IP Library Patent Application 14176446
Patent Application
App. No. 14/176,446

DETECTING OUTLIERS IN NETWORK TRAFFIC TIME SERIES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/176,446
Abstract

According to an aspect of the invention, a system and method is configured to detect time series outliers in network traffic.

Claims (43)

1 . A computer-implemented method, comprising:

identifying, by computer, an outlier for a network traffic metric if observed network traffic is outside of a prediction interval during a time period; and

identifying an anomaly for the network traffic metric only when a count of outliers for the network traffic metric identified during the time period is greater than or equal to two, and exceeds an anomaly threshold for the network traffic metric.

2 . The computer-implemented method of claim 1 , further comprising merging identified anomalies for each of a plurality of network traffic metrics to identify a single event.

3 . The computer-implemented method of claim 2 , further comprising providing information about the network traffic to a user upon identification of the single event.

4 . The computer-implemented method of claim 1 , wherein prior to identifying the outlier, the method further comprising:

generating a forecast of network traffic using a model, the forecast being based on previously observed network traffic;

generating a prediction interval that extends above and below the forecast of the network traffic, the prediction interval being based on previously observed deviations from predicted network traffic; and

comparing observed network traffic to the prediction interval.

5 . The computer-implemented method of claim 4 , wherein the model includes at least a first and a second seasonality, and wherein the forecast is generated based on previously observed network traffic at first and second time periods associated with the first and the second seasonality.

6 . The computer-implemented method of claim 4 , wherein the model is a Holt-Winters model having daily and weekly seasonality.

7 . The computer-implemented method of claim 4 , wherein said generating the forecast of network traffic using the model includes:

generating the forecast based on at least two weeks of network traffic data; and

generating the prediction interval based on at least one week of network traffic data.

8 . A non-transitory computer-readable storage medium storing instructions that, when executed by a computer, cause the computer to perform a method comprising:

Identifying an outlier for a network traffic metric if observed network traffic is outside of a prediction interval during a time period; and

identifying an anomaly for the network traffic metric only when a count of outliers for the network traffic metric identified during the time period is greater than or equal to two, and exceeds an anomaly threshold for the network traffic metric.

9 . The non-transitory computer-readable storage medium of claim 8 , further comprising merging identified anomalies for each of a plurality of network traffic metrics to identify a single event.

10 . The non-transitory computer-readable storage medium of claim 9 , further comprising providing information about the network traffic to a user upon identification of the single event.

11 . The non-transitory computer-readable storage medium of claim 8 , wherein prior to identifying the outlier, the method further comprising:

generating a forecast of network traffic using a model, the forecast being based on previously observed network traffic;

generating a prediction interval that extends above and below the forecast of the network traffic, the prediction interval being based on previously observed deviations from predicted network traffic; and

comparing observed network traffic to the prediction interval.

12 . The non-transitory computer-readable storage medium of claim 11 , wherein the model includes at least a first and a second seasonality, and wherein the forecast is generated based on previously observed network traffic at first and second time periods associated with the first and the second seasonality.

13 . The non-transitory computer-readable storage medium of claim 11 , wherein the model is a Holt-Winters model having daily and weekly seasonality.

14 . The non-transitory computer-readable storage medium of claim 11 , wherein said generating the forecast of network traffic using the model includes:

generating the forecast based on at least two weeks of network traffic data; and

generating the prediction interval based on at least one week of network traffic data.

15 . An apparatus, comprising:

a processor; and

a storage medium storing instructions that, when executed by the processor, cause the apparatus to perform a method comprising:

identifying an outlier for a network traffic metric if observed network traffic is outside of a prediction interval during a time period; and

identifying an anomaly for the network traffic metric only when a count of outliers for the network traffic metric identified during the time period is greater than or equal to two, and exceeds an anomaly threshold for the network traffic metric.

16 . The apparatus of claim 15 , wherein the method further comprises merging identified anomalies for each of a plurality of network traffic metrics to identify a single event.

17 . The apparatus of claim 16 , wherein the method further comprises providing information about the network traffic to a user upon identification of the single event.

18 . The apparatus of claim 15 , wherein prior to identifying the outlier, the method further comprises:

generating a forecast of network traffic using a model, the forecast being based on previously observed network traffic;

generating a prediction interval that extends above and below the forecast of the network traffic, the prediction interval being based on previously observed deviations from predicted network traffic; and

comparing observed network traffic to the prediction interval.

19 . The apparatus of claim 18 , wherein the model includes at least a first and a second seasonality, and wherein the forecast is generated based on previously observed network traffic at first and second time periods associated with the first and the second seasonality.

20 . The apparatus of claim 18 , wherein said generating the forecast of network traffic using the model includes:

generating the forecast based on at least two weeks of network traffic data; and

generating the prediction interval based on at least one week of network traffic data.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2019
From: MAZU NETWORKS, LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 048680/0142 →
CHANGE OF NAME Recorded Mar 14, 2019
From: MAZU NETWORKS, INC.
To: MAZU NETWORKS, LLC
Reel/Frame 048597/0169 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2019
From: GOPALAN, PREM K.; ELVERSON, BRYAN THOMAS
To: MAZU NETWORKS, INC.
Reel/Frame 048529/0162 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →