Patent attributes
A method for discovering and diagnosing network anomalies. The method includes receiving key performance indicator (KPI) data and alarm data. The method includes extracting features based on samples obtained by discretizing the KPI data and the alarm data. The method includes generating a set of rules based on the features. The method includes identifying a sample as a normal sample or an anomaly sample. In response to identifying the sample as the anomaly sample, the method includes identifying a first rule that corresponds to the sample, wherein the first rule indicates symptoms and root causes of an anomaly included in the sample. The method further includes applying the root causes to derive a root cause explanation of the anomaly and performing a corrective action to resolve the anomaly based on the first rule.