Automated End-to-End Network Fault Isolation for TANFINET BharatNet
TANFINET Hackathon Submission โ Problem Statement #2: End-to-End Network Fault Localization
Solving the 2-6 hour manual fault investigation bottleneck with AI-powered automation in <60 seconds.
Current Process (2-6 hours):
- NOC engineer receives customer complaints
- Manually correlates syslog messages
- Manually checks SNMP metrics across devices
- Identifies root cause device
- Separately calculates affected customers
- Manually routes ticket to correct team
Our Solution (<60 seconds): Fully automated AI pipeline that detects, diagnoses, localises, and routes faults with customer impact calculation โ all in a single workflow.
No existing tool combines fault detection AND customer impact calculation in one automated workflow. NetFaultAI:
- โ Detects faults across 6 signature types (NLP + Anomaly Detection)
- โ Localises root cause device using graph topology
- โ Calculates blast radius automatically (customers affected downstream)
- โ Maps geographical impact (radius in km, area in kmยฒ)
- โ Routes tickets automatically (field dispatch vs remote NOC)
- โ Displays on GIS map with real GPS coordinates
A virtualised replica of the Puducherry BharatNet 4-tier hierarchy running inside Mininet โ enabling real network interface faults to be injected, scraped, and fed directly into the AI pipeline:
- โ
Real kernel-level faults via
ip link set down/tc netem - โ Live SNMP-style telemetry scraped from Mininet interfaces โ CSV
- โ Bidirectional: dashboard injects faults โ Mininet executes them โ telemetry feeds back to AI
- โ Topology manifest auto-generated on start (maps canonical names โ Linux interfaces)
Time Savings: 2-6 hours โ <60 seconds (99.7% reduction)
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ INPUT LAYER โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Syslog Messages โ SNMP Metrics โ
โ (Simulated / Live Mininet) โ (CPU/Memory/Bandwidth/Loss) โ
โโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโ
โ โ
โผ โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโ
โ NLP Engine (40%) โ โ Anomaly Engine (40%) โ
โ distilBERT + Regex โ โ Isolation Forest โ
โ 6-class classifier โ โ SNMP outlier detect โ
โโโโโโโโโโโโโโฌโโโโโโโโโโโโ โโโโโโโโโโโโโโฌโโโโโโโโโโโโ
โ โ
โโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโ
โ Fusion Engine โ
โ (Weighted voting) โ
โ Context: 20% โ
โโโโโโโโโโโโฌโโโโโโโโโโโ
โ
โโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโ
โ โ โ
โผ โผ โผ
โโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโ
โ OSI Mapper โ โBlast Radius โ โ GIS Engine โ
โ Layer 1-7 โ โ Geographicalโ โ Folium Map โ
โโโโโโโโฌโโโโโโโ โโโโโโโโฌโโโโโโโ โโโโโโโโฌโโโโโโโ
โ โ โ
โโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโ
โ Ticket Router โ
โ Field / NOC L2 โ
โโโโโโโโโโโโฌโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 6-PAGE DASHBOARD โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 1. AI Analysis 2. NOC Operations 3. Complaint โ
โ 4. Live Feed 5. Executive SLA 6. Field Engineer โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โฒ โฒ
โ โโโโโโโโโโโโโโโโโโโโโโ โ
โโโโโโโ Mininet Digital โโโโโ
