Service Model for Anomaly Detection in Shared Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing complex relationships between customers, services, and computing resources in a remote network management platform is challenging, leading to difficulties in tracking service dependencies and identifying impacts of resource failures, which can result in delayed recovery for customers.

Innovation Solution

A service model is implemented within the remote network management platform to capture and manage relationships between customers, services, and computing resources, using persistent storage and processors to determine affected customers and resources during anomalies or infrastructure updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a managed network maintains hundreds or thousands of computing resources to support various services, then the service capacity and functionality are improved, but the complexity of tracking relationships between customers, services, and computing resources increases

Engineering Contradiction:
Improveservice capacityVSAvoidrelationship tracking complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a service model as an intermediary data structure that captures and manages the relationships between customers, services, and computing resources. This service model acts as a mediator layer that simplifies the complex many-to-many relationships by providing a structured representation that can be queried and analyzed, thereby reducing the complexity of tracking relationships while maintaining the ability to support numerous computing resources and services

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the managed network expands the number of services and computing resources, then the functionality and service offerings are improved, but the difficulty of identifying affected customers during resource failures increases

Engineering Contradiction:
Improveservice offeringsVSAvoidfailure impact identification
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The service model serves as an intermediary that explicitly captures the relationships between computing resources and affected customers. When a resource failure occurs, this structured model enables rapid querying to identify which customers are impacted, transforming a previously difficult detection problem into a straightforward lookup operation based on the pre-established relationships in the service model

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If the managed network lacks real-time visibility into service dependencies, then the operational simplicity is maintained, but the recovery time for affected customers increases to days or weeks

Engineering Contradiction:
Improveoperational simplicityVSAvoidcustomer recovery time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing and maintaining the service model that captures all relationships between customers, services, and computing resources before failures occur. This advance preparation enables immediate identification of affected customers when failures happen, reducing recovery time from days or weeks to near-real-time without significantly complicating ongoing operations

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11133992B2Detection and notification of anomalies in shared computer networks
Publication Date: 2021.09.28 SERVICENOW INC
  • US11133992B2 patent drawing
  • US11133992B2 patent drawing
  • US11133992B2 patent drawing

AI summary

A computational instance of a remote network management platform may be dedicated to a managed network. The computational instance may include persistent storage that contains: (i) mappings between end-user networks, services available to the end-user networks, and allocation identifiers, (ii) mappings between end-user networks, computing resources allocated to the end-user networks, and resource identifiers, and (iii) mappings between the respective allocation identifiers and the respective resource identifiers. Using the mappings, the computational instance may able to (i) determine that a particular computing resource is exhibiting an anomaly, (ii) determine a resource identifier associated with the particular computing resource, (iii) determine a allocation identifier based on the resource identifier, (iv) determine a particular end-user network associated with the allocation identifier; and (v) provide, to the managed network, an indication that the particular end-user network is potentially impacted by the anomaly.