Network Anomaly Detection Models for Real-Time Fault Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless network operators face inefficiencies in detecting and classifying anomalies due to reliance on outdated methods, such as static thresholds and human inspection, which can lead to delayed identification of potential problems affecting user experience.

Innovation Solution

A system architecture that implements machine learning models for real-time anomaly detection and classification, utilizing an online computing node to parse network data, detect anomalies, and periodically update models through an offline storage and training function, enabling proactive identification and autonomous issue resolution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If static thresholds are used for anomaly detection, then the system is simple to operate, but it fails to detect abnormal network behaviors that manifest as spikes or gradual trends

Engineering Contradiction:
Improvesimplicity of anomaly detectionVSAvoidaccuracy of anomaly detection
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent replaces static threshold-based mechanical anomaly detection with machine learning models that automatically learn optimal detection thresholds from historical network data. The ML models analyze patterns in network parameters and dynamically adjust detection criteria, substituting rigid mechanical thresholding with adaptive intelligent detection that accurately identifies spikes, gradual trends, and other abnormal behaviors without manual configuration.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If network monitor teams visually inspect resource usage, then human expertise can be applied, but it takes a lot of time and human resources to collect and plot data

Engineering Contradiction:
Improveability to spot abnormal trendsVSAvoidtime to collect and plot data
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements self-service anomaly detection where machine learning models automatically collect, process, and analyze network data without requiring human teams to manually plot and inspect resource usage. The system autonomously learns from historical data, detects anomalies in real-time, and generates insights, eliminating the time-consuming manual data collection and visual inspection processes while maintaining or improving detection accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent substitutes manual visual inspection by human monitor teams with automated machine learning-based detection systems. The ML models process large volumes of network data rapidly, identifying abnormal trends and patterns that would be difficult for humans to spot manually, while significantly reducing the time required for data collection, plotting, and analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If more network parameters are monitored, then detection accuracy improves, but the complexity of data collection and analysis increases

Engineering Contradiction:
Improvecomprehensive anomaly detectionVSAvoidcomplexity of data processing system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent employs universal machine learning models that can handle multiple network parameters simultaneously through a unified detection framework. The ML models are designed to process diverse network metrics (throughput, latency, packet loss, etc.) using the same underlying algorithms, eliminating the need for separate detection mechanisms for each parameter and reducing overall system complexity while maintaining comprehensive monitoring capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the analysis of multiple network parameters into a unified anomaly detection process using machine learning models. Instead of analyzing each parameter separately with individual threshold rules, the ML models integrate multiple parameters and their interrelationships, detecting anomalies based on combined patterns across all monitored metrics, thereby simplifying the data processing architecture.

Inventive Principle:
Principle #5Merging (Combining)

4Adaptability or versatility

If human teams inspect network data, then contextual understanding can be applied, but delays occur in identifying potential problems

Engineering Contradiction:
Improvecontextual analysis capabilityVSAvoiddelay in identifying problems
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent replaces manual contextual analysis by human teams with machine learning models that automatically learn contextual relationships from historical network data. The ML models analyze patterns, correlations, and dependencies between different network parameters and time periods, enabling contextual understanding of anomalies without human intervention and eliminating the delays associated with manual inspection and interpretation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3871056B1Anomaly detection and classification in networked systems
Publication Date: 2023.05.03 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3871056B1 patent drawingFigure 1
  • EP3871056B1 patent drawingFigure 2
  • EP3871056B1 patent drawingFigure 3

AI summary

Systems and methods are disclosed for detecting and classifying faults in a networked system. An offline storage and training function (112) can store network data (208) and periodically train machine learning models (212, 214) for identifying faults. Machine learning models can include separate detection (212) and classification (214) models. These machine learning models (212, 214) can be periodically provided to an online anomaly detection function (106) and an online anomaly classification function (108) for detecting and classifying anomalies in real time.