Network Entity Group Anomaly Detection via Frequency Distribution Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network assurance systems face challenges in detecting network entity groups with abnormal time-evolving behavior, which can impact network performance due to changes in interference, environmental conditions, and configuration issues, especially in large-scale distributed systems like LLNs where traditional methods struggle with complexity and dynamic behavior.
Innovation Solution
A network assurance service that calculates frequency distributions of performance measurements over time, determines distance metrics between network and entity frequency distributions, and identifies outlier groupings based on changes in these metrics, providing an indication to user interfaces for actionable insights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional network monitoring methods are used to track network metrics, then basic network health assessment is achieved, but the system cannot detect abnormal time-evolving behavior of network entity groups in large-scale distributed systems
Solution Approach 1:
The patent segments the large-scale network into multiple entity groups based on spatial, functional, or topological characteristics. Instead of monitoring individual entities, the system aggregates entities into groups and monitors group-level metrics, reducing the complexity of detecting abnormal behaviors in large-scale distributed systems while maintaining detection precision.
Solution Approach 2:
The patent introduces a new dimension of analysis by examining the temporal evolution of network metrics. Instead of only monitoring static metric values, the system analyzes how metrics change over time, detecting abnormal time-evolving behaviors by comparing metric trajectories against expected patterns, thereby enhancing detection capability without proportionally increasing system complexity.
2Reliability
If comprehensive network metrics are tracked to assess network health, then user experience assurance is improved, but the complexity of analyzing large numbers of parameters increases
Solution Approach 1:
The patent merges multiple individual network metrics into aggregated group-level metrics. By combining metrics from multiple entities within an entity group, the system maintains comprehensive network health assessment while reducing the total number of parameters that need to be analyzed, thereby lowering analysis complexity.
Solution Approach 2:
The patent introduces entity groups as intermediary layers between individual network entities and the overall network system. These intermediary groups serve as aggregation points that summarize individual entity behaviors, enabling comprehensive monitoring without directly analyzing every individual parameter, thus reducing complexity while maintaining reliability.
3Measurement precision
If traditional anomaly detection methods are applied to individual network entities, then isolated issues can be detected, but abnormal behaviors of network entity groups with time-evolving patterns cannot be identified
Solution Approach 1:
The patent transitions from static anomaly detection to dynamic temporal analysis. Instead of detecting anomalies based on single-point metric values, the system monitors the evolution of metrics over time, detecting abnormal patterns in how metrics change. This dynamic approach improves detection accuracy for time-evolving behaviors while adapting to various network conditions and entity types.
Data Source
AI summary
In one embodiment, a network assurance service that monitors a network calculates network frequency distributions of a performance measurement from the network over a plurality of different time periods. The service calculates entity frequency distributions of the performance measurement for a plurality of different groupings of one or more network entities in the network over the plurality of different time periods. The service determines distance measurements between the network frequency distributions and the entity frequency distributions. The service identifies a particular one of the grouping of one or more networking entities as an outlier, based on a change in distance measurements between the network frequency distributions and the entity frequency distributions for the particular grouping. The service provides an indication of the identified outlier grouping to a user interface.


