IP Library Granted Patent US 10,454,753
Granted Patent B2
US 10,454,753 · App. 15/494,519 · Granted Oct 22, 2019

Ranking network anomalies in an anomaly cluster

Inventors: Amit Sasturkar (San Jose, CA); Alan Ngai (Santa Clara, CA)
Assignee: Lightbend, Inc.
H04L41/0631G06F11/079G06F11/0709G06F11/3006G06F11/3409G06F16/24578G06F16/26G06F16/285H04L41/064H04L41/065H04L41/145H04L41/22H04L43/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,454,753
App. No.
15/494,519
Granted
Oct 22, 2019
Kind
B2
Abstract

The technology disclosed relates to organizing network performance metrics into historical anomaly dependency data. In particular, it relates to calculating cascading failure relationships between correlated anomalies detected in a network. It also relates to illustrating to a network administrator causes of system failure by laying out the graph to show a progression over time of the cascading failures and identify root causes of the cascading failures. It also relates to ranking anomalies and anomaly clusters in the network based on attributes of the resources exhibiting anomalous performances and attributes of the anomalous performances. It further relates to depicting evolution of resource failures across a network by visually coding impacted resources and adjusting the visual coding over time and allowing replay over time to visualize propagation of anomalous performances among the impacted resource.

Claims (70)

1. A system including one or more processors coupled to memory, the memory loaded with computer instructions to rank anomalies in an anomaly cluster, the instructions, when executed on the processors, implement actions comprising:

accessing performance data for a multiplicity of metrics across a multiplicity of resources on a network and automatically setting criteria based on the performance data over time that qualifies a subset of the performance data as anomalous instance data, wherein the anomalous instance data are grouped in a cluster of operation anomalies that are interrelated as cascading failures traced over active network communication paths among resources, wherein the communication paths propagate anomalous performances;

constructing a map that graphically depicts propagation of the anomalous performances along the active network communication paths as edges between nodes representing the resources; and

calculating impact rankings for the nodes, based at least on attributes of the resources exhibiting anomalous performances.

2. The system of claim 1 , wherein resource attributes include predetermined importance values assigned to the resources exhibiting anomalous performances.

3. The system of claim 1 , wherein resource attributes include visibility of the resources exhibiting anomalous performances.

4. The system of claim 1 , wherein resource attributes include conditions of service level agreements violated by anomalous performances of the resources.

5. The system of claim 1 , further implementing actions comprising ranking anomaly clusters by:

accessing performance data for a multiplicity of metrics across a multiplicity of resources on a network and automatically setting criteria based on the performance data over time that qualifies a subset of the performance data as anomalous instance data;

grouping the anomalous instance data into an anomaly cluster including anomaly nodes that represent detected anomalies that compromise respective resources and probability weighted directed edges connecting correlated anomaly nodes, wherein the probability weighted directed edges express strength of a correlation between the correlated anomaly nodes that are connected by the edges;

scoring importance of the anomaly cluster by calculating anomaly node importance values for anomaly nodes in the cluster, propagating the anomaly node importance values to terminal nodes in the anomaly cluster and aggregating the propagated anomaly values of the terminal nodes; and

repeating the scoring for a plurality of anomaly clusters and reporting at least relative scoring of the anomaly clusters for further processing.

6. A system including one or more processors coupled to memory, the memory loaded with computer instructions to depict evolution of resource failures across a network, the instructions, when executed on the processors, implement actions comprising:

constructing a resource connectivity graph with services indicated grouped within resource blocks, wherein the resource blocks are connected to represent an active communication network path among the resources;

visually coding record instances in resource blocks and resource blocks to indicate impaired performance due to anomalies occurred at the services; and

adjusting the visual coding over time and allowing replay over time to visualize propagation of anomalous performances among the resource blocks.

7. A system including one or more processors coupled to memory, the memory loaded with computer instructions to organize network performance metrics into historical anomaly dependency data, the instructions, when executed on the processors, implement actions comprising:

accessing performance data for a multiplicity of metrics across a multiplicity of resources on a network and automatically setting criteria based on the performance data over time that qualifies a subset of the performance data as anomalous instance data;

constructing a map of active network communication paths that carry communications among first and second resources subject to anomalous performance and representing the active network communication paths as edges between nodes representing first and second resources, thereby forming connected node pairs;

calculating cascading failure relationships from time-stamped anomalous instance data for the connected node pairs, wherein the cascading failure relationships are based at least in part on whether conditional probabilities of anomalous performance of the second resources given prior anomalous performance of the first resources exceed a predetermined threshold;

wherein calculating the conditional probabilities makes use of a statistical measure of likelihood:

conditional probability=p(anomalous second service|anomalous first service); and

automatically representing the anomalous performance of the second resource as a cascading failure resulting from the anomalous performance of the first resource based on the calculated cascading failure relationships.

