Network Traffic Root Cause Detection via Data Mining
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current telecommunication networks lack pre-emptive fault detection capabilities, relying on reactive methods that fail to identify hidden problems, leading to inefficient issue resolution and potential service disruptions.
Innovation Solution
Implementing a system that continuously monitors network traffic using data mining techniques such as feature selection, covariance analysis, and cross-validation to detect issues before they become critical, allowing for proactive problem identification and solution implementation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If reactive fault detection methods are used in current telecommunication networks, then the system complexity remains low and operations support systems can handle basic fault management, but the system cannot detect hidden problems pre-emptively and must wait for alarms and event notifications to be triggered
Solution Approach 1:
The system performs preliminary actions by continuously analyzing network traffic information before faults occur. Data mining techniques are applied to detect patterns and anomalies that indicate potential problems, enabling the system to identify and address issues before they manifest as actual faults requiring alarm notifications.
Solution Approach 2:
An intermediary data mining system is introduced between the network traffic information generation and the traditional OSS fault management. This intermediary layer processes raw network data to extract meaningful patterns and predictions, bridging the gap between passive data collection and active fault detection without requiring complete system redesign.
2Measurement precision
If additional probing and active measurements are implemented to complement collected information, then more data is available for analysis, but the information is still received reactively via separate processes after problems are identified
Solution Approach 1:
The system implements continuous analysis of network traffic information using data mining techniques, eliminating the need for separate reactive probing processes. The continuous monitoring and pattern recognition occur continuously on existing traffic data, providing constant problem detection capability without interrupting normal network operations or requiring additional active measurements.
Solution Approach 2:
The patent replaces the mechanical approach of active probing and separate measurement processes with an information-based data mining system. Instead of mechanically injecting test signals into the network, the system uses computational analysis of existing traffic patterns to detect problems, substituting physical measurement mechanisms with information processing.
3Loss of information
If conventional fault management methods are used in OSS, then the system can handle basic alarm and event notification processing, but it is incapable of detecting hidden problems and patterns in network traffic information
Solution Approach 1:
The system changes the analytical parameters by applying data mining techniques that examine multiple dimensions of network traffic information simultaneously. Instead of relying on single threshold-based alarm parameters, the system analyzes patterns across multiple parameters including traffic volume, timing patterns, source/destination relationships, and error rates to detect hidden problems that conventional methods miss.
Solution Approach 2:
The patent adds another dimension to fault detection by introducing pattern recognition and predictive analytics to the traditional alarm-based OSS framework. This additional dimension of analysis transforms the system from reactive threshold monitoring to proactive pattern-based detection, enabling identification of hidden problems through multi-dimensional data correlation.
Data Source
AI summary
A device retrieves a first subset of events from data associated with a network, and determines one or more discriminating features of the first subset of events using a feature selection method. The device also retrieves one or more additional subsets of events, different than the first subset of events, from the data associated with the network, and cross validates the one or more discriminating features based on the one or more additional subsets of events. The device further detects a feature that is a root cause of a problem in the network based on the cross validated one or more discriminating features.