โ Twin (WSL/Linux) โ
โ telemetry_agent โ
โ fault_controller โ
โโโโโโโโโโโโโโโโโโโโโโ
| Fault Type | OSI Layer | Detection Method | Time to Detect |
|---|---|---|---|
| Voltage Issue | L1 Physical | Battery/UPS alarms + 0% bandwidth | <50ms |
| Hardware Defect | L1 Physical | SFP/laser failure (dBm readings) | <50ms |
| Traffic Congestion | L3 Network | QoS drops + 99% bandwidth | <50ms |
| Latency Degradation | L1 Physical | RTT spikes + micro-bending | <50ms |
| Connection Issue | L1+L3 | BGP drops + fiber cuts (LOS) | <50ms |
| Legacy Bottleneck | L2 Data Link | 99% CPU/Memory + low throughput | <50ms |
Unified Confidence = (NLP ร 0.40) + (Anomaly ร 0.40) + (Context ร 0.20)- NLP Engine: distilBERT fine-tuned (92%+ accuracy) + regex fallback (90%+)
- Anomaly Engine: Isolation Forest on SNMP metrics
- Context Engine: Blast radius severity + node criticality
The system handles simultaneous faults across multiple nodes:
- Incident Ledger: UUID-tagged verdict store, last 20 incidents, OPEN/RESOLVED states
- Multi-Polygon GIS: Each concurrent incident rendered as a separate colour-coded blast zone
- Topology Clustering: BHQ nodes with >10 offline GPs collapse into a single "Nx GP OFFLINE" cluster node
- Bounding-box Zoom: Map auto-zooms to fit all concurrent fault locations
- Webhook Boilerplate: ServiceNow + Grafana integration stubs (commented, production-ready)
Fault at BHQ-KARAIKAL:
โข 28 villages affected
โข 14.03 km radius
โข 226.58 kmยฒ area
โข Districts: KARAIKAL
โข Nearest alternate: BHQ-ARIANKUPPAM (105.75 km)
Maps each fault to its true OSI layer:
- Layer 1 (Physical): Power, hardware, fiber issues โ Field engineer dispatch
- Layer 2 (Data Link): MAC/switching issues โ NOC L2 remote fix
- Layer 3 (Network): Routing, QoS, congestion โ NOC L2 remote fix
Cascade Detection: When L1 fails, L2-L7 cascade simultaneously.
Field Dispatch Tickets (L1 faults):
Priority: CRITICAL
Assignment: Field Engineer
GPS: 10.912990ยฐN, 79.847562ยฐE โ Google Maps link
Tools: UPS battery, Generator, Multimeter
ETA: 2 hours
Remote NOC L2 Tickets (L2/L3 faults):
Priority: HIGH
Assignment: NOC L2 Engineer
CLI Commands: show policy-map interface...
ETA: 30 minutes
- 106 real nodes from Puducherry Phase-I BSNL data
- 4-tier hierarchy: SHQ โ DHQ โ BHQ (OLT) โ GP (Village)
- Real GPS coordinates for all 99 villages
- 2 districts: KARAIKAL (28 villages), PONDICHERRY (71 villages)
| Page | Purpose | Key Widget |
|---|---|---|
| 1. AI Analysis | Fault injection + graph topology | NetworkX graph with per-incident colouring |
| 2. NOC Operations | Live GIS + OSI stack + tickets | Folium multi-polygon fault map |
| 3. Complaint Portal | Customer complaint lookup | Blast-radius-filtered customer table |
| 4. Live Feed | Real-time telemetry stream | Scrolling SNMP log + threat ticker |
| 5. Executive SLA | Financial impact per incident | โน penalty calculator (live ticking) |
| 6. Field Engineer | Mobile-optimised dispatch | GPS + D-Link DIR-615 digital twin LEDs |
The mininet_digital_twin/ module virtualises the Puducherry BharatNet inside Mininet, creating a live kernel-level network that the AI pipeline can both monitor and control.