8. The system of claim 7 , wherein the time-stamped anomalous instance data identify at least start times of anomalous performances of the first and second resources that are within a predetermined time period, further including automatically representing anomalous performance of the second resource as a cascading failure resulting from the anomalous performance of the first resource.

9. The system of claim 7 , wherein the time-stamped anomalous instance data identify at least end times of anomalous performances of the first and second resources that are within a predetermined time period, further including automatically representing anomalous performance of the second resource as a cascading failure resulting from the anomalous performance of the first resource.

10. The system of claim 7 , further including calculating cascading failure relationships based at least in part on historical frequency of anomalous performance of the second resources given prior anomalous performance of the first resources.

11. The system of claim 7 , further implementing actions comprising illustrating to a network administrator causes of system failure by:

generating for display a cluster of operation anomalies that are interrelated as cascading failures in an anomaly impact graph, including:

depicting anomalous instance data in the cluster as nodes in a plot;

representing active network communication paths that carry communications among first and second resources subject to anomalous performances as edges between the nodes, thereby forming connected node pairs; and

depicting at least part of the plot to show a progression over time of the cascading failures for the connected node pairs and to identify one or more root causes of the cascading failures.

12. The system of claim 7 , further implementing actions comprising illustrating to a network administrator causes of system failure by:

generating for display an anomaly impact graph interface that depicts a cluster of operation anomalies that are interrelated as cascading failures, including:

nodes in a diagram that represent anomalous instance data for different resources in the cluster;

edges between the nodes that represent active network communication path data for communications among first and second resources, wherein the edges and nodes form connected node pairs; and

arrangement of the diagram that shows progression over time of cascading failure result links between anomalous performances of the first and second resources occurring within a predetermined time period.

13. A computer implemented method to rank anomalies in an anomaly cluster, including:

accessing performance data for a multiplicity of metrics across a multiplicity of resources on a network and automatically setting criteria based on the performance data over time that qualifies a subset of the performance data as anomalous instance data, wherein the anomalous instance data are grouped in a cluster of operation anomalies that are interrelated as cascading failures traced over active network communication paths among resources, wherein the communication paths propagate anomalous performances;

constructing a map that graphically depicts propagation of the anomalous performances along the active network communication paths as edges between nodes representing the resources; and

calculating impact rankings for the nodes, based at least on attributes of the resources exhibiting anomalous performances.

14. The computer implemented method of claim 13 , further including ranking anomaly clusters by:

accessing performance data for a multiplicity of metrics across a multiplicity of resources on a network and automatically setting criteria based on the performance data over time that qualifies a subset of the performance data as anomalous instance data;

grouping the anomalous instance data into an anomaly cluster including anomaly nodes that represent detected anomalies that compromise respective resources and probability weighted directed edges connecting correlated anomaly nodes, wherein the probability weighted directed edges express strength of a correlation between the correlated anomaly nodes that are connected by the edges;

scoring importance of the anomaly cluster by calculating anomaly node importance values for anomaly nodes in the cluster, propagating the anomaly node importance values to terminal nodes in the anomaly cluster and aggregating the propagated anomaly values of the terminal nodes; and

repeating the scoring for a plurality of anomaly clusters and reporting at least relative scoring of the anomaly clusters for further processing.

15. A computer implemented method to rank anomalies in an anomaly cluster, including:

accessing performance data for a multiplicity of metrics across a multiplicity of resources on a network and automatically setting criteria based on the performance data over time that qualifies a subset of the performance data as anomalous instance data, wherein the anomalous instance data are grouped in a cluster of operation anomalies that are interrelated as cascading failures traced over active network communication paths among resources, wherein the communication paths propagate anomalous performances;

constructing a map that graphically depicts propagation of the anomalous performances along the active network communication paths as edges between nodes representing the resources; and

calculating impact rankings for the nodes, based at least on attributes of the anomalous performances.

16. A computer implemented method to depict evolution of resource failures across a network, the method including:

constructing a resource connectivity graph with services indicated grouped within resource blocks, wherein the resource blocks are connected to represent an active communication network path among the resources;

visually coding record instances in resource blocks and resource blocks to indicate impaired performance due to anomalies occurred at the services; and

adjusting the visual coding over time and allowing replay over time to visualize propagation of anomalous performances among the resource blocks.

17. A computer implemented method to organize network performance metrics into historical anomaly dependency data, the method including:

accessing performance data for a multiplicity of metrics across a multiplicity of resources on a network and automatically setting criteria based on the performance data over time that qualifies a subset of the performance data as anomalous instance data;

constructing a map of active network communication paths that carry communications among first and second resources subject to anomalous performance and representing the active network communication paths as edges between nodes representing first and second resources, thereby forming connected node pairs;

calculating cascading failure relationships from time-stamped anomalous instance data for the connected node pairs, wherein the cascading failure relationships are based at least in part on whether conditional probabilities of anomalous performance of the second resources given prior anomalous performance of the first resources exceed a predetermined threshold;

wherein calculating the conditional probabilities makes use of a statistical measure of likelihood:

conditional probability=p(anomalous second service|anomalous first service); and

automatically representing the anomalous performance of the second resource as a cascading failure resulting from the anomalous performance of the first resource based on the calculated cascading failure relationships.

