performance or violate regulatory requirements. For instance, a core router operating on an unauthorized frequency band.Major: Significant discrepancies that affect network quality but don't cause outages. For example, QoS settings that don't meet service level agreements.Minor: Small discrepancies that have minimal impact on network performance. For instance, a slight deviation in antenna tilt angle.

[0159] The discrepancy identification module (220) may also maintain a detailed log of all identified discrepancies, including timestamps and contextual information, to facilitate troubleshooting and historical analysis. Discrepancy log corresponds to a comprehensive record of all identified discrepancies, including details such as parameter name, expected value (first value), actual value (second value), timestamp of discovery, affected core node(s), severity category, and related network conditions at the time of discovery.

[0160] In an embodiment, the data management module (222) may be responsible for storing the second values of the one or more parameters of the plurality of parameters. The data management module (222) may interact with a database (210) and an elastic search system to efficiently store and retrieve both structured and unstructured audit data. The database (210) may be optimized for storing and querying large volumes of audit data. It may use a relational database management system (RDBMS) like PostgreSQL or MySQL. The elastic search system may be a RESTful search and analytics engine capable of addressing a growing number of use cases. The elastic search system may be used for storing and rapidly searching unstructured and semi-structured audit data.

[0161] In an embodiment, the data management module (222) may implement data retention policies, ensuring that historical audit data is maintained for a specified period to support long-term trend analysis and compliance reporting. In summary, the data management module (222) receives new audit data from the audit execution module (216) and stores the structured data (e.g., parameter values, discrepancy records) in the database (210). The unstructured data (e.g., raw logs, contextual information) is indexed and stored in the elastic search system. The module applies compression to older data to reduce storage usage. Based on the data retention policy, it moves aging data to archive storage and eventually deletes data that has exceeded its retention period. When historical data is needed for analysis, the data management module (222) retrieves it from the appropriate storage location (database, elastic search, or archives) and provides it to the requesting module.

[0162] In an embodiment, the reporting module (224) may generate comprehensive reports indicating the one or more parameters of the plurality of parameters identified as having discrepancy. These reports may include detailed visualizations, such as graphs and charts, to illustrate the nature and extent of discrepancies across the network. The reporting module (224) may offer customizable report templates to cater to different stakeholder needs, from high- level executive summaries to detailed technical reports for network engineers. The module may also be capable of scheduling automated report generation and distribution, ensuring that relevant parties are kept informed of network audit status on a regular basis. The reporting module (224) could be configured to generate and email a daily summary report to the network operations team, a weekly detailed report to network engineers, and a monthly executive summary to management.

[0163] In an embodiment, the network module (226) may be responsible for establishing and maintaining secure network connections with the core nodes (114). The secure network connections correspond to encrypted and authenticated communication channels between the auditing system (102) and the core nodes (114), ensuring the confidentiality and integrity of audit data. The network module(226) may implement robust error handling and retry mechanisms to ensure reliable communication even in the face of network instability. The error handling scenarios may include connection timeout, authentication failure, and data corruption.

[0164] The network module (226) may also handle network protocol negotiations, adapting to the specific requirements of each core node (114) to ensure seamless interaction across diverse network elements.

[0165] In an embodiment, the scheduling module (228) may be tasked with scheduling recurring audits at configurable time intervals. The scheduling module (228) may offer flexible scheduling options, allowing administrators to set up daily, weekly, or custom audit schedules based on operational requirements. The scheduling module (228) may also be capable of triggering ad-hoc audits in response to detected modifications in network configuration or topology. When such changes are detected, the scheduling module (228) may initiate an immediate audit to ensure that the network remains compliant and optimally configured despite the alterations. An example of triggers for ad-hoc audits may include addition of a new core node (114) to the network, major software update applied to multiple network elements, and sudden spike in network traffic or error rates.

[0166] In an embodiment, the corrective action module (230) may be responsible for initiating corrective actions for parameters identified as having discrepancies. These corrective actions correspond to automated or manual interventions taken to resolve identified discrepancies and bring the network configuration back into alignment with expected values. The module's actions may include sending configuration update commands to affected core nodes (114) to align the second values with the first values, such as adjusting timer settings in a Mobility Management Entity (MME) or Access and Mobility Management Function (AMF). It may automatically adjust QoS settings on core network elements like Serving Gateways (S-GW) or User Plane Functions (UPF) found to have incorrect values. For discrepancies exceeding predefined thresholds, it can generate alerts for manual review by network administrators. In cases of criticalsecurity parameter misconfigurations, such as incorrect firewall rules in a Packet Data Network Gateway (P-GW), the module can send urgent email notifications. Additionally, it may initiate controlled restarts of specific network services or components if certain critical discrepancies cannot be resolved through configuration changes alone. Through these varied actions, the corrective action module ensures prompt and appropriate addressing of discrepancies in core network parameters, thereby maintaining the integrity and performance of the network infrastructure.

[0167] The corrective action module (230) may implement a rules engine that allows administrators to define custom actions based on specific discrepancy types or severity levels. The rules engine may allow the definition and execution of conditional statements (rules) to determine appropriate corrective actions based on the nature and context of identified discrepancies. Example rules:IF discrepancy ype = "QoS_setting" AND severity = "critical" THEN send_configuration_update AND alert_network_adminIF discrepancy_type = "transmit_power" AND deviation < 5% THEN log_discrepancyIF discrepancy_count > 10 IN last_24_hours THEN trigger_comprehensive_audit

[0168] These rules allow for a flexible and automated approach to handling various types of discrepancies, ensuring that the most appropriate action is taken in each case.

[0169] In an embodiment, the user interface module (212) of the system (102) may enable a user interface portal that serves as a centralized interface for user interaction. The user interface portal may provide a unified interface for users to interact with various components of the system (102). The user interface portal may present an intuitive interface for inputting the plurality of parameters and first values, displaying audit results and reports, and providing options for schedulingaudits and viewing historical audit data. The user interface portal may implement role-based access control, ensuring that users only have access to the information and functions appropriate to their responsibilities.

[0170] In an embodiment, a load balancer may be incorporated into the system (102) to distribute audit requests across a plurality of servers (112). Load balancer is a device or software component that distributes incoming network traffic across multiple servers to ensure no single server becomes overwhelmed. The load balancer may receive audit requests from the user interface portal, assess the current load on each of the plurality of servers (112), and route each audit request to the web server (112) with the lowest current load.

[0171] In an embodiment, an application gateway may be employed to manage access to the audit module (214). The application gateway acts as an intermediary between clients and application servers, providing an additional layer of security and control. The application gateway may authenticate and authorize incoming requests from the servers (112), route validated requests to the appropriate instance of the audit module (214), and handle request and response translations between the servers (112) and the audit module (214). Example workflow:- A request arrives at the application gateway from the web server (112).- The gateway authenticates the request using JWT (JSON (JavaScript Object Notation) Web Tokens).- It checks the user's permissions against the requested operation.- If authorized, the gateway translates the request into the format expected by the audit module (214).- The gateway routes the request to the appropriate microservice instance based on the requested operation.- When the microservice responds, the gateway translates the response back into the format expected by the web server (112).

[0172] The application gateway may implement advanced security measures, such as rate limiting and threat detection, to protect the core audit functionality from potential abuse or attacks.

[0173] In an embodiment, the system (102) may utilize a database management system to manage the database (210) and the elastic search components. The database management system (DBMS) is a software system that enables users to define, create, maintain, and control access to the database (210) and elastic search. The DBMS may handle data insertion, updating, and retrieval operations, manage data consistency between the database (210) and the elastic search, implement data backup and recovery procedures, and optimize query performance for both structured and unstructured data searches. The database management system may employ advanced indexing and partitioning strategies to ensure efficient data access even as the volume of audit data grows over time.

