Network Agent Anomaly Detection for Distributed Transaction Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current application monitoring tools fail to provide detailed insights into how application performance is affected by network issues in distributed web services, making it difficult for administrators to diagnose performance problems accurately.

Innovation Solution

A system that monitors both applications and network flows during business transactions, using network agents to capture and analyze packets and data to detect anomalies, and reports performance data in terms of both application and network performance, providing a comprehensive view of performance issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If standard application monitoring tools are used, then application performance data is collected, but network performance issues affecting the application cannot be identified

Engineering Contradiction:
Improveperformance diagnosis accuracyVSAvoidnetwork performance information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent combines application monitoring and network monitoring into a unified system. Application agents collect application performance data while network agents simultaneously collect network flow data, and both are correlated together to provide comprehensive performance diagnosis that identifies both application and network issues affecting business transactions.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces network agents as intermediary components that capture network flow data between applications and external systems. These agents act as mediators that observe network traffic without interfering with application operations, enabling indirect measurement of network performance impact on applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If distributed web services are expanded across multiple machines, then service capability is improved, but monitoring and tracking becomes more difficult

Engineering Contradiction:
Improveservice distribution capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the monitoring system into distributed components: application agents deployed on individual application machines, network agents deployed on network infrastructure, and a central server that aggregates data. This segmentation allows the monitoring system to scale with the distributed architecture without becoming unmanageable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal monitoring framework that can monitor multiple types of data (application metrics, network flow data, business transaction performance) across multiple machines and network configurations. The system is designed to work with distributed web services regardless of specific topology or technology stack.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If detailed performance data is collected from both application and network, then diagnosis capability is improved, but data collection complexity increases

Engineering Contradiction:
Improveperformance measurement detailVSAvoidmonitoring system structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent divides detailed data collection into specialized segments: application agents handle application-level metrics, network agents handle network-level flow data, and the central server handles correlation and analysis. This segmentation allows comprehensive data collection without requiring a single complex system to handle all aspects.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements self-service mechanisms where agents automatically discover and monitor relevant applications and network flows without manual configuration. The system autonomously correlates data from multiple sources and generates performance reports, reducing the operational complexity of managing detailed monitoring.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10212063B2Network aware distributed business transaction anomaly detection
Publication Date: 2019.02.19 CISCO TECHNOLOGY INC
  • US10212063B2 patent drawing
  • US10212063B2 patent drawing
  • US10212063B2 patent drawing

AI summary

A system monitors applications and network flows used during the business transaction to determine distributed business transaction anomalies caused at least in part by network performance issues. A network flow associated with a business transaction is monitored by a network agent. The network agent may capture packets, analyze the packets and other network data to determine one or more baselines, and dynamically compare subsequent network flow performance to those baselines to determine an anomaly. When an anomaly in a network flow is detected, this information may be provided to a user along with other data regarding a business transaction that is utilizing the network flow. Concurrently with the network agent monitoring, application agents may monitor one or more applications performing the business transaction. The present system reports performance data for a business transaction in terms of application performance and network performance, all in the context of a distributed business transaction.