<?xml version="1.0" encoding="US-ASCII"?>
<!DOCTYPE rfc SYSTEM "rfc2629.dtd">
<?rfc toc="yes"?>
<?rfc tocompact="yes"?>
<?rfc tocdepth="2"?>
<?rfc tocindent="yes"?>
<?rfc symrefs="yes"?>
<?rfc sortrefs="yes"?>
<?rfc comments="yes"?>
<?rfc inline="yes"?>
<?rfc compact="yes"?>
<?rfc subcompact="no"?>
<rfc category="exp" docName="draft-netana-nmop-network-anomaly-semantics-02"
     ipr="trust200902">
  <front>
    <title abbrev="Network Anomaly Semantics">Semantic Metadata Annotation for
    Network Anomaly Detection</title>

    <author fullname="Thomas Graf" initials="T" surname="Graf">
      <organization>Swisscom</organization>

      <address>
        <postal>
          <street>Binzring 17</street>

          <city>Zurich</city>

          <code>8045</code>

          <country>Switzerland</country>
        </postal>

        <email>thomas.graf@swisscom.com</email>
      </address>
    </author>

    <author fullname="Wanting Du" initials="W" surname="Du">
      <organization>Swisscom</organization>

      <address>
        <postal>
          <street>Binzring 17</street>

          <city>Zurich</city>

          <code>8045</code>

          <country>Switzerland</country>
        </postal>

        <email>wanting.du@swisscom.com</email>
      </address>
    </author>

    <author fullname="Alex Huang Feng" initials="A." surname="Huang Feng">
      <organization>INSA-Lyon</organization>

      <address>
        <postal>
          <street/>

          <city>Lyon</city>

          <region/>

          <code/>

          <country>France</country>
        </postal>

        <phone/>

        <facsimile/>

        <email>alex.huang-feng@insa-lyon.fr</email>

        <uri/>
      </address>
    </author>

    <author fullname="Vincenzo Riccobene" initials="V." surname="Riccobene">
      <organization>Huawei</organization>

      <address>
        <postal>
          <street/>

          <city>Dublin</city>

          <region/>

          <code/>

          <country>Ireland</country>
        </postal>

        <phone/>

        <facsimile/>

        <email>vincenzo.riccobene@huawei-partners.com</email>

        <uri/>
      </address>
    </author>

    <author fullname="Antonio Roberto" initials="A." surname="Roberto">
      <organization>Huawei</organization>

      <address>
        <postal>
          <street/>

          <city>Dublin</city>

          <region/>

          <code/>

          <country>Ireland</country>
        </postal>

        <phone/>

        <facsimile/>

        <email>antonio.roberto@huawei.com</email>

        <uri/>
      </address>
    </author>

    <date day="07" month="July" year="2024"/>

    <area>Operations and Management</area>

    <workgroup>NMOP</workgroup>

    <abstract>
      <t>This document explains why and how semantic metadata annotation helps
      to test, validate and compare outlier detection, supports supervised and
      semi-supervised machine learning development, enables data exchange
      among network operators, vendors and academia and make anomalies for
      humans apprehensible. The proposed semantics uniforms the network
      anomaly data exchange between and among operators and vendors to improve
      their network outlier detection systems.</t>
    </abstract>

    <note removeInRFC="true">
      <name>Discussion Venues</name>

      <t>Discussion of this document takes place on the Operations and
      Management Area Working Group Working Group mailing list
      (nmop@ietf.org), which is archived at <eref
      target="https://mailarchive.ietf.org/arch/browse/nmop/"/>.</t>

      <t>Source for this draft and an issue tracker can be found at <eref
      target="https://github.com/network-analytics/draft-netana-nmop-network-anomaly-semantics/"/>.</t>
    </note>
  </front>

  <middle>
    <section anchor="Introduction" title="Introduction">
      <t><xref target="I-D.netana-nmop-network-anomaly-architecture"/>
      provides an overall introduction into how anomaly detection is being
      applied into the IP network domain and which operational data is needed.
      It approaches the problem space by automating what a Network Engineer
      would normally do when verifying a network connectivity service. Monitor
      from different network plane perspectives to understand wherever one
      network plane affects another negatively.</t>

