Virtual Network Assistant Using Unsupervised ML for Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Complex computer networks face challenges in efficiently diagnosing and resolving issues, as existing methods often require extensive resource allocation and manual tagging of network events, leading to inefficiencies and potential false positives.
Innovation Solution
The implementation of a virtual network assistant (VNA) equipped with a proactive analytics and correlation engine (PACE) that utilizes an unsupervised machine learning-based model to dynamically analyze network event data, differentiate between transient and anomalous behavior, and adaptively tune the model in real-time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual tagging and extensive resource allocation are used for network event analysis, then diagnostic accuracy is improved, but resource expenditure and system complexity increase
Solution Approach 1:
The system performs self-service through automated machine learning model construction and execution. The VNA automatically builds unsupervised ML models from historical network event data without requiring manual tagging or expert intervention, enabling the system to diagnose network issues independently while maintaining high diagnostic accuracy and reducing operational complexity
Solution Approach 2:
Manual tagging and human analysis are replaced with automated machine learning systems. The unsupervised ML models automatically process network event data, identify patterns, and diagnose issues without mechanical human intervention, thereby improving diagnostic accuracy while reducing the complexity associated with manual processes
2Reliability
If all network events are analyzed in detail, then diagnostic thoroughness is improved, but processing time and resource consumption increase
Solution Approach 1:
The system applies partial action by focusing analysis only on network events that deviate from normal patterns as identified by the ML models. Instead of analyzing all events equally, the system performs detailed analysis only when necessary (when anomalies are detected), thereby maintaining diagnostic thoroughness while significantly reducing processing time and resource consumption
Solution Approach 2:
The ML models perform preliminary filtering and classification of network events before detailed analysis. By pre-processing data to identify normal versus anomalous events, the system prepares the data in advance, enabling rapid decision-making about which events require thorough investigation and which can be quickly dismissed
3Productivity
If traditional network diagnostic methods are used, then implementation simplicity is maintained, but resource efficiency and automation level decrease
Solution Approach 1:
Traditional manual network diagnostic methods are replaced with automated machine learning systems. The VNA uses unsupervised ML models to automatically analyze network events, identify patterns, and diagnose issues without human intervention, dramatically improving resource efficiency and achieving high levels of automation while maintaining implementation feasibility through standardized ML workflows
Data Source
AI summary
Techniques are described in which a network management system processes network event data received from the AP devices. The NMS is configured to dynamically determine, in real-time, a minimum (MIN) threshold and a maximum (MAX) threshold for expected occurrences for each event type, wherein the MIN thresholds and MAX thresholds define ranges of expected occurrences for the network events of the corresponding event types. The NMS applies an unsupervised machine learning model to the network event data to determine predicted counts of occurrences of the network events for each of the event types and identify, based on the predicted counts of occurrences and the dynamically-determined minimum threshold values and maximum threshold values for each event type, one or more of the network events as indicative of abnormal network behavior.


