Network Anomaly Diagnosis Using Customer Probes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer network providers face challenges in efficiently detecting and diagnosing network anomalies due to the complexity and fragmentation of monitoring software, often resulting in missed problems amidst false-positive error reports.

Innovation Solution

A method and system that receive network anomaly reports from customers, associate them with attributes, detect anomalies by comparing report volumes to historical baselines, and preferentially allocate repair resources based on identified issues, using a database and modules for receiving, linking, monitoring, analysis, and allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple different monitoring programs are used to monitor different aspects of the network, then comprehensive network monitoring coverage is achieved, but the complexity of the monitoring system increases and makes it difficult to detect problems efficiently

Engineering Contradiction:
Improvenetwork monitoring coverageVSAvoidmonitoring system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines multiple fragmented monitoring programs into a single unified monitoring system that collects, correlates, and analyzes network anomaly reports from various sources. This unified approach maintains comprehensive monitoring coverage while reducing system complexity by providing a centralized platform for problem detection and analysis.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If comprehensive network monitoring is implemented, then more network problems are detected, but false-positive error reports increase and cause problems to be mistakenly ignored

Engineering Contradiction:
Improveproblem detection capabilityVSAvoidsignal-to-noise ratio
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system implements feedback mechanisms where anomaly reports are correlated with historical data, network configurations, and other relevant information. This feedback loop enables the system to learn from past experiences, distinguish true anomalies from false positives, and improve detection accuracy over time while maintaining comprehensive monitoring coverage.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary analysis layer that processes raw anomaly reports before presenting them to operators. This intermediary layer correlates multiple reports, filters false positives, and prioritizes genuine problems, thereby maintaining high detection reliability while reducing the noise of false-positive error reports.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If manual analysis of network anomaly reports is performed, then detailed investigation of each anomaly is possible, but the time required to detect and respond to problems increases

Engineering Contradiction:
Improveanomaly analysis depthVSAvoidproblem detection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary automated analysis of network anomaly reports, pre-processing and correlating data before human operators need to review it. This preliminary action filters obvious false positives, groups related anomalies, and prepares prioritized lists for operator review, thereby maintaining detailed analysis capability while significantly reducing the time required for problem detection and response.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9973397B2Diagnosis of network anomalies using customer probes
Publication Date: 2018.05.15 GUAVUS INC
  • US9973397B2 patent drawing
  • US9973397B2 patent drawing
  • US9973397B2 patent drawing

AI summary

Methods, apparatuses and systems for diagnosing network anomalies and allocating repair resources in a computer network receive network anomaly reports (NARs) from a group of customers. Each NAR specifies a network anomaly observed by a customer at a network endpoint. Each NAR is entered into a database and associated in the database with attributes including at least one customer attribute associated with the sender of that NAR or network attribute associated with the network anomaly specified in that NAR. A time period is detected during which the difference between an aggregate number of NARs received within that time period and a baseline number of NARs received during prior time periods of substantially identical duration exceeds a threshold. The attributes associated with the NARs received during the time period are analyzed to identify a network anomaly specified in those NARs. Repair resources are further preferentially allocated to the identified network anomaly.