Network Event Correlation with Application Performance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network monitoring tools fail to effectively correlate application performance drops with network events, as they operate on distinct sets of information, preventing network administrators from determining if network events impact application performance.
Innovation Solution
A method and network device that determine the physical topology of a network, monitor network events based on control plane information, and correlate performance drops of applications with detected network events to identify causes, enabling remedial actions to improve network processing and application performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network monitoring tools operate on distinct sets of information for network events and application performance, then they can independently monitor each aspect, but they fail to correlate the two to determine if network events impact application performance
Solution Approach 1:
The patent merges previously separate network event monitoring and application performance monitoring into a unified system. The network device correlates control plane information (network events) with application plane information (performance metrics) by establishing temporal and causal relationships between them, enabling precise identification of which network events cause application performance drops.
Solution Approach 2:
The patent introduces an intermediary correlation mechanism that connects network events and application performance. This intermediary layer analyzes temporal sequences, establishes causal relationships, and bridges the information gap between distinct monitoring domains, allowing administrators to determine impact relationships without directly merging the monitoring tools themselves.
2Ease of operation
If network administrators use traditional monitoring tools, then they can monitor network events and application performance separately, but they cannot determine the cause of performance drops
Solution Approach 1:
The patent implements feedback mechanisms where the system continuously monitors both network events and application performance, then feeds this correlated information back to administrators. When performance drops occur, the system automatically provides feedback identifying the triggering network events, transforming a complex analysis task into an automated feedback-driven process that maintains operational simplicity while enabling cause identification.
Solution Approach 2:
The patent performs preliminary correlation analysis by establishing relationships between network events and application performance before administrators need to investigate. The system pre-processes and correlates data in real-time, so when performance drops occur, the cause identification is already prepared and immediately available, eliminating the need for manual causal analysis.
3Reliability
If the system correlates application performance drops with network events, then it can identify causes of performance issues, but it requires integrating control plane information with application plane information
Solution Approach 1:
The patent makes the network device multi-functional by enabling it to perform both traditional network event monitoring and new application performance correlation functions. The same network device that monitors control plane information is enhanced to also analyze application plane information and correlate them, eliminating the need for separate specialized systems while maintaining diagnosis reliability.
Solution Approach 2:
The patent segments the correlation function into distinct analytical layers: temporal sequence analysis, causal relationship establishment, and impact determination. This segmentation allows the complex integration task to be broken down into manageable functional modules that process control plane and application plane information separately before synthesizing correlated results, reducing overall system complexity.
Data Source
AI summary
In some implementations, a method is provided. The method includes determining a physical topology of a network and monitoring network events based, at least in part, on control plane information received from one or more devices in the network. The method also includes monitoring the performance of each of a plurality of applications running on the network based, at least in part, on a set of application calls initiated by each application. When a drop in performance of an application is detected, the drop in performance is correlated with one or more of a plurality of detected network events to determine a cause of the drop in performance.