      <t>In order to fine tune outlier detection as described in <xref
      target="I-D.netana-nmop-network-anomaly-lifecycle"/>, the results
      provided as analytical data need to be reviewed by a Network Engineer.
      Keeping the human out of the monitoring but still involving him in the
      alert verification loop.</t>

      <t>This document describes what information is needed to understand the
      output of the outlier detection for a Network Engineer, but also at the
      same time is semantically structured that it can be used for outlier
      detection testing by comparing the results systematically and set a
      baseline for supervised machine learning which requires labeled
      operational data.</t>
    </section>

    <section anchor="Conventions_and_Definitions"
             title="Conventions and Definitions">
      <t>The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
      "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and
      "OPTIONAL" in this document are to be interpreted as described in BCP 14
      <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when,
      they appear in all capitals, as shown here.</t>

      <section anchor="Terminology" title="Terminology">
        <t>This document defines the following terms:</t>

        <t>Message Broker: is an intermediary software component that
        translates messages from the formal messaging protocol of the sender
        to the formal messaging protocol of the receiver routed in topics.
        Message brokers are elements in Data Mesh where software applications
        communicate by exchanging formally-defined messages.</t>

        <t>Stream Catalog: provides a single point of access that allows users
        to centrally search semantics for information across a Message
        Broker.</t>

        <t>Additionally it makes use of the terms defined in <xref
        target="I-D.netana-nmop-network-anomaly-architecture"/> and <xref
        target="I-D.ietf-nmop-terminology"/>.</t>

        <t>The following terms are used as defined in <xref
        target="I-D.netana-nmop-network-anomaly-architecture"/>:</t>

        <t><list style="symbols">
            <t>Outlier</t>
          </list></t>

        <t>The following terms are used as defined in <xref
        target="I-D.ietf-nmop-terminology"/>:</t>

        <t><list style="symbols">
            <t>System</t>

            <t>Detect</t>

            <t>Event</t>

            <t>State</t>

            <t>Relevance</t>

            <t>Occurrence</t>

            <t>Problem</t>

            <t>Symptom</t>

            <t>Cause</t>

            <t>Alert</t>
          </list></t>
      </section>
    </section>

    <section anchor="Observed_Symptoms" title="Observed Symptoms">
      <t>In this section observed network symptoms are specified and
      categorized according to the following scheme:</t>

      <dl>
        <dt>Action:</dt>

        <dd>
          <t>Which action the network node performed for a packet in the
          Forwarding Plane, a path or adjacency in the Control Plane or state
          or statistical changes in the Management Plane. For Forwarding Plane
          we distinguish between missing, where the drop occurred outside the
          measured network node, drop and on-path delay, which was measured on
          the network node. For Control Plane we distinguish between
          reachability, which refers to a change in the routing or forwarding
          information base (RIB/FIB) and adjacency which refers to a change in
          peering or link-layer resolution. For Management Plane we refer to
          state or statistical changes on interfaces.</t>
        </dd>
      </dl>

      <dl>
        <dt>Reason:</dt>

        <dd>
          <t>For each action, one or more reasons describe why this action was
          used. For Drops in Forwarding Plane we distinguish between
          Unreachable because network layer reachability information was
          missing, Administered because an administrator configured a rule
          preventing the forwarding for this packet and Corrupt where the
          network node was unable to determine where to forward to due to
          packet, software or hardware error. For on-path delay we distinguish
          between Minimum, Average and Maximum Delay for a given flow. For
          Control Plane wherever a the reachability was updated or withdrawn
          or the adjacency was established or teared down. For Management
          Plane we distinguish between interfaces states up and down, and
          statistical errors, discards or unknown protocol counters.</t>
        </dd>
      </dl>

      <dl>
        <dt>Cause:</dt>

        <dd>
          <t>For each reason one or more cause describe the cause why the
          network node has chosen that action.</t>
        </dd>
      </dl>

      <t><xref target="symptom_forwarding_plane_actions_table"/> consolidates
      for the forwarding plane a list of common symptoms with their Actions,
      Reasons and Causes.</t>