[0174] In an embodiment, the system (102) incorporates a distributed event streaming platform for real-time processing of audit events. This platform is designed to handle high-volume, real-time data streams including network parameter values and operational metrics from both network nodes (114) and ongoing audit processes, processing and analyzing this data in a distributed manner. Its primary functions include detecting anomalies or threshold violations in the realtime data , triggering immediate alerts or actions based on predefined conditions, and feeding processed data back to the audit module (214). This real-time data processing and integration capability enhances the audit process by allowing it to dynamically adapt to current network conditions, providing immediate insights and enabling rapid responses to potential issues as they arise during ongoing audits.

[0175] In an example, the distributed event streaming platform may receive a stream of real-time performance data from core nodes (114), processes this data using predefined rules, such as "Flag any latency spike above 100ms", when a rule is triggered, the platform may generate an alert and sends it to the appropriate system component (e.g., the corrective action module (230)), finally the processeddata may then be fed into the audit module (214) for inclusion in the next scheduled audit.

[0176] The distributed event streaming platform may implement complex event processing algorithms to identify critical patterns or sequences of events that may indicate emerging network issues.

[0177] In yet another embodiment, the audit execution module (216) is configured to perform two types of audits namely live audit jobs and one-time audits. Live audit jobs are continuous, real-time monitoring processes that constantly check network parameters against expected values. For example, the module might continuously monitor the packet loss rate of core routers, triggering an immediate alert to the network operations center if the rate exceeds 1% for more than 5 minutes. On the other hand, one-time audits are comprehensive checks of all specified parameters, executed at a specific point in time. These can be initiated on- demand by network administrators or scheduled to run at regular intervals (e.g., daily or weekly). One-time audits provide a thorough snapshot of the network's state, allowing for detailed analysis and reporting. By combining these two audit types, the system ensures both real-time responsiveness to immediate issues and periodic, in-depth examinations of the entire network configuration.

[0178] This real-time monitoring capability allows for rapid detection and response to network issues, potentially preventing service degradation before it impacts end-users. The audit template utilized by the system (102) may be highly dynamic in nature, allowing for real-time updates and modifications.

[0179] In summary, the distributed event streaming platform detects an anomaly in network traffic patterns. The distributed event streaming platform may trigger the scheduling module (228) to initiate an ad-hoc audit. The audit module (214) performs a targeted audit of the affected network segment. The analysis module (218) identifies a misconfiguration in a core router. The corrective action module (230) applies a fix to the router configuration. The reporting module (224) generates a detailed report of the incident and resolution. The user interface portaldisplays a real-time update of the event and its resolution to relevant stakeholders. This integrated approach ensures that network issues are detected, diagnosed, and resolved quickly and efficiently, with minimal manual intervention. Furthermore, this approach not only enhances network reliability and performance but also significantly reduces the manual effort required for network management and compliance reporting.

[0180] Referring to FIG. 3, the system architecture (300) illustrates a comprehensive network auditing system designed to perform audits on parameters of core nodes in a network. The architecture is divided into two main zones for enhanced security namely a demilitarized zone (DMZ) and a non-demilitarized zone (non-DMZ). A demilitarized zone (DMZ) is a designated area or network segment where certain activities or resources are isolated for security reasons, allowing controlled access to external networks while protecting internal resources. A non-demilitarized zone (non-DMZ) refers to an internal network, or LAN, where sensitive data and applications are located, and access is tightly controlled. The system (102) comprises several key components working in coordination to provide a robust auditing solution.

[0181] At the forefront of the system (102) is the User interface portal (302), serving as the primary user interface. It allows users to input parameters and first values for auditing, displays audit results and reports, and provides options for scheduling audits and viewing historical audit data. Working in tandem with the user interface portal is the Load Balancer (304), which efficiently distributes incoming audit requests across multiple Servers (112). The Load Balancer (304) assesses the current load on each server (112) and routes requests accordingly, ensuring optimal system performance. It lies in DMZ and there is security firewall 1 between the user interface portal (302) and the load balancer (304).

[0182] The Servers (112) handle incoming requests from the User interface portal, processing and forwarding them to the Application Gateway (308). There is a security firewall 2 between the servers (112) and the Application Gateway (308).This gateway acts as a crucial security barrier between the user interface portal (302) and core auditing services, authenticating and authorizing incoming requests before routing validated requests to the appropriate Audit Microservices (310).

[0183] The Audit Microservices (310) form the core of the system's functionality. They process audit requests and perform the actual auditing tasks, extracting data from the database or elastic search as needed. These microservices are capable of performing both live audit jobs (318) and one-time audits (320), storing or updating data in the database or elastic search as required. Working alongside the Audit Microservices is the Reports Spark Job (312), which generates comprehensive audit reports.

[0184] Data storage and management are handled by a combination of a Database (210) for structured audit data, and an Elastic Search (316) for unstructured and semi-structured audit data. The database management system (322) oversees data operations across both the database and elastic search, ensuring data consistency and optimizing query performance.

[0185] The system (102) also interfaces with external network management systems through the external system (324), which includes a Network Management System - Distributed Event Streaming Platform (326) for real-time data processing. This allows the system to incorporate live network data into its auditing processes.

[0186] The workflow of the system (102) begins when an end user submits an audit request via the user interface portal, specifying parameters to be audited. This request is then routed through the load balancer (304) to an available web server (112), which processes it and forwards it to the application gateway (308). After authentication, the request is directed to the appropriate audit microservice (310). The audit microservice (310) then obtains second values of parameters from core nodes, compares these with the first values from the audit template, analyzes the results to identify discrepancies, identifies parameters as having discrepancy if second values don't match first values, and stores the second values in the database.

[0187] Incorporated within the system (102) is software within a coverage platform (CP) that automates the audit process by setting parameters or comparing them with extracted site parameters and identifying deviations. The system (102) also offers dynamic parameter management, allowing users to set, remove, or change values of parameters on the fly. This flexibility extends to software releases, where the set of parameters may change, and administrators can define, set, or adjust the list of parameters as needed.

[0188] This sophisticated architecture enables a flexible, scalable, and secure system for performing comprehensive network audits on parameters. It is adaptable to changing network configurations and audit requirements, allowing for continuous monitoring of critical network parameters, rapid detection of discrepancies, and maintenance of a detailed historical record of network performance and configuration.

[0189] In the dynamic landscape of network management, the concept of parameters plays a crucial role in maintaining optimal network performance. These parameters are critical settings within the network that require special attention and frequent auditing. The system's flexibility in handling these parameters is exemplified by its ability to adapt to changes across software releases.

[0190] Consider a scenario where a specific network parameter, let's say "packet forwarding rate," is identified as an elevated parameter in an earlier software release with a value of 1000 packets per second (pps). This value, denoted as X, is set as the benchmark for optimal performance. However, as network technologies evolve and new software is released, this optimal value might change. In a new software release, the same "packet forwarding rate" parameter might be set to 1500 pps, denoted as Y, to accommodate increased network traffic demands.

[0191] The system (102) allows for these changes to be implemented seamlessly at the central level. The admin user, typically a network administrator with high-level access, can perform real-time audits and update these parameters asneeded. This centralized control ensures consistency across the network and allows for rapid adaptation to new performance standards.

[0192] The parameters audit process focuses specifically on parameters that reside within the core network. In atypical network architecture, data traffic flows from the radio access network (RAN) to the core network. The core network, being the central part of the telecommunication system, has its own set of parameters crucial for optimal functioning. These parameters govern various aspects of network performance, such as routing efficiency, quality of service, and resource allocation.

