Network Data Collection Flaw Detection via Metric Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network metrics collected using different techniques, such as SNMP and netflow, often fail to match precisely due to differences in sampling and timing, leading to potential configuration errors and flaws in network anomaly detection systems.

Innovation Solution

A computer-implemented method compares metrics from different data flows collected using SNMP and netflow techniques to detect incongruities, employing a system with a network evaluation server, data collector modules, and provisioning databases to identify and alert on potential configuration flaws before passing data to anomaly detection systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple network data collection techniques (SNMP and netflow) are used to collect metrics, then the reliability of anomaly detection is improved, but the complexity of data collection increases

Engineering Contradiction:
Improveanomaly detection reliabilityVSAvoiddata collection complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component that receives and compares metrics from multiple data collection techniques (SNMP and netflow). This intermediary acts as a mediator that reconciles the differences between the two techniques by comparing their outputs and identifying incongruities, thereby maintaining reliability while managing the complexity of using multiple collection methods.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If metrics from different data collection techniques are compared to detect flaws, then the precision of data quality assessment is improved, but the time required for data processing increases

Engineering Contradiction:
Improvedata quality assessment precisionVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by comparing metrics from different data collection techniques before the data is used for anomaly detection. By performing the comparison and flaw detection in advance, the system ensures high precision in data quality assessment while minimizing the time impact on the main anomaly detection process, as the comparison is done proactively rather than reactively.

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If network operational flaws are detected by comparing metrics, then the purity of collected data is improved, but the complexity of the detection system increases

Engineering Contradiction:
Improvedata purityVSAvoiddetection system complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where metrics from multiple data collection techniques are continuously compared and the results are used to identify operational flaws. This feedback loop allows the system to maintain high data purity by detecting and flagging inconsistencies, while the complexity is managed through automated comparison algorithms that systematically evaluate the feedback from multiple sources.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10742672B2Comparing metrics from different data flows to detect flaws in network data collection for anomaly detection
Publication Date: 2020.08.11 LEVEL 3 COMMUNICATIONS LLC
  • US10742672B2 patent drawing
  • US10742672B2 patent drawing
  • US10742672B2 patent drawing

AI summary

In an embodiment, a computer-implemented method compares metrics from different data flows to detect flaws in collection of data describing operation of a network. The method uses a first network data collection technique to collect a first metric describing a characteristic of a network interface. Using a second network data collection technique different from the first network data collection technique, a second metric describing the characteristic of the network interface is collected. The first metric is compared with the second metric to determine whether the first and second metrics are incongruous. When the first and second metrics are determined to be incongruous, a flaw is detected to exist in the first or second network data collection techniques.