Virtual Network Assistant Using Unsupervised ML for Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complex computer networks face challenges in efficiently diagnosing and resolving issues, as existing methods often require extensive resource allocation and manual tagging of network events, leading to inefficiencies and potential false positives.

Innovation Solution

The implementation of a virtual network assistant (VNA) equipped with a proactive analytics and correlation engine (PACE) that utilizes an unsupervised machine learning-based model to dynamically analyze network event data, differentiate between transient and anomalous behavior, and adaptively tune the model in real-time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual tagging and extensive resource allocation are used for network event analysis, then diagnostic accuracy is improved, but resource expenditure and system complexity increase

Engineering Contradiction:
Improvediagnostic accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs self-service through automated machine learning model construction and execution. The VNA automatically builds unsupervised ML models from historical network event data without requiring manual tagging or expert intervention, enabling the system to diagnose network issues independently while maintaining high diagnostic accuracy and reducing operational complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual tagging and human analysis are replaced with automated machine learning systems. The unsupervised ML models automatically process network event data, identify patterns, and diagnose issues without mechanical human intervention, thereby improving diagnostic accuracy while reducing the complexity associated with manual processes

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If all network events are analyzed in detail, then diagnostic thoroughness is improved, but processing time and resource consumption increase

Engineering Contradiction:
Improvediagnostic thoroughnessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies partial action by focusing analysis only on network events that deviate from normal patterns as identified by the ML models. Instead of analyzing all events equally, the system performs detailed analysis only when necessary (when anomalies are detected), thereby maintaining diagnostic thoroughness while significantly reducing processing time and resource consumption

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The ML models perform preliminary filtering and classification of network events before detailed analysis. By pre-processing data to identify normal versus anomalous events, the system prepares the data in advance, enabling rapid decision-making about which events require thorough investigation and which can be quickly dismissed

Inventive Principle:
Principle #10Preliminary action

3Productivity

If traditional network diagnostic methods are used, then implementation simplicity is maintained, but resource efficiency and automation level decrease

Engineering Contradiction:
Improveresource efficiencyVSAvoidautomation level
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

Traditional manual network diagnostic methods are replaced with automated machine learning systems. The VNA uses unsupervised ML models to automatically analyze network events, identify patterns, and diagnose issues without human intervention, dramatically improving resource efficiency and achieving high levels of automation while maintaining implementation feasibility through standardized ML workflows

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250055772A1Virtual network assistant having proactive analytics and correlation engine using unsupervised ML model
Publication Date: 2025.02.13 JUNIPER NETWORKS INC
  • US20250055772A1 patent drawing
  • US20250055772A1 patent drawing
  • US20250055772A1 patent drawing

AI summary

Techniques are described in which a network management system processes network event data received from the AP devices. The NMS is configured to dynamically determine, in real-time, a minimum (MIN) threshold and a maximum (MAX) threshold for expected occurrences for each event type, wherein the MIN thresholds and MAX thresholds define ranges of expected occurrences for the network events of the corresponding event types. The NMS applies an unsupervised machine learning model to the network event data to determine predicted counts of occurrences of the network events for each of the event types and identify, based on the predicted counts of occurrences and the dynamically-determined minimum threshold values and maximum threshold values for each event type, one or more of the network events as indicative of abnormal network behavior.