[0193] To initiate the audit process, the admin user sets up a template for the audit of parameters of a plurality of core nodes in the telecommunication network. This template serves as a blueprint for the audit, defining which parameters are to be considered as elevated and what their expected values should be. The admin user meticulously identifies the parameters for the nodes in the core networks and sets the expected values for these parameters.

[0194] The process of creating and validating the audit template is thorough. The admin user first downloads a template from the system (102). This template is then populated with the relevant parameters and their expected values. Once filled, the admin uploads the completed audit template back into the system (102). At this point, the system (102) performs a series of basic validations on the template. These checks include verifying whether the specified parameters exist in the system's parameter list, ensuring the parameters are applicable to the particular type of node being audited, and confirming that the set values fall within acceptable ranges for each parameter.

[0195] During the actual audit process, the system (102) reads the current parameter values directly from the nodes in the core network. It then extracts the list of parameters from the audit template and compares these expected values with the actual values read from the network. This comparison is at the heart of the auditprocess. If there's a mismatch between the expected value in the template and the actual value read from the network, the system flags this as a discrepancy.

[0196] For instance, if the audit template specifies that the "packet forwarding rate" should be 1500 pps (Y), but the actual read value from a core network node is still 1000 pps (X), this would be flagged as a discrepancy. This discrepancy could indicate that a necessary configuration update was missed or that there's an issue preventing the node from operating at the new expected rate.

[0197] It's important to note that not all network parameters are treated as elevated. The admin has the flexibility to designate which parameters are elevated and which are not. During the audit process, parameters that are not identified as elevated are simply skipped. This focused approach allows for efficient auditing of the most critical network parameters without getting bogged down in less crucial details.

[0198] The system (102) supports a dynamic, editable list of parameters, allowing for flexible and timely audits. These audits can be performed periodically, ensuring that the network consistently operates within defined parameters. The audit template, which forms the basis of these audits, can be regularly updated by the admin or end user to reflect the latest network requirements or performance standards.

[0199] When performing an audit, the system (102) uses this dynamic audit template to fetch current parameter values from multiple core nodes across the network. These fetched values are then compared against the expected values in the template. The resulting audit data can be presented in various ways - at the individual node level, aggregated by geographic region, or organized by the audited parameters themselves. This flexibility in reporting allows network administrators to gain insights at various levels of granularity.

[0200] A key aspect of this system is its ability to handle dynamic parameters in core network elements. These parameters, along with their expectedvalues, can change with each software release cycle. This dynamism allows the network to evolve and improve over time, with each software update potentially bringing new optimal settings or entirely new parameters to monitor.

[0201] By maintaining this flexible, dynamic approach to network auditing, the system ensures that telecommunications networks can be continuously optimized, adapting quickly to new technologies, changing network conditions, and evolving performance standards. This approach results in a set of compliant and non-compliant parameters after each audit, providing network administrators with clear insights into the current state of their network and areas that may require attention or optimization.

[0202] FIG. 4 with reference to FIG. 2 of system (102) and FIG. 5 for method (500) illustrates an example of a flow diagram (400) for the audit of parameters of a plurality of core nodes in telecommunication networks, in accordance with an embodiment of the present disclosure.

[0203] At step 402, the admin user initiates the audit process by downloading the audit template from the system. This template is a structured document, typically in a spreadsheet format (e.g., CSV or Excel), that contains predefined columns for parameter names, expected values, and potentially additional metadata such as parameter descriptions or applicable network types. The system may provide multiple template versions tailored to different network technologies (e.g., 4G, 5G) or node types (e.g., core routers, core networks).

[0204] At step 404, the admin user performs a thorough validation of the downloaded template. This involves checking the template's structure, ensuring all required columns are present and correctly labeled. The admin then populates the template with expected operational values (first values) for the parameters. Each elevated parameter represents a parameter which is associated with each of the core nodes globally. These values are determined based on network design specifications, vendor recommendations, and operational experience. For example,the admin might set the expected value for "maximum packet loss rate" to 0. 1% or "core router CPU utilization threshold" to 80%.

[0205] At step 406, the admin uploads the completed template to the system.This upload process may involve selecting the appropriate file from the admin's local system and using a secure file transfer protocol to transmit the template to the audit system's server. The system may display a progress bar during the upload process to indicate the status of the file transfer.

[0206] At step 408, the system (102) performs an automated check to verify if the template upload was successful. This check involves multiple aspects: ensuring the file was received in its entirety without corruption, validating that the file format matches the expected template structure, and verifying that all mandatory fields are populated. The system (102) may also perform preliminary data validation, such as checking if numeric values fall within expected ranges.

[0207] At step 410, if the upload is successful, the system (102) confirms the success by displaying a notification to the admin. The system (102) then processes the template data, storing the parameters and their expected values in the system's database. The system (102) may also create a log entry documenting the successful template update, including a timestamp and the admin's identifier for audit trail purposes.

[0208] At step 412, if the upload fails, the system (102) presents detailed error messages or warnings to the admin. These messages precisely identify the problematic areas of the template, such as incorrectly formatted cells, out-of-range values, or missing critical parameters. The admin reviews these issues, makes necessary corrections in the template, and re-initiates the upload process.

[0209] At step 414, during a live audit, the system (102) establishes a connection to the distributed event streaming platform. This platform continuously ingests data from various core nodes in real-time. The system (102) configuresfilters on this data stream to focus on the specific parameters defined as elevated in the audit template.

[0210] At step 416, the system (102) extracts relevant information from the processed data stream. This includes identifying the specific network sites or nodes, listing all available parameters, and recording their current values (second values). The extraction process may involve parsing complex data structures, resolving any naming inconsistencies between different core nodes, and handling any missing or corrupted data points.

[0211] At step 418, the system (102) cross-references the list of parameters extracted from the network against the list of parameters defined in the audit template. This process may involve fuzzy matching to account for slight variations in parameter names between the template and actual network data.

[0212] At step 420, the system (102) performs a detailed comparison between the current (second) values of parameters and their expected (first) values from the audit template. This comparison may involve more than simple equality checks; it might include checking if values fall within acceptable ranges, analyzing trends over time, or applying more complex evaluation rules defined in the template.

[0213] At step 422, parameters not designated as elevated are filtered out of the main audit process. However, the system (102) may still log these non-elevated parameters and their values for completeness and potential future analysis.

[0214] At step 424, the system (102) conducts a final evaluation of each elevated parameter, determining if its current value complies with the expected value or falls within an acceptable range defined in the template.

[0215] At step 426, based on the compliance evaluation, the system records detailed information about each discrepancy, including the parameter name,expected and actual values, the magnitude of the discrepancy, timestamp, and any contextual information that might be relevant fortroubleshooting.

[0216] At step 428, all audit results, including parameter values, compliance statuses, and discrepancy details, are stored in the system's database. This data is structured to facilitate easy retrieval for reporting, trend analysis, and integration with other network management tools.

[0217] At step 430, for the daily one-time audit, the system initializes by establishing a connection to the distributed event streaming platform, similar to the live audit process. However, it configures the data retrieval to capture a comprehensive snapshot of all relevant network parameters at a specific point in time, typically during a low-traffic period.

[0218] At step 432, the system (102) loads the complete set of configuration data from the core nodes. This data dump provides a comprehensive view of the entire network's configuration at the time of the audit. The system (102) then proceeds to perform steps 416 through 428, applying the same detailed analysis and reporting processes used in the live audit, but covering the entire network configuration in a single, thorough examination.

[0219] This process ensures a comprehensive and detailed audit of the telecommunication network, providing network administrators with insights into the network's compliance with defined standards and operational expectations.

