Network Component Overload Diagnosis via Scaled Composite Weighting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for identifying causes of threshold notifications in network traffic are inefficient and prone to inaccuracies, especially in complex networks with multiple interconnected devices, requiring manual analysis and relying heavily on administrative expertise.
Innovation Solution
A method and system that identifies overloaded network components, determines contributing factors from packet information, calculates a scaled composite weight, and stores common factors to facilitate prompt control actions and periodic updates for network management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual analysis methods are used to identify causes of threshold notifications, then administrative expertise can be applied to diagnose network issues, but the process becomes inefficient and time-consuming
Solution Approach 1:
The system performs self-diagnosis by automatically analyzing threshold notifications and identifying contributing factors without requiring manual administrative intervention. The network monitoring system autonomously correlates events, analyzes packet data, and determines root causes, enabling the system to serve itself in the diagnostic process.
Solution Approach 2:
Manual mechanical analysis processes are replaced with automated computational methods. The system uses algorithmic event correlation, automated packet data analysis, and computational weighting mechanisms to substitute human administrative expertise with machine-based diagnostic processes, significantly reducing analysis time while maintaining or improving accuracy.
2Measurement precision
If comprehensive packet data analysis is performed to accurately identify contributing factors, then diagnostic accuracy improves, but resource utilization increases
Solution Approach 1:
The system extracts only the essential and relevant features from packet data that are necessary for identifying contributing factors. Rather than analyzing all packet data comprehensively, the system selectively extracts key attributes such as source/destination addresses, packet types, and flow characteristics that directly contribute to threshold violations, reducing computational overhead while maintaining diagnostic accuracy.
Solution Approach 2:
The system applies different levels of analysis depth to different data elements based on their relevance. High-priority fields such as event correlation data and packet header information receive detailed analysis, while less critical data receives minimal processing. This localized quality approach optimizes resource utilization by concentrating computational effort where it provides the most diagnostic value.
3Adaptability or versatility
If multiple network components are monitored simultaneously to identify common factors, then the scope of detection increases, but system complexity increases
Solution Approach 1:
The system merges the monitoring functions into a unified event correlation mechanism that handles multiple network components simultaneously. By combining event data, packet data, and threshold information into a single correlated analysis framework, the system manages complex multi-component monitoring without proportionally increasing overall system complexity. The unified approach allows scalable expansion to additional components.
Solution Approach 2:
The event correlation system is designed as a universal platform that can monitor and analyze diverse network components including routers, switches, servers, and communication devices. The system uses standardized event formats and universal correlation algorithms that work across different device types, enabling broad monitoring scope without requiring device-specific complex processing for each component type.
Data Source
AI summary
Disclosed are a method, system, and computer program product for identifying one or more common factors or causes which explain the one or more network threshold violations. In one embodiment, the method or the system identifies one or more network components within a network and then identifies which of the one or more network components is overloaded. The method or the system then identifies one or more simple factors for the identified network components where the one or more simple factors constitute one or more causes for overloaded network activity. The method or the system then determines a scaled composite weight for a simple factor to determine whether the scaled composite weight exceeds a second threshold. If certain simple factors are determined to exceed the second threshold, such simple factors are added to a list of common factors which are in turn stored in a tangible computer accessible medium.


