NFAT Correlation Engine for Network Status Determination
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network systems are inflexible and inefficient in determining the status of complex network conditions, failing to effectively collect, analyze, and report information necessary for scalable and dependable network performance, accessibility, configuration, and deployment.
Innovation Solution
A correlation policy management system utilizing a non-deterministic finite automata tree (NFAT) structure to evaluate complex network conditions, enabling simultaneous correlation of multiple events and policies, and facilitating automated actions based on collected data, with components like observability frameworks, message buses, data enrichers, correlation engines, and policy action managers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional network systems are used to determine network status, then system simplicity is maintained, but the ability to effectively collect, analyze, and report information for complex network conditions deteriorates
Solution Approach 1:
The patent segments the network monitoring system into distinct functional modules: event collectors that gather raw data from multiple sources, event processors that filter and normalize events, pattern matchers that apply correlation rules, and result generators that produce actionable insights. This segmentation allows each component to specialize in specific tasks, improving both reliability of status determination and productivity of information processing.
Solution Approach 2:
The patent introduces event processors and pattern matchers as intermediary components between raw event data and final network status determination. These intermediaries transform unstructured event streams into structured correlation results, enabling the system to effectively analyze complex network conditions while maintaining high processing efficiency through standardized transformation pipelines.
2Adaptability or versatility
If conventional correlation methods are used for network events, then implementation simplicity is maintained, but the ability to simultaneously correlate multiple events and policies deteriorates
Solution Approach 1:
The patent implements a universal correlation engine that can simultaneously handle multiple event types, correlation patterns, and policy rules through a single integrated architecture. The pattern matcher component uses regex-based pattern matching that can evaluate multiple events against multiple correlation rules in parallel, providing multi-event correlation capability without requiring separate specialized systems for each event type.
Solution Approach 2:
The patent uses template-based correlation rules that can be copied and instantiated multiple times with different parameters. Each correlation rule is defined as a reusable template that can be applied to different event streams and policy sets, allowing the system to correlate multiple events and policies simultaneously by instantiating the same correlation logic with different configurations rather than creating complex custom processing for each scenario.
3Adaptability or versatility
If static network configurations are used, then system stability is maintained, but network flexibility and scalability deteriorate
Solution Approach 1:
The patent implements dynamic correlation rules that can be modified, added, or removed at runtime without requiring system reconfiguration. The correlation engine continuously loads and applies correlation rules from configurable sources, allowing network monitoring behavior to adapt dynamically to changing network conditions and requirements while maintaining stable operation through continuous rule evaluation rather than static configuration.
Solution Approach 2:
The patent enables flexible network monitoring by allowing correlation rule parameters such as event thresholds, time windows, and pattern expressions to be dynamically adjusted. The system can change monitoring parameters on-the-fly based on network conditions, enabling scalable adaptation to different network sizes and complexities while maintaining stable correlation processing through parameterized rule evaluation rather than structural reconfiguration.
Data Source
AI summary
A method includes processing event data to detect a status of a network function. The event data is processed based on two or more conditions defined by a correlation policy. The correlation policy includes a non-deterministic finite automata tree (NFAT) structure correlation policy having a policy type. The method also includes determining a first value of a first condition of the two or more conditions. The method further includes determining a second value of a second condition of the two or more conditions. The method additionally includes determining the policy type of the NFAT structure correlation policy. The method also includes determining whether the first value is greater than a first preset value indicative of whether the first condition is satisfied. The method further includes determining whether the second value is greater than a second preset value indicative of whether the second condition is satisfied.


