SYSTEMS AND METHODS FOR DETECTING NETWORK CONDITIONS BASED ON CORRELATION BETWEEN TREND LINES
First Claim
1. A method of monitoring a network, comprising:
- capturing a set of network operation data from a managed network;
identifying a set of trend line data for at least two conditions of the managed network represented in the set of network operation data;
generating a comparison of the trend line data for the at least two conditions to determine a correlation between the at least two conditions; and
identifying a set of potential events in the set of trend line data based on the determined correlation.
1 Assignment
0 Petitions
Accused Products
Abstract
Embodiments relate systems and methods for detecting network conditions based on a correlation between trend lines. In embodiments, a network management server can monitor the status and operation of network machines, such as servers or targets, as well as network transmission hardware (e.g. routers). Streams of network operation data from those sources can be captured and stored. The management server or other logic can examine the network operation data to identify trend lines for network conditions, such as application faults, attempted intrusions, or other events or conditions. Trend line data can be treated to generate second or other higher-order derivatives, such as third-order derivatives or others. A time correlation between two or more trend lines and/or their higher order derivatives, for instance, the occurrence of a peak value in the same time window, can be used to identify an event, state or condition.
93 Citations
23 Claims
-
1. A method of monitoring a network, comprising:
-
capturing a set of network operation data from a managed network; identifying a set of trend line data for at least two conditions of the managed network represented in the set of network operation data; generating a comparison of the trend line data for the at least two conditions to determine a correlation between the at least two conditions; and identifying a set of potential events in the set of trend line data based on the determined correlation. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 19, 21, 22)
-
-
12. A network management system, comprising:
-
an interface to a managed network; and a management server, communicating with the managed network via interface, the management server being configured to— capture a set of network operation data from a managed network, identify a set of trend line data for at least two conditions of the managed network represented in the set of network operation data, generate a comparison of the trend line data for the at least two conditions to determine a correlation between the at least two conditions, and identify a set of potential events in the set of trend line data based on the determined correlation. - View Dependent Claims (13, 14, 15, 16, 17, 18)
-
-
23. A computer readable storage medium, the computer readable storage medium storing a set of identified potential events generated via a method of:
-
capturing a set of network operation data from a managed network; identifying a set of trend line data for at least two conditions of the managed network represented in the set of network operation data; generating a comparison of the trend line data for the at least two conditions to determine a correlation between the at least two conditions; and identifying a set of potential events in the set of trend line data based on the determined correlation.
-
Specification