IP Library Granted Patent US 11,652,832
Granted Patent B2
US 11,652,832 · App. 16/918,033 · Granted May 16, 2023

Automated identification of anomalous devices

Inventors: Kar-Fai Tse (Peachtree Corners, GA); Chaoting Xuan (Duluth, GA); Ravish Chawla (Chamblee, GA); Erich Stuntebeck (Johns Creek, GA); Stephen Jonathan Parry-Barwick (Sydney, AU)
Assignee: VMware, Inc.
H04L63/1425H04L41/0627H04L41/0813H04L41/147H04L41/149H04L43/0817H04L63/102H04L63/1416H04L63/1441H04L63/20H04W12/121H04W12/37H04L43/028H04L43/0876H04L43/10H04L43/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,652,832
App. No.
16/918,033
Granted
May 16, 2023
Kind
B2
Abstract

Disclosed are various approaches for automating the detection and identification of anomalous devices in a management service. Device check-ins are received by a management service and housed in a data store. The quantity of device check-ins over various time periods can be analyzed using various approaches to identify anomalous devices.

Claims (33)

1. A system, comprising:

a computing device comprising a processor and a memory, the computing device executing a management service that manages a plurality of client devices; and

machine-readable instructions stored in the memory that, when executed by the processor, cause the computing device to at least:

obtain a plurality of device check-ins associated with the plurality of client devices over a first time period;

obtain a set of device check-ins corresponding to the first time period, wherein respective ones of the device check-ins correspond to respective ones of the client devices;

calculate a variance of the set of device check-ins based on a quantity of device check-ins that correspond to individual client devices;

identify an anomalous device based upon the quantity of device check-ins for the anomalous device exceeding a variance threshold, wherein the variance threshold is based upon a variance factor, the variance factor comprising at least 1.5 times an average variance of the set of device check-ins; and

publish a notification to a notification channel in response to identifying the anomalous device.

2. The system of claim 1 , wherein the machine-readable instructions further cause the computing device to at least obtain a response in the notification channel to perform a remedial action with respect to the anomalous device.

3. The system of claim 2 , wherein the machine-readable instructions that cause the computing device to perform the remedial action further cause the computing device to at least perform the remedial action in response to a reply received from an admin device associated with an administrative user.

4. The system of claim 1 , wherein the machine-readable instructions further cause the computing device to at least identify the anomalous device based upon an analysis of a second time period that is greater than the first time period.

5. The system of claim 1 , wherein the machine-readable instructions further cause the computing device to at least execute a long short-term memory forecaster to detect a quantity of device check-ins in a subsequent time period based upon a historical log of device check-ins.

6. A method, comprising:

obtaining a plurality of device check-ins associated with a plurality of client devices over a first time period;

obtaining a set of device check-ins corresponding to the first time period, wherein respective ones of the device check-ins correspond to respective ones of the client devices;

calculating a variance of the set of device check-ins based on a quantity of device check-ins that correspond to individual client devices;

identifying an anomalous device based upon the quantity of device check-ins for the anomalous device exceeding a variance threshold, wherein the variance threshold is based upon a variance factor, the variance factor comprising at least 1.5 times an average variance of the set of device check-ins; and

publishing a notification to a notification channel in response to identifying the anomalous device.

7. The method of claim 6 , further comprising obtaining a response in the notification channel to perform a remedial action with respect to the anomalous device.

8. The method of claim 7 , wherein performing the remedial action further comprises performing the remedial action in response to a reply received from an admin device associated with an administrative user.

9. The method of claim 6 , further comprising identifying the anomalous device based upon an analysis of a second time period that is greater than the first time period.

10. The method of claim 6 , further comprising identifying the anomalous device based upon an analysis of a second time period that is greater than the first time period, wherein the anomalous device is associated with the quantity of device check-ins that is less than the variance threshold, and the anomalous device is detected by being associated with more than one time period of an elevated quantity of device check-ins.

11. The method of claim 6 , further comprising executing a long short-term memory forecaster to detect a quantity of device check-ins in a subsequent time period based upon a historical log of device check-ins.

12. A non-transitory, computer-readable medium comprising machine-readable instructions that, when executed by a processor, cause a computing device to at least:

obtain a plurality of device check-ins associated with a plurality of client devices over a first time period;

obtain a set of device check-ins corresponding to the first time period, wherein respective ones of the device check-ins correspond to respective ones of the client devices;

calculate a variance of the set of device check-ins based on a quantity of device check-ins that correspond to individual client devices;

identify an anomalous device based upon the quantity of device check-ins for the anomalous device exceeding a variance threshold, wherein the variance threshold is based upon a variance factor, the variance factor comprising at least 1.5 times an average variance of the set of device check-ins; and

publish a notification to a notification channel in response to identifying the anomalous device.

13. The non-transitory, computer-readable medium of claim 12 , wherein the machine-readable instructions further cause the computing device to at least obtain a response in the notification channel to perform a remedial action with respect to the anomalous device.

14. The non-transitory, computer-readable medium of claim 13 , wherein the machine-readable instructions that cause the computing device to perform the remedial action further cause the computing device to at least perform the remedial action in response to a reply received from an admin device associated with an administrative user.

15. The non-transitory, computer-readable medium of claim 12 , wherein the machine-readable instructions further cause the computing device to at least identify the anomalous device based upon an analysis of a second time period that is greater than the first time period, wherein the anomalous device is associated with the quantity of device check-ins that is less than the variance threshold, and the anomalous device is detected by being associated with a cluster of other devices causing an elevated quantity of device check-ins.

16. The non-transitory, computer-readable medium of claim 12 , wherein the machine-readable instructions further cause the computing device to at least identify the anomalous device based upon an analysis of a second time period that is greater than the first time period, wherein the anomalous device is associated with the quantity of device check-ins that is less than the variance threshold, and the anomalous device is detected by being associated with more than one time period of an elevated quantity of device check-ins.

Assignments (5)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF RECEIVING PARTY PREVIOUSLY RECORDED ON REEL 053098 FRAME 0705. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT OF ASSIGNORS INTEREST. Recorded Oct 26, 2021
From: TSE, KAR-FAI; XUAN, CHAOTING; CHAWLA, RAVISH; STUNTEBECK, ERICH; PARRY-BARWICK, STEPHEN JONATHAN
To: VMWARE, INC.
Reel/Frame 058608/0475 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2020
From: TSE, KAR-FAI; XUAN, CHAOTING; CHAWLA, RAVISH; STUNTEBECK, ERICH; PARRY-BARWICK, STEPHEN JONATHAN
To: INC., VMWARE, INC.
Reel/Frame 053098/0705 →