Hierarchical Anomaly Localization in Communication Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing techniques for detecting and localizing performance issues and network anomalies in wide-area networks are limited, as they can only localize anomalies at specific probe locations and do not effectively determine root cause nodes or prioritize issues based on severity and scope.
Innovation Solution
The method involves obtaining reported status for nodes in a hierarchical network topology, determining a subset of root cause abnormal nodes using a greedy algorithm that selects nodes with more abnormal and indeterminate descendants than normal descendants, and prioritizing these nodes based on anomaly size and scope.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If active probes are placed at specific locations in the network, then anomaly detection capability at probe locations is improved, but the ability to localize anomalies at any node and determine root cause nodes deteriorates
Solution Approach 1:
The network topology is segmented into a hierarchical structure with root nodes and leaf nodes at different levels. This segmentation allows the system to analyze anomalies at multiple granularities - from individual probe locations to entire network regions - enabling both precise local detection and comprehensive root cause identification across the distributed network architecture.
Solution Approach 2:
The patent introduces a hierarchical dimension to the anomaly detection process by organizing network nodes into multiple levels (root nodes at higher levels, leaf nodes at lower levels). This dimensional transformation enables the system to detect anomalies not only at specific probe locations but also to trace them up the hierarchy to identify root cause nodes, thereby resolving the contradiction between localized detection precision and global localization capability.
2Reliability
If all abnormal nodes are processed equally, then comprehensive anomaly coverage is improved, but the efficiency of identifying root cause nodes deteriorates
Solution Approach 1:
The patent applies different processing qualities to different nodes based on their hierarchical position and anomaly characteristics. Root nodes receive prioritized processing with focused analysis on their descendant abnormal nodes, while leaf nodes undergo standard anomaly detection. This differentiated approach ensures comprehensive coverage of all abnormal nodes while efficiently concentrating resources on identifying root cause nodes at higher hierarchical levels.
Solution Approach 2:
Instead of applying full analytical resources to every abnormal node, the system performs partial analysis at leaf nodes and directs excessive (intensified) analysis resources toward root nodes that are suspected of causing widespread anomalies. This selective allocation of analytical effort maintains comprehensive coverage while dramatically improving root cause identification efficiency.
3Reliability
If a comprehensive analysis of all nodes is performed, then complete anomaly detection is improved, but the time and computational resources required deteriorates
Solution Approach 1:
The system performs preliminary anomaly detection at leaf nodes first, identifying abnormal conditions before propagating analysis upward to root nodes. This preliminary action at the network periphery allows the system to filter and prioritize which root nodes require intensive analysis, thereby reducing overall detection time while maintaining complete anomaly detection through the hierarchical progression from leaves to roots.
Data Source
AI summary
Example methods disclosed herein to prioritize anomalies in a communication network include classifying respective nodes in the communication network as normal, abnormal or indeterminate based on measurements received for the nodes. Disclosed example methods also include selecting a subset of the nodes classified as abnormal to be root cause abnormal nodes representing sources of the anomalies in the communication network, respective ones of the root cause abnormal nodes being abnormal nodes identified in the communication network and determined to have respective sets of direct descendent nodes having majorities of nodes classified as abnormal or indeterminate. Disclosed example methods further include combining respective anomaly sizes and anomaly scopes determined for the respective ones of root cause abnormal nodes based on the measurements to determine respective rankings for the root cause abnormal nodes, and outputting the respective rankings to prioritize the set of root cause abnormal nodes.


