Networking Device Anomaly Detection via Counter Relationship Modeling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Analyzing logs from networking devices is tedious and inefficient, as most data is normal, with only a small percentage representing anomalies, and relying on human operators to monitor individual counters is difficult due to the complexity of interrelationships between counters.
Innovation Solution
A monitoring process that compares a networking device's configuration to an object relationship model to identify sets of related counters, using machine learning-based anomaly detection to generate alerts for detected anomalies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If human operators monitor individual counters to detect anomalies, then detection capability is maintained, but the process becomes extremely tedious and inefficient
Solution Approach 1:
The system enables self-service anomaly detection by automatically collecting counter data from networking devices, processing it through machine learning models, and generating anomaly alerts without requiring human operators to manually monitor individual counters. The anomaly detection system serves itself by autonomously identifying patterns and relationships between counters that would be impossible for human operators to detect efficiently
Solution Approach 2:
The patent replaces the mechanical process of human operators manually monitoring and analyzing counter data with an automated electronic system using machine learning algorithms. The system substitutes human cognitive processing with computational models that can rapidly analyze counter relationships and detect anomalies, dramatically improving detection efficiency while reducing operational complexity
2Ease of operation
If counters are viewed in isolation to simplify monitoring, then individual counter analysis becomes straightforward, but underlying network events are overlooked
Solution Approach 1:
The system merges the analysis of multiple individual counters by collecting and processing counter data from various networking devices simultaneously. The machine learning models combine information from numerous counters to detect patterns and relationships that would be invisible when examining counters in isolation, thereby improving anomaly detection accuracy while maintaining ease of operation through automated processing
Solution Approach 2:
The patent introduces machine learning models as intermediaries between raw counter data and anomaly detection. These intermediary processing layers analyze counter relationships and generate meaningful insights, bridging the gap between simple individual counter monitoring and complex multi-counter pattern recognition, thereby improving detection accuracy without exposing the complexity to operators
3Measurement precision
If machine learning-based anomaly detection is implemented, then anomaly detection accuracy is improved, but system complexity increases
Solution Approach 1:
The system segments the anomaly detection functionality into distinct modular components: counter data collection modules that gather data from networking devices, machine learning model processing modules that analyze the data, and alert generation modules that communicate anomalies. This segmentation allows each component to be independently optimized and managed, reducing overall system complexity while maintaining high detection accuracy through specialized processing in each segment
Data Source
AI summary
In one embodiment, a monitoring process identifies a set of counters maintained by a networking device by comparing a configuration of the networking device to an object relationship model. The monitoring process obtains counter values from the identified set of counters maintained by the networking device. The monitoring process detects an anomaly by using the obtained counter values as input to a machine learning-based anomaly detector. The monitoring process generates an anomaly detection alert for the detected anomaly.


