IP Library Granted Patent US 12,375,508
Granted Patent B2
US 12,375,508 · App. 17/502,622 · Granted Jul 29, 2025

Methodology for intelligent pattern detection and anomaly detection in machine to machine communication network

Inventors: Jins George (Fremont, CA); Subramanian Balakrishnan (Cupertino, CA); Narendra Sharma (Sunnyvale, CA)
Assignee: Aeris Communications, Inc.
H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,375,508
App. No.
17/502,622
Granted
Jul 29, 2025
Kind
B2
Abstract

The present invention relates generally to network communications, and more particularly to machine-to-machine (M2M) data communications. The present invention provides for a method, apparatus and computer program product for detecting anomalous performance event across a machine-to-machine (M2M) network and thereafter alerting users of performance issues in real-time or near real-time.

Claims (36)

1. A method for detecting an abnormal performance event across a machine-to-machine (M2M) network, comprising:

determining one or more performance events to monitor;

acquiring data of one or more monitored performance events including “bytes in” and “bytes out” from a data stream that captures the monitored performance event;

comparing the acquired event data with one or more predetermined event characteristic limits over a predetermined period to assess for asymmetry in the data stream based on “bytes in” and “bytes out”; and

issuing an alert in response to compared acquired event data exceeding the one or more predetermined event characteristic limits.

2. The method of claim 1 , wherein the acquiring data further includes identifying one or more event data streams to monitor and identifying data within the one or more event data streams by sourcing information from one or more log files of a server.

3. The method of claim 2 , wherein the server is an authentication, authorization and accounting server.

4. The method of claim 1 , wherein acquiring data further includes collecting firewall data including destination IP address and device IP address.

5. The method of claim 4 , further comprising combining the “bytes in” and “bytes out” data with the destination IP address using device internet protocol (IP) address and time of the event to produce “bytes in” and “bytes out” to a particular destination IP address.

6. The method of claim 5 , wherein the comparing further includes using the “bytes in” and “bytes out” to a particular IP address of the data stream in view of history, captured data over a period of time, or other performance characteristics to detect anomaly.

7. The method of claim 1 , wherein the comparing further includes comparing the acquired data identified from the one or more event streams with one or more predetermined event characteristic limits over a predetermined period to identify asymmetry.

8. The method of claim 1 , wherein the issuing an alert further includes directing an asynchronous alert command to a command interface message queue associated with a predetermined output routing for receipt by one or more receiving devices associated with the predetermined output routing.

9. The method of claim 8 , wherein the predetermined output is the alert is sent to a device having an application programming interface of an interested party.

10. The method of claim 9 , wherein the alert includes one or more of: a voice call, an email and a text message.

11. The method of claim 9 , wherein the application programming interface of an interested party comprises at least one or more of an Alerts section displaying near real time alerts from multiple sources and a Device Details section displaying details of events in relation to a device.

12. An apparatus for detecting an abnormal performance event across a machine-to-machine (M2M) network, comprising:

a device protocol capable of communications with a server across a M2M network,

a device capable of communicating with a server system across the network using a communication adapter;

the server system having an application module for

determining one or more performance events to monitor;

acquiring event data of one or more events as “bytes in” and “bytes out” from a data stream that captures the monitored performance event;

comparing acquired event data with one or more predetermined event characteristic limits over a predetermined period to assess for asymmetry in the data stream based on “bytes in” and “bytes out”; and

issuing a command in response to compared acquired event data exceeding the one or more predetermined event characteristic limits; and

a notification means for issuing an alert to one or more recipients in response to the issued command, wherein the alert includes information in relation the event.

13. The apparatus of claim 12 , wherein the server is in communication with one or more receiving devices.

14. The apparatus of claim 12 , wherein the application module further includes logic to identify one or more event data streams to monitor and identify data within the one or more event data streams by sourcing information from one or more log files of a server.

15. The apparatus of claim 12 , wherein the application module further includes logic to collect firewall data including destination IP address and device IP address, and combining the “bytes in” and “bytes out” data with the destination IP address using device internet protocol (IP) address and time of the event to produce “bytes in” and “bytes out” to a particular destination IP address.

16. The apparatus of claim 12 , wherein the application module further includes logic to compare the acquired data identified from the one or more event streams with one or more predetermined event characteristic limits over a predetermined period to identify asymmetry.

17. The apparatus of claim 15 , wherein the application module further includes logic to use the “bytes in” and “bytes out” to a particular IP address of the data stream in view of history, captured data over a period of time, or other performance characteristics to detect anomaly.

18. The apparatus of claim 17 , wherein the application module further includes logic to issue an alert to the one or more receiving devices.