[0220] FIG. 5 with reference to FIG. 2 of system (102) illustrates an exemplary flow diagram of a method (500) for performing an audit for a plurality of parameters of core nodes in a network, in accordance with embodiments of the present disclosure.

[0221] At step 502, the method (500) includes receiving, by a user interface module (212), the plurality of parameters having first values to be considered as parameters for performing auditing. The plurality of parameters along withcorresponding first values are populated in an audit template. The first values correspond to values expected during operations in the network, each elevated parameter represents a parameter which is associated with each of the core nodes globally. The user interface module (212) provides an intuitive interface for network administrators or authorized personnel to input the parameters and their expected values. This step is crucial for establishing the baseline against which the actual network configuration will be compared. The audit template serves as a structured framework for organizing the parameters and their expected values, ensuring consistency across audits. The parameters typically comprise a subset of core network configuration parameters designated as critical for network performance and compliance. These may include quality of service (QoS) settings, which define traffic prioritization and resource allocation; network latency thresholds, which set acceptable limits for data transmission delays; packet loss rate limits, which specify the maximum acceptable rate of data packet loss; frequency band allocations, which determine the distribution of available spectrum; transmit power levels, which control the strength of signal transmission; and antenna configurations, which affect signal coverage and interference patterns. By focusing on these parameters, the audit process can efficiently determine discrepancies that have the most significant impact on network performance and regulatory compliance.

[0222] At step 504, the method (500) includes obtaining, by the audit module (214), second values of the plurality of parameters from the core nodes. This step involves the actual data collection from the core nodes The audit module (214) establishes secure network connections with the core nodes using protocols such as Simple Network Management Protocol (SNMP), Secure Shell (SSH), or proprietary network management protocols. These protocols ensure that the data collection process is both secure and efficient. The system authenticates itself with each core node to gain authorized access. Once connected, the audit module (214) executes commands or queries on each core node to retrieve the current values of the specified parameters. This process is designed to be non-intrusive, minimizingany potential impact on network performance during the audit. The audit module (214) is capable of parallel processing, allowing it to collect data from multiple core nodes simultaneously, thus reducing the overall time required for the audit.

[0223] At step 506, the method (500) includes performing, by the audit execution module (216), the audit by comparing the second values of the plurality of parameters with the first values of the plurality of parameters. This comparison is the heart of the audit process, where the actual configuration of the network is measured against the expected configuration. The audit execution module (216) employs sophisticated comparison algorithms that can handle various data types and formats, ensuring accurate comparisons across all parameter types. The module is designed to identify not only exact mismatches but also values that fall outside of acceptable ranges or thresholds. This nuanced approach allows for the detection of subtle discrepancies that might otherwise go unnoticed. The audit execution module (216) can be configured to perform both live audit jobs and one-time audits. Live audit jobs continuously monitor and audit network parameters in real-time, providing immediate alerts for any discrepancies. This real-time monitoring is particularly useful for critical network parameters that require constant oversight. One-time audits, on the other hand, are executed on-demand or as scheduled, performing a comprehensive audit of all specified parameters at a given point in time. These one-time audits are valuable for periodic compliance checks or when investigating specific issues.

[0224] At step 508, the method (500) includes analyzing, by the analysis module (218), the results of the comparison to determine discrepancies without manual intervention. The analysis module (218) employs advanced algorithms and machine learning techniques to interpret the comparison results. The analysis module (218) can determine patterns and trends in the discrepancies, providing deeper insights into the nature and potential causes of configuration mismatches. The analysis module (218) is capable of prioritizing discrepancies based on their potential impact on network performance and security, allowing network administrators to focus on the most critical issues first. Additionally, the analysismodule (218) can correlate discrepancies across different parameters and nodes, potentially uncovering systemic issues or interdependencies that might not be apparent from individual parameter comparisons. The analysis module (218) also analyzes historical audit data to identify parameter discrepancy patterns over time. This historical analysis can reveal gradual drift in network configurations or recurring issues that require attention. Based on these identified patterns, the analysis module (218) generates recommendations for parameter adjustments, providing network administrators with actionable insights to improve network performance and stability.

[0225] At step 510, method generates audit reports a reporting module (224) generates comprehensive reports indicating the one or more parameters of the plurality of parameters identified as having discrepancies. These reports are designed to be both detailed and accessible, providing network administrators with a clear view of the network's current state and any areas requiring attention. The reports can be customized to focus on specific areas of interest or to provide different levels of detail for different audiences within the organization. The reporting module (224) can also generate trend reports, showing how network configuration and compliance have changed over time.

[0226] The method (500) further includes identifying, by the discrepancy identification module (220), the one or more parameters of the plurality of parameters as having discrepancy on determining that the second values of the one or more parameters of the plurality of parameters do not match with the corresponding first values of the plurality of parameters. This step creates a clear record of which parameters are out of compliance with the expected values. The discrepancy identification module (220) not only identifies the discrepancies but also categorizes them based on severity and potential impact. This categorization helps in prioritizing remediation efforts. The module can also provide context for each discrepancy, such as the magnitude of the deviation from the expected value and any relevant historical data. This contextual information is crucial for understanding the significance of each discrepancy and making informed decisionsabout how to address it. The discrepancy identification module (220) is designed to handle complex network configurations, including scenarios where parameters may have interdependencies or where discrepancies in one area may have cascading effects on other parts of the network.

[0227] The method (500) includes storing, by the data management module (222), the second values of the one or more parameters of the plurality of parameters. This step ensures that a complete record of the audit is maintained for future reference and analysis. The data management module (222) employs sophisticated data storage and retrieval mechanisms to handle the large volumes of data generated by network audits efficiently. It stores structured audit data, including parameter values, audit results, and historical trends, in a relational database. This structured storage allows for quick retrieval and analysis of specific audit data. Additionally, the module stores unstructured and semi-structured audit data in an elastic search engine, enabling fast, full-text search capabilities. This dual storage approach provides flexibility in how the audit data can be accessed and analyzed. The data management module (222) also implements data retention policies, ensuring that audit data is kept for the required duration for compliance purposes while also managing storage resources effectively.

[0228] The method (500) further includes several additional steps and features that enhance its functionality and utility. For instance, the method allows for the dynamic updating of the audit template. Network administrators can modify the template based on evolving network requirements or newly identified critical parameters. The audit execution module (216) then incorporates these updates into subsequent audits, ensuring that the audit process remains relevant and effective as the network environment changes. This flexibility is crucial in the rapidly evolving landscape of network technologies and security requirements.

[0229] The method (500) also incorporates a scheduling feature, allowing for the automation of the audit process. A scheduling module (228) can set up recurring audits at configurable time intervals, ensuring regular monitoring of thenetwork configuration without the need for manual initiation. This automated scheduling can be particularly useful for maintaining continuous compliance with regulatory requirements or internal policies. The scheduling module (228) can also be configured to trigger ad-hoc audits in response to specific events or changes in the network, providing an additional layer of oversight and responsiveness.

[0230] To enhance the efficiency and focus of the audit process, the method allows for the selective auditing of specific core nodes. Network administrators can input a selection of specific nodes to be audited, and the audit execution module (216) configures the audit to be performed only on these selected nodes. This feature is particularly useful in large, complex networks where full audits may be time-consuming, or when investigating issues related to specific network segments or devices.

[0231] The method (500) also includes a corrective action component, which can initiate actions to address identified discrepancies. These corrective actions can include sending configuration update commands such as update, modify, alter followed by name of the parameter to affected core nodes to align their current values with the expected values. For discrepancies that exceed predefined thresholds or require human oversight, the system can generate alerts for manual review by network administrators. Additionally, all discrepancies are logged for future analysis and reporting, contributing to a comprehensive audit trail and supporting long-term network optimization efforts.