      <table align="center" anchor="symptom_forwarding_plane_actions_table">
        <name slugifiedName="symptom_forwarding_plane_actions">Describing
        Symptoms and their Actions, Reason and Cause for Forwarding
        Plane</name>

        <thead>
          <tr>
            <th align="left" colspan="1" rowspan="1">Action</th>

            <th align="left" colspan="1" rowspan="1">Reason</th>

            <th align="left" colspan="1" rowspan="1">Cause</th>
          </tr>
        </thead>

        <tbody>
          <tr>
            <td align="left" colspan="1" rowspan="1">Missing</td>

            <td align="left" colspan="1" rowspan="1">Previous</td>

            <td align="left" colspan="1" rowspan="1">Time</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Drop</td>

            <td align="left" colspan="1" rowspan="1">Unreachable</td>

            <td align="left" colspan="1" rowspan="1">next-hop</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Drop</td>

            <td align="left" colspan="1" rowspan="1">Unreachable</td>

            <td align="left" colspan="1" rowspan="1">link-layer</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Drop</td>

            <td align="left" colspan="1" rowspan="1">Unreachable</td>

            <td align="left" colspan="1" rowspan="1">Time To Life expired</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Drop</td>

            <td align="left" colspan="1" rowspan="1">Unreachable</td>

            <td align="left" colspan="1" rowspan="1">Fragmentation needed and
            Don't Fragment set</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Drop</td>

            <td align="left" colspan="1" rowspan="1">Administered</td>

            <td align="left" colspan="1" rowspan="1">Access-List</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Drop</td>

            <td align="left" colspan="1" rowspan="1">Administered</td>

            <td align="left" colspan="1" rowspan="1">Unicast Reverse Path
            Forwarding</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Drop</td>

            <td align="left" colspan="1" rowspan="1">Administered</td>

            <td align="left" colspan="1" rowspan="1">Discard Route</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Drop</td>

            <td align="left" colspan="1" rowspan="1">Administered</td>

            <td align="left" colspan="1" rowspan="1">Policed</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Drop</td>

            <td align="left" colspan="1" rowspan="1">Administered</td>

            <td align="left" colspan="1" rowspan="1">Shaped</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Drop</td>

            <td align="left" colspan="1" rowspan="1">Corrupt</td>

            <td align="left" colspan="1" rowspan="1">Bad Packet</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Drop</td>

            <td align="left" colspan="1" rowspan="1">Corrupt</td>

            <td align="left" colspan="1" rowspan="1">Bad Egress Interface</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Delay</td>

            <td align="left" colspan="1" rowspan="1">Min</td>

            <td align="left" colspan="1" rowspan="1">-</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Delay</td>

            <td align="left" colspan="1" rowspan="1">Mean</td>

            <td align="left" colspan="1" rowspan="1">-</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Delay</td>

            <td align="left" colspan="1" rowspan="1">Max</td>

            <td align="left" colspan="1" rowspan="1">-</td>
          </tr>
        </tbody>
      </table>

      <t><xref target="symptom_control_plane_actions_table"/> consolidates for
      the control plane a list of common symptoms with their actions, reasons
      and causess.</t>

      <table align="center" anchor="symptom_control_plane_actions_table">
        <name slugifiedName="symptom_control_plane_actions">Describing
        Symptoms and their Actions, Reason and Cause for Control Plane</name>

        <thead>
          <tr>
            <th align="left" colspan="1" rowspan="1">Action</th>

            <th align="left" colspan="1" rowspan="1">Reason</th>

            <th align="left" colspan="1" rowspan="1">Cause</th>
          </tr>
        </thead>

        <tbody>
          <tr>
            <td align="left" colspan="1" rowspan="1">Reachability</td>

            <td align="left" colspan="1" rowspan="1">Update</td>

            <td align="left" colspan="1" rowspan="1">Imported</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Reachability</td>

            <td align="left" colspan="1" rowspan="1">Update</td>

            <td align="left" colspan="1" rowspan="1">Received</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Reachability</td>

            <td align="left" colspan="1" rowspan="1">Withdraw</td>

            <td align="left" colspan="1" rowspan="1">Received</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Reachability</td>

