US2023362081A1PendingUtilityA1

System and method for using real-time packet data to detect and manage network issues

Assignee: VMWARE INCPriority: Apr 18, 2016Filed: Jul 7, 2023Published: Nov 9, 2023
Est. expiryApr 18, 2036(~9.7 yrs left)· nominal 20-yr term from priority
H04L 41/0631H04L 43/16H04L 43/0882H04L 47/11H04L 41/142H04L 61/4511H04L 43/0811H04L 47/28H04L 61/103H04W 8/02H04L 43/0829H04L 43/0817H04L 43/0852H04L 61/4523H04L 61/5014
76
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method is disclosed of extracting information from real-time network packet data to analyze connectivity data for client devices in a network. The method includes: detecting when client devices initiate a connectivity event; after detecting a connectivity event, waiting a period of time for the client device to either reach or fail to reach a network connected state; after waiting a period of time, recording connectivity event information; and sending the recorded connectivity event information to an analytics system for network incident and/or network congestion analysis.

Claims

exact text as granted — not AI-modified
1 - 25 . (canceled) 
     
     
         26 . A method for analyzing and remediating network incidents, the method comprising:
 executing performance calculations on collected network data to compute performance metrics;   detecting a network incident by using the computed performance metrics to correlate with a sequence of other metrics that are associated with symptoms related to network incidents;   identifying a root cause of the detected network incident; and   identifying, and providing for display, remediation of the identified root cause of the detected network incident.   
     
     
         27 . The method of  claim 26 , wherein the detected incident comprises a network infrastructure incident relating to one or more network infrastructure elements, and the plurality of network incidents comprises a plurality of network infrastructure incidents relating to a plurality of sets of network infrastructure elements. 
     
     
         28 . The method of  claim 26 , wherein the detected incident comprises a client network incident relating to a particular client, and the plurality of network incidents comprise a plurality of client network incidents relating to a plurality of clients. 
     
     
         29 . The method of  claim 26 , wherein using the computed performance metrics comprises detecting a presence of a sequence of metric values. 
     
     
         30 . The method of  claim 26 , wherein using the computed performance metrics comprises detecting a cyclical presence of a sequence of metric values. 
     
     
         31 . The method of  claim 26 , wherein detecting the network incident comprises identifying deviations in historical time-series data computed based on network incidents over a duration of time. 
     
     
         32 . A method for automatic detection of a network incident from real-time network data, the method comprising:
 collecting network data;   computing performance metric values based on the collected network data;   identifying a network incident by detecting a pattern of metric values over a time window, wherein detecting a pattern comprises detecting a proportion of metric values crossing a threshold exceeding a defined percentage amount, detecting a presence of a sequence of metric values, detecting a cyclical presence of a sequence of metric values, or combinations thereof; and   identifying a root cause of the identified network incident.   
     
     
         33 . The method of  claim 32 , wherein identifying root cause comprises correlating a sequence of performance metrics with other composite metrics that define relevant symptoms and mapping a set of one or more symptoms identified through the correlation to a root cause. 
     
     
         34 . The method of  claim 33 , wherein identifying the root cause comprises aggregating root causes of network incidents over a longer time period than the time window. 
     
     
         35 . The method of  claim 32  further comprising identifying remediation for the network incident. 
     
     
         36 . The method of  claim 35  further comprising programming, via a controller or a direct interface, configuration settings of one or more network infrastructure elements to effectuate the identified remediation. 
     
     
         37 . The method of  claim 32  further comprising
 identifying a plurality of network incidents based on the computed performance metric values; 
 computing historical time-series data based on computed network incidents over time; and 
 identifying the root cause based on the historical time-series data. 
 
     
     
         38 . The method of  claim 37  further comprising identifying deviations in the computed historical time-series data. 
     
     
         39 . The method of  claim 38  further comprising identifying changes in the computed historical time-series data and/or identifying factors contributing to these changes, wherein the identifying factors comprise configuration changes, topology changes, changes and upgrades of the network elements, or combinations thereof, in the network. 
     
     
         40 . The method of  claim 32  further comprising assigning a priority to the identified network incident, and accounting for the assigned priority in identifying the root cause. 
     
     
         41 . The method of  claim 40 , wherein the priority is determined based on a percentage of affected entities, relative deviation from the historical baseline, presence of important entities within the affected entities, or combinations thereof. 
     
     
         42 . The method of  claim 32 , wherein the collected network data comprises data obtained from deep packet analysis of real time network traffic, and data from Layer 2 to Layer 4 packet header values. 
     
     
         43 . A non-transitory machine-readable medium storing a program which when executed by at least one processing unit automatically detects a network incident from real-time network data, the program comprising sets of instructions for:
 collecting network data;   computing performance metric values based on the collected network data;   identifying a network incident by detecting a pattern of metric values over a time window, wherein detecting a pattern comprises detecting a proportion of metric values crossing a threshold exceeding a defined percentage amount, detecting a presence of a sequence of metric values, detecting a cyclical presence of a sequence of metric values, or combinations thereof; and   identifying a root cause of the identified network incident.   
     
     
         44 . The non-transitory machine-readable medium of  claim 43 , wherein the set of instructions for identifying root cause comprises a set of instructions for correlating a sequence of performance metrics with other composite metrics that define relevant symptoms and mapping a set of one or more symptoms identified through the correlation to a root cause. 
     
     
         45 . The non-transitory machine-readable medium of  claim 44 , wherein the set of instructions for identifying the root cause comprises a set of instructions for aggregating root causes of network incidents over a longer time period than the time window.

Join the waitlist — get patent alerts

Track US2023362081A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.