IP Library Granted Patent US 12671643
Granted Patent B2
US 12671643 · App. 18/643,006 · Granted Jun 30, 2026

Anomaly detection mechanism evaluations

Inventors: Gad Miller (Paris, FR); Tristan Hugues Emile Victor Besson (Saint-Cyr-l'École, FR)
Assignee: Cisco Technology, Inc.
H04L43/08H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12671643
App. No.
18/643,006
Granted
Jun 30, 2026
Kind
B2
Abstract

In one implementation, a device may obtain anomaly detection time series indicative of anomalies detected by a plurality of anomaly detectors for a network. The device may determine a degree of correlation over time between the anomaly detection time series. The device may make, based on the degree of correlation over time between the anomaly detection time series, a performance evaluation for a particular anomaly detector from among the plurality of anomaly detectors. The device may provide the performance evaluation to a user interface for review.

Claims (35)

1 . A method, comprising:

obtaining, by a device, a plurality of anomaly detection time series indicative of anomalies detected by a plurality of anomaly detectors for a network, wherein each of the plurality of anomaly detectors provide a respective anomaly detection time series of the plurality of anomaly detection time series, and wherein the anomalies are associated with anomalous values of a path performance metric;

comparing, by the device, the plurality of anomaly detection time series to determine a degree of correlation over time between the plurality of anomaly detection time series;

making, by the device and based on the degree of correlation over time between the plurality of anomaly detection time series, a performance evaluation for an anomaly detector from among the plurality of anomaly detectors, wherein the anomaly detector uses a different anomaly detection model than at least one other anomaly detector in the plurality of anomaly detectors;

providing, by the device, the performance evaluation to a user interface for review.

2 . The method as in claim 1 , wherein the performance evaluation indicates good performance by the anomaly detector when the degree of correlation over time indicates a positive correlation between the anomaly detection time series.

3 . The method as in claim 1 , wherein the plurality of anomaly detectors generates the plurality of anomaly detection time series based on outputs of testing agents configured to perform testing in the network.

4 . The method as in claim 3 , wherein the plurality of anomaly detection time series are associated with the testing agents performing testing in the network with respect to a particular server.

5 . The method as in claim 3 , wherein the testing agents perform testing in the network by sending probing packets via the network.

6 . The method as in claim 1 , wherein the anomaly detector is executed by a router in the network.

7 . An apparatus, comprising:

one or more network interfaces;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process when executed configured to:

obtain a plurality of anomaly detection time series indicative of anomalies detected by a plurality of anomaly detectors for a network, wherein each of the plurality of anomaly detectors provide a respective anomaly detection time series of the plurality of anomaly detection time series, and wherein the anomalies are associated with anomalous values of a path performance metric;

compare the plurality of anomaly detection time series to determine a degree of correlation over time between the plurality of anomaly detection time series;

make, based on the degree of correlation over time between the plurality of anomaly detection time series, a performance evaluation for an anomaly detector from among the plurality of anomaly detectors, wherein the anomaly detector uses a different anomaly detection model than at least one other anomaly detector in the plurality of anomaly detectors;

provide the performance evaluation to a user interface for review; and

update the anomaly detector based on the performance evaluation, including optimizing a model parameter of the anomaly detector based on the performance evaluation.

8 . The apparatus as in claim 7 , wherein the performance evaluation indicates good performance by the anomaly detector when the degree of correlation over time indicates a positive correlation between the anomaly detection time series.

9 . The apparatus as in claim 7 , wherein the plurality of anomaly detectors generates the plurality of anomaly detection time series based on outputs of testing agents configured to perform testing in the network.

10 . The apparatus as in claim 9 , wherein the plurality of anomaly detection time series are associated with the testing agents performing testing in the network with respect to a particular server.

11 . The apparatus as in claim 9 , wherein the testing agents perform testing in the network by sending probing packets via the network.

12 . The apparatus as in claim 9 , wherein the anomaly detector is executed by a router in the network.

13 . A tangible, non-transitory, computer-readable medium storing program instructions that cause a device to execute a process comprising:

obtaining a plurality of anomaly detection time series indicative of anomalies detected by a plurality of anomaly detectors for a network, wherein each of the plurality of anomaly detectors provide a respective anomaly detection time series of the plurality of anomaly detection time series, and wherein the anomalies are associated with anomalous values of a path performance metric;

comparing the plurality of anomaly detection time series to determine a degree of correlation over time between the plurality of anomaly detection time series;

making, based on the degree of correlation over time between the plurality of anomaly detection time series, a performance evaluation for an anomaly detector from among the plurality of anomaly detectors, wherein the anomaly detector uses a different anomaly detection model than at least one other anomaly detector in the plurality of anomaly detectors;

providing the performance evaluation to a user interface for review; and

updating the anomaly detector based on the performance evaluation, including optimizing a model parameter of the anomaly detector based on the performance evaluation.

14 . The tangible, non-transitory, computer-readable medium as in claim 13 , wherein the performance evaluation indicates good performance by the anomaly detector when the degree of correlation over time indicates a positive correlation between the anomaly detection time series.

15 . The tangible, non-transitory, computer-readable medium as in claim 13 , wherein the plurality of anomaly detectors generates the plurality of anomaly detection time series based on outputs of testing agents configured to perform testing in the network.

16 . The tangible, non-transitory, computer-readable medium as in claim 15 , wherein the plurality of anomaly detection time series are associated with the testing agents performing testing in the network with respect to a particular server.

17 . The tangible, non-transitory, computer-readable medium as in claim 15 , wherein the testing agents perform testing in the network by sending probing packets via the network.

18 . The tangible, non-transitory, computer-readable medium as in claim 13 , wherein the anomaly detector is executed by a router in the network.