18. The computer implemented method of claim 17 , further including illustrating to a network administrator causes of system failure by:

generating for display a cluster of operation anomalies that are interrelated as cascading failures in an anomaly impact graph, including:

depicting anomalous instance data in the cluster as nodes in a plot;

representing active network communication paths that carry communications among first and second resources subject to anomalous performances as edges between the nodes, thereby forming connected node pairs; and

depicting at least part of the plot to show a progression over time of the cascading failures for the connected node pairs and to identify one or more root causes of the cascading failures.

19. The computer implemented method of claim 17 , further including illustrating to a network administrator causes of system failure by:

generating for display an anomaly impact graph interface that depicts a cluster of operation anomalies that are interrelated as cascading failures, including:

nodes in a diagram that represent anomalous instance data for different resources in the cluster;

edges between the nodes that represent active network communication path data for communications among first and second resources, wherein the edges and nodes form connected node pairs; and

arrangement of the diagram that shows progression over time of cascading failure result links between anomalous performances of the first and second resources occurring within a predetermined time period.

Assignments (9)
RELEASE OF SECURITY INTEREST Recorded Feb 25, 2026
From: COMERICA BANK
To: LIGHTBEND, INC.
Reel/Frame 073891/0063 →
FIRST AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 11, 2025
From: LIGHTBEND, INC.
To: ESPRESSO CAPITAL LTD.
Reel/Frame 071557/0332 →
SECURITY INTEREST Recorded Aug 15, 2024
From: LIGHTBEND, INC.
To: COMERICA BANK
Reel/Frame 068299/0618 →
RELEASE OF SECURITY INTEREST Recorded Aug 6, 2024
From: NH EXPANSION CREDIT FUND HOLDINGS LP
To: LIGHTBEND, INC.
Reel/Frame 068202/0017 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 1, 2024
From: LIGHTBEND, INC.
To: ESPRESSO CAPITAL LTD.
Reel/Frame 068233/0670 →
SECURITY INTEREST Recorded Mar 24, 2021
From: LIGHTBEND, INC.
To: COMERICA BANK
Reel/Frame 055707/0278 →
RELEASE OF SECURITY INTEREST Recorded Feb 22, 2021
From: HERCULES CAPITAL, INC.
To: LIGHTBEND, INC.
Reel/Frame 055358/0862 →
SECURITY INTEREST Recorded Nov 5, 2020
From: LIGHTBEND, INC.
To: NH EXPANSION CREDIT FUND HOLDINGS LP
Reel/Frame 054283/0387 →
SECURITY INTEREST Recorded Feb 22, 2018
From: LIGHTBEND, INC.
To: HERCULES CAPITAL, INC., AS AGENT
Reel/Frame 045011/0525 →
Continuity (5)
Continuation 14276846 · May 13, 2014
Provisional Application 61859279 · Jul 28, 2013
Provisional Application 61859282 · Jul 28, 2013
Provisional Application 61859280 · Jul 28, 2013
Related Publication 20170230229A1 · Aug 10, 2017
Cited By (87)
US 12,206,696 US 12,244,621 US 12,267,345 US 12,278,726 US 12,309,185 US 12,323,449 US 12,335,286 US 12,335,348 US 12,341,797 US 12,348,545 US 12,355,626 US 12,355,787 US 12,355,793 US 12,363,148 US 12,368,745 US 12,368,746 US 12,368,747 US 12,375,573 US 12,395,573 US 12,401,669 US 12,405,849 US 12,407,701 US 12,407,702 US 12,418,552 US 12,418,555 US 12,425,428 US 12,425,430 US 12,445,474 US 12,452,279 US 12,457,231 US 12,463,995 US 12,463,996 US 12,463,997 US 12,464,003 US 12,470,577 US 12,470,578 US 12,483,576 US 12,489,770 US 12,495,052 US 12,500,910 US 12,500,911 US 12,500,912 US 12,505,126 US 12,506,762 US 12,513,221 US 12,537,836 US 12,537,837 US 12,537,839 US 12,537,840 US 12,537,884 US 12,549,575 US 12,549,577 US 12,556,548 US 12,556,559 US 12,563,060 US 12,563,064 US 12,563,071 US 12,563,072 US 12,580,934 US 12,580,935 US 12,580,936 US 12,580,937 US 12,587,553 US 12,592,950 US 12,598,205 US 12,613,930 US 12,615,271 US 12,621,324 US 12,621,329 US 12,627,686 US 12,627,687 US 12,627,690 US 12,634,312 US 12,634,376 US 12,652,302 US 12,659,325 US 12,659,326 US 12,659,327 US 12,659,333 US 12,676,874 US 12,689,638 US 12,689,640 US 12,695,768 US 12,706,932 US 12,706,933 US 12,712,897 US 12,719,896