ML-Based Network Anomaly Prediction via Event Aggregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large-scale network deployments, identifying and managing network anomalies and errors is challenging due to concurrent processes and the difficulty in interpreting and scaling event or behavior logs, making it hard to maintain communication performance.

Innovation Solution

An electronic device with an interface circuit, memory, and a processor that implements a pretrained machine-learning model, such as a neural network, to aggregate event information, predict anomalies, and perform remedial actions, including alerts, corrections, and diagnostics based on aggregated data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If event or behavior logs are maintained for diagnostic purposes in large-scale networks, then network monitoring capability is improved, but the difficulty of interpreting and scaling logs increases

Engineering Contradiction:
Improvenetwork monitoring capabilityVSAvoidlog interpretation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces machine learning models as an intermediary between raw event logs and human operators. The ML models automatically analyze log data, identify patterns, and generate human-interpretable insights, thereby reducing the complexity of log interpretation while maintaining comprehensive monitoring capability in large-scale networks

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual log analysis (mechanical human interpretation) with automated machine learning systems. The ML models process and interpret event logs automatically, substituting the manual mechanical process of human analysis with an automated computational system that scales efficiently with network size

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If multiple processes run concurrently to manage large network deployments, then network management capability is improved, but the difficulty of identifying root cause increases

Engineering Contradiction:
Improvenetwork management capabilityVSAvoidroot cause identification difficulty
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms where machine learning models continuously analyze events from multiple concurrent processes, track correlations over time, and provide feedback about potential root causes. This feedback loop enables the system to maintain high management capability while reducing root cause identification difficulty through pattern recognition across process boundaries

Inventive Principle:
Principle #23Feedback

3Loss of information

If event logs are collected and stored for analysis, then diagnostic information availability is improved, but the difficulty of translating logs into human-interpretable format increases

Engineering Contradiction:
Improvediagnostic information availabilityVSAvoidlog translation ease
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent enables the system to serve itself by implementing automated machine learning models that independently analyze raw event logs and generate human-interpretable diagnostic information without requiring manual translation efforts. The ML system performs the translation function autonomously, maintaining full diagnostic information availability while eliminating the operational burden of manual log translation

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11652701B2Predicting network anomalies based on event counts
Publication Date: 2023.05.16 RUCKUS IP HOLDINGS LLC
  • US11652701B2 patent drawing
  • US11652701B2 patent drawing
  • US11652701B2 patent drawing

AI summary

An electronic device (such as a controller) is described. During operation, the electronic device receives, from a second electronic devices, information that specifies occurrences of different types of events in a network (which includes the second electronic devices). For example, the information may include counts of the occurrences of the different types of events in the network, which may be collected by the second electronic devices. Then, the electronic device aggregates the information about the different types of events in the network, and stores the aggregated information in memory. Moreover, the electronic device predicts an occurrence of an anomaly or an error in the network based at least in part on the aggregated information and a pretrained machine-learning model (such as a neural network). Next, the electronic device selectively performs a remedial action based at least in part on the prediction.