[0232] To ensure the ongoing relevance and effectiveness of the audit process, the method incorporates mechanisms for detecting changes in network configuration or topology. When such changes are detected, the system can trigger ad-hoc audits to assess the impact of these changes on network compliance and performance. Furthermore, the audit template itself can be updated based on these detected changes, ensuring that the audit parameters remain aligned with the current network structure and requirements.

[0233] The method (500) leverages a sophisticated system architecture to support its operations. A user interface portal serves as the primary interface for user interaction, allowing for the input of audit parameters, display of audit results and reports, and access to scheduling options and historical audit data. A load balancer distributes audit requests across multiple servers, optimizing resource utilization and ensuring responsiveness even under high load conditions. An application gateway manages access to the audit module, handling authentication, authorization, and request routing to ensure secure and efficient execution of audit processes.

[0234] The system's data storage and management capabilities are robust and scalable. A combination of traditional relational databases and elastic search engines provides flexible and efficient storage and retrieval of both structured and unstructured audit data. A database management system oversees these storage solutions, handling data insertion, updating, and retrieval operations while maintaining data consistency and implementing backup and recovery procedures.

[0235] Real-time processing of audit events is facilitated by a distributed event streaming platform. This platform ingests ingest real-time data including network parameter values and operational metrics from core network nodes and audit processes, analyzes real-time data to detect anomalies or threshold violations, and can trigger immediate alerts or actions based on predefined conditions. The processed data is then fed back into the audit module, allowing for continuous refinement and updating of the audit process.

[0236] In another exemplary embodiment, a User Equipment (UE) (108) for facilitating an audit for a plurality of parameters of core nodes in a network is described. The UE (108) is configured to receive notifications from the system's user interface module (212), containing instructions for performing an audit. The selection of the UE is based on the user type stored in the system's database, ensuring that the appropriate personnel are engaged in the audit process. Upon receiving the notification, the UE executes the audit process as defined, collectingdata on the specified parameters and their values. This collected data is then transmitted back to the system's audit module for processing. Finally, the UE receives an audit completion notification once the system's audit execution module (216) has successfully completed the audit. This UE-centric approach allows for greater flexibility in conducting audits, enabling authorized personnel to initiate and monitor audits from mobile devices or remote locations, thus enhancing the responsiveness and efficiency of the network management process.

[0237] In another exemplary embodiment, a non-transitory computer- readable storage medium storing computer-executable instructions is described. When executed by one or more processors, the instructions cause the one or more processors to perform a method for performing an audit for a plurality of parameters of core nodes in a network. The method comprises creating, by a user interface module (212), an audit template for an audit in a coverage platform. An audit module (214) sends, via a user interface portal (302), a notification to one of a plurality of user equipment's (108) selected based on a user type stored in a database (210). An audit execution module (216) receives collected data comprising the plurality of parameters along with first values to be considered as parameters for performing auditing from the user equipment (108) as defined in the notification. The audit module (214) obtains second values of the plurality of parameters from the core nodes. The audit execution module (216) performs the audit by comparing the second values of the plurality of parameters with the first values of the plurality of parameters. An analysis module (218) analyzes the results of the comparison to determine discrepancies associated with the plurality of parameters without manual intervention. A discrepancy identification module (220) marks the one or more parameters of the plurality of parameters as having discrepancy on determining that the second values of the one or more parameters of the plurality of parameters do not match with the corresponding first values of the one or more parameters. Finally, a data management module (222) stores the second values of the one or more parameters of the plurality of parameters and the identified one or more parameters having the discrepancy. This method enables efficient and automatedauditing of network core nodes, facilitating the identification of configuration discrepancies and ensuring optimal network performance without extensive manual intervention.

[0238] FIG. 6 illustrates an example computer system (600) in which or with which the embodiments of the present disclosure may be implemented.

[0239] As shown in FIG. 6, the computer system (600) may include an external storage device (610), a bus (620), a main memory (630), a read-only memory (640), a mass storage device (650), a communication port(s) (660), and a processor (670). A person skilled in the art will appreciate that the computer system (600) may include more than one processor and communication ports. The processor (670) may include various modules associated with embodiments of the present disclosure. The communication port(s) (660) may be any of an RS-232 port for use with a modem-based dialup connection, a 10 / 100 Ethernet port, a Gigabit or 10 Gigabit port using copper or fiber, a serial port, a parallel port, or other existing or future ports. The communication ports(s) (660) may be chosen depending on a network, such as a Local Area Network (LAN), Wide Area Network (WAN), or any network to which the computer system (600) connects.

[0240] In an embodiment, the main memory (630) may be Random Access Memory (RAM), or any other dynamic storage device commonly known in the art. The read-only memory (640) may be any static storage device(s) e.g., but not limited to, a Programmable Read Only Memory (PROM) chip for storing static information e.g., start-up or basic input / output system (BIOS) instructions for the processor (670). The mass storage device (650) may be any current or future mass storage solution, which can be used to store information and / or instructions. Exemplary mass storage solutions include, but are not limited to, Parallel Advanced Technology Attachment (PATA) or Serial Advanced Technology Attachment (SATA) hard disk drives or solid-state drives (internal or external, e.g., having Universal Serial Bus (USB) and / or Firewire interfaces).

[0241] In an embodiment, the bus (620) may communicatively couple the processor(s) (670) with the other memory, storage, and communication blocks. The bus (620) may be, e.g. a Peripheral Component Interconnect (PCI) / PCI Extended (PCI-X) bus, Small Computer System Interface (SCSI), Universal Serial Bus (USB), or the like, for connecting expansion cards, drives, and other subsystems as well as other buses, such a front side bus (FSB), which connects the processor (670) to the computer system (600).

[0242] In another embodiment, operator, and administrative interfaces, e.g., a display, keyboard, and cursor control device may also be coupled to the bus (620) to support direct operator interaction with the computer system (600). Other operator and administrative interfaces can be provided through network connections connected through the communication port(s) (660). Components described above are meant only to exemplify various possibilities. In no way should the aforementioned exemplary computer system (600) limit the scope of the present disclosure.

[0243] FIG. 7 with reference to FIG. 5 for method (500) illustrates illustrates an exemplary flow diagram (700) illustrating steps performed by the system (102) for performing the configuration audit of the one or more network parameters, in accordance with an embodiment of the present disclosure.

[0244] At step 702, the processing engine (208) may be configured to fetch an audit template (golden audit template) maintained by the network administrator (user). For example, the audit template may include the at least one configured value (also known as golden value) corresponding to each of one or more network parameters. In an aspect, the audit template is fetched on receiving the at least one request from the user. In an aspect, the processing engine (208) may be configured to receive the request from the user pertaining to the configuration audit. In an example, the received request may include details of required parameters (defined parameter).

[0245] At step 704, the processing engine (208) may be configured to read or retrieve a network value (current value) corresponding to a network parameter from the EMS or the database in real-time. In an example, the processing engine (208) may be configured to retrieve the details of the defined parameters from the user request. Based on the retrieved details, the processing engine (208) may be configured to read the value corresponding to the defined parameter from the EMS using a communication path.

[0246] At step 706, the processing engine (208) is configured to compare the read network value with the configurable value corresponding to the specific network parameter that is stored in the database (210).

[0247] At step 708, the processing engine (208) may be configured to check whether the configurable and current values are compliant. For example, if the network value is the same as the configurable value, then the system (102) may consider the data as compliant. Conversely, if the current value is not the same as the golden value, then the system (102) may consider the data as non-compliant (discrepancy) (step 710).

