AI Network Alarm Correlation for Root Cause Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network and system management technologies struggle to efficiently identify and address large-scale issues or faults due to overwhelming alarm storms, delayed notifications, and the inability to pinpoint the root cause of problems.
Innovation Solution
The use of machine learning and artificial intelligence to correlate alarm data with network topology data, generate extended correlated events, and identify the root cause of issues, thereby facilitating timely and effective solutions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional alarm generation methods are used, then devices can detect issues, but alarm storms overwhelm diagnostic tools and hide the root cause
Solution Approach 1:
The patent introduces an intermediary system that sits between network devices and diagnostic tools. This intermediary collects alarms from multiple devices, correlates them with topology data, and presents a simplified view to operators. The intermediary absorbs the complexity of alarm storm processing while maintaining reliable issue detection capability.
Solution Approach 2:
The system segments the alarm processing function by separating collection, correlation, and presentation stages. Alarms are collected from multiple devices, correlated with topology information, and then presented as consolidated issues with identified root causes. This segmentation prevents diagnostic tools from being overwhelmed by raw alarm storms.
2Measurement precision
If devices generate alarms independently, then each issue is detected, but multiple alarms distract from the actual root cause
Solution Approach 1:
The patent merges multiple independent alarm signals into a single correlated event by analyzing their temporal and spatial relationships. Topology data is used to understand device connections, allowing the system to combine alarms from multiple devices that are actually symptoms of a single root cause issue, thereby preserving root cause identification while maintaining detection accuracy.
Solution Approach 2:
The system uses feedback loops to continuously monitor alarm patterns and refine root cause identification. By analyzing the relationship between alarms and topology data, the system learns to better distinguish causal relationships from coincidental correlations, improving both detection accuracy and root cause identification over time.
3Area of stationary object
If passive devices are used, then network coverage is extended, but these devices cannot generate alarms for issues
Solution Approach 1:
The patent implements self-service by enabling passive devices to autonomously generate and transmit alarm information without requiring active configuration or processing capabilities. The passive devices simply collect and forward alarm data, which is then processed by the intermediary system, allowing network coverage extension while maintaining reliable alarm generation capability through distributed participation.
4Ease of operation
If users report issues manually, then user feedback is obtained, but notification delays reduce resolution efficiency
Solution Approach 1:
The system implements self-service by automatically monitoring network conditions and generating notifications without requiring user initiation. The intermediary system continuously collects alarm data, identifies issues, and proactively notifies operators, eliminating the time loss associated with manual user reporting while maintaining ease of operation through automated processes.
Data Source
AI summary
Aspects of the subject disclosure may include, for example, obtaining a plurality of alarms associated with a network, correlating the plurality of alarms to data that identifies a topology of the network to obtain a plurality of correlated events, applying a model that is based on machine learning to the plurality of correlated events to generate an extended correlated event, identifying a solution to the extended correlated event, and implementing the solution as part of the network. Other embodiments are disclosed.


