Network State Restoration for Fast Anomaly Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network monitoring systems struggle to rapidly and effectively revert networks to a known-good state in response to anomalies such as DDOS attacks, route hijacking, or infrastructure failures, often leading to prolonged disruptions and potential overblocking of legitimate traffic.
Innovation Solution
A network monitoring system that collects and compares sets of metrics over time to detect anomalies, generates policies to revert the network to a previous known-good state, and applies these policies to restrict or limit anomalous traffic, using techniques like QoS, routing updates, and DNS adjustments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If network monitoring systems use traditional anomaly detection methods, then they can identify disruptive events, but they fail to rapidly revert networks to known-good states leading to prolonged disruptions
Solution Approach 1:
The system performs preliminary actions by continuously collecting and storing metrics data in temporal context windows before anomalies occur. When an anomaly is detected, pre-defined countermeasures are immediately applied based on the stored historical data, eliminating the need for analysis delays and enabling instant network restoration to known-good states.
Solution Approach 2:
The system implements self-service by automatically detecting anomalies through metric comparison and autonomously applying appropriate countermeasures without human intervention. The closed-loop system self-corrects network disruptions by reverting to previously identified good states, reducing overall response time and minimizing disruption duration.
2Reliability
If network monitoring systems apply aggressive countermeasures to stop anomalies, then they can limit disruptive events, but they risk overblocking legitimate traffic
Solution Approach 1:
The system applies local quality by implementing targeted countermeasures that affect only the specific anomalous traffic patterns detected, rather than applying blanket blocking rules. By analyzing metric deviations locally and applying precise countermeasures, the system mitigates anomalies effectively while preserving legitimate traffic flow that does not exhibit anomalous characteristics.
Solution Approach 2:
The system uses feedback mechanisms to continuously monitor the effects of applied countermeasures and adjust accordingly. By comparing post-countermeasure metrics against historical baselines, the system verifies that anomalies are stopped while legitimate traffic remains unaffected, preventing overblocking through real-time validation and adjustment.
3Adaptability or versatility
If network monitoring systems collect and analyze extensive metrics data, then they can detect various types of anomalies, but the complexity of processing and responding increases
Solution Approach 1:
The system applies segmentation by dividing metrics data into organized temporal context windows and categorizing them by type and source. This structured segmentation enables efficient processing of extensive metrics data through modular analysis, allowing the system to detect various anomaly types while maintaining manageable processing complexity through systematic data organization.
Solution Approach 2:
The system implements universality by creating a multi-functional metrics collection and analysis framework that handles multiple anomaly types through a unified approach. The same temporal context window structure and countermeasure application mechanism work across different anomaly scenarios, reducing overall system complexity while maintaining broad adaptability to various disruptive events.
Data Source
AI summary
A method for network anomaly detection and policy-based network state restoration includes collecting a first set of metrics associated with a network at a first time indicating a first state of the network and storing the first set of metrics in association with the first state in a memory at the first time. A second set of metrics associated with the network is collected at a second time indicating a second state of the network. An indication of an anomaly on the network is determined based on a comparison of the second set of metrics with the first set of metrics. A network policy is applied to revert the network from the second state to the first state by restoring configuration parameters and operational settings of the network to match the stored first set of metrics exactly as recorded at the first time in response to determining the indication of the anomaly. The network may be monitored in response to applying the network policy and action may be taken based on the monitoring.


