Network State Restoration for Fast Anomaly Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network monitoring systems struggle to rapidly and effectively revert networks to a known-good state in response to anomalies such as DDOS attacks, route hijacking, or infrastructure failures, often leading to prolonged disruptions and potential overblocking of legitimate traffic.

Innovation Solution

A network monitoring system that collects and compares sets of metrics over time to detect anomalies, generates policies to revert the network to a previous known-good state, and applies these policies to restrict or limit anomalous traffic, using techniques like QoS, routing updates, and DNS adjustments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If network monitoring systems use traditional anomaly detection methods, then they can identify disruptive events, but they fail to rapidly revert networks to known-good states leading to prolonged disruptions

Engineering Contradiction:
Improveanomaly response speedVSAvoidnetwork disruption duration
Core Design Contradiction:
SpeedVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously collecting and storing metrics data in temporal context windows before anomalies occur. When an anomaly is detected, pre-defined countermeasures are immediately applied based on the stored historical data, eliminating the need for analysis delays and enabling instant network restoration to known-good states.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service by automatically detecting anomalies through metric comparison and autonomously applying appropriate countermeasures without human intervention. The closed-loop system self-corrects network disruptions by reverting to previously identified good states, reducing overall response time and minimizing disruption duration.

Inventive Principle:
Principle #25Self-service

2Reliability

If network monitoring systems apply aggressive countermeasures to stop anomalies, then they can limit disruptive events, but they risk overblocking legitimate traffic

Engineering Contradiction:
Improveanomaly mitigation effectivenessVSAvoidoverblocking of legitimate traffic
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The system applies local quality by implementing targeted countermeasures that affect only the specific anomalous traffic patterns detected, rather than applying blanket blocking rules. By analyzing metric deviations locally and applying precise countermeasures, the system mitigates anomalies effectively while preserving legitimate traffic flow that does not exhibit anomalous characteristics.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses feedback mechanisms to continuously monitor the effects of applied countermeasures and adjust accordingly. By comparing post-countermeasure metrics against historical baselines, the system verifies that anomalies are stopped while legitimate traffic remains unaffected, preventing overblocking through real-time validation and adjustment.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If network monitoring systems collect and analyze extensive metrics data, then they can detect various types of anomalies, but the complexity of processing and responding increases

Engineering Contradiction:
Improveanomaly type coverageVSAvoidsystem processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system applies segmentation by dividing metrics data into organized temporal context windows and categorizing them by type and source. This structured segmentation enables efficient processing of extensive metrics data through modular analysis, allowing the system to detect various anomaly types while maintaining manageable processing complexity through systematic data organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements universality by creating a multi-functional metrics collection and analysis framework that handles multiple anomaly types through a unified approach. The same temporal context window structure and countermeasure application mechanism work across different anomaly scenarios, reducing overall system complexity while maintaining broad adaptability to various disruptive events.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12526216B2Systems and methods for network anomaly detection and policy-based network state restoration
Publication Date: 2026.01.13 NETSCOUT SYSTEMS INC
  • US12526216B2 patent drawing
  • US12526216B2 patent drawing
  • US12526216B2 patent drawing

AI summary

A method for network anomaly detection and policy-based network state restoration includes collecting a first set of metrics associated with a network at a first time indicating a first state of the network and storing the first set of metrics in association with the first state in a memory at the first time. A second set of metrics associated with the network is collected at a second time indicating a second state of the network. An indication of an anomaly on the network is determined based on a comparison of the second set of metrics with the first set of metrics. A network policy is applied to revert the network from the second state to the first state by restoring configuration parameters and operational settings of the network to match the stored first set of metrics exactly as recorded at the first time in response to determining the indication of the anomaly. The network may be monitored in response to applying the network policy and action may be taken based on the monitoring.