US2022417081A1PendingUtilityA1

System and method for network incident remediation recommendations

Assignee: VMWARE INCPriority: Nov 10, 2017Filed: Aug 29, 2022Published: Dec 29, 2022
Est. expiryNov 10, 2037(~11.3 yrs left)· nominal 20-yr term from priority
H04L 41/0654H04L 41/0677H04L 41/0631H04L 41/0609H04L 41/069
67
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for analyzing network incidents within a network and providing prioritized remediation recommendations is disclosed. The method includes: receiving network data and computing a plurality of network incidents from the network data, collecting network incidents related to a particular network issue over a time period and grouping the network incidents according to root-cause symptoms, generating a network incident graph by superimposing groups of network incidents over a network graph, analyzing the network incident graph to identify localized areas with systemic issues; and based on the analysis of the network incident graph, generating and displaying a list of remediation recommendations. Each remediation recommendation includes a systemic issue in the network, a remediation to resolve the issue, and a quantified expected benefit from implementing the remediation.

Claims

exact text as granted — not AI-modified
1 - 27 . (canceled) 
     
     
         28 . A method for identifying network incidents and providing remediation recommendations for the network incidents, the method comprising:
 analyzing a stream of network data that is captured over a time period from a plurality of network elements that are defined at different layers of a network stack, in order to identify a plurality of incidents within the network over the time period; and   identifying a plurality of groups of network incidents with the network incidents in each group related to the same issue;   analyzing the grouped network incidents to identify, and to provide a display of, a list of remediations that includes a remediation recommendation for each group of incidents.   
     
     
         29 . The method of  claim 28 , wherein each network incident has a set of possible root-causes for the incident. 
     
     
         30 . The method of  claim 29 , wherein each group's remediation further includes an identification of at least one root cause for the network incidents in the group. 
     
     
         31 . The method of  claim 28 , wherein each group's remediation further includes a quantified expected benefit from implementing the remediation recommendation for the group. 
     
     
         32 . The method of  claim 28 , wherein identifying the plurality of groups comprises extracting and analyzing metadata from data collected from network elements at different layers of a network stack. 
     
     
         33 . The method of  claim 32 , wherein the metadata includes protocol level metadata, device quality of experience (QoE) metadata, and application-level metadata. 
     
     
         34 . The method of  claim 28 , wherein network incidents are associated with client incident hours, the method further comprising computing for each group an aggregate client incident hour based on the client incident hours of each network incident in the group, wherein analyzing the grouped network incidents comprises generating a sorted order of the groups based on the aggregate client incident hours of the groups. 
     
     
         35 . The method of  claim 34 , wherein
 generating the sorted order comprises generating a sorted order that lists the groups from highest to lowest aggregated incident hours, and   providing the display of the list of remediations comprises providing a display of a subset of N groups of network incidents that have the highest aggregate incident hours, N being an integer.   
     
     
         36 . The method of  claim 34 , wherein each group's remediation further includes a quantified expected benefit from implementing the remediation recommendation for the group, and the quantified expected benefit from implementing at least one remediation recommendation is expressed in client incident hours. 
     
     
         37 . The method of  claim 28 , wherein the different layers of the network stack include client, infrastructure and application layers, and each network incident in a set of identified network incidents is a client, infrastructure, or application incident that negatively affects a subset of elements in the network. 
     
     
         38 . The method of  claim 28 , wherein the list of remediations is sorted based on actionability, wherein actionability is defined as how quickly a particular remediation may be applied. 
     
     
         39 . The method of  claim 28  further comprising:
 receiving selection of a remediation recommendation from the list of remediations; 
 implementing the selected remediation recommendation from the list of remediations. 
 
     
     
         40 . A non-transitory machine readable medium comprising a program that when executed by at least one processing unit identifies network incidents and provides remediation recommendations for the network incidents, the program comprising sets of instructions for:
 analyzing a stream of network data that is captured over a time period from a plurality of network elements that are defined at different layers of a network stack, in order to identify a plurality of incidents within the network over the time period; and   identifying a plurality of groups of network incidents with the network incidents in each group related to the same issue;   analyzing the grouped network incidents to identify, and to provide a display of, a list of remediations that includes a remediation recommendation for each group of incidents.   
     
     
         41 . The non-transitory machine readable medium of  claim 40 , wherein each network incident has a set of possible root-causes for the incident. 
     
     
         42 . The non-transitory machine readable medium of  claim 41 , wherein each group's remediation further includes an identification of at least one root cause for the network incidents in the group. 
     
     
         43 . The non-transitory machine readable medium of  claim 40 , wherein each group's remediation further includes a quantified expected benefit from implementing the remediation recommendation for the group. 
     
     
         44 . The non-transitory machine readable medium of  claim 40 , wherein the set of instructions for identifying the plurality of groups comprises sets of instructions for extracting and analyzing metadata from data collected from network elements at different layers of a network stack. 
     
     
         45 . The non-transitory machine readable medium of  claim 44 , wherein the metadata includes protocol level metadata, device quality of experience (QoE) metadata, and application-level metadata. 
     
     
         46 . The non-transitory machine readable medium of  claim 40 , wherein network incidents are associated with client incident hours, the program further comprises a set of instructions for computing for each group an aggregate client incident hour based on the client incident hours of each network incident in the group, wherein the set of instructions for analyzing the grouped network incidents comprises a set of instructions for generating a sorted order of the groups based on the aggregate client incident hours of the groups. 
     
     
         47 . The non-transitory machine readable medium of  claim 46 , wherein the sets of instructions for:
 generating the sorted order comprises a set of instructions for generating a sorted order that lists the groups from highest to lowest aggregated incident hours, and   providing the display of the list of remediations comprises a set of instructions for providing a display of a subset of N groups of network incidents that have the highest aggregate incident hours, N being an integer.

Join the waitlist — get patent alerts

Track US2022417081A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.