[0248] FIG. 8 with reference to FIG. 2 of system (102) and FIG. 5 for method (500) illustrates an exemplary a user interface (800) that enables the user (network administrator) to provide one or more inputs, in accordance with an embodiment of the present disclosure.

[0249] In an aspect, the user (110) using the user interface may provide one or more inputs. The one or more inputs may be the one or more audit templates (golden audit templates) and the selected network parameters. The one or more audit templates may comprise the at least one configurable values (golden values) corresponding to the at least one network parameter. For example, the configurable values (golden values) may be configured according to the parameter node and the operating system version of the parameter node. In an aspect, the user (110) may use the UE (108) connected to the network (104) to access an application through the user interface. The application may enable the user (network administrator) withvarious preferences to provide one or more inputs. The various preferences may include an upload data, a create data, a select data, an update data, a download data, and a delete data. For example, the user may upload an input file by choosing an admin template option. The input file may include one or more audit templates. The input file may include an excel file, a text file, a comma-separated values (CSV) file. The user may upload the input file corresponding to the parameter node and the operating system of the parameter node. For example, the parameter node may be an “OSDC”, and the operating system version may be “03.03.07”. In another example, the user may be able to download the existing configurable values (golden setting) as defined in the audit template (golden audit template). In another aspect, the user may be able to add, delete, and modify the existing audit template. The user may modify or delete the configurable values by choosing an exclude scope option. For example, if the user intends to exclude one or more configurable values from the audit template. The user may upload the input file with the configurable values that are to be excluded. Upon uploading the input file, the processing unit (208) may parse the input file and remove the configurable values from the audit template. The user may perform the configuration audit after excluding the unnecessary configurable values from the audit template.

[0250] In an aspect, the user (network administrator) may upload one or more audit templates. The one or more audit templates may be validated by the system (102) through the processing unit (208). The processing engine (208) may parse the audit template to identify at least one configurable value. By parsing the audit template, the processing engine (208) may be configured to validate the same and provide a downloaded status report for the uploaded template. In an exemplary aspect, the audit template may be a file such as a text file, an excel file, and a csv file. The processing engine (208) may check for a file extension to validate the file. The file extension may be a .doc, .xlsl, etc. For example, if the audit template an excel file. The processing engine (208) parses the file extension. The file extension matches with the uploaded file type, the processing engine (208) may generate the status report as valid template. The processing engine (208) sends the status reportto the user through the UE (108). The status report may include a timestamp, a status, and a file format. The status may include a valid, an invalid, a corrupted, a missing, and a not found. If the file is a valid file, the report may give the status as valid. The file may store the at least one configurable value in a table form. The table may include one or more headers. The one or more headers may include a parameter node, a parameter type, and a configurable value. The processing engine (208) may evaluate the one or more headers in the table. If the one or more header matches with the at least one configurable value, the processing engine (208) generates a valid status report and sends the report to the UE (108).

[0251] In another aspect, the user (110) may upload a list of SAP (Service Access Point) IDs in the application using UE (108). The application may exclude the list of SAP IDs from the scope of the audit template. The network administrator (user) may be able to view / add / delete the list of SAP IDs from the excluded scope. For example, the audit template may include the SAP ID. The processing unit (208) may match the received list of SAP ID with the SAP ID in the audit template. Upon matching the SAP ID, the matched SAP ID may be removed from the audit template.

[0252] FIG. 9 with reference to FIG. 2 of system (102) and FIG. 5 for method (500) illustrates an exemplary representation (900) of the network discrepancies of multiple network operators (vendors) in a live dashboard status, in accordance with an embodiment of the present disclosure.

[0253] The system (102) may be configured to perform multiple network operator configuration audits. In an aspect, the user (110) using the UE (108) may be connected to the application, such as the web application using the network (104). In an exemplary aspect, the user interface may be the web application. The web application may have a main page, the live dashboard, and a plurality of modules. The plurality of modules may include a home, a configuration management, an audit and query, and an audit template (5G golden audit). The user (110) may perform the configuration audit of the network parameters by using anavigation path. The user (110) using UE (108) may perform multiple network operator configuration audits by using the navigation path: “Main Page -> Modules - > Configuration Management -> Audit and Query->RAN-> 5G Golden Audit”.

[0254] FIG. 9 shows the network discrepancies for the multiple network operators (vendor 1, vendor 2, vendor 3) with the live dashboard. For example, the vendors may be network operators / service providers. The live dashboard may be an interactive real-time user interface displaying various network metrics. The various network metrics may include a location, a vendor name, a compliant count, a compliance percentage, a non-compliant count, a non-compliance percentage, weekly trends, and a chart. For example, the compliant count and the non-compliant count may illustrate a state of adherence to the at least one configurable value provided in the audit template. For example, suppose the configurable value for a frequency band is set as “X” and the collected value for the frequency band matches with “X”. In that case, the frequency band complies with the configurable value, hence the compliant count may be increased by 1. Conversely, if the collected value doesn’t match the configurable value, then the non-compliant count may increase by 1. The location may be captured from the UE (108) by a location services. The location services may include a GPS (Global Positioning System), a Wi-fi (Wireless Fidelity), and a mobile network data. In an aspect, the compliance percentage may be used to measure the degree to which the compliance of standards is met according to the audit template. The compliance percentage for the network operator may be calculated by dividing the compliance count of the vendor 1 by the total compliance count of all network operators.

[0255] In an aspect, the application may provide a data visualization of the compliance report. The data visualization may include a chart, a graph, a map, a table, and an infographic. For example, the compliance report may be represented using the graph for the configured time. The configured time may include a week, a month, and a year. The graph may represent the compliance for the week. The weekly trend graph may represent the network compliance according to the vendor(network operator). The weekly trend graph may be used to spot upward or downward trends over the week and aid in overcoming future drawbacks.

[0256] In another aspect, the live dashboard may include an interactive option, a customizable layout, and an alert and notification. The interactive option may include a filter, a zoom, a search bar and a drill down. For example, the filter may be used to select a time interval to be visualized in the live dashboard. The time interval may include a time and a date. For example, the user (110) may select the time as 12.10 P.M. and the date as 20 / 09 / 2024. The live dashboard may visualize the compliance report for the selected time and data. Also, the search tab may be used to search for the compliance of a particular network parameter. For example, the user (110) may check the compliance of the network frequency of the vendor 1. The live dashboard may display the network frequency of vendor 1.

[0257] FIG. 10 illustrates another exemplary representation (1000) of various types of discrepancies related to the network parameters, in accordance with an embodiment of the present disclosure.

[0258] In an aspect, the user (110) may connect to the application such as the web application using the network (104). In an exemplary aspect, the web application may include the main page, the live dashboard, and the module. The user may perform the configuration audit of the network parameters by using the access path. The access path may be “Main Page -> Modules - > Configuration Management^ Audit and Query->RAN-> ABC 5G Golden Audit”. For example, the live dashboard may display various parameters such as a circle, a node type, a cell number (CNUM), a service access point (SAP) ID, one or more network discrepancies count, an index and an operating system version (Software version). The one or more network discrepancies count includes a total discrepancy count, a low impact discrepancy count and a high impact discrepancy count. The processing engine (208) may be configured to determine the network discrepancies by comparing the collected network value corresponding to the network parameter and the received configurable value corresponding to the network parameter. Theprocessing engine (208) may calculate the one or more network discrepancy counts based on the compared results. For example, if the collected value is lower than the configurable value, the discrepancy is counted under the low-impact discrepancy count. Conversely, if the collected value exceeds the configurable value, the discrepancy is counted under the high-impact discrepancy count. Also, if the collected value is not comparable with the configurable value, the discrepancy is counted under the total discrepancy count.