19. The apparatus of claim 17 , wherein the alert includes one or more of: a voice call, an email and a text message.

20. A computer program product stored on a non-transitory computer readable storage medium, comprising: computer readable program means for causing a computer to control an execution of an application to perform a method for detecting anomalous performance event data across a machine-to-machine (M2M) network, comprising:

determining one or more performance events to monitor;

acquiring data of one or more monitored performance events as “bytes in” and “bytes out” from a data stream that captures the monitored performance event;

comparing the acquired event data with one or more predetermined event characteristic limits over a predetermined period to assess for asymmetry in the data stream based on “bytes in” and “bytes out”; and

issuing an alert in response to compared acquired event data exceeding the one or more predetermined event characteristic limits.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2021
From: GEORGE, JINS; BALAKRISHNAN, SUBRAMANIAN; SHARMA, NARENDRA
To: AERIS COMMUNICATIONS, INC.
Reel/Frame 057815/0007 →
Continuity (4)
Continuation In Part 16827034 · Mar 23, 2020
Continuation In Part 16282429 · Feb 22, 2019
Continuation 13533815 · Jun 26, 2012
Related Publication 20220038483A1 · Feb 3, 2022
References Cited (44)
US 7103504B1 · McGlaughlin et al. · 2006 [cited by applicant]
US 7844687B1 · Gelvin · 2010 [cited by examiner]
US 7933666B2 · Campbell et al. · 2011 [cited by applicant]
US 8108517B2 · Kalavade · 2012 [cited by applicant]
US 8407769B2 · Salmela et al. · 2013 [cited by applicant]
US 8416741B2 · Chan et al. · 2013 [cited by applicant]
US 8565080B2 · Kavanaugh et al. · 2013 [cited by applicant]
US 8566447B2 · Cohen · 2013 [cited by examiner]
US 8583076B2 · Foldare · 2013 [cited by applicant]
US 10419552B2 · Li · 2019 [cited by applicant]
US 20060153089A1 · Silverman · 2006 [cited by examiner]
US 20070168053A1 · Hendrickson et al. · 2007 [cited by applicant]
US 20080114806A1 · Kosche · 2008 [cited by applicant]
US 20080205292A1 · Denby · 2008 [cited by examiner]
US 20080209033A1 · Ginter · 2008 [cited by examiner]
US 20090052338A1 · Kelley · 2009 [cited by examiner]
US 20090106729A1 · Adi et al. · 2009 [cited by applicant]
US 20090138593A1 · Kalavade · 2009 [cited by examiner]
US 20090222553A1 · Qian · 2009 [cited by examiner]
US 20090249129A1 · Femia · 2009 [cited by examiner]
US 20090327429A1 · Hughes · 2009 [cited by examiner]
US 20100033575A1 · Lee et al. · 2010 [cited by applicant]
US 20100281168A1 · Li · 2010 [cited by examiner]
US 20100286937A1 · Hedley et al. · 2010 [cited by applicant]
US 20100302009A1 · Hoeksel et al. · 2010 [cited by applicant]
US 20110029830A1 · Miller et al. · 2011 [cited by applicant]
US 20110060496A1 · Nielsen et al. · 2011 [cited by applicant]
US 20110125672A1 · Rosenthal et al. · 2011 [cited by applicant]
US 20110191465A1 · Hofstaedter · 2011 [cited by examiner]
US 20110200052A1 · Mungo et al. · 2011 [cited by applicant]
US 20110252132A1 · Wetzer et al. · 2011 [cited by applicant]
US 20120304007A1 · Hanks et al. · 2012 [cited by applicant]
US 20120306613A1 · De La Rue et al. · 2012 [cited by applicant]
US 20120310559A1 · Taft · 2012 [cited by applicant]
US 20120317274A1 · Richter · 2012 [cited by examiner]
US 20130201870A1 · Gupta · 2013 [cited by applicant]
US 20130202291A1 · Cavaliere et al. · 2013 [cited by applicant]
US 20130332240A1 · Patri et al. · 2013 [cited by applicant]
US 20130337867A1 · Brennan et al. · 2013 [cited by applicant]
US 20130343213A1 · Reynolds · 2013 [cited by examiner]
US 20140206373A1 · Ljung · 2014 [cited by applicant]
US 20140359552A1 · Misra et al. · 2014 [cited by applicant]
US 20150356497A1 · Reeder et al. · 2015 [cited by applicant]
The International Search Report and the Written Opinion mailed Dec. 9, 2013 for International Application No. PCT/US2013/042304. [cited by applicant]