            <td align="left" colspan="1" rowspan="1">Withdraw</td>

            <td align="left" colspan="1" rowspan="1">Peer Down</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Reachability</td>

            <td align="left" colspan="1" rowspan="1">Withdraw</td>

            <td align="left" colspan="1" rowspan="1">Suppressed</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Reachability</td>

            <td align="left" colspan="1" rowspan="1">Withdraw</td>

            <td align="left" colspan="1" rowspan="1">Stale</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Reachability</td>

            <td align="left" colspan="1" rowspan="1">Withdraw</td>

            <td align="left" colspan="1" rowspan="1">Route Policy
            Filtered</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Reachability</td>

            <td align="left" colspan="1" rowspan="1">Withdraw</td>

            <td align="left" colspan="1" rowspan="1">Maximum Number of
            Prefixes Reached</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Adjacency</td>

            <td align="left" colspan="1" rowspan="1">Established</td>

            <td align="left" colspan="1" rowspan="1">Peer</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Adjacency</td>

            <td align="left" colspan="1" rowspan="1">Established</td>

            <td align="left" colspan="1" rowspan="1">Link-Layer</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Adjacency</td>

            <td align="left" colspan="1" rowspan="1">Locally Teared Down</td>

            <td align="left" colspan="1" rowspan="1">Peer</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Adjacency</td>

            <td align="left" colspan="1" rowspan="1">Remotely Teared Down</td>

            <td align="left" colspan="1" rowspan="1">Peer</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Adjacency</td>

            <td align="left" colspan="1" rowspan="1">Locally Teared Down</td>

            <td align="left" colspan="1" rowspan="1">Link-Layer</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Adjacency</td>

            <td align="left" colspan="1" rowspan="1">Remotely Teared Down</td>

            <td align="left" colspan="1" rowspan="1">Link-Layer</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Adjacency</td>

            <td align="left" colspan="1" rowspan="1">Locally Teared Down</td>

            <td align="left" colspan="1" rowspan="1">Administrative</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Adjacency</td>

            <td align="left" colspan="1" rowspan="1">Remotely Teared Down</td>

            <td align="left" colspan="1" rowspan="1">Administrative</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Adjacency</td>

            <td align="left" colspan="1" rowspan="1">Locally Teared Down</td>

            <td align="left" colspan="1" rowspan="1">Maximum Number of
            Prefixes Reached</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Adjacency</td>

            <td align="left" colspan="1" rowspan="1">Remotely Teared Down</td>

            <td align="left" colspan="1" rowspan="1">Maximum Number of
            Prefixes Reached</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Adjacency</td>

            <td align="left" colspan="1" rowspan="1">Locally Teared Down</td>

            <td align="left" colspan="1" rowspan="1">Transport Connection
            Failed</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Adjacency</td>

            <td align="left" colspan="1" rowspan="1">Remotely Teared Down</td>

            <td align="left" colspan="1" rowspan="1">Transport Connection
            Failed</td>
          </tr>
        </tbody>
      </table>

      <t><xref target="symptom_management_plane_actions_table"/> consolidates
      for the management plane a list of common symptoms with their Actions,
      Reasons and Causes.</t>

      <table align="center" anchor="symptom_management_plane_actions_table">
        <name slugifiedName="symptom_management_plane_actions">Describing
        Symptoms and their Actions, Reason and Cause for Management
        Plane</name>

        <thead>
          <tr>
            <th align="left" colspan="1" rowspan="1">Action</th>

            <th align="left" colspan="1" rowspan="1">Reason</th>

            <th align="left" colspan="1" rowspan="1">Cause</th>
          </tr>
        </thead>

        <tbody>
          <tr>
            <td align="left" colspan="1" rowspan="1">Interface</td>

            <td align="left" colspan="1" rowspan="1">Up</td>

            <td align="left" colspan="1" rowspan="1">Link-Layer</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Interface</td>

            <td align="left" colspan="1" rowspan="1">Down</td>

            <td align="left" colspan="1" rowspan="1">Link-Layer</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Interface</td>

            <td align="left" colspan="1" rowspan="1">Errors</td>

            <td align="left" colspan="1" rowspan="1">-</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Interface</td>

