Hughes Network Systems is only three years into its artificial intelligence (AI) efforts, according to CTO Frank Kelly, but the service provider has already made strides in using automation to identify security anomalies, reduce customer service congestion, and improve resiliency across its very small aperture terminal (VSAT) and enterprise networks.

The company announced AIOps capabilities for SD-WAN in 2020 to predict and self-heal anomalies in network behavior, which has since proven to prevent 70% of service-disrupting symptoms “without even having anyone get involved,” Kelly said.

These AIOps capabilities include the capability to detect – using memory usage or errors in TCP sessions – that a device requires Hughes to manually reset certain components inside of the hardware.

[caption id="attachment_126801" align="aligncenter" width="150"] Frank Kelly, CTO, Hughes Network Systems,
Source: Hughes Network Systems[/caption]

More recently, Hughes announced its Active Power Edge, a power distribution unit designed to monitor power and connection status at endpoints and leverage AI to reset outlets and power cycle connected devices.

The Active Power Edge will allow Hughes to reach out to the various devices at a location to see if any aren't responding. “If those devices aren't responding, [Hughes] may just go ahead and hit the power cord because we know by experience, most of the time when there's an issue in the network, rule number one is restart it, go out, unplug it, plug it in,” Kelly said.

This will be especially useful in business scenarios where it’s inconvenient to run tests and restart devices on site, he added, such as in the case of a restaurant during rush hour.

The company will also absorb data on a “very regular basis” from the Active Power Edge to bolster its self-healing algorithms.

AI Remediation Requires Trust

Hughes uses AI remediation for SD-WAN and 4G wireless, where AIOps not only detects anomalies in network behavior, but also assesses the risk-reward of potential corrective actions, autonomously takes appropriate measures, and tracks performance to ensure a return to steady-state parameters.

While the company has already implemented detection capabilities in VSAT networks, the goal is to extend remediation capabilities to them as well, and ultimately drive down customer call center costs, Kelly told SDxCentral. "The only way we're going to do that is auto remediation."

But remediation is the “toughest nut to crack" when it comes to implementing network automation, mostly because network management teams are reluctant to trust that the algorithms will do more good than harm.

“Trust has to be rebuilt on every new problem. And that's the challenge, every time there's a new algorithm, no one trusts the computer until they do it themselves,” he added. “They want to save time but on the other hand, they don't want to have to deal with fallout if you take some automated action that just caused something else to go nuts in a way that wouldn't have otherwise gone nuts.”

That said, there will always be what Kelly called a “validation process” for each new platform or type of problem before IT teams have complete confidence in AI.

“Operations and customer service don't want to create a new, immediate action without them validating it first. So it isn't about the trouble shooting part and the isolation. It's about what happens when you take those actions. You have to prove that that works,” he said.

Automated MDR on Hughes Horizon

Hughes announced its managed detection and response (MDR) services in January, and plans to launch security orchestration, automation, and response (SOAR) capabilities to enhance its current MDR capabilities this year. Other service providers have announced MDR undertakings due to mounting layoffs impacting security budgets and aggravating cybersecurity threats for businesses.

Fortinet recently dedicated 500 FortiGuard Labs researchers to the development of a machine learning (ML) model for MDR services. And Forrester analysts expect Amazon / Amazon Web Services (AWS) to acquire an MDR vendor in 2023.

Kelly said Hughes' SOC operations teams already run manual detect and remediate processes in its PCI-compliant enterprise networks, and that experience will help differentiate the service from others on the market. “We know how to review the data and how to find these issues. And the goal is to have ways of automatically resolving them,” he added. “Then what we're reporting to a customer is a security issue resolved, not a security issue that they have to go fix.”

For example, an automated MDR service could disable rogue devices from a network, or detect traffic heading into geographic areas that “shouldn’t be connected to my network at all,” Kelly explained. “We're looking at doing some really interesting stuff in the MDR space.”