Predictive Network Analytics for Proactive Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise networks with tens of thousands of devices face challenges in monitoring performance in real-time, leading to delayed detection of anomalies that can escalate into problems, as existing tools are insufficient for assessing how the performance of one device or service impacts others.
Innovation Solution
Implementing a system that monitors and analyzes performance metrics of network entities, using predictive analytics to forecast potential issues by determining statistical likelihoods and issuing alerts before problems arise, enabling proactive management within a remote network management platform.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional monitoring tools are used to detect performance issues, then issues can be detected after they occur, but the detection is delayed and cannot predict future problems
Solution Approach 1:
The system performs preliminary actions by analyzing historical performance data and establishing baseline patterns before anomalies occur. This enables the system to predict future performance issues and alert operators in advance, rather than waiting for problems to manifest. The predictive analytics component continuously processes data to identify potential issues before they impact service delivery.
Solution Approach 2:
Instead of waiting for performance degradation to trigger alerts, the system inverts the approach by predicting future degradation based on historical patterns. The anomaly detection works backwards from expected baseline behavior to identify deviations, and the predictive analytics moves forward in time to forecast potential issues, effectively reversing the traditional reactive monitoring paradigm.
2Loss of information
If comprehensive performance monitoring is implemented across all network entities, then complete visibility is achieved, but system complexity increases
Solution Approach 1:
The system extracts and separates the predictive analytics functionality from traditional monitoring tools, creating a dedicated component that handles pattern recognition and forecasting. This extraction allows the monitoring system to maintain comprehensive data collection while offloading complex analytical processing to a specialized module, thereby managing overall system complexity.
Solution Approach 2:
The predictive analytics component serves as an intermediary between raw performance data collection and operational decision-making. It processes comprehensive performance data from multiple network entities, identifies patterns and anomalies, and presents simplified predictions and recommendations to operators, thereby managing the complexity of comprehensive monitoring.
3Speed
If real-time analysis of all performance data is performed, then immediate detection is possible, but computational resources are consumed
Solution Approach 1:
The system applies partial action by focusing computational resources on analyzing only the most critical performance metrics and network entities that have historical patterns indicating potential issues. Rather than uniformly processing all data at maximum depth, the predictive analytics selectively intensifies analysis where anomalies are most likely to occur, reducing overall computational consumption while maintaining detection speed for critical issues.
Data Source
AI summary
A computing system and method for remote monitoring and forecasting of performance of a managed network is disclosed. The computing system may be disposed within a remote network management platform and be configured for monitoring respective performance of each of a plurality of network entities of the managed network. For each network entity, an alert may be issued in response to determining that the monitored respective performance is below a respective threshold performance level. Based on analysis of a group of alerts, a likelihood may be determined that a different alert will be issued for the monitored performance of a particular network entity of the plurality for which no respective alert has yet been issued. In response to the likelihood exceeding a threshold, an alert prediction for the performance of the particular network entity may be issued together with a score corresponding to the likelihood.