            <td align="left" colspan="1" rowspan="1">Discards</td>

            <td align="left" colspan="1" rowspan="1">-</td>
          </tr>

          <tr>
            <td align="left" colspan="1" rowspan="1">Interface</td>

            <td align="left" colspan="1" rowspan="1">Unknown Protocol</td>

            <td align="left" colspan="1" rowspan="1">-</td>
          </tr>
        </tbody>
      </table>
    </section>

    <section anchor="Semantic_Metadata" title="Semantic Metadata">
      <t>Metadata adds additional context to data. For instance, in networks
      the software version of a network node where Management Plane metrics
      are obtained from as described in<xref
      target="I-D.claise-opsawg-collected-data-manifest"/>. Where in Semantic
      Metadata the meaning or ontology of the annotated data is being
      described. In this section a YANG model is defined in order to provide a
      structure for the metadata related to anomalies happening in the
      network. The module is intended to describe the metadata used to
      "annotate" the operational data collected from the network nodes, which
      can include time series data and logs, as well as other forms of data
      that is "time-bounded". The aspects discussed so far in this document
      are grouped under the concept of "anomaly" which represents a collection
      of symptoms. The anomaly overall has a set of parameters that describe
      the overall behavior of the network in a given time-window including all
      the spotted symptoms (network anomalies).</t>

      <section anchor="symptom-model-tree"
               title="Overview of the Model for the Symptom Semantic Metadata">
        <t><xref target="symptom-semantic-metadata-tree"/> contains the YANG
        tree diagram <xref target="RFC8340"/> of the <xref
        target="ietf-interfaces-with-symptoms-module"/> which augments the
        <xref target="RFC8343"/> defined ietf-interfaces and the <xref
        target="ietf-symptom-semantic-metadata-module"/>.</t>

        <t>For each symptom, the following parameters have been assigned: A
        unique ID for identification, a description of the symptom, a list of
        affected metrics or counters, start and end time to specify the
        time-window, a confident score indicating how accurate the symptom was
        detected, a concern score indicating how critical the symptom is, the
        annotator indicating if it has been identified by a network expert or
        an algorithm, the tags with key value where Action, Reason and Cause
        can be annotated as described in previous section.</t>

        <t><figure anchor="ietf-interfaces-with-symptoms-module"
            title="ietf-interfaces-with-symptoms Example YANG Module">
            <artwork><![CDATA[
<CODE BEGINS> file "ietf-interfaces-with-symptoms@2024-06-29.yang"
module ietf-interfaces-with-symptoms {
    yang-version 1.1;
    namespace "http://example.org/example-ietf-interfaces-with-symptoms";
    prefix "ifws";

    import ietf-symptom-semantic-metadata {
        prefix "sm";
    }
    import ietf-interfaces {
        prefix "if";
    }

    revision 2024-06-29 {
        description
          "Initial version";
        reference
          "Example: Symptoms Annotated IETF Interface";
    }

    augment "/if:interfaces/if:interface" {
        description
        "Augment interfaces with symptoms";
        uses sm:symptom-group;
    }
    augment "/if:interfaces-state/if:interface" {
        description
         "Augment interfaces with symptoms";
        uses sm:symptom-group;
  }
}
<CODE ENDS>]]></artwork>
          </figure></t>

