Network attribute analysis
There is provided a computer-implemented method for analysing one or more network attributes of a network. One or more first network attributes of the network are analysed using a first machine learning model to generate a first output comprising information about an event in the network. If an estimated confidence level for the first output is less than a confidence level threshold, the one or more first network attributes are analysed using a second machine learning model to generate a second output. The second output is indicative of one or more second network attributes of the network to analyse using the first machine learning model.
1 . A method performed by processing circuitry of a first entity for processing one or more network attributes of a network, the method comprising:
processing one or more first network attributes of the network using a first machine learning model to generate a first output comprising information about an event in the network;
if an estimated confidence level for the first output is less than a confidence level threshold, processing the one or more first network attributes using a second machine learning model to generate a second output, the second output being indicative of one or more second network attributes of the network to process using the first machine learning model;
repeating the method for one or more iterations, for each iteration of the one or more iterations, if a second output is generated, the one or more second network attributes from the iteration are processed using the first machine learning model in the subsequent iteration; and
initiating a reconfiguration in the network for the one or more second network attributes to be acquired.
2 . The method as claimed in claim 1 , wherein:
the method is repeated until the confidence level for the first output is equal to or greater than the confidence level threshold.
3 . The method as claimed in claim 1 , the method comprising:
if the estimated confidence level for the first output is equal to or greater than the confidence level threshold, generating a report on the first output; and
if the estimated confidence level for the first output is less than the confidence level threshold, generating a report on the second output.
4 . The method as claimed in claim 3 , wherein:
the report on the first output comprises information indicative of the one or more first network attributes.
5 . The method as claimed in claim 1 , wherein:
the one or more first network attributes and the first output are processed using the second machine learning model to generate the second output.
6 . The method as claimed in claim 1 , wherein:
the information about the event in the network comprises any one or more of:
information indicative of a time of the event in the network;
information indicative of a level within the network at which the event occurs; and
information indicative of a cause of the event in the network.
7 . The method as claimed in claim 6 , wherein:
the level within the network is any one or more of:
a level at which one or more network nodes are deployed in the network;
a level at which one or more computing platforms are deployed in the network;
a level at which virtualization or containerization occurs in the network; and
a level at which one or more services are hosted or executed in the network.
8 . The method as claimed in claim 6 , wherein:
the information about the event in the network comprises, for one or more levels within the network, a percentage value indicative of a likelihood that the event in the network occurs at that level within the network; and
the highest percentage value is the information indicative of the level within the network at which the event occurs.
9 . The method as claimed in claim 1 , wherein:
all of the one or more second network attributes are different from the one or more first network attributes; or
the one or more second network attributes comprise at least one of the one or more first network attributes and at least one other network attribute of the network.
10 . The method as claimed in claim 1 , wherein:
the one or more first network attributes comprise two or more first network attributes that are acquired from different locations in the network; and
the one or more second network attributes comprise two or more second network attributes that are acquired from different locations in the network.
11 . The method as claimed in claim 1 , wherein:
the one or more first network attributes are acquired from any one or more of a log file, a trace file, and a performance management counter; and
the one or more second network attributes are acquired from any one or more of a log file, a trace file, and a performance management counter.
12 . The method as claimed in claim 1 , wherein:
the one or more first network attributes comprise at least two first network attributes and the at least two first network attributes are in a time series; and
the one or more second network attributes comprise at least two second network attributes and the at least two second network attributes are in a time series.
13 . The method as claimed in claim 1 , wherein:
the one or more first network attributes comprise at least two first network attributes and each of the at least two first network attributes have the same time stamp; and
the one or more second network attributes comprise at least two second network attributes and each of the at least two second network attributes have the same time stamp.
14 . The method as claimed in claim 1 , wherein:
the one or more first network attributes comprise at least two first network attributes that are in different formats;
the method comprises converting the at least two first network attributes into the same format;
the one or more second network attributes comprise at least two second network attributes that are in different formats; and
the method comprises converting the at least two second network attributes into the same format.
15 . The method as claimed in claim 1 , wherein:
processing the one or more first network attributes using the second machine learning model to generate the second output comprises:
using the second machine learning model to:
compare the one or more first network attributes to one or more second outputs previously generated using the second machine learning model, wherein each previously generated second output is indicative of one or more second network attributes of the network previously processed using the first machine learning model; and
generate the second output based on a result of the comparison.
16 . A computer-implemented method performed by processing circuitry of a second entity for processing for training a machine learning model to process one or more network attributes of a network, the method comprising:
training a first machine learning model to process one or more first network attributes of the network to generate a first output comprising information about an event in the network;
training a second machine learning model to process the one or more first network attributes to generate a second output if an estimated confidence level for the first output is less than a confidence level threshold, the second output being indicative of one or more second network attributes of the network to process using the first machine learning model, if a second output is generated, the one or more second network attributes from an iteration are processed using the first machine learning model in a subsequent iteration; and
initiating a reconfiguration in the network for the one or more second network attributes to be acquired.
17 . The method as claimed in claim 16 , wherein:
the first machine learning model is trained using a first training dataset, wherein the first training dataset comprises information indicative of a past occurrence of the event in the network and one or more first network attributes of the network corresponding to the past occurrence of the event; and
the second machine learning model is trained using a second training dataset, wherein the second training dataset comprises the one or more first network attributes of the network corresponding to the past occurrence of the event and one or more second network attributes of the network corresponding to the past occurrence of the event.
18 . The method as claimed in claim 17 , wherein:
the information indicative of the past occurrence of the event has a time stamp indicative of a time of the past occurrence of the event;
each first network attribute of the one or more first network attributes has a time stamp indicative of a time at which the first network attribute was recorded; and
for each first network attribute of the one or more first network attributes, the time at which the first network attribute was recorded is a time that falls within a predefined time interval that precedes the time of the past occurrence of the event.
19 . A computer program comprising instructions stored in a non-transitory medium which, when executed by processing circuitry, cause the processing circuitry to perform a method according to for processing one or more network attributes of a network, the method comprising:
processing one or more first network attributes of the network using a first machine learning model to generate a first output comprising information about an event in the network;
if an estimated confidence level for the first output is less than a confidence level threshold, processing the one or more first network attributes using a second machine learning model to generate a second output, the second output being indicative of one or more second network attributes of the network to process using the first machine learning model;
repeating the method for one or more iterations, for each iteration of the one or more iterations, if a second output is generated, the one or more second network attributes from the iteration are processed using the first machine learning model in the subsequent iteration; and
initiating a reconfiguration in the network for the one or more second network attributes to be acquired.