Network Event Correlation for Brink-of-Failure Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network monitoring technologies are labor-intensive and ineffective in preventing outages, as they fail to detect subtle and correlated events that can lead to catastrophic failures and security breaches, especially in data networks, which are less reliable than voice networks.

Innovation Solution

A system that continuously monitors and correlates network events to detect 'brink-of-failure' and 'breach-of-security' conditions, providing alerts and corrective actions to network administrators, using a combination of databases and correlation algorithms to prioritize events and predict potential outages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional network monitoring methods are used, then labor intensity is reduced, but detection precision and reliability of identifying correlated events leading to failures deteriorate

Engineering Contradiction:
Improvelabor intensityVSAvoiddetection precision
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary correlation engine that acts as a mediator between raw network events and failure detection. This engine correlates multiple seemingly unrelated events across different network elements to identify patterns that precede failures, thereby improving detection precision without requiring additional manual labor from operators.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual monitoring and analysis (mechanical human effort) with an automated computer-based correlation system. The system automatically collects, stores, and analyzes network events using software algorithms, eliminating the need for human operators to manually track and correlate events while significantly improving detection accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual network monitoring is performed, then detection capability is maintained, but productivity and responsiveness to impending failures deteriorate

Engineering Contradiction:
Improvedetection capabilityVSAvoidresponsiveness
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements continuous automated monitoring and correlation of network events without interruption. The system continuously collects events from multiple sources, constantly updates correlations, and maintains readiness to detect failure patterns at any moment, ensuring both reliable detection capability and immediate responsiveness when failures are imminent.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs self-monitoring and self-analysis of network events without requiring external human intervention. The correlation engine automatically processes events, identifies patterns, and generates alerts, enabling the system to maintain high detection capability and respond rapidly to failures independently of human operators.

Inventive Principle:
Principle #25Self-service

3Device complexity

If separate systems are used for reliability and security monitoring, then system complexity is reduced, but measurement precision of correlated network conditions deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidcorrelation accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent merges reliability monitoring and security monitoring into a unified correlation system. The single platform collects both reliability events (network failures, outages) and security events (unauthorized access, attacks) from the same network infrastructure, enabling cross-correlation between these previously separate domains to identify combined patterns that indicate impending failures or security breaches.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7363528B2Brink of failure and breach of security detection and recovery system
Publication Date: 2008.04.22 NOKIA OF AMERICA CORP
  • US7363528B2 patent drawing
  • US7363528B2 patent drawing
  • US7363528B2 patent drawing

AI summary

A method and apparatus for managing a network includes detecting occurrence of a network event associated with a new network condition including unplanned and planned macro-events associated with network elements and communication links of the network. The network event is classified as being associated with at least one of a network element failure, communications link failure, and a security breach. In response to the network event exceeding a network degradation threshold, the network event is identified as a network degradation event, and an alert is sent to a network administrator to normalize the network degradation event.