NFV Alarm Causality Templates for Root Cause Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Identifying the root cause of alarms in a network function virtualization (NFV) architecture is complicated due to its multi-vendor layered nature, where different vendors provide hardware, virtual resources, and virtual functions, leading to diverse alarm definitions and making it difficult to pinpoint the source of failures or faults across various layers.
Innovation Solution
The use of causality templates learned from past data, including time series of alarms from virtual functions, virtual resources, and hardware resources, to define clusters of alarm types based on correlations and determine causal connections, allowing for real-time identification of root causes through directed graphs and logical relations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple vendors provide hardware, virtual resources, and virtual functions in NFV architecture, then system adaptability and operational efficiency are improved, but device complexity and difficulty of detecting and measuring root causes increase
Solution Approach 1:
The patent segments the complex NFV alarm system into multiple analysis layers: data collection layer (gathering alarms from hardware, virtual resources, and virtual functions), data processing layer (correlating alarms and identifying patterns), and root cause identification layer (determining causal relationships). This segmentation manages the complexity introduced by multi-vendor environments while preserving system adaptability.
Solution Approach 2:
The patent introduces an intermediary alarm correlation system that sits between the diverse alarm sources from multiple vendors and the root cause analysis process. This intermediary standardizes and correlates alarms from different vendors, making the complex multi-vendor environment manageable without reducing system adaptability.
2Productivity
If multiple vendors provide hardware, virtual resources, and virtual functions in NFV architecture, then system adaptability and operational efficiency are improved, but difficulty of detecting and measuring root causes increases
Solution Approach 1:
The patent performs preliminary actions by collecting and correlating alarm data in advance, building a comprehensive alarm database that captures relationships between alarms from different vendors. When root cause analysis is needed, this pre-processed data enables rapid detection and measurement, maintaining operational efficiency while reducing analysis difficulty.
Solution Approach 2:
The patent implements feedback mechanisms where alarm correlation results and root cause identification outcomes are fed back into the system to improve future analysis. This continuous feedback loop enhances the system's ability to detect and measure root causes in multi-vendor environments while maintaining high operational efficiency.
3Productivity
If dynamic resource allocation is implemented in NFV architecture, then operational efficiencies such as scaling and healing are improved, but device complexity and difficulty of fault management increase
Solution Approach 1:
The patent embraces the dynamic nature of NFV resource allocation by implementing a flexible alarm correlation system that can adapt to changing resource configurations. The system dynamically tracks relationships between alarms and resources, managing the complexity introduced by dynamic allocation while preserving operational efficiencies like scaling and healing.
4Productivity
If dynamic resource allocation is implemented in NFV architecture, then operational efficiencies such as scaling and healing are improved, but difficulty of fault management increases
Solution Approach 1:
The patent performs preliminary data collection and correlation during dynamic resource allocation events, building a historical record of alarm relationships as resources are created, migrated, or destroyed. This preliminary action enables easier fault management by having pre-analyzed data available when faults occur, maintaining operational efficiencies while reducing fault management difficulty.
Data Source
AI summary
A processor accesses a plurality of time series of alarms of a plurality of alarm types that are produced by resources of a network function virtualization (NFV) system. The processor identifies clusters of the plurality of alarm types based on similarities between the plurality of time series and determine causal connections between alarm types in the clusters based on temporal proximity and ordering of the alarm types in the clusters. The processor then stores one or more causality templates representative of the causal connections in a memory.


