IP Library Granted Patent US 10,063,405
Granted Patent B2
US 10,063,405 · App. 14/984,746 · Granted Aug 28, 2018

Real time transmission monitoring and anomaly detection

Inventors: Takeshi Shibata (San Jose, CA); Miyuki Hanaoka (San Jose, CA); Hiroaki Shikano (Campbell, CA); Prasad V. Rallapalli (Pleasanton, CA)
Assignee: HITACHI, LTD.
H04L41/0631H04L41/0677H04L49/555H04L41/0618
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,063,405
App. No.
14/984,746
Granted
Aug 28, 2018
Kind
B2
Abstract

A network monitoring system compares gathered network information with path information. The comparison between gathered network information and path information provides traceability of automatic and dynamic rerouting function of network and makes it possible to understand the relation between root cause and observed problems. The combined monitoring of data plane with control plane enables identification of the original failure point where behavior is changing though routing failure is propagated around. This will allow the identification of network issues that may lead to service outages and impairments as well as alerting of issues affecting customer satisfaction, and is effective to reduce MTTD (Mean Time To Detect)/MTTR (Mean Time To Repair) and increase service availability in all markets.

Claims (69)

1. A management computer configured to manage a network, the management computer comprising:

a memory, configured to store anomaly criteria information for the network and path information for the network;

a processor, configured to:

apply the path information to at least one of data plane packet information and control plane packet information to generate matching information, the matching information comprising first entries from at least one of the data plane packet information and control plane packet information matched to corresponding second entries from the path information having paths, the data plane packet information and the control plane packet information include information of packet transferred on the paths; and

monitor the network for an anomaly based on the matching information and the anomaly criteria information;

wherein the processor is configured to determine the path information by:

determining multicast group and source pairs of the network;

determining upstream routers associated with each of the multicast group and source pairs;

determining paths based on the upstream routers; and

determining connections to the paths from a connecting point.

2. The management computer of claim 1 , wherein the path information comprises incoming interface information and outgoing interface information for each router in each of the paths, wherein the control plane packet information comprises incoming data plane packet information and outgoing data plane packet information for each interface of each router, wherein the processor is configured to generate the matching information by:

matching first information from the path information, the first information comprising the incoming interface information and the outgoing interface information for each of the paths, to second information from the data plane packet information, the second information comprising the incoming data plane packet information and the outgoing data plane packet information associated with an interface that matches an interface indicated by the incoming interface information and the outgoing interface information.

3. The management computer of claim 1 , wherein the path information comprises incoming interface information and outgoing interface information for each router in each of the paths, wherein the control plane packet information comprises incoming control plane packet information and outgoing control plane packet information for each interface of each router, wherein the processor is configured to generate the matching information by:

matching first information from the path information, the first information comprising the incoming interface information and the outgoing interface information for each of the paths, to second information from the control plane packet information, the second information comprising the incoming control plane packet information and the outgoing control plane packet information associated with an interface that matches an interface indicated by the incoming interface information and the outgoing interface information.

4. The management computer of claim 1 , wherein the processor is configured to determine the path information by:

determining one or more possible routes from each router in the network;

determining endpoints of service for the network;

determining neighboring routers in the network for each of the endpoints of service; and

determining connections between the neighboring routers based on the one or more possible routes.

5. The management computer of claim 1 , wherein the anomaly criteria comprises at least one of: link utilization ratio, and a number of a type of message across a plurality of message cycles based on robustness count;

wherein the processor is configured to monitor the network for an anomaly by:

comparing an entry from the matching information to the anomaly criteria; and

for the anomaly criteria not being met, raise an alert.

6. The management computer of claim 1 , wherein the processor is configured to:

determine an addition or a deletion of endpoints of service of the network from service request packets associated with the endpoints of service and route changes associated with the endpoints of service; and

determine the path information by:

determining one or more possible routes from each router in the network;

determining endpoints of service for the network;

determining neighboring routers in the network for each of the endpoints of service; and

determining connections between the neighboring routers based on the one or more possible routes.

7. The management computer of claim 1 , wherein the processor is configured to:

determine an addition or a deletion of endpoints of service of the network from service request packets indicative of the endpoints of service and route changes having endpoints of service;

determine the path information by:

determining one or more possible routes from each router and mobile network equipment in the network;

determining endpoints of service for the network;

determining neighboring routers and mobile network equipment in the network for each of the endpoints of service; and

determining connections between the neighboring routers and mobile network equipment based on the one or more possible routes.

8. A non-transitory computer readable medium, storing instructions for executing a process for a network, the instructions comprising:

managing anomaly criteria information for the network and path information for the network;

applying the path information to at least one of data plane packet information and control plane packet information to generate matching information, the matching information comprising first entries from at least one of the data plane packet information and control plane packet information having sources matched to corresponding second entries from the path information having paths corresponding to the sources; and

monitoring the network for an anomaly based on the matching information and the anomaly criteria information;

wherein the determining the path information comprises:

determining multicast group and source pairs of the network;

determining upstream routers associated with each of the multicast group and source pairs;

determining paths based on the upstream routers; and

determining connections to the paths from a connecting point.

9. The non-transitory computer readable medium of claim 8 , wherein determining the path information comprises:

determining one or more possible routes from each router in the network;

determining endpoints of service for the network;

determining neighboring routers in the network for each of the endpoints of service; and

determining connections between the neighboring routers based on the one or more possible routes.

10. The non-transitory computer readable medium of claim 8 , wherein the anomaly criteria comprises at least one of: link utilization ratio, and a number of a type of message across a plurality of message cycles based on robustness count;

wherein the monitoring the network for an anomaly comprises:

comparing an entry from the matching information to the anomaly criteria; and

for the anomaly criteria not being met, raise an alert.

11. The non-transitory computer readable medium of claim 8 , the instructions further comprising:

determining an addition or a deletion of endpoints of service of the network from service request packets associated with the endpoints of service and route changes associated with the endpoints of service; and

wherein the determining the path information comprises:

determining one or more possible routes from each router in the network;

determining endpoints of service for the network;

determining neighboring routers in the network for each of the endpoints of service; and

determining connections between the neighboring routers based on the one or more possible routes.

12. The non-transitory computer readable medium of claim 8 , the instructions further comprising:

determine an addition or a deletion of endpoints of service of the network from service request packets indicative of the endpoints of service and route changes having endpoints of service;

wherein determining the path information comprises:

determining one or more possible routes from each router and mobile network equipment in the network;

determining endpoints of service for the network;

determining neighboring routers and mobile network equipment in the network for each of the endpoints of service; and

determining connections between the neighboring routers and mobile network equipment based on the one or more possible routes.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 4, 2016
From: SHIBATA, TAKESHI; HANAOKA, MIYUKI; SHIKANO, HIROAKI; RALLAPALLI, PRASAD V.
To: HITACHI, LTD.
Reel/Frame 037401/0178 →
Continuity (1)
Related Publication 20170195167A1 · Jul 6, 2017
Cited By (1)
US 50,590