This paper presents the design implementation and evaluation of NetMon a hybrid network monitoring system designed for Kubernetes-based 5G packet core deployments specifically evaluated on Ericssons Access and Mobility Management Function AMF clusters NetMon combines eBPF-based passive kernel-level traffic observation with active TCP probing and centralized correlation to detect and localize netwo
The search context provided does not contain information regarding a paper titled "Hybrid Monitoring for Early Fault Detection in Cloud-Native 5G Systems" or a system named NetMon evaluated on Ericsson’s A platform.
The available results cover related topics, including: Cloud-Native Network Monitoring: General architectures, tools (Prometheus, Grafana, OpenTelemetry), and best practices for Kubernetes-based environments. Automated Fault Detection: Research using Large Language Models (LLMs) and Chaos Mesh for fault detection in OpenAirInterface 5G cores. End-to-End Monitoring: Experimental frameworks using Open5GS and Prometheus for containerized 5G cores with over-the-air transmissions. MonArch: A network slice monitoring architecture for cloud-native 5G deployments.
If you can provide more specific details or upload the relevant document, I may be able to assist further.
Overview. The paper presents NetMon, a hybrid network-monitoring system for cloud-native 5G packet-core deployments, with an evaluation focused on Kubernetes-hosted Ericsson Access and Mobility Management Function (AMF) clusters. Rather than relying on a single observability mechanism, NetMon combines passive, kernel-level traffic observation using eBPF with active TCP probing and a centralized correlation layer. The goal is to detect and localize network faults earlier than conventional monitoring approaches that may depend on application logs, host metrics, or isolated network checks.
Key contributions and insights. The main contribution is a practical architecture for monitoring distributed 5G core functions in containerized environments. eBPF provides low-overhead visibility into kernel and network-stack behavior—such as connection state, traffic flow, and host-level anomalies—without requiring invasive application instrumentation. Active TCP probes complement this passive view by supplying direct reachability and latency signals, which can expose failures that passive observation alone may miss, such as silent drops, asymmetric routing, or intermittent path degradation. The centralized correlation component is especially important because it can fuse signals across pods, nodes, connections, and time windows to reduce false positives and attribute faults to more specific sources, such as a node, pod, network path, or service endpoint. The evaluation on AMF clusters highlights the value of hybrid monitoring in a realistic telecom workload, where faults may be transient, cross-host, and difficult to isolate from a single vantage point.
Why it matters. As 5G packet cores move to cloud-native platforms, operational complexity increases: microservice churn, dynamic scheduling, overlay networking, and multi-node traffic paths make network faults harder to detect before they affect service-level objectives. AMF is a particularly important target because it handles core signaling functions related to registration, authentication, and mobility; failures there can translate into attach failures, session disruptions, or degraded RAN-core interaction. NetMon is relevant because it points toward a monitoring model that is both sufficiently lightweight for production-like deployments and sufficiently cross-cutting to support early fault detection and localization. More broadly, the work is useful for operators and platform engineers seeking to improve reliability, observability, and automated fault triage in cloud-native telecom infrastructure.