IP Library Granted Patent US 11,729,043
Granted Patent B2
US 11,729,043 · App. 16/013,717 · Granted Aug 15, 2023

Traffic outage detection in the internet

Inventors: Ricardo V. Oliveira (San Francisco, CA); Matias Fontanini (San Francisco, CA)
Assignee: Cisco Technology, Inc.
H04L41/046H04L41/12H04L43/045H04L43/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,729,043
App. No.
16/013,717
Granted
Aug 15, 2023
Kind
B2
Abstract

Techniques for performing traffic outage detection in the Internet are disclosed. In some embodiments, a system, process, and/or computer program product for traffic outage detection in the Internet includes deploying a plurality of agents and a plurality of tests to be executed by the deployed agents; collecting path trace data from the plurality of agents to identify one or more terminal events; and detecting a network outage based on the one or more terminal events.

Claims (54)

1. A system, comprising:

a processor configured to:

deploy a plurality of agents and a plurality of tests to be executed by the deployed agents;

collect path trace data from the plurality of agents, wherein the path trace data is based on collected test results from each of the plurality agents for the plurality of tests;

filter the path trace data to remove:

a) one or more interfaces in a source network or a stub network by determining whether the one or more interfaces are in an autonomous system number (ASN) blacklist,

b) one or more noisy interfaces indicative of time exceeded or noisy targets indicative of issues reaching a domain, and

c) one or more interfaces that cannot be geolocated;

identify and aggregate one or more terminal events by determining that a trace, from the path trace data after being filtered, terminates at a particular interface; and

detect a network outage at the particular interface in response to determining that the one or more terminal events in the aggregate satisfy a dynamic outage interface threshold, wherein the dynamic outage interface threshold is calculated daily based on a number of interfaces in a geographic location; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system recited in claim 1 , wherein each of the plurality of agents is controlled by an agent controller.

3. The system recited in claim 1 , wherein a graphical visualization of the network outage is generated by a web tier.

4. The system recited in claim 1 , where in each of the plurality of tests that can be performed by the agents is configurable.

5. The system recited in claim 1 , wherein the processor is further configured to:

filter the path trace data using a plurality of filtering operations including filtering noisy interfaces and/or noisy targets and filtering HyperText Transfer Protocol (HTTP) ports 80 and 443.

6. The system recited in claim 1 , wherein the processor is further configured to:

merge outage events based on aggregations of terminal events on an Autonomous System Number (ASN) basis.

7. The system recited in claim 1 , wherein the processor is further configured to:

generate a graphical visualization of the outage detection.

8. The system recited in claim 1 , wherein the processor is further configured to:

generate a graphical visualization of the outage detection; and

output the graphical visualization of the outage detection.

9. A method, comprising:

deploying a plurality of agents and a plurality of tests to be executed by the deployed agents;

collecting path trace data from the plurality of agents, wherein the path trace data is based on collected test results from each of the plurality agents for the plurality of tests;

filtering the path trace data to remove:

a) one or more interfaces in a source network or a stub network by determining whether the one or more interfaces are in an autonomous system number (ASN) blacklist,

b) one or more noisy interfaces indicative of time exceeded or noisy targets indicative of issues reaching a domain, and

c) one or more interfaces that cannot be geolocated;

identifying and aggregating one or more terminal events by determining that a trace, from the path trace data after being filtered, terminates at a particular interface; and

detecting a network outage at the particular interface in response to determining that the one or more terminal events in the aggregate satisfy a dynamic outage interface threshold, wherein the dynamic outage interface threshold is calculated daily based on a number of interfaces in a geographic location.

10. The method of claim 9 , wherein the plurality of agents are controlled by an agent controller.

11. The method of claim 9 , wherein a graphical visualization is generated by a web tier.

12. The method of claim 9 , wherein each of the plurality of tests that can be performed by the agents is configurable.

13. The method of claim 9 , further comprising:

merging outage events based on aggregations of terminal events on an Autonomous System Number (ASN) basis.

14. A computer program product, the computer program product being embodied in a non-transitory tangible computer readable storage medium and comprising computer instructions for:

deploying a plurality of agents and a plurality of tests to be executed by the deployed agents;

collecting path trace data from the plurality of agents, wherein the path trace data is based on collected test results from each of the plurality agents for the plurality of tests;

filtering the path trace data to remove:

a) one or more interfaces in a source network or a stub network by determining whether the one or more interfaces are in an autonomous system number (ASN) blacklist,

b) one or more noisy interfaces indicative of time exceeded or noisy targets indicative of issues reaching a domain, and

c) one or more interfaces that cannot be geolocated;

identifying and aggregating one or more terminal events by determining that a trace, from the path trace data after being filtered, terminates at a particular interface; and

detecting a network outage at the particular interface by determining whether the one or more terminal events in the aggregate satisfy a dynamic outage interface threshold, wherein the dynamic outage interface threshold is calculated daily based on a number of interfaces in a geographic location.

15. The computer program product recited in claim 14 , wherein the plurality of agents are controlled by an agent controller.

16. The computer program product recited in claim 14 , wherein a graphical visualization is generated by a web tier.

17. The computer program product recited in claim 14 , further comprising computer instructions for:

merging outage events based on aggregations of terminal events on an Autonomous System Number (ASN) basis.

18. The system recited in claim 1 , wherein the processor is further configured to:

filter the collected path trace data using at least one or more of: a whitelist filter, a noise filter, a geography-based filter, and a port-based filter.

19. The system recited in claim 1 , wherein the processor is further configured to:

filter the collected path trace data using at least two or more of: a whitelist filter, a noise filter, a geography-based filter, and a port-based filter.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2021
From: THOUSANDEYES LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 056348/0993 →
CHANGE OF NAME Recorded Nov 18, 2020
From: THOUSANDEYES, INC.
To: THOUSANDEYES LLC
Reel/Frame 054476/0337 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2018
From: OLIVEIRA, RICARDO V.; FONTANINI, MATIAS
To: THOUSANDEYES, INC.
Reel/Frame 046954/0850 →
Continuity (2)
Provisional Application 62569266 · Oct 6, 2017
Related Publication 20190109757A1 · Apr 11, 2019