Cross-domain Probing Orchestrator for Network Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The lack of standardization across domains for probing in computer network monitoring makes it challenging to accurately detect network anomalies and determine their root cause, especially when dealing with disparate systems, tools, and layers, which hampers end-to-end service assurance and quick fault resolution.

Innovation Solution

A cross-domain probing architecture is introduced, where a probe controller orchestrator provides access to cross-domain probing across multiple domains with different probing protocols and capabilities, correlating domain-specific probe test results into a common data format to facilitate standardized processing and anomaly detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If domain-specific probing is used across multiple network domains, then probing capability and protocol specialization are improved, but data integration and cross-domain anomaly detection deteriorate due to lack of standardization

Engineering Contradiction:
Improveprobing capabilityVSAvoiddata integration
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent introduces a data correlation engine as an intermediary component that receives data from multiple domain-specific probes, standardizes the data formats, correlates the data across domains, and produces unified cross-domain data. This mediator resolves the incompatibility between different domain-specific probing protocols and enables effective cross-domain data integration and anomaly detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Area of stationary object

If multiple disparate monitoring systems and tools are deployed across network domains, then monitoring coverage is improved, but system complexity and difficulty of piecing together monitoring data worsen

Engineering Contradiction:
Improvemonitoring coverageVSAvoidsystem complexity
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

The patent creates a universal data correlation engine that can handle multiple types of monitoring data from different domains and tools through a single standardized interface. This multi-functional system receives, standardizes, and correlates various monitoring data types (flow data, packet captures, performance metrics) from diverse sources, eliminating the need for separate integration mechanisms for each tool and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If domain-specific probing protocols are used in each network domain, then protocol optimization for specific domains is improved, but ease of operation and standardized processing deteriorate

Engineering Contradiction:
Improveprotocol optimizationVSAvoidstandardized processing
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent transforms domain-specific probing data by changing its parameter representation through standardization. The data correlation engine converts data from various domain-specific protocols into a unified data format with standardized parameters, enabling consistent processing and analysis across all domains while preserving the optimized characteristics of each domain's native protocol through the correlation process.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250106138A1Cross-domain probing architecture for computer network monitoring
Publication Date: 2025.03.27 CISCO TECHNOLOGY INC
  • US20250106138A1 patent drawing
  • US20250106138A1 patent drawing
  • US20250106138A1 patent drawing

AI summary

In one implementation, a “probe controller orchestrator” provides access to cross-domain probing via the probe controller orchestrator for a plurality of probe controllers across a plurality of different network domains with a respective different probing protocol and associated probing capability. The probe controller orchestrator, in particular, obtains domain-specific probe test results from each of the plurality of probe controllers, and correlates the domain-specific probe test results into cross-domain data formatted in a common data format understandable by each of the plurality of probe controllers. As such, the probe controller orchestrator may then respond to requests received from the plurality of probe controllers with the cross-domain data in order to cause respective domain-specific processing.