IP Library › Granted Patent US 12,438,790
Granted Patent B1
US 12,438,790 · App. 18/617,031 · Granted Oct 7, 2025

Network anomaly detection using clustering

Inventors: Brian Robert Silverstein (Santa Clara, CA); Lorne Schell (Montreal, CA); Fanny Riols (Montreal, CA); Katrina Suzanne Stankiewicz (Montreal, CA)
Assignee: ServiceNow, Inc.
H04L43/0817G06F16/282G06F16/285H04L41/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,790
App. No.
18/617,031
Filed
Mar 26, 2024
Granted
Oct 7, 2025
Kind
B1
Art Unit
2441
USPC
709/224
Abstract

Systems and methods are provided that include accessing a representation of a network that includes a plurality of elements; generating a plurality of clusters representative of the network, each cluster of the plurality of clusters including a respective non-overlapping subset of elements of the plurality of elements; obtaining, for each element of the subset of elements of a particular cluster of the plurality of clusters, historical data indicative of operation of at least two of the respective elements of the particular cluster; training, using the historical data, a model to detect anomalous activity in the particular cluster; obtaining operational data for a particular element of the subset of elements of the particular cluster; and determining, by applying the model to the operational data, that the particular element of the cluster exhibits anomalous activity.

Claims (72)

1. A method comprising:

accessing a representation of a network comprising a plurality of elements;

generating a plurality of clusters representative of the network, each cluster of the plurality of clusters comprising a respective non-overlapping subset of elements of the plurality of elements;

obtaining, for each element of the subset of elements of a particular cluster of the plurality of clusters, historical data indicative of operation of at least two of the respective elements of the particular cluster;

training, using the historical data, a model to detect anomalous activity in the particular cluster;

obtaining operational data for a particular element of the subset of elements of the particular cluster; and

determining, by applying the model to the operational data, that the particular element of the cluster exhibits anomalous activity.

2. The method of claim 1 , wherein the plurality of elements comprises a plurality of non-volatile storage, a plurality of processors, or a plurality of server devices.

3. The method of claim 1 , wherein each element in the plurality of elements is represented in a database as part of a hierarchical structure, and wherein generating the plurality of clusters comprises grouping the elements based on the database representation such that each cluster comprises a respective set of elements that are near each other within the hierarchical structure.

4. The method of claim 3 , wherein generating the plurality of clusters comprises grouping the elements such that none of the clusters comprises more than a maximum number of elements.

5. The method of claim 3 , further comprising:

determining, by applying the model to operational data for at least one element of the particular cluster, that a plurality of elements of the particular cluster exhibits anomalous activity;

responsively applying, to a generative machine learning model, an input that includes (i) a representation of a part of the hierarchical structure from the database representation that represents the elements of the particular cluster and (ii) the operational data for the at least one element of the particular cluster; and

obtaining a model output indicative of a common cause of the anomalous activity exhibited by the plurality of elements of the particular cluster.

6. The method of claim 1 , wherein using the historical data to train the model to detect anomalous activity in the particular cluster comprises using historical data indicative of operation of all of the respective elements of the particular cluster.

7. The method of claim 1 , wherein the particular element comprises a controller comprising one or more processors, and wherein determining that the particular element of the cluster exhibits anomalous activity comprises:

determining, by the controller of the particular element applying the model to the operational data, that the particular element of the cluster exhibits anomalous activity.

8. The method of claim 1 , wherein using the historical data to train the model to detect anomalous activity in the particular cluster comprises using historical data indicative of operation of a randomly-selected subset of the respective elements of the particular cluster.

9. The method of claim 1 , wherein determining, by applying the model to the operational data, that the particular element of the cluster exhibits anomalous activity comprises determining, by applying the model to the operational data, that the particular element of the cluster exhibits anomalous activity at a rate greater than a threshold rate, and wherein the method further comprises:

responsive to determining that the particular element of the cluster exhibits anomalous activity at a rate greater than the threshold rate, assigning the particular element to a cluster other than the particular cluster.

10. The method of claim 1 , further comprising:

adding, to the plurality of elements, an additional element;

responsive to determining that the additional element is similar to the subset of elements of the particular cluster, assigning the additional element to the particular cluster;

obtaining additional operational data for the additional element; and

determining, by applying the model to the additional operational data, that the additional element exhibits anomalous activity.

11. The method of claim 1 , wherein using the historical data to train the model to detect anomalous activity in the particular cluster comprises determining a baseline rate at which elements of the particular cluster exhibited model-predicted anomalies within the historical data, and wherein the method further comprises:

obtaining additional operational data for the elements of the particular cluster;

determining, by applying the model to the additional operational data, that the elements of the particular cluster exhibit anomalies at a rate that is greater than a specified multiple of the baseline rate; and

responsively retraining the model.

12. The method of claim 1 , wherein the model is configured to receive as input a specified set of operational outputs, wherein the particular element does not generate all of the specified set of operational outputs, wherein applying the model to the operational data comprises expanding a set of operational outputs generated by the particular element to include all of the specified set of operational outputs by generating at least one additional operational output for the particular element, and wherein generating at least one additional operational output for the particular element comprises generating a time series operational output composed of all values set to zero, all values set to a pre-specified negative value, or all values set to a pre-specified mean output value.

