Network inventory management and anomaly detection system
A method of generating a consolidated asset inventory database. The method creates a consolidated asset inventory based on asset information obtained from various sources, in which asset objects are associated with various asset attributes. The consolidation includes, for a given network infrastructure asset, identifying asset data from multiple sources relating to the same asset based on common identifier values and combining the identified asset data into a consolidated data representation of the asset associated with the common identifier value(s) and including attributes from the multiple sources. After identifying an asset attribute for which a value in the consolidated asset data representation is missing or invalid, a trained prediction model is applied to other attributes of the asset to generate a predicted value for the identified attribute which is stored in the consolidated asset data representation in the database. Methods for identifying network connectivity and detecting network anomalies are also disclosed.
1 . A method for detecting network anomalies, comprising:
receiving asset data defining a plurality of network assets of a computer network infrastructure from a plurality of network information sources;
creating a consolidated asset inventory database using an analytics engine based on the asset information, comprising a plurality of asset data objects representing assets, each data object associated with a plurality of asset attributes;
wherein the consolidating comprises, for a given network infrastructure asset:
identifying asset data from two or more of the sources relating to the same given network infrastructure asset based on one or more common identifier values;
identifying relationships detecting previously unknown interactions between the asset data and to create a relational model;
combining the identified asset data and the relational model into a consolidated data representation of the asset in the consolidated inventory database associated with the one or more common identifier values and including attributes from the multiple sources;
creating at least one prediction model comprising a neural network by converting non-numeric asset attribute values into a numerical representation as input to the neural network,
producing classifications and probabilities for a respective target attribute;
training the at least one prediction model, based on asset information, to predict the respective target attribute for each of the plurality of network assets based on at least one other asset attribute,
applying the at least one prediction model to one or more other attributes of the given asset to generate a predicted value for the identified attribute; and
storing the predicted value for the attribute in the consolidated asset data representation for the given asset in the database;
accessing interaction data relating to an interaction between network assets of the plurality of network assets, the interaction data providing information on interactions occurring between the network assets;
receiving a time parameter pertaining to time of the interaction;
creating a connectivity graph indicating connections between a set of network assets in the database, the connectivity graph comprising nodes that are encodings of the set of network assets and edges that are encodings of connections between network assets in the network determined based on interaction data relating to a given time period defined the time parameter;
generating a node embedding for a node of the graph, wherein the node embedding comprises a vector representation of the nodes and the within the graph; and
comparing the node embedding to one or more further node embeddings to detect an anomaly.
2 . A method according to claim 1 , wherein the one or more further node embeddings comprise node embeddings corresponding to the same node at one or more other times.
3 . A method according to claim 1 , comprising performing one or more of:
detecting an anomaly if the node embedding deviates from the one or more further node embeddings;
in response to detecting an anomaly, transmitting a notification of the anomaly to a user device;
in response to detecting an anomaly, performing a control action in the network and/or at the asset associated with the node identified as anomalous.
4 . A method according to claim 1 , wherein creating a connectivity graph comprises creating a node for each of a plurality of assets and associating with each node an asset vector, comprising a set of attribute values associated with the asset, the method optionally comprising repeating the generating and comparing steps for a plurality of nodes of the graph.
5 . A method according to any of claim 1 , comprising creating an adjacency matrix defining graph connectivity, the adjacency matrix defining edges between nodes corresponding to links between assets in the network, and associating with each edge one or more attributes specifying link attributes of the corresponding network link.
6 . A method according to claim 1 , comprising:
collecting asset data relating to assets and asset connectivity for a training period;
generating training samples based on the collected asset data, each training sample specifying a connectivity graph;
for each training sample, generating node embeddings for nodes of the connectivity graph for the training sample; and
wherein the comparing step compares the node embedding to one or more of the generated node embeddings.