        <t><figure anchor="symptom-semantic-metadata-tree"
            title="YANG tree diagram for ietf-symptom-semantic-metadata">
            <artwork><![CDATA[
module: ietf-interfaces
  +--rw interfaces
  |  +--rw interface* [name]
  |     +--rw name                        string
  |     +--rw description?                string
  |     +--rw type                        identityref
  |     +--rw enabled?                    boolean
  |     +--rw link-up-down-trap-enable?   enumeration {if-mib}?
  |     +--ro admin-status                enumeration {if-mib}?
  |     +--ro oper-status                 enumeration
  |     +--ro last-change?                yang:date-and-time
  |     +--ro if-index                    int32 {if-mib}?
  |     +--ro phys-address?               yang:phys-address
  |     +--ro higher-layer-if*            interface-ref
  |     +--ro lower-layer-if*             interface-ref
  |     +--ro speed?                      yang:gauge64
  |     +--ro statistics
  |     |  +--ro discontinuity-time    yang:date-and-time
  |     |  +--ro in-octets?            yang:counter64
  |     |  +--ro in-unicast-pkts?      yang:counter64
  |     |  +--ro in-broadcast-pkts?    yang:counter64
  |     |  +--ro in-multicast-pkts?    yang:counter64
  |     |  +--ro in-discards?          yang:counter32
  |     |  +--ro in-errors?            yang:counter32
  |     |  +--ro in-unknown-protos?    yang:counter32
  |     |  +--ro out-octets?           yang:counter64
  |     |  +--ro out-unicast-pkts?     yang:counter64
  |     |  +--ro out-broadcast-pkts?   yang:counter64
  |     |  +--ro out-multicast-pkts?   yang:counter64
  |     |  +--ro out-discards?         yang:counter32
  |     |  +--ro out-errors?           yang:counter32
  |     +--rw ifws:symptom
  |        +--rw ifws:id?                        yang:uuid
  |        +--rw ifws:event-id?                  yang:uuid
  |        +--rw ifws:description?               string
  |        +--rw ifws:start-time?                yang:date-and-time
  |        +--rw ifws:end-time?                  yang:date-and-time
  |        +--rw ifws:confidence-score?          score
  |        +--rw ifws:concern-score?             score
  |        +--rw ifws:tags* [key]
  |        |  +--rw ifws:key      string
  |        |  +--rw ifws:value    string
  |        +--rw (ifws:pattern)?
  |        |  +--:(ifws:drop)
  |        |  |  +--rw ifws:drop                 empty
  |        |  +--:(ifws:spike)
  |        |  |  +--rw ifws:spike                empty
  |        |  +--:(ifws:mean-shift)
  |        |  |  +--rw ifws:mean-shift           empty
  |        |  +--:(ifws:seasonality-shift)
  |        |  |  +--rw ifws:seasonality-shift    empty
  |        |  +--:(ifws:trend)
  |        |  |  +--rw ifws:trend                empty
  |        |  +--:(ifws:other)
  |        |     +--rw ifws:other                string
  |        +--rw ifws:annotator
  |           +--rw (ifws:annotator-type)
  |           |  +--:(ifws:human)
  |           |  |  +--rw ifws:human        empty
  |           |  +--:(ifws:algorithm)
  |           |     +--rw ifws:algorithm    empty
  |           +--rw ifws:name?              string
  x--ro interfaces-state
     x--ro interface* [name]
        x--ro name               string
        x--ro type               identityref
        x--ro admin-status       enumeration {if-mib}?
        x--ro oper-status        enumeration
        x--ro last-change?       yang:date-and-time
        x--ro if-index           int32 {if-mib}?
        x--ro phys-address?      yang:phys-address
        x--ro higher-layer-if*   interface-state-ref
        x--ro lower-layer-if*    interface-state-ref
        x--ro speed?             yang:gauge64
        x--ro statistics
        |  x--ro discontinuity-time    yang:date-and-time
        |  x--ro in-octets?            yang:counter64
        |  x--ro in-unicast-pkts?      yang:counter64
        |  x--ro in-broadcast-pkts?    yang:counter64
        |  x--ro in-multicast-pkts?    yang:counter64
        |  x--ro in-discards?          yang:counter32
        |  x--ro in-errors?            yang:counter32
        |  x--ro in-unknown-protos?    yang:counter32
        |  x--ro out-octets?           yang:counter64
        |  x--ro out-unicast-pkts?     yang:counter64
        |  x--ro out-broadcast-pkts?   yang:counter64
        |  x--ro out-multicast-pkts?   yang:counter64
        |  x--ro out-discards?         yang:counter32
        |  x--ro out-errors?           yang:counter32
        +--ro ifws:symptom
           +--ro ifws:id?                        yang:uuid
           +--ro ifws:event-id?                  yang:uuid
           +--ro ifws:description?               string
           +--ro ifws:start-time?                yang:date-and-time
           +--ro ifws:end-time?                  yang:date-and-time
           +--ro ifws:confidence-score?          score
           +--ro ifws:concern-score?             score
           +--ro ifws:tags* [key]
           |  +--ro ifws:key      string
           |  +--ro ifws:value    string
           +--ro (ifws:pattern)?
           |  +--:(ifws:drop)
           |  |  +--ro ifws:drop                 empty
           |  +--:(ifws:spike)
           |  |  +--ro ifws:spike                empty
           |  +--:(ifws:mean-shift)
           |  |  +--ro ifws:mean-shift           empty
           |  +--:(ifws:seasonality-shift)
           |  |  +--ro ifws:seasonality-shift    empty
           |  +--:(ifws:trend)
           |  |  +--ro ifws:trend                empty
           |  +--:(ifws:other)
           |     +--ro ifws:other                string
           +--ro ifws:annotator
              +--ro (ifws:annotator-type)
              |  +--:(ifws:human)
              |  |  +--ro ifws:human        empty
              |  +--:(ifws:algorithm)
              |     +--ro ifws:algorithm    empty
              +--ro ifws:name?              string
                    
