ML Anomaly Detection for Multi-Layer Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional anomaly detection in networks is reactive, time-consuming, and requires extensive expertise, struggling to scale with large and complex networks, and lacks accuracy due to reliance on rule-based engines and manual interventions.

Innovation Solution

Implementing supervised machine learning using Performance Monitoring data to build classifiers that differentiate between normal and anomalous behavior, enabling real-time detection and proactive alerts by analyzing multivariate data across optical, TDM, and packet layers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If rule-based engines with hard-coded if-else statements are used for anomaly detection, then the system can detect anomalies using simple thresholds, but the reaction time is slow and engineering time is expensive

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidreaction time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-training machine learning models with historical network data before deployment. The models learn normal and anomalous patterns in advance, enabling real-time detection without requiring complex rule-based analysis during actual anomaly events. This preliminary training phase stores knowledge that accelerates subsequent detection operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the mechanical rule-based engine with a machine learning-based system. Instead of using hard-coded if-else statements and manual threshold comparisons, the system employs trained models that automatically learn complex patterns from data. This substitution eliminates the need for manual rule creation and enables faster, more accurate real-time detection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual investigation and remediation are performed after failure, then the system can address problems, but the approach is reactive and involves traffic loss

Engineering Contradiction:
Improvenetwork availabilityVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary detection using pre-trained machine learning models that continuously analyze network data in real-time. By detecting anomalies before they escalate into failures, the system enables proactive remediation actions. This preliminary detection phase prevents the need for reactive responses that cause traffic loss and service interruptions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where detected anomalies trigger automated or guided remediation actions, and the outcomes feed back into the model for continuous improvement. This closed-loop system learns from each incident, progressively improving detection accuracy and enabling faster response times, thereby maintaining network availability without traffic loss.

Inventive Principle:
Principle #23Feedback

3Device complexity

If conventional rule-based approaches are used, then the system can operate with simple thresholds, but it does not scale with large and complex networks

Engineering Contradiction:
Improvesystem simplicityVSAvoidscalability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal machine learning platform that can detect anomalies across diverse network types, protocols, and devices. The system processes multiple data formats and adapts to different network configurations through automated feature extraction and model training. This universal approach eliminates the need for separate rule sets for each network type, enabling seamless scaling from small to large complex networks while maintaining operational simplicity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system replaces manual rule-based management with automated machine learning operations. The ML models automatically adapt to new network configurations and patterns through continuous learning from data, eliminating the need for manual rule updates and expert intervention. This automation enables the system to scale efficiently across large complex networks without proportionally increasing operational complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Measurement precision

If experts are required for anomaly detection, then the system can achieve accurate detection, but experts are rare and engineering time is expensive

Engineering Contradiction:
Improvedetection accuracyVSAvoidoperational complexity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system implements self-service capabilities through automated machine learning model training and deployment. The platform automatically processes historical data, trains detection models, validates performance, and deploys them without requiring expert intervention. This self-service automation captures expert knowledge within the models, enabling accurate anomaly detection to be performed by standard operational personnel rather than requiring rare experts.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the need for human experts with automated machine learning systems. The models encode complex detection logic and pattern recognition capabilities that previously required expert knowledge. By substituting human expertise with algorithmic intelligence, the system maintains high detection accuracy while dramatically reducing operational complexity and eliminating dependency on rare skilled personnel.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11792217B2Systems and methods to detect abnormal behavior in networks
Publication Date: 2023.10.17 CIENA CORP
  • US11792217B2 patent drawing
  • US11792217B2 patent drawing
  • US11792217B2 patent drawing

AI summary

Systems and methods include receiving a machine learning model that is configured to detect anomalies in network devices operating in a multi-layer network, wherein the machine learning model is trained via unsupervised learning that includes training the machine learning model with unlabeled data that describes an operational status of the network devices over time; receiving live data related to a current operational status of the network devices; analyzing the live data with the machine learning model; and detecting an anomaly related to any of the network device based on the analyzing.