SHQ-PUDUCHERRY (OVSKernelSwitch โ core)
โโโ DHQ-KARAIKAL (OVSKernelSwitch โ aggregation)
โ โโโ BHQ-KARAIKAL (OVSKernelSwitch โ OLT)
โ โโโ GP-Ambagarathur (Host 10.1.1.1)
โ โโโ GP-Edatheru (Host 10.1.1.2)
โโโ DHQ-PONDICHERRY (OVSKernelSwitch โ aggregation)
โโโ BHQ-ARIANKUPPAM (OVSKernelSwitch โ OLT)
โ โโโ GP-Nallalapuram (Host 10.1.2.1)
โ โโโ GP-Periyapattinam (Host 10.1.2.2)
โโโ BHQ-VILLIANUR-1 (OVSKernelSwitch โ OLT)
โโโ GP-Sethur (Host 10.1.3.1)
โโโ GP-Vailankanni (Host 10.1.3.2)
| Segment | Bandwidth | Delay | Emulates |
|---|---|---|---|
| SHQ โ DHQ | 100 Mbps | 1 ms | 10 Gbps backbone |
| DHQ โ BHQ | 100 Mbps | 2 ms | Distribution uplink |
| BHQ โ GP host | 10 Mbps | 3 ms | GPON last-mile |
| File | Role |
|---|---|
mininet_topology.py |
Builds and starts the virtual network; writes topology_manifest.json |
fault_controller.py (engines/) |
Injects real kernel faults (ip link down, tc netem loss) into Mininet interfaces |
telemetry_agent.py (engines/) |
Scrapes live interface stats from Mininet โ writes current_telemetry.csv |
# Terminal 1 โ start virtual network
sudo python3 mininet_digital_twin/mininet_topology.py
# Terminal 2 โ start telemetry scraper
sudo python3 engines/telemetry_agent.py
# Terminal 3 โ inject a fault interactively
sudo python3 engines/fault_controller.py
# Terminal 4 โ run the Streamlit dashboard (reads live CSV)
streamlit run main.pyEmergency cleanup if Mininet crashes:
sudo mn -cMininet short names map to NetFaultAI canonical names:
| Mininet Name | Canonical Name |
|---|---|
shq1 |
SHQ-PUDUCHERRY |
dhqkar |
DHQ-KARAIKAL |
dhqpon |
DHQ-PONDICHERRY |
bhqkar |
BHQ-KARAIKAL |
bhqari |
BHQ-ARIANKUPPAM |
bhqvil |
BHQ-VILLIANUR-1 |
gpkar1 |
GP-Ambagarathur |
gpkar2 |
GP-Edatheru |
Note:
mininet_digital_twin/live_export/is a runtime-only folder. Its contents (current_telemetry.csv,active_faults.json,fault_overrides.json,topology_manifest.json) are generated at runtime and are excluded from version control via.gitignore.
Python 3.10+
16 GB RAM (recommended)
NVIDIA GPU (optional, for model training only)
# For Mininet Digital Twin (WSL Ubuntu only):
sudo apt-get install mininet openvswitch-switch# Clone the repository
git clone https://github.com/username/NetFaultAI.git
cd NetFaultAI
# Create virtual environment
python -m venv venv
source venv/bin/activate # Windows: venv\Scripts\activate
# Install dependencies
pip install -r requirements.txt# Generate training data (3,600 samples)
python training/generate_syslog_data.py
# Train model (~15-20 minutes on RTX 3050)
python training/train_distilbert.py
# Output: models/distilbert_finetuned/System works with regex fallback if model not trained (90%+ accuracy).
streamlit run main.pyBrowser opens at http://localhost:8501
python tests/test_all.py # Full suite (13 tests)
python tests/test_all.py --test nlp # NLP only
python tests/test_all.py --test performance # Performance only- Open AI Analysis page
- Select a fault type (e.g., "Voltage Issue")
- Click "๐ฅ Inject Fault"
- View NLP classification, anomaly score, blast radius, network graph
- Switch to NOC Operations โ see GIS overlay, OSI stack, auto-ticket
- Switch to Executive SLA โ see live โน penalty accumulating
- Switch to Field Engineer โ see GPS dispatch + D-Link LED widget
NetFaultAI/
โ
โโโ main.py # Streamlit entry point + incident ledger
โโโ requirements.txt # Python dependencies
โโโ .gitignore # Excludes venv/, __pycache__/, live_export/
โ
โโโ pages/ # Streamlit multi-page app