[0259] In an aspect, the processing engine (208) may visualize the determined at least one network discrepancy based on a selected geographic location on a display unit of the UE (108). In an aspect, the live dashboard may be configured to update after a predefined time. The predefined time may include a second, a minute, or an hour. For example, the application in the UE (108) may provide an option to select the geographic location. The geographic location may be a list of states based on a country. The network discrepancy may be visualized as a list of entries based on the selected geographic location. The user interface of the UE (108) may show the low impact discrepancy count, the high impact discrepancy count, and the total discrepancy count. For example, the geographic location may be Mumbai. The total discrepancy count may be 1356.

[0260] In an aspect, the application in the UE (108) may provide a download option to download an entire list of configurable value (golden value parameter) discrepancies. For example, the list of configurable value discrepancies may include a node type, a parameter type, a parameter, a network type, and a discrepancy type. For example, the ODSC may be the node type. The parameter type may be tabular. The network type may be cell. The parameter may be carrier frequency, and the discrepancy type may be high.

[0261] FIG. 11 illustrates an exemplary graphical illustration (1100) showing types of discrepancies in a dashboard, in accordance with an embodiment of the present disclosure. In an aspect, the graphical illustration (1100) may represent the relationship between a discrepancy and a timeline. For example, thetimeline may be a day, a month, a year, etc. The timeline may be 15 days. The discrepancy may be determined based on the comparison of the collected network value and the configurable value corresponding to the network parameter. For example, the network parameter may be a frequency bandwidth. The collected network value is “X”, and the configurable value is “Y”. The collected network value and the configurable value do not match, hence there is a discrepancy in the network. The discrepancy may be calculated as the difference between the configurable value and the collected network value. For example, the discrepancy may be calculated as “X - Y” = difference. For example, a smaller difference may indicate a low discrepancy, a medium difference may indicate a high discrepancy, and a larger difference may indicate a total discrepancy.

[0262] In an aspect, the types of network discrepancies may include one or more indicators. For example, one or more indicators may include the total impact discrepancy (1102), the high impact discrepancy (1104), and the low impact discrepancy (1106). In an example, the ranges for the one or more indicators may be configured by the users (network administrators). The ranges may be stored in the memory (204). The ranges may be categorized as “A”, “B”, “C” and “D”. The network discrepancies may be determined based on the collected network values corresponding to the network parameters. If the collected network values fall in the range between “A” and “B”, then the network discrepancy may be referred to as the total discrepancy. Further, if the collected network values fall between “B” and “C”, then the network discrepancy may be referred to as the low impact discrepancy. Conversely, if the collected network values fall between “C” and “D”, the network discrepancy may be referred to as the high impact discrepancy. For example, to view the graphical illustration (1100), the user (110) may click any one of the one or more indicators using the user interface of the UE (108). The user interface may visualize a 15 -day trend line graph for the clicked indicator (as shown in FIG. 11).

[0263] The present disclosure provides technical advancement related to network configuration auditing and management. This advancement addresses the limitations of existing solutions by introducing an automated, scalable, andintelligent system for performing comprehensive audits of core network nodes. The disclosure involves a sophisticated microservice architecture combined with realtime data processing and machine learning-based analysis, which offer significant improvements in audit accuracy, efficiency, and responsiveness. By implementing a dynamic audit template system and automated discrepancy identification, the disclosed invention enhances network administrators' ability to maintain optimal network configurations and ensure compliance with performance standards. This results in improved network reliability, reduced downtime, and enhanced overall network performance. The system's capability to perform both continuous real-time monitoring and scheduled in-depth audits provides unprecedented flexibility in network management. Furthermore, the integration of historical trend analysis and predictive recommendations enables proactive network optimization, reducing the likelihood of performance issues and security vulnerabilities. The disclosure's approach to automating corrective actions for identified discrepancies significantly reduces the manual workload on network administrators, allowing them to focus on strategic network planning and development. By leveraging advanced data storage and retrieval mechanisms, including elastic search capabilities, the system ensures that vast amounts of audit data can be efficiently processed and analyzed, providing deeper insights into network behavior over time. This comprehensive approach to network auditing and management represents a significant leap forward in ensuring the reliability, security, and performance of complex network infrastructures in an increasingly connected digital landscape.

[0264] The present disclosure provides technical advancement related to performing a configuration audit of one or more network parameters. This advancement addresses the limitations of existing solutions by providing a system and a method that enables real-time audit with a live dashboard using the UE. The disclosure involves performing configuration of audit of network parameters on real-time basis and provides a consolidated compliance report, which offers significant improvements in performance of the network. By implementing the system and method for comparing the collected network values with theconfigurable set of values corresponding to the network parameters, the disclosed disclosure enhances overall network performance, resulting in a reduction of network discrepancies.

[0265] While considerable emphasis has been placed herein on the preferred embodiments, it will be appreciated that many embodiments can be made and that many changes can be made in the preferred embodiments without departing from the principles of the disclosure. These and other changes in the preferred embodiments of the disclosure will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter to be implemented merely as illustrative of the disclosure and not as limitation.ADVANTAGES OF THE PRESENT DISCLOSURE

[0266] The present disclosure provides a system and method for performing audit of a plurality of core nodes in the telecommunication networks using dynamic templates, which significantly enhances the flexibility and relevance of network audits. This approach allows administrators to modify audit parameters in real-time, ensuring that audits remain aligned with evolving network requirements and industry standards.

[0267] The present disclosure offers a comprehensive audit solution that spans across multiple core nodes of various network technologies. This broad coverage enables a holistic view of the network's configuration and performance, facilitating more effective optimization and troubleshooting strategies.

[0268] The present disclosure implements a recurring audit mechanism based on the parameters specified in the audit template. This automated, scheduled approach ensures consistent monitoring of critical network parameters without manual intervention, leading to more timely detection of configuration discrepancies and potential performance issues.

[0269] The present disclosure significantly reduces the time and effort required for network audits while simultaneously improving the accuracy of results. By automating the audit process and leveraging advanced data analysis techniques, the system minimizes human error and provides more reliable, actionable insights for network management and optimization.

[0270] The present disclosure enables efficient storage and retrieval of audit data, facilitating historical trend analysis and informed decision-making. This comprehensive data management approach supports proactive network maintenance and long-term performance improvements.

[0271] The present disclosure incorporates intelligent discrepancy identification and prioritization, allowing network administrators to focus on the most critical configuration issues. This targeted approach enhances the efficiency of network troubleshooting and optimization efforts.

[0272] The present disclosure offers a scalable solution capable of handling large, complex network infrastructures. Its microservice architecture and distributed processing capabilities ensure that the system can adapt to growing network sizes and increasing audit frequencies without compromising performance.

[0273] The present disclosure provides a user-friendly interface for both initiating audits and reviewing results, making advanced network auditing capabilities accessible to a wider range of network management personnel. This ease of use promotes more frequent and thorough network health checks.

[0274] The present disclosure provides a system and a method for performing real-time audit with a live dashboard through a user equipment (UE).

[0275] The present disclosure provides a system and a method that increases the overall efficiency and functionality of the network by providing a comprehensive and real-time view of the network.

[0276] The present disclosure provides a system and a method that facilitates the network administrators to identify areas of the network that may be experiencing issues and take corrective action before the occurrence of a major problem.

[0277] The present disclosure provides a system and a method that allows a high level of visibility into the network for managing and optimizing the network.

[0278] The present disclosure provides a system and a method that improves the performance and efficiency of the network by analyzing and visualizing data related to network nodes.

