Predicting Network Reactions During Disruptive Activity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large data center fabrics, it is challenging for network administrators to determine and focus on real issues during maintenance or disruptive activities due to the overwhelming number of alerts and anomalies that arise, making it difficult to distinguish between expected and unexpected events.
Innovation Solution
A method that determines disruptive activities within a computer network, collects time-relevant telemetry data, and uses machine learning to predict expected reactions, sharing these predictions with management devices to differentiate between anticipated and unexpected events, thereby providing a preview of potential anomalies before they occur.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If network administrators monitor all alerts and anomalies during disruptive activities, then complete visibility of network events is achieved, but the ability to distinguish between expected and unexpected events deteriorates due to overwhelming information volume
Solution Approach 1:
The system performs preliminary action by predicting expected reactions before disruptive activities occur. Machine learning models analyze historical data and generate predictions of anticipated alerts and anomalies prior to maintenance windows or device changes, allowing administrators to prepare for expected events and filter them during actual disruptions.
Solution Approach 2:
The system implements feedback by continuously comparing actual network reactions during disruptive activities against predicted reactions. This feedback loop allows the machine learning models to refine their predictions over time, improving accuracy in distinguishing between expected and unexpected events as more data becomes available.
2Reliability
If network administrators investigate all alerts and anomalies, then complete problem detection is achieved, but the time required to identify critical issues increases
Solution Approach 1:
The system performs preliminary detection by predicting which alerts and anomalies are most likely to occur during disruptive activities before they actually happen. This allows administrators to prioritize investigation of predicted critical issues rather than reviewing all alerts chronologically, significantly reducing time to identify problems while maintaining detection completeness.
Solution Approach 2:
The system extracts and separates expected events from unexpected events by using machine learning predictions as a filter. Expected reactions that were predicted in advance can be automatically acknowledged or filtered out, leaving only unexpected anomalies that require administrator attention, thus reducing investigation time while maintaining complete problem detection.
3Ease of operation
If the system provides detailed predictions of expected reactions, then the ability to filter unexpected events is improved, but the complexity of the monitoring and prediction system increases
Solution Approach 1:
The system uses copying by creating a virtual model of network behavior through machine learning predictions. Instead of adding complex real-time analysis components to every monitoring point, the system copies historical patterns and creates predictive models that can be applied consistently across the network, simplifying the overall architecture while improving event filtering capability.
Data Source
AI summary
In one embodiment, a method herein may comprise: determining, by a process, a disruptive activity within a particular computer network of a plurality of computer networks; determining, by the process, telemetry data for the particular computer network, the telemetry data being time-relevant to the disruptive activity; determining, by the process, a set of expected reactions that the particular computer network is expected to experience due to the disruptive activity in correlation to the telemetry data for the particular computer network; and sharing, from the process, the set of expected reactions with a management device of the particular computer network to cause the management device to distinguish between the set of expected reactions and any unexpected events during the disruptive activity.