โ โโโ 1_AI_Analysis.py # Topology graph + fault injection
โ โโโ 2_NOC_Operations.py # GIS map + OSI stack + tickets
โ โโโ 3_Complaint_Portal.py # Customer complaint lookup
โ โโโ 4_Live_Feed.py # Real-time telemetry stream
โ โโโ 5_Executive_SLA.py # Financial SLA penalty dashboard
โ โโโ 6_Field_Engineer.py # Mobile field dispatch + HW twin
โ
โโโ engines/ # AI/ML engines
โ โโโ fusion.py # Multi-stream AI fusion (Phase 2: multi-fault)
โ โโโ nlp_engine.py # distilBERT + regex 6-class classifier
โ โโโ anomaly_engine.py # Isolation Forest SNMP outlier detection
โ โโโ blast_radius.py # Geographical impact calculator
โ โโโ osi_mapper.py # OSI layer 1-7 fault mapping
โ โโโ ticket_router.py # Auto field/NOC ticket generation
โ โโโ fault_scenarios.py # 6 demo fault scenarios
โ โโโ llm_rag_engine.py # LLM RAG assistant (experimental)
โ โโโ fault_controller.py # Mininet fault injector companion
โ โโโ telemetry_agent.py # Mininet live telemetry scraper
โ
โโโ graph/ # Network topology
โ โโโ topology_builder.py # 106-node BharatNet graph builder
โ โโโ gis_map.py # Folium interactive map generator
โ
โโโ mininet_digital_twin/ # Live virtual network (WSL/Linux only)
โ โโโ mininet_topology.py # 4-tier OVS topology + auto manifest
โ โโโ live_export/ # Runtime outputs (git-ignored)
โ โโโ .gitkeep
โ
โโโ models/ # Trained model artefacts
โ โโโ anomaly/
โ โ โโโ iforest.pkl # Trained Isolation Forest
โ โ โโโ scaler.pkl # Feature scaler
โ โ โโโ thresholds.pkl # Anomaly thresholds
โ โโโ distilbert_finetuned/
โ โโโ tfidf_svm_model.pkl # TF-IDF + SVM (fast fallback)
โ โโโ config.json # Model config (6 fault classes)
โ โโโ label_map.json # ID โ label mappings
โ โโโ training_metrics.json # Accuracy / F1 / confusion matrix
โ โโโ version.txt # Model version tag
โ
โโโ data/ # Network + training data
โ โโโ data_loader.py # NetworkDataLoader API
โ โโโ customer_db.py # Customer lookup (O(1) by GP)
โ โโโ realtime_feed.py # Live telemetry feed reader
โ โโโ network_hierarchy.json # 106-node SHQโDHQโBHQโGP structure
โ โโโ customers.csv # 198 synthetic customer records
โ โโโ puducherry_gp_data.csv # 99 villages + GPS coordinates
โ โโโ puducherry_olt_data.csv # 4 OLT locations + GPS
โ โโโ sample_snmp_metrics.csv # SNMP baseline samples
โ โโโ sample_syslogs.csv # Syslog baseline samples
โ โโโ syslog_training_data.csv # 3,600 labeled training samples
โ โโโ snmp_exports/ # Per-fault SNMP scenario CSVs
โ โโโ snmp_fault_voltage_issue.csv
โ โโโ snmp_fault_hardware_defect.csv
โ โโโ snmp_fault_traffic_congestion.csv
โ โโโ snmp_fault_latency_degradation.csv
โ โโโ snmp_fault_connection_issue.csv
โ โโโ snmp_fault_legacy_bottleneck.csv
โ โโโ snmp_multi_fault_scenario.csv
โ โโโ snmp_normal_baseline.csv
โ โโโ snmp_zabbix_format_export.csv
โ โโโ demo_snmp_export.csv
โ
โโโ training/ # Model training scripts
โ โโโ generate_syslog_data.py # Generates 3,600 labeled syslog samples
โ โโโ train_distilbert.py # Fine-tunes distilBERT (RTX 3050 optimised)
โ
โโโ tests/
โโโ test_all.py # 13 comprehensive integration tests
- Network Topology: Puducherry Phase-I BharatNet (BSNL)
- Training Data: 3,600 synthetic syslog samples (600 per class ร 6 types)
- GPS Coordinates: Real village locations (10.87ยฐNโ12.00ยฐN, 79.64ยฐEโ79.85ยฐE)
- NLP: distilBERT fine-tuned (67M parameters, 92%+ accuracy) + TF-IDF SVM fallback
- Anomaly: Isolation Forest (100 trees, contamination=0.05, 8-core parallel)
- Fusion: Weighted voting (NLP 40%, Anomaly 40%, Context 20%)
- Pipeline Execution: <2ms (excluding model cold start)
