Adaptive Thresholds for Network Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face challenges in setting effective thresholds for detecting network anomalies, leading to false alarms or missed performance degradation due to static thresholds that do not account for varying usage patterns across different cell sites and time periods.
Innovation Solution
A system that calculates adaptive thresholds based on normalized trends and deviations for specific network infrastructure elements and time periods, using data from performance indicators like dropped calls, to generate alarms only when significant anomalies occur.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single system-wide threshold is set for a given parameter, then the threshold management is simple, but false alarms increase in cell sites with normally large parameter values
Solution Approach 1:
The patent segments the system-wide threshold into individual cell site-specific thresholds. Each cell site receives a customized threshold based on its historical performance data and characteristics, eliminating false alarms in cell sites with normally large parameter values while maintaining simple threshold management through automated generation.
Solution Approach 2:
The patent applies local quality by making thresholds specific to each cell site's local characteristics rather than uniform across the entire system. Each cell site's threshold is tailored to its unique performance patterns, ensuring appropriate sensitivity for local conditions while maintaining system-wide consistency through the automated methodology.
2Reliability
If the predetermined threshold is set to a high value to avoid false alarms, then false alarms decrease, but performance degradation not reaching catastrophic levels goes unnoticed
Solution Approach 1:
The patent makes thresholds dynamic rather than static by continuously updating them based on current performance data and trends. This allows the system to detect performance degradation at appropriate levels for each cell site while adapting to changing conditions, preventing both false alarms and missed detections.
Solution Approach 2:
The patent implements feedback by using historical performance data and current trends to continuously refine and update thresholds. This feedback mechanism ensures thresholds remain sensitive to actual performance degradation while automatically adjusting to normal variations, eliminating the need for manual threshold setting.
3Reliability
If separate predetermined threshold values are set for each network component and time period, then alarm accuracy improves, but the number of thresholds to manage increases exponentially
Solution Approach 1:
The patent enables self-service by automatically generating and updating cell site-specific thresholds using historical performance data and current trends. The system performs the threshold management task autonomously without requiring manual intervention, eliminating the complexity of managing numerous thresholds while maintaining high alarm accuracy.
Solution Approach 2:
The patent changes the approach from manually setting fixed parameter values to automatically generating parameters based on historical data and current trends. This transformation allows the system to manage multiple cell site-specific thresholds efficiently by deriving them from existing performance metrics rather than requiring separate manual configurations.
4Ease of manufacture
If static thresholds are used in expanding communication systems, then initial threshold setup is simple, but thresholds become obsolete as the system grows and must be manually updated
Solution Approach 1:
The patent transforms static thresholds into dynamic, adaptive thresholds that automatically adjust as the communication system expands and changes. By using historical performance data and current trends, the system continuously updates thresholds to remain relevant, eliminating the need for manual updates while maintaining ease of initial setup through automated generation.
Data Source
AI summary
A system is configured to generate an alarm when an anomaly occurs at a network infrastructure element. The system includes a transceiver configured to receive data associated with a performance indicator on a predefined basis. The system also includes a processor configured to use the received data to determine a normalized trend for the performance indicator for at least one of a given network infrastructure element and a given time period. The processor is further configured to apply a degree of deviation to the determined normalized trend for at least one of the given network infrastructure element and the given time period to generate an adaptive threshold for the performance indicator. An alarm generator generates an alarm to indicate an anomaly at the given network infrastructure element when newly received data associated with the performance indicator is beyond the adaptive threshold associated with the performance indicator.


