SD-WAN Anomaly Detection via Machine-Trained Flow Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software-defined wide-area networks (SD-WANs) face challenges in detecting and autonomously remediating anomalies in real-time to ensure optimal application performance, particularly as workforces become distributed and applications migrate across multiple clouds, leading to network issues that impact end-user performance.

Innovation Solution

An anomaly detection and remediation system utilizing machine-trained processes within an Edge Network Intelligence (ENI) platform that analyzes flow data from multiple forwarding elements to identify anomalies and implement remedial actions, such as altering transit FE orders or routing paths, to improve network performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If manual monitoring and remediation of network anomalies is performed, then system complexity is reduced, but response time and productivity deteriorate

Engineering Contradiction:
Improvesystem complexityVSAvoidresponse time
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The system enables self-service through automated anomaly detection and remediation. Machine learning models continuously monitor network flow data, automatically identify anomalies, and trigger remedial actions without human intervention, allowing the network system to self-diagnose and self-heal performance issues

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual mechanical monitoring and remediation processes are replaced with automated electronic systems. Machine learning algorithms analyze network data and orchestrate remediation actions, substituting human-operated mechanical processes with intelligent automated systems that operate continuously without fatigue

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If real-time anomaly detection and remediation is implemented, then application performance is improved, but system complexity increases

Engineering Contradiction:
Improveapplication performanceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex anomaly detection and remediation functionality into distinct modular components: data collection modules at network edges, machine learning model components for anomaly detection, and automated remediation orchestration modules. This segmentation allows each component to be independently developed, deployed, and managed, reducing overall system complexity while maintaining real-time performance

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary orchestration layer is introduced between network monitoring and remediation actions. This intermediary layer coordinates between various network components, standardizes anomaly detection processes, and manages remediation workflows, thereby managing complexity through structured intermediation rather than direct point-to-point connections

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If automated remedial actions are implemented, then productivity is improved, but reliability may worsen due to potential incorrect actions

Engineering Contradiction:
Improveremediation efficiencyVSAvoidremediation accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements continuous feedback loops where remediation actions are monitored and their effects measured. Machine learning models learn from the outcomes of previous remediation actions, adjusting their detection and response strategies based on actual performance data. This feedback mechanism ensures that automated actions improve over time and maintain high reliability

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary analysis and validation before executing remediation actions. Machine learning models evaluate multiple potential remediation options and select the most appropriate action based on predicted outcomes. Pre-configured remediation playbooks ensure that only validated, proven-effective actions are automatically executed, maintaining reliability while improving productivity

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12057993B1Identifying and remediating anomalies in a self-healing network
Publication Date: 2024.08.06 VELOCLOUD NETWORKS LLC
  • US12057993B1 patent drawing
  • US12057993B1 patent drawing
  • US12057993B1 patent drawing

AI summary

Some embodiments of the invention provide a method of detecting and remediating anomalies in an SD-WAN implemented by multiple forwarding elements (FEs) located at multiple sites connected by the SD-WAN. The method receives, from the multiple FEs, multiple sets of flow data associated with application traffic that traverses the multiple FEs. The method uses a first set of machine-trained processes to analyze the multiple sets of flow data in order to identify at least one anomaly associated with at least one particular FE in the multiple FEs. The method uses a second set of machine-trained processes to identify at least one remedial action for remediating the identified anomaly. The method implements the identified remedial action by directing an SD-WAN controller deployed in the SD-WAN to implement the identified remedial action.