- With BERT: ~50ms per inference
- Target: <100ms โ (55ร faster than target)
- Current: 106 nodes (Puducherry)
- Designed for: 10,000+ nodes (All India BharatNet)
- Graph algorithms: O(n) BFS, O(n log n) shortest path
======================================================================
NetFaultAI โ Test Suite Results
======================================================================
Phase 1-2: Data & Topology โ 3/3 tests passed
Phase 3-5: AI Engines โ 7/7 tests passed
Phase 6 & Integration โ 3/3 tests passed
Total: โ 13/13 tests passed (100%)
Performance: โ 1.8ms (target <100ms)
System Status: READY FOR PRODUCTION
Based on 15 academic papers (2021-2025):
- LogBERT (ICDM 2021): Transformer-based log anomaly detection
- GNN Fault Localization (TMC 2023): Graph neural networks for root cause
- Isolation Forest (IEEE Trans 2012): Unsupervised anomaly detection
- Telecom RCA (AAAI 2024): Root cause analysis in 5G networks
- Network Embedding (KDD 2023): Graph representation learning
Requirements Met:
- โ Real-time fault detection (<60 seconds)
- โ Root cause localisation (graph BFS + AI)
- โ Customer impact calculation (blast radius)
- โ Automated ticketing (field + NOC routing)
- โ OSI layer awareness (L1-L7 mapping)
- โ Geographical visualisation (GIS maps)
Innovation:
- โ First system to automate blast radius in telecom
- โ Geographical intelligence (distance, area, village names)
- โ Multi-stream AI fusion (NLP + Anomaly + Context)
- โ Real BharatNet topology (not synthetic)
- โ Live Mininet Digital Twin โ real kernel faults, not just simulation
Fault Detection: Manual (30-60 minutes)
Root Cause Analysis: Manual (1-2 hours)
Customer Impact Calc: Manual (1-3 hours)
Ticket Routing: Manual (15-30 minutes)
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Total Time: 2-6 hours
Fault Detection: Automated (<1 second)
Root Cause Analysis: Automated (<1 second)
Customer Impact Calc: Automated (<1 second)
Ticket Routing: Automated (<1 second)
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Total Time: <60 seconds
Time Reduction: 99.7%
Cost Savings: ~โน50,000/incident (labour cost)
Customer Satisfaction: MTTR reduced 120ร (6 hours โ 3 minutes)
- Python 3.10+
- Streamlit โ Dashboard framework
- PyTorch + HuggingFace โ NLP models
- scikit-learn โ Anomaly detection + TF-IDF SVM
- NetworkX โ Graph topology
- Folium โ GIS mapping
- Pandas / NumPy โ Data processing
- Plotly โ SLA charts + telemetry graphs
- Mininet + OVS โ Network virtualisation (Digital Twin)
- Development: Intel i5-12450H, 16 GB RAM, RTX 3050 6 GB
- Training Time: 15-20 minutes (distilBERT fine-tuning)
- Inference Time: <2ms (optimised pipeline)
MIT License โ see LICENSE file
Built in TANFINET Hackathon 2025
- BSNL โ Puducherry Phase-I network data
- BharatNet โ National fiber backbone programme
- TANFINET โ Hackathon organisation
- HuggingFace โ Pre-trained language models
- Streamlit โ Dashboard framework
- Mininet / Open vSwitch โ Network emulation platform
For questions or demo requests:
- GitHub Issues: Create an issue
- Email: shriharsang@gmail.com
- Multi-vendor equipment support (Cisco, Juniper, Nokia)
- Historical trend analysis (predict failures before they occur)
- Integration with existing OSS/BSS systems
- Real Mininet โ full 106-node topology (currently 12-node representative sample)
- Real-time streaming telemetry via gRPC
- Expand to All India BharatNet (250,000+ GPs)
NetFaultAI โ Bringing AI-powered automation to India's digital infrastructure ๐ฎ๐ณ