Network Disruption Detection via BGP Routing Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional approaches to network disruption detection rely on hearsay reporting and indirect methods, such as social media analysis, which are ineffective in identifying localized or widespread network outages, and fail to differentiate between specific service disruptions and broader internet issues.
Innovation Solution
A network disruption detection engine that gathers and analyzes routing path messages to identify anomalies by comparing current messages with historical data, using machine learning to detect deviations indicative of network disruptions, and geolocating affected areas to provide accurate and proactive disruption reporting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional approaches use social media analysis and hearsay reporting to detect network disruptions, then the system can operate with simple infrastructure, but the detection precision and reliability are insufficient to differentiate between localized and widespread outages
Solution Approach 1:
The patent introduces BGP routing messages as an intermediary indicator that indirectly reflects network health. Instead of directly monitoring service availability, the system analyzes routing path updates which serve as a mediator signal - when routers update their routing tables to avoid certain regions, this routing behavior indirectly indicates network disruptions without requiring direct service probing
Solution Approach 2:
The patent replaces traditional mechanical probing methods (traceroute, service availability checks) with an information-based approach using BGP routing data. Instead of actively testing network paths with probe packets, the system passively analyzes routing update messages that routers naturally generate, substituting active mechanical detection with passive information analysis
2Reliability
If the system actively probes network paths using traceroute and service availability checks to detect disruptions, then detection coverage can be improved, but the time required for detection and the resources consumed increase significantly
Solution Approach 1:
The system performs preliminary action by continuously collecting and storing BGP routing messages during normal network operation, building a historical baseline of routing behavior before disruptions occur. This pre-collection of routing data enables immediate comparison and anomaly detection when disruptions happen, eliminating the need for time-consuming active probing at the moment of detection
Solution Approach 2:
The patent implements continuous monitoring of BGP routing updates that naturally occur as routers maintain their routing tables. This continuous passive data collection provides ongoing network health information without interruption, ensuring that disruptions are detected immediately when they cause routing changes rather than waiting for periodic probes
3Adaptability or versatility
If social media mining techniques are used to gather user reports about service outages, then the system can identify user-impacting disruptions, but the system cannot detect general internet disruptions that do not affect specific services
Solution Approach 1:
The patent applies universality by using BGP routing messages as a universal indicator that works across all network disruptions regardless of service type or location. The same routing message analysis approach detects both localized service outages and widespread internet disruptions, providing a single unified detection mechanism that adapts to various disruption scenarios without requiring service-specific monitoring
Data Source
AI summary
A network disruption detection engine gathers and stores network routing path update messages that routinely modify routing tables used by internet routers for transporting message traffic between a source and a destination. Routing path messages continually maintain a network transport infrastructure both for intranets used for particular entities such as corporations, and internet traffic between arbitrary source and destination nodes. Major disruptions or outages typically result in an increase in routing path messages, typically focused on a particular set, region or network entity where the disruption occurred, as other routing entities seek to avoid the troubled region. Analysis of this sudden activity of routing messages and extracting message content about the network region they seek to avoid allows identification and queries of a widespread network outage.


