IP Library Granted Patent US 10,382,283
Granted Patent B2
US 10,382,283 · App. 15/318,002 · Granted Aug 13, 2019

Network topology estimation based on event correlation

Inventors: László Hévizi (Piliscsaba, HU); Gábor Magyar (Dunaharaszti, HU)
Assignee: Telefonaktiebolaget LM Ericsson (Publ)
H04L41/12H04L41/064H04L41/065H04L41/069H04L41/0618H04L41/0627H04L41/0677
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,382,283
App. No.
15/318,002
Filed
Dec 12, 2016
Granted
Aug 13, 2019
Kind
B2
Art Unit
2451
USPC
709/224
Abstract

A management node ( 100 ) obtains indications of network events occurring at a plurality of nodes ( 210 - 1, 210 - 2, 210 - 3, 210 - 4, 220 - 1, 220 - 2 , 230 - 1, 230 - 2 ) of the communication network. Further, the management node ( 100 ) performs a correlation of times of the indicated network events. On the basis of the correlation, the management node ( 100 ) identifies clusters of nodes ( 210 - 1, 210 - 2 , 210 - 3, 210 - 4, 220 - 1, 220 - 2, 230 - 1, 230 - 2 ) with correlated network events. On the basis of the clusters, the management node ( 100 ) determines a topology model of the communication network.

Claims (52)

1. A method of managing a communication network, the method comprising:

obtaining, by a management node, indications of network events occurring at a plurality of nodes of the communication network;

performing, by the management node, a correlation of times of the indicated network events;

identifying, by the management node, based on the correlation, clusters of nodes with the correlated network events;

determining, by the management node, based on the clusters, a topology model of the communication network, wherein the determining the topology model comprises comparing the clusters to identify a hierarchy of the clusters, and the hierarchy indicating, for each of the clusters, whether the cluster is estimated to be a subset of one or more of other clusters; and

in response to the hierarchy indicating that a first cluster of the clusters is estimated to be a subset of a second cluster of the clusters, assuming, by the management node, in the topology model that a link exists between a first vertex formed of nodes of the first cluster and a second vertex formed of one or more nodes of the second cluster, which are not elements of the first cluster.

2. The method of claim 1 , wherein the determining the topology model further comprises determining a network element which is a candidate to be a common source of the network events indicated by nodes of at least one cluster of the clusters.

3. The method of claim 1 , further comprising:

obtaining, by the management node, further indications of further network events occurring at, at least some of the plurality of nodes of the communication network;

performing, by the management node, a further correlation of times of the indicated further network events;

based on the further correlation, detecting, by the management node, a correlation of at least some of the indicated network events; and

checking consistency, by the management node, of the detected correlation with the topology model.

4. The method of claim 3 , further comprising, in response to the detected correlation being inconsistent with the topology model, deciding, by the management node, between:

updating the topology model; and

identifying the detected correlation as being accidental.

5. The method of claim 4 , wherein the updating the topology model comprises:

identifying at least one further cluster of nodes with the correlated network events; and

based on the clusters and the at least one further cluster, determining an updated topology model of the communication network.

6. The method of claim 1 , wherein the identifying the clusters of nodes with the correlated network events comprises:

based on the correlation, detecting correlations of at least some of the indicated network events; and

if, for a group of the nodes, a number of the detected correlations exceeds a threshold, identifying the group as one of the clusters of nodes with the correlated network events.

7. The method of claim 1 , wherein the identifying the clusters of nodes with the correlated network events comprises, in response to two or more of the network events occurring in a time window, detecting the two or more network events as being correlated.

8. The method of claim 1 , wherein the network events comprise alarms concerning nodes of the plurality of nodes.

9. The method of claim 1 , further comprising:

receiving, by the management node, a plurality of alarms concerning at least some nodes of the plurality of nodes; and

in response to the topology model indicating that the plurality of alarms has a common source, generating, by the management node, a single trouble ticket for the plurality of alarms.

10. A management node for a communication network, the management node comprising:

processing circuitry; and

memory containing instructions executable by the processing circuitry, whereby the management node is operative to:

obtain indications of network events occurring at a plurality of nodes of the communication network;

perform a correlation of times of the indicated network events;

based on the correlation, identify clusters of nodes with the correlated network events;

based on the clusters, determine a topology model of the communication network, wherein the instructions are such that the management node is operative to determine the topology model by comparing the clusters to identify a hierarchy of the clusters, and the hierarchy indicating, for each of the clusters, whether the cluster is estimated to be a subset of one or more of other clusters; and

in response to the hierarchy indicating that a first cluster of the clusters is estimated to be a subset of a second cluster of the clusters, assume in the topology model that a link exists between a first vertex formed of nodes of the first cluster and a second vertex formed of one or more nodes of the second cluster, which are not elements of the first cluster.

11. The management node of claim 10 , wherein the instructions are such that the management node is operative to determine the topology model further by determining a network element which is a candidate to be a common source of the network events indicated by nodes of at least one cluster of the clusters.

12. The management node of claim 10 , wherein the instructions are such that the management node is further operative to:

obtain further indications of further network events occurring at, at least some of the plurality of nodes of the communication network;

perform a further correlation of times of the indicated further network events;

based on the further correlation, detect a correlation of at least some of the indicated network events; and

check consistency of the detected correlation with the topology model.

13. The management node of claim 12 , wherein the instructions are such that the management node is further operative to, in response to the detected correlation being inconsistent with the topology model, decide between updating the topology model and identifying the detected correlation as being accidental.

14. The management node of claim 13 , wherein the instructions are such that the management node is operative to update the topology model by:

identifying at least one further cluster of nodes with the correlated network events; and

based on the clusters and the at least one further cluster, determining an updated topology model of the communication network.

15. The management node of claim 10 , wherein the instructions are such that the management node is operative to identify the clusters of nodes with the correlated network events by:

based on the correlation, detecting correlations of at least some of the indicated network events; and

if, for a group of the nodes, a number of the detected correlations exceeds a threshold, identifying the group as one of the clusters of nodes with the correlated network events.

16. The management node of claim 10 , wherein the instructions are such that the management node is operative to identify the clusters of nodes with the correlated network events by, in response to two or more of the network events occurring in a time window, detecting the two or more network events as being correlated.

17. The management node of claim 10 , wherein the network events comprise alarms concerning nodes of the plurality of nodes.

18. The management node of claim 10 , wherein the instructions are such that the management node is further operative to:

receive a plurality of alarms from at least some nodes of the plurality of nodes; and

in response to the topology model indicating that the plurality of alarms has a common source, generate a single trouble ticket for the plurality of alarms.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2016
From: HÉVIZI, LÁSZLÓ; MAGYAR, GÁBOR
To: TELEFONAKTIEBOLAGET L M ERICSSON (PUBL)
Reel/Frame 040706/0115 →
CHANGE OF NAME Recorded Dec 12, 2016
From: TELEFONAKTIEBOLAGET L M ERICSSON (PUBL)
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 040885/0537 →
Continuity (1)
Related Publication 20170134240A1 · May 11, 2017