Networking Device Anomaly Detection via Counter Relationship Modeling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Analyzing logs from networking devices is tedious and inefficient, as most data is normal, with only a small percentage representing anomalies, and relying on human operators to monitor individual counters is difficult due to the complexity of interrelationships between counters.

Innovation Solution

A monitoring process that compares a networking device's configuration to an object relationship model to identify sets of related counters, using machine learning-based anomaly detection to generate alerts for detected anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If human operators monitor individual counters to detect anomalies, then detection capability is maintained, but the process becomes extremely tedious and inefficient

Engineering Contradiction:
Improveanomaly detection efficiencyVSAvoidmonitoring complexity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The system enables self-service anomaly detection by automatically collecting counter data from networking devices, processing it through machine learning models, and generating anomaly alerts without requiring human operators to manually monitor individual counters. The anomaly detection system serves itself by autonomously identifying patterns and relationships between counters that would be impossible for human operators to detect efficiently

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical process of human operators manually monitoring and analyzing counter data with an automated electronic system using machine learning algorithms. The system substitutes human cognitive processing with computational models that can rapidly analyze counter relationships and detect anomalies, dramatically improving detection efficiency while reducing operational complexity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If counters are viewed in isolation to simplify monitoring, then individual counter analysis becomes straightforward, but underlying network events are overlooked

Engineering Contradiction:
Improvecounter analysis simplicityVSAvoidanomaly detection accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system merges the analysis of multiple individual counters by collecting and processing counter data from various networking devices simultaneously. The machine learning models combine information from numerous counters to detect patterns and relationships that would be invisible when examining counters in isolation, thereby improving anomaly detection accuracy while maintaining ease of operation through automated processing

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces machine learning models as intermediaries between raw counter data and anomaly detection. These intermediary processing layers analyze counter relationships and generate meaningful insights, bridging the gap between simple individual counter monitoring and complex multi-counter pattern recognition, thereby improving detection accuracy without exposing the complexity to operators

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If machine learning-based anomaly detection is implemented, then anomaly detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the anomaly detection functionality into distinct modular components: counter data collection modules that gather data from networking devices, machine learning model processing modules that analyze the data, and alert generation modules that communicate anomalies. This segmentation allows each component to be independently optimized and managed, reducing overall system complexity while maintaining high detection accuracy through specialized processing in each segment

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11277424B2Anomaly detection for a networking device based on monitoring related sets of counters
Publication Date: 2022.03.15 CISCO TECHNOLOGY INC
  • US11277424B2 patent drawing
  • US11277424B2 patent drawing
  • US11277424B2 patent drawing

AI summary

In one embodiment, a monitoring process identifies a set of counters maintained by a networking device by comparing a configuration of the networking device to an object relationship model. The monitoring process obtains counter values from the identified set of counters maintained by the networking device. The monitoring process detects an anomaly by using the obtained counter values as input to a machine learning-based anomaly detector. The monitoring process generates an anomaly detection alert for the detected anomaly.