Network Anomaly Monitoring With Correlated-Group Tagging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network monitoring systems struggle to efficiently process large amounts of real-time data for anomaly detection and management, particularly in wireless telecommunications networks, making it difficult for operators to identify and prioritize anomalies effectively.
Innovation Solution
A method and system for automatized monitoring of anomalies that involves receiving real-time network data, detecting anomalies, computing groups of correlated anomalies, and applying tags with associated conditions and actions, including user-defined and system-related tags, to facilitate automated anomaly detection and reconfiguration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If automated anomaly detection systems process all real-time network data, then anomaly detection capability is improved, but system complexity and processing burden increase
Solution Approach 1:
The patent segments the complex anomaly detection task into multiple processing stages: data collection from multiple sources, preliminary filtering to remove duplicate and low-value events, correlation analysis to group related anomalies, and prioritization ranking. This segmentation reduces system complexity by breaking down the monolithic processing burden into manageable modules while maintaining comprehensive anomaly detection capability.
Solution Approach 2:
The patent extracts and removes low-value data elements (duplicate alarms, noise events) from the processing stream before main analysis. By taking out irrelevant information early in the pipeline, the system reduces processing burden and complexity while focusing computational resources on significant anomalies that require attention.
2Measurement precision
If operators manually analyze large amounts of network monitoring data, then anomaly identification accuracy is improved, but time consumption and operational burden increase
Solution Approach 1:
The system performs preliminary actions by automatically collecting, filtering, correlating, and prioritizing anomalies before presentation to operators. This preliminary processing prepares the data in advance, organizing it into meaningful groups with assigned priority levels, so operators receive pre-processed information ready for decision-making rather than raw unprocessed data.
Solution Approach 2:
The patent introduces an automated processing system as an intermediary between raw network data and operator analysis. This intermediary performs initial filtering, correlation, and prioritization tasks, reducing the volume and complexity of data presented to operators while maintaining accuracy through systematic processing rules and algorithms.
3Reliability
If comprehensive anomaly monitoring is implemented across the entire network, then network reliability is improved, but resource consumption and processing load increase
Solution Approach 1:
The patent applies local quality by implementing differential processing strategies for different network elements and anomaly types. High-priority anomalies receive comprehensive analysis while lower-priority events undergo simplified processing. The system dynamically adjusts processing intensity based on anomaly severity, network criticality, and current system state, optimizing resource consumption while maintaining reliable monitoring coverage.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention concerns a method and system for automatized monitoring of anomalies during operation of a network, the method comprising: - receiving (70) real-time network data describing operation of the network, - processing (72) the received real-time network data to detect anomalies, and postprocessing anomalies to compute groups of correlated anomalies, the method further comprising : - configuring (74) tags relating to anomalies, each tag belonging to a tag category and having an associated identifier, an associated label, a condition field allowing to define one or several associated condition(s), - assigning (76) tags among the previously configured tags to groups of correlated anomalies, comprising automatic assigning of conditional tags if the associated condition or conditions is validated for said groups of correlated anomalies. Optionally, for each group of correlated anomalies tagged with a tag having at least one associated action, the at least one action is applied.