            ]]></artwork>
          </figure></t>
      </section>

      <section anchor="YANG-Symptom-Module" title="YANG Module">
        <t>The YANG module has one typdef defining the score and a grouping
        which can be augmented.</t>

        <t><figure anchor="ietf-symptom-semantic-metadata-module"
            title="ietf-symptom-semantic-metadata YANG Module">
            <artwork><![CDATA[
<CODE BEGINS> file "ietf-symptom-semantic-metadata@2024-06-29.yang"
module ietf-symptom-semantic-metadata {
    yang-version 1.1;
    namespace "urn:ietf:params:xml:ns:yang:ietf-symptom-semantic-metadata";
    prefix sm;

    import ietf-yang-types {
        prefix yang;
        reference
          "RFC 6991: Common YANG Data Types";
    }

  organization "IETF NMOP (Network Management Operations) Working Group";
  contact
    "WG Web:   <http:/tools.ietf.org/wg/netconf/>
     WG List:  <mailto:nmop@ietf.org>

     Authors:  Thomas Graf
               <mailto:thomas.graf@swisscom.com>
               Wanting Du
               <mailto:wanting.du@swisscom.com>
               Alex Huang Feng
               <mailto:alex.huang-feng@insa-lyon.fr>
               Vincenzo Riccobene
               <mailto:vincenzo.riccobene@huawei-partners.com>
               Antonio Roberto
               <mailto:antonio.roberto@huawei.com>";
    description
        "This module defines symptom objects to be used by a network
         anomaly detection system. The defined objects can be used to
         augment operational network collected observability data and 
         analytical problem data equally. Describing the observed
         symptoms, confidence and concern scores and outlier patterns.

         Copyright (c) 2023 IETF Trust and the persons identified as
         authors of the code.  All rights reserved.

         Redistribution and use in source and binary forms, with or
         without modification, is permitted pursuant to, and subject
         to the license terms contained in, the Revised BSD License
         set forth in Section 4.c of the IETF Trust's Legal Provisions
         Relating to IETF Documents
         (https://trustee.ietf.org/license-info).

         This version of this YANG module is part of RFC XXXX; see the RFC
         itself for full legal notices.";

    revision 2024-06-29 {
        description
          "Initial version";
        reference
          "RFC XXX: Semantic Metadata Annotation for Network Anomaly Detection";
    }

