Ads by TechWords

See your link here
Receive the latest technology news and information.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Network Monitor with a Brain

By analyzing network traffic in real time, this statistical tool catches anomalies early, then diagnoses the cause.

September 12, 2005 12:00 PM ET

Computerworld - Horizon AwardsThere's a lot not to like about conventional computer performance monitoring tools, say the product developers at NetScout Systems Inc.: They're much too slow, they flag problems without diagnosing them, and they give so many false alerts they are often ignored.

NetScout, a Computerworld Horizon Award winner, says the answer lies in its Progressive Analytics offering, a statistical tool that learns normal network behavior over time and spots and diagnoses anomalies long before conventional tools are aware of them. It will be introduced commercially by the end of the year, the company says.

Progressive Analytics is the brainchild of Ron Hiller, now director of engineering analytics at NetScout in Westford, Mass. Hiller worked on network anomaly detection years ago at Bell Laboratories and, he says, "it became obvious that the standard approaches really don't work."

So Hiller found some venture capital, launched Quantiva Inc. in 2000 and began applying the lessons learned from telephone network problems. In April, NetScout bought Quantiva and began incorporating Hiller's work into its nGenius family of performance management products.

Hiller says traditional products are based on simple rules, such as sounding an alarm if percentage utilization of a resource or response time rises to some predetermined level. Users are encouraged to set the thresholds high to avoid false alerts, and they often don't get an alert soon enough to diagnose and respond before a service outage occurs.

But Hiller says Progressive Analytics detects anomalies by analyzing network traffic in real time and comparing it to normal patterns of behavior. It then automatically diagnoses the cause of the problem, rather than leaving that to manual efforts.

He says conventional tools are often not trusted because of false alarms.

"The network operations guy will come in in the morning and delete all the ones from the night before," he says. "If the phone never rings, he still has his job." Progressive Analytics reduces the number of false alerts by a factor of 100, he says.

Hiller says NetScout tested the technique on the network traffic of a major financial services Web site. "It found anomalies caused by a mainframe in the back office that the company's network operations center had not detected with their conventional tools," he says.

"I don't see this as something routine in the marketplace yet, and I think that it could provide some tremendous advantages for NetScout over time," says Dennis Drogseth, an analyst at Enterprise Management Associates in Boulder, Colo. "Quantiva brings them ... toward a higher-level value proposition that includes application as well as network performance at a more strategic level. This can enable them to reach up the food chain in IT toward more executive buyers."



Jump to comments

Additional Resources

Microsoft
Here are some of the key reasons why you would want to run Unified Access Gateway with DirectAccess.
Microsoft
Review how one energy firm tightened protection and simplified IT work using business-ready security solutions.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

IT Jobs