Claims

CLAIMS1. A system (102) for performing an audit of core nodes in a network (104), the system (102) comprising: a user interface module (212) configured for receiving a plurality of parameters along with first values for performing auditing, wherein the plurality of parameters along with corresponding first values are populated in an audit template; an audit module (214) configured for obtaining second values of the plurality of parameters from the core nodes in the network; an audit execution module (216) configured for comparing the second values of the plurality of parameters with the first values of the plurality of parameters; an analysis module (218) configured for analyzing results of the comparison to determine discrepancies associated with one or more parameters of the plurality of parameters; and a reporting module (224) configured for generating an audit report based on the determined discrepancies.

2. The system (102) as claimed in claim 1, wherein the plurality of parameters comprise a subset of network configuration parameters of the core nodes in the network including at least one of: quality of service (QoS) settings, network latency thresholds, packet loss rate limits, frequency band allocations, transmit power levels, antenna configurations, a bandwidth, a throughput, a carrier frequency, an allowable data transmission, a latency, a packet loss, a jitter, a signal strength, a bit error rate (BER), and a propagation delay.

3. The system (102) as claimed in claim 1, wherein the audit template is a dynamic audit template, and whereinthe user interface module (212) is configured for receiving updates to the audit template; the audit execution module (216) is configured for modifying the audit template based on the received updates; and the audit execution module (216) is configured for performing a subsequent audit using the modified audit template.

4. The system (102) as claimed in claim 1, wherein the first values correspond to values expected during operations in the network, each parameter represents a parameter which is associated with each of the core nodes, wherein obtaining the second values of the plurality of parameters comprises: establishing, by a network module (226), secure network connections with the core nodes using at least one of:Simple Network Management Protocol (SNMP), Secure Shell (SSH) protocol, or a proprietary network management protocol; authenticating, by the network module (226), the system (102) with each core node; and executing, by the audit module (214), commands or queries on each core node to retrieve second values of the plurality of parameters.

5. The system (102) as claimed in claim 1, further comprising a discrepancy identification module (220) configured for identifying one or more parameters of the plurality of parameters as having discrepancy on determining that the second values of the one or more parameters do not match with the corresponding first values of the one or more parameters.

6. The system (102) as claimed in claim 1, whereinthe analysis module (218) is configured for analyzing historical audit data to identify parameter discrepancy patterns; and the analysis module (218) is configured for generating recommendations for parameter adjustments based on the identified patterns.

7. The system (102) as claimed in claim 6, wherein a corrective action module (230) is configured for initiating corrective actions for parameters identified as having discrepancies or based on selecting one of the generated recommendations, wherein the corrective actions comprise at least one of: sending configuration update commands to affected core nodes to align the second values with the first values; generating alerts for manual review by a network administrator for the discrepancies exceeding a predefined threshold; or logging the discrepancies for future analysis and reporting.

8. The system (102) as claimed in claim 1, wherein: the audit execution module (216) is configured to perform both live audit jobs (318) and one-time audits (320), wherein: live audit jobs (318) continuously monitor and audit the plurality of parameters in real-time, providing immediate alerts for the discrepancies; and one-time audits (320) are executed on-demand or scheduled at configurable time intervals, performing an audit of one or more selected parameters at a given point in time.

9. The system (102) as claimed in claim 1, wherein the user interface module (212) is configured to visualize the one or more discrepancies are visualized based on a selected geographic location.

10. A method (500) for performing an audit of core nodes (114) in a network, the method comprising: receiving (502), by a user interface module (212), a plurality of parameters along with first values of the plurality of parameters for performing auditing, wherein the plurality of parameters along with corresponding first values are populated in an audit template; obtaining (504), by a audit module (214), second values of the plurality of parameters from the core nodes in the network; performing (506), by an audit execution module (216), the audit by comparing the second values of the plurality of parameters with the first values of the plurality of parameters; analyzing (508), by an analysis module (218), results of the comparison to determine discrepancies associated with the plurality of parameters; and generating, by a reporting module (224), an audit report based on the determined discrepancies.

11. The method (500) as claimed in claim 10, wherein the plurality of parameters comprise a subset of network configuration parameters of the core nodes in the network including at least one of: quality of service (QoS) settings, network latency thresholds, packet loss rate limits, frequency band allocations, transmit power levels, antenna configurations, a bandwidth, a throughput, a carrier frequency, an allowable data transmission, a latency, a packet loss, a jitter, a signal strength, a bit error rate (BER), and a propagation delay.

12. The method (500) as claimed in claim 10, wherein the audit template is a dynamic audit template, and the method (550) further comprises: receiving, by the user interface module (212), updates to the audit template;modifying, by the audit execution module (216), the audit template based on the received updates; and performing, by the audit execution module (216), a subsequent audit using the modified audit template.

13. The method (500) as claimed in claim 10, wherein the first values correspond to values expected during operations in the network, each parameter represents a parameter which is associated with each of the core nodes, wherein obtaining the second values of the plurality of parameters comprises: establishing, by a network module (226), secure network connections with the core nodes using at least one of:Simple Network Management Protocol (SNMP), Secure Shell (SSH) protocol, or a proprietary network management protocol; authenticating, by the network module (226), the system (102) with each core node; and executing, by the audit module (214), commands or queries on each core node to retrieve the second values of the plurality of parameters.

14. The method (500) as claimed in claim 10, further comprising identifying by a discrepancy identification module (220) one or more parameters of the plurality of parameters as having discrepancy on determining that the second values of the one or more parameters do not match with the corresponding first values of the one or more parameters.

15. The method (500) as claimed in claim 10, further comprising: analyzing, by the analysis module (218), historical audit data to identify parameter discrepancy patterns; and generating, by the analysis module (218), recommendations for parameter adjustments based on the identified patterns.

16. The method (500) as claimed in claim 15, further comprising: initiating, by a corrective action module (230), corrective actions for parameters identified as having discrepancies or based on selecting one of the generated recommendations, wherein the corrective actions comprise at least one of: sending configuration update commands to affected core nodes to align the second values with the first values; generating alerts for manual review by a network administrator for the discrepancies exceeding a predefined threshold; or logging the discrepancies for future analysis and reporting.

17. The method (500) as claimed in claim 11, further comprising: performing, by the audit execution module (214), both live audit jobs (318) and one-time audits (320), wherein: live audit jobs (318) continuously monitor and audit network parameters in real-time, providing immediate alerts for the discrepancies; and one-time audits (320) are executed on-demand or scheduled at configurable time intervals, performing an audit of selected one more parameters at a given point in time.

18. The method (500) as claimed in claim 10, wherein the user interface module (212) is configured to visualize the one or more discrepancies are visualized based on a selected geographic location.

19. A user equipment (UE) (108) for facilitating an audit of core nodes in a network, the UE (108) is configured to:receive a notification comprising instructions for performing an audit and transmit the notification to the system (102), wherein the system is configured to perform the steps as claimed in claim 1.

20. A non-transitory computer-readable storage medium storing computerexecutable instructions that, when executed by one or more processors, cause the one or more processors to perform a method for performing an audit of core nodes in a network, the method comprising: receiving (502), by a user interface module (212), a plurality of parameters along with first values for performing auditing, wherein the plurality of parameters along with corresponding first values are populated in an audit template; obtaining (504), by an audit module (214), second values of the plurality of parameters from the core nodes in the network; performing (506), by an audit execution module (216), the audit by comparing the second values of the plurality of parameters with the first values of the plurality of parameters; analyzing (508), by an analysis module (218), results of the comparison to determine discrepancies associated with the plurality of parameters; and generating by a reporting module (224) an audit report based on the determined discrepancies.

Citation Information

Patent Citations

  • Data collection method and system

    CN109495347A

  • System for monitoring a distributed network using a node crawler

    US11522781B1

  • System and method for collecting network performance information

    US20080002677A1

  • Location-based service network automation platform

    US20230370866A1