    typedef score {
      type uint8 {
        range "0 .. 1";
      }
    }

    grouping symptom-group {
        container symptom {
            leaf id {
                type yang:uuid;
                description
                    "Unique ID of the symptom type";
            }
            leaf event-id {
                type yang:uuid;
                description "Reference to the network event this symptom is part of";
            }
            leaf description {
                type string;
                description
                    "Textual description of the symptom";
            }
            leaf start-time {
                type yang:date-and-time;
                description
                    "Date and time indicating the beginning of the symptom";
            }
            leaf end-time {
                type yang:date-and-time;
                description
                    "Date and time indicating the end of the symptom";
            }
            leaf confidence-score {
                type score;
            }
            leaf concern-score {
                type score;
            }
            list tags {
                key "key";
                leaf key {
                    type "string";
                    mandatory "true";
                }
                leaf value {
                    type "string";
                    mandatory "true";
                }
            }
            choice pattern {
                mandatory "false";
                description
                    "Network Plane affected by the symptom";
                case drop {
                    leaf drop {
                        mandatory "true";
                        type empty;
                    }
                }
                case spike {
                    leaf spike {
                        mandatory "true";
                        type empty;
                    }
                }
                case mean-shift {
                    leaf mean-shift {
                        mandatory "true";
                        type empty;
                    }
                }
                case seasonality-shift {
                    leaf seasonality-shift {
                        mandatory "true";
                        type empty;
                    }
                }
                case trend {
                    leaf trend {
                        mandatory "true";
                        type empty;
                    }
                }
                case other {
                    leaf other {
                        type string;
                        mandatory "true";
                        description "specify the type";
                    }
                }
            }
            container annotator {
                choice annotator-type {
                    mandatory "true";
                    case human {
                        leaf human {
                            mandatory "true";
                            type empty;
                        }
                    }
                    case algorithm {
                        leaf algorithm {
                            mandatory "true";
                            type empty;
                        }
                    }
                }
                leaf name {
                    mandatory "false";
                    type string;
                }   
            }
        }
    }
}
<CODE ENDS>]]></artwork>
          </figure></t>
      </section>
    </section>

    <section anchor="Security" title="Security Considerations">
      <t>The security considerations.</t>
    </section>

    <section anchor="Implementation" title="Implementation status">
      <t>This section provides pointers to existing open source
      implementations of this draft. Note to the RFC-editor: Please remove
      this before publishing.</t>

      <section anchor="Implementation-Antagonist" title="Antagonist">
        <t>A tool called Antagonist has been implemented during the IETF 119
        Hackathon, in order to validate the application of the YANG models
        defined in this draft. Antagonist provides visual support for two
        important use cases in the scope of this document: <ul>
            <li>the generation of a ground truth in relation to symptoms and
            problems in timeseries data</li>

            <li>the visual validation of results produced by automated network
            anomaly detection tools.</li>
          </ul> The open source code can be found here: <xref
        target="Antagonist"/></t>
      </section>
    </section>

    <section anchor="Acknowledgements" title="Acknowledgements">
      <t>The authors would like to thank xxx for their review and valuable
      comments.</t>
    </section>
  </middle>

  <back>
    <references title="Normative References">
      <?rfc include='reference.RFC.2119'?>

      <?rfc include='reference.RFC.8174'?>

      <?rfc include='reference.RFC.8340'?>

      <?rfc include='reference.RFC.9232'?>

      <?rfc include='reference.I-D.ietf-nmop-terminology'?>

      <?rfc include='reference.I-D.netana-nmop-network-anomaly-architecture'?>

      <reference anchor="Antagonist"
                 target="https://github.com/vriccobene/antagonist">
        <front>
          <title>Antagonist: Anomaly tagging on historical data</title>

          <author fullname="Vincenzo Riccobene" initials="V."
                  surname="Riccobene"/>

          <author fullname="Antonio Roberto" initials="A." surname="Roberto"/>

          <author fullname="Wanting Du" initials="W." surname="Du"/>

          <author fullname="Thomas Graf" initials="T." surname="Graf"/>

          <author fullname="Alex Huang Feng" initials="H."
                  surname="Huang Feng"/>
        </front>
      </reference>
    </references>

    <references title="Informative References">
      <?rfc include='reference.RFC.4364'?>

      <?rfc include='reference.RFC.5102'?>

      <?rfc include='reference.RFC.7011'?>

      <?rfc include='reference.RFC.7270'?>

      <?rfc include='reference.RFC.7854'?>

      <?rfc include='reference.RFC.8343'?>

      <?rfc include='reference.RFC.9418'?>

      <?rfc include='reference.I-D.netana-nmop-network-anomaly-lifecycle'?>

      <?rfc include='reference.I-D.ietf-ippm-pam'?>

      <?rfc include='reference.I-D.claise-opsawg-collected-data-manifest'?>

      <?rfc include='reference.I-D.ietf-opsawg-ipfix-on-path-telemetry'?>
    </references>
  </back>
</rfc>
