US2023362081A1PendingUtilityA1
System and method for using real-time packet data to detect and manage network issues
Est. expiryApr 18, 2036(~9.7 yrs left)· nominal 20-yr term from priority
H04L 41/0631H04L 43/16H04L 43/0882H04L 47/11H04L 41/142H04L 61/4511H04L 43/0811H04L 47/28H04L 61/103H04W 8/02H04L 43/0829H04L 43/0817H04L 43/0852H04L 61/4523H04L 61/5014
76
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A system and method is disclosed of extracting information from real-time network packet data to analyze connectivity data for client devices in a network. The method includes: detecting when client devices initiate a connectivity event; after detecting a connectivity event, waiting a period of time for the client device to either reach or fail to reach a network connected state; after waiting a period of time, recording connectivity event information; and sending the recorded connectivity event information to an analytics system for network incident and/or network congestion analysis.
Claims
exact text as granted — not AI-modified1 - 25 . (canceled)
26 . A method for analyzing and remediating network incidents, the method comprising:
executing performance calculations on collected network data to compute performance metrics; detecting a network incident by using the computed performance metrics to correlate with a sequence of other metrics that are associated with symptoms related to network incidents; identifying a root cause of the detected network incident; and identifying, and providing for display, remediation of the identified root cause of the detected network incident.
27 . The method of claim 26 , wherein the detected incident comprises a network infrastructure incident relating to one or more network infrastructure elements, and the plurality of network incidents comprises a plurality of network infrastructure incidents relating to a plurality of sets of network infrastructure elements.
28 . The method of claim 26 , wherein the detected incident comprises a client network incident relating to a particular client, and the plurality of network incidents comprise a plurality of client network incidents relating to a plurality of clients.
29 . The method of claim 26 , wherein using the computed performance metrics comprises detecting a presence of a sequence of metric values.
30 . The method of claim 26 , wherein using the computed performance metrics comprises detecting a cyclical presence of a sequence of metric values.
31 . The method of claim 26 , wherein detecting the network incident comprises identifying deviations in historical time-series data computed based on network incidents over a duration of time.
32 . A method for automatic detection of a network incident from real-time network data, the method comprising:
collecting network data; computing performance metric values based on the collected network data; identifying a network incident by detecting a pattern of metric values over a time window, wherein detecting a pattern comprises detecting a proportion of metric values crossing a threshold exceeding a defined percentage amount, detecting a presence of a sequence of metric values, detecting a cyclical presence of a sequence of metric values, or combinations thereof; and identifying a root cause of the identified network incident.
33 . The method of claim 32 , wherein identifying root cause comprises correlating a sequence of performance metrics with other composite metrics that define relevant symptoms and mapping a set of one or more symptoms identified through the correlation to a root cause.
34 . The method of claim 33 , wherein identifying the root cause comprises aggregating root causes of network incidents over a longer time period than the time window.
35 . The method of claim 32 further comprising identifying remediation for the network incident.
36 . The method of claim 35 further comprising programming, via a controller or a direct interface, configuration settings of one or more network infrastructure elements to effectuate the identified remediation.
37 . The method of claim 32 further comprising
identifying a plurality of network incidents based on the computed performance metric values;
computing historical time-series data based on computed network incidents over time; and
identifying the root cause based on the historical time-series data.
38 . The method of claim 37 further comprising identifying deviations in the computed historical time-series data.
39 . The method of claim 38 further comprising identifying changes in the computed historical time-series data and/or identifying factors contributing to these changes, wherein the identifying factors comprise configuration changes, topology changes, changes and upgrades of the network elements, or combinations thereof, in the network.
40 . The method of claim 32 further comprising assigning a priority to the identified network incident, and accounting for the assigned priority in identifying the root cause.
41 . The method of claim 40 , wherein the priority is determined based on a percentage of affected entities, relative deviation from the historical baseline, presence of important entities within the affected entities, or combinations thereof.
42 . The method of claim 32 , wherein the collected network data comprises data obtained from deep packet analysis of real time network traffic, and data from Layer 2 to Layer 4 packet header values.
43 . A non-transitory machine-readable medium storing a program which when executed by at least one processing unit automatically detects a network incident from real-time network data, the program comprising sets of instructions for:
collecting network data; computing performance metric values based on the collected network data; identifying a network incident by detecting a pattern of metric values over a time window, wherein detecting a pattern comprises detecting a proportion of metric values crossing a threshold exceeding a defined percentage amount, detecting a presence of a sequence of metric values, detecting a cyclical presence of a sequence of metric values, or combinations thereof; and identifying a root cause of the identified network incident.
44 . The non-transitory machine-readable medium of claim 43 , wherein the set of instructions for identifying root cause comprises a set of instructions for correlating a sequence of performance metrics with other composite metrics that define relevant symptoms and mapping a set of one or more symptoms identified through the correlation to a root cause.
45 . The non-transitory machine-readable medium of claim 44 , wherein the set of instructions for identifying the root cause comprises a set of instructions for aggregating root causes of network incidents over a longer time period than the time window.Join the waitlist — get patent alerts
Track US2023362081A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.