IP Library › Granted Patent US 12,316,518
Granted Patent B2
US 12,316,518 · App. 18/419,024 · Granted May 27, 2025

Network anomaly detection

Inventors: Mikhal Shemer (Tel Aviv, IL); Roee Engelberg (Tel Aviv, IL); Yonit Tova Halperin Worzel (Tel Aviv, IL); Alex Gontmakher (Holon, IL); Alexander Goldshtein (Tel Aviv, IL); Gal Elidan (Modiin, IL); Benjamin Dov Kessler (Jerusalem, IL)
Assignee: Google LLC
H04L43/0817G06F9/45558G06F18/214H04L41/0627H04L41/0631H04L43/065G06F2009/45575G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,316,518
App. No.
18/419,024
Granted
May 27, 2025
Kind
B2
Abstract

A cloud network is a complex environment in which hundreds and thousands of users or entities can each host, create, modify, and develop multiple virtual machines. Each virtual machine can have complex behavior unknown to the provider or maintainer of the cloud. Technologies disclosed include methods, systems, and apparatuses to monitor the complex environment to detect network anomalies using machine learning techniques. In addition, techniques to modify and adapt to user feedback are provided allowing the developed models to be tuned for specific use cases, virtual machine types, and users.

Claims (33)

1. A method of detecting states of a network, the method comprising:

generating, by one or more processors, at least a first model for detecting a current state of the network based on characteristics of a given virtual machine;

obtaining, by the one or more processors, time series data related to network parameters associated with the current state of the network based on the given virtual machine;

determining, by the one or more processors, that the current state of the network meets a predetermined state differing from a normal state of the network using at least the first model based on the time series data;

providing, by the one or more processors, an actionable notification in response to determining that the current state of the network meets the predetermined state differing from the normal state of the network; and

performing, by the one or more processors, an action in response to determining that the current state of the network meets the predetermined state differing from the normal state of the network, wherein the action comprises at least one of: restarting the network, changing security protocols, changing firewall rules, or stopping or slowing egress or ingress of traffic.

2. The method of claim 1 , further comprising generating, by the one or more processors, multiple models for detecting the current state of the network based on the characteristics of the given virtual machine.

3. The method of claim 1 , further comprising training, by the one or more processors, at least the first model on time series training data related to network parameters.

4. The method of claim 1 , further comprising determining a presence of a pattern that is indicative of the current state of the network differing from the normal state of the network.

5. The method of claim 1 , wherein the predetermined state is an anomalous state or a user defined state.

6. The method of claim 1 , further comprising determining, by the one or more processors, a cause for the current state of the network differing from the normal state of the network using at least the first model and the time series data related to the network parameters.

7. The method of claim 1 , further comprising distinguishing, by the one or more processors, between an anomalous condition for the network and a malfunction within the given virtual machine.

8. The method of claim 1 , wherein the characteristics of the given virtual machine comprise at least one of a size of the given virtual machine, an amount of resources dedicated to the given virtual machine, or underlying software being used on the given virtual machine.

9. A system comprising:

one or more processors; and

one or more storage devices coupled to the one or more processors and storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations for detecting states of a network, the operations comprising:

generating at least a first model for detecting a current state of the network based on characteristics of a given virtual machine;

obtaining time series data related to network parameters associated with the current state of the network based on the given virtual machine;

determining that the current state of the network meets a predetermined state differing from a normal state of the network using at least the first model based on the time series data;

providing an actionable notification in response to determining that the current state of the network meets the predetermined state differing from the normal state of the network; and

performing an action in response to determining that the current state of the network meets the predetermined state differing from the normal state of the network, wherein the action comprises at least one of: restarting the network, changing security protocols, changing firewall rules, or stopping or slowing egress or ingress of traffic.

10. The system of claim 9 , wherein the operations further comprise training at least the first model on time series training data related to network parameters.

11. The system of claim 9 , wherein the operations further comprise determining a presence of a pattern that is indicative of the current state of the network differing from the normal state of the network.

12. The system of claim 9 , wherein the characteristics of the given virtual machine comprise at least one of a size of the given virtual machine, an amount of resources dedicated to the given virtual machine, or underlying software being used on the given virtual machine.

13. A non-transitory computer readable medium for storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations for detecting states of a network, the operations comprising:

generating at least a first model for detecting a current state of the network based on characteristics of a given virtual machine;

obtaining time series data related to network parameters associated with the current state of the network based on the given virtual machine;

determining that the current state of the network meets a predetermined state differing from a normal state of the network using at least the first model based on the time series data; and

providing an actionable notification in response to determining that the current state of the network meets the predetermined state differing from the normal state of the network; and

performing an action in response to determining that the current state of the network meets the predetermined state differing from the normal state of the network, wherein the action comprises at least one of: restarting the network, changing security protocols, changing firewall rules, or stopping or slowing egress or ingress of traffic.

14. The non-transitory computer readable medium of claim 13 , wherein the operations further comprise training at least the first model on time series training data related to network parameters.

15. The non-transitory computer readable medium of claim 13 , wherein the operations further comprise determining a presence of a pattern that is indicative of the current state of the network differing from the normal state of the network.

16. The non-transitory computer readable medium of claim 13 , wherein the characteristics of the given virtual machine comprise at least one of a size of the given virtual machine, an amount of resources dedicated to the given virtual machine, or underlying software being used on the given virtual machine.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2024
From: SHEMER, MIKHAL; ENGELBERG, ROEE; WORZEL, YONIT TOVA HALPERIN; GONTMAKHER, ALEX; GOLDSHTEIN, ALEXANDER; ELIDAN, GAL; KESSLER, BENJAMIN DOV
To: GOOGLE LLC
Reel/Frame 066211/0148 →
Continuity (4)
Continuation 18158623 · Jan 24, 2023
Continuation 17381909 · Jul 21, 2021
Provisional Application 63054493 · Jul 21, 2020
Related Publication 20240163193A1 · May 16, 2024
References Cited (12)
US 11403131B2 · Mohapatra et al. · 2022 [cited by applicant]
US 11595282B2 · Shemer et al. · 2023 [cited by applicant]
US 11929900B2 · Shemer · 2024 [cited by examiner]
US 20170199910A1 · Konik et al. · 2017 [cited by applicant]
US 20190260794A1 · Woodford et al. · 2019 [cited by applicant]
US 20190372827A1 · Vasseur et al. · 2019 [cited by applicant]
US 20200004601A1 · Ahmad · 2020 [cited by examiner]
US 20200028862A1 · Lin et al. · 2020 [cited by applicant]
US 20200076677A1 · Mermoud et al. · 2020 [cited by applicant]
US 20200219028A1 · Papaemmanouil · 2020 [cited by examiner]
US 20210160262A1 · Bynum et al. · 2021 [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2021/042587 dated Oct. 15, 2021. 15 pages. [cited by applicant]