Network Assurance Service Data Modeling for ML Analyzer Stability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network assurance systems face challenges in detecting disruptive changes in data dynamics caused by software or configuration changes, which can affect the performance of machine learning-based analyzers and lead to incorrect assessments or suboptimal network control.

Innovation Solution

A network assurance service forms a reporting entity model based on data from monitored entities, identifies behavioral changes, correlates them to specific changes, and performs mitigation actions to prevent these changes from impacting the machine learning-based analyzer, using components like entity modeling engines, monitoring engines, and dynamics change correlators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network assurance systems continuously monitor network data to assess health, then network health assessment accuracy is improved, but the system becomes vulnerable to false alarms when software or configuration changes alter data dynamics

Engineering Contradiction:
Improvenetwork health assessment accuracyVSAvoidfalse alarm rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system performs preliminary actions by creating a baseline model of normal data dynamics before changes occur. When changes are detected, the system compares current data against this pre-established baseline to determine whether deviations represent actual network issues or expected behavior changes, thereby reducing false alarms while maintaining assessment accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where monitored network data is continuously fed back into the model to refine understanding of normal behavior patterns. This feedback loop allows the system to adapt to legitimate changes while maintaining the ability to detect actual anomalies, resolving the contradiction between accurate monitoring and false alarm reduction.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If the number of applications and metrics in the network increases, then network functionality and monitoring capability are improved, but the complexity of detecting disruptive changes increases

Engineering Contradiction:
Improvenetwork functionalityVSAvoiddetection complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments the complex network monitoring task by creating separate models for different network entities and metrics. Each model independently learns the normal behavior patterns of its specific domain, allowing the system to handle increased numbers of applications and metrics without proportionally increasing overall detection complexity through modular analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs universal detection mechanisms that can be applied across multiple different network applications and metrics simultaneously. The same foundational modeling and change-detection algorithms serve multiple purposes, allowing the system to scale its monitoring capabilities without linearly increasing complexity in the detection layer.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10623273B2Data source modeling to detect disruptive changes in data dynamics
Publication Date: 2020.04.14 CISCO TECHNOLOGY INC
  • US10623273B2 patent drawing
  • US10623273B2 patent drawing
  • US10623273B2 patent drawing

AI summary

In one embodiment, a network assurance service receives, from a reporting entity, data regarding a monitored network for input to a machine learning-based analyzer of the network assurance service. The service forms a reporting entity model of the reporting entity, based on at least a portion of the data received from the reporting entity. The service identifies a behavioral change of the reporting entity by comparing a sample of the data received from the reporting entity to the reporting entity model. The service correlates the behavioral change of the reporting entity to a change made to the reporting entity. The service causes performance of a mitigation action, to prevent the behavioral change from affecting operation of the machine learning-based analyzer.