13. A non-transitory computer-readable medium, having stored thereon program instructions that, upon execution by a computing system, cause the computing system to perform operations comprising:

accessing a representation of a network comprising a plurality of elements;

generating a plurality of clusters representative of the network, each cluster of the plurality of clusters comprising a respective non-overlapping subset of elements of the plurality of elements;

obtaining, for each element of the subset of elements of a particular cluster of the plurality of clusters, historical data indicative of operation of at least two of the respective elements of the particular cluster;

training, using the historical data, a model to detect anomalous activity in the particular cluster;

obtaining operational data for a particular element of the subset of elements of the particular cluster; and

determining, by applying the model to the operational data, that the particular element of the cluster exhibits anomalous activity.

14. The non-transitory computer-readable medium of claim 13 , wherein each element in the plurality of elements is represented in a database as part of a hierarchical structure, wherein generating the plurality of clusters comprises grouping the elements based on the database representation such that each cluster comprises a respective set of elements that are near each other within the hierarchical structure, and wherein the operations further comprise:

determining, by applying the model to operational data for at least one element of the particular cluster, that a plurality of elements of the particular cluster exhibits anomalous activity;

responsively applying, to a generative machine learning model, an input that includes (i) a representation of a part of the hierarchical structure from the database representation that represents the elements of the particular cluster and (ii) the operational data for the at least one element of the particular cluster; and

obtaining a model output indicative of a common cause of the anomalous activity exhibited by the plurality of elements of the particular cluster.

15. The non-transitory computer-readable medium of claim 13 , wherein the operations further comprise:

adding, to the plurality of elements, an additional element;

responsive to determining that the additional element is similar to the subset of elements of the particular cluster, assigning the additional element to the particular cluster;

obtaining additional operational data for the additional element; and

determining, by applying the model to the additional operational data, that the additional element exhibits anomalous activity.

16. The non-transitory computer-readable medium of claim 13 , wherein using the historical data to train the model to detect anomalous activity in the particular cluster comprises determining a baseline rate at which elements of the particular cluster exhibited model-predicted anomalies within the historical data, and wherein the operations further comprise:

obtaining additional operational data for the elements of the particular cluster;

determining, by applying the model to the additional operational data, that the elements of the particular cluster exhibit anomalies at a rate that is greater than a specified multiple of the baseline rate; and

responsively retraining the model.

17. A system comprising:

one or more processors; and

memory, containing program instructions that, upon execution by the one or more processors, cause the system to perform operations comprising:

accessing a representation of a network comprising a plurality of elements;

generating a plurality of clusters representative of the network, each cluster of the plurality of clusters comprising a respective non-overlapping subset of elements of the plurality of elements;

obtaining, for each element of the subset of elements of a particular cluster of the plurality of clusters, historical data indicative of operation of at least two of the respective elements of the particular cluster;

training, using the historical data, a model to detect anomalous activity in the particular cluster;

obtaining operational data for a particular element of the subset of elements of the particular cluster; and

determining, by applying the model to the operational data, that the particular element of the cluster exhibits anomalous activity.

18. The system of claim 17 , wherein each element in the plurality of elements is represented in a database as part of a hierarchical structure, wherein generating the plurality of clusters comprises grouping the elements based on the database representation such that each cluster comprises a respective set of elements that are near each other within the hierarchical structure, and wherein the operations further comprise:

determining, by applying the model to operational data for at least one element of the particular cluster, that a plurality of elements of the particular cluster exhibits anomalous activity;

responsively applying, to a generative machine learning model, an input that includes (i) a representation of a part of the hierarchical structure from the database representation that represents the elements of the particular cluster and (ii) the operational data for the at least one element of the particular cluster; and

obtaining a model output indicative of a common cause of the anomalous activity exhibited by the plurality of elements of the particular cluster.

19. The system of claim 17 , wherein the operations further comprise:

adding, to the plurality of elements, an additional element;

responsive to determining that the additional element is similar to the subset of elements of the particular cluster, assigning the additional element to the particular cluster;

obtaining additional operational data for the additional element; and

determining, by applying the model to the additional operational data, that the additional element exhibits anomalous activity.

20. The system of claim 17 , wherein using the historical data to train the model to detect anomalous activity in the particular cluster comprises determining a baseline rate at which elements of the particular cluster exhibited model-predicted anomalies within the historical data, and wherein the operations further comprise:

obtaining additional operational data for the elements of the particular cluster;

determining, by applying the model to the additional operational data, that the elements of the particular cluster exhibit anomalies at a rate that is greater than a specified multiple of the baseline rate; and

responsively retraining the model.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2025
From: ELEMENT AI; SERVICENOW CANADA INC.
To: SERVICENOW, INC.
Reel/Frame 071025/0742 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2024
From: SCHELL, LORNE; RIOLS, FANNY; STANKIEWICZ, KATRINA SUZANNE
To: SERVICENOW CANADA INC.
Reel/Frame 066966/0190 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2024
From: SILVERSTEIN, BRIAN ROBERT
To: SERVICENOW, INC.
Reel/Frame 066966/0559 →
References Cited (183)
US 4941084A · Terada · 1990 [cited by applicant]
US 5185860A · Wu · 1993 [cited by applicant]
US 5237518A · Sztipanovits · 1993 [cited by applicant]
US 5261097A · Saxon · 1993 [cited by applicant]
US 5265252A · Rawson, III · 1993 [cited by applicant]
US 5367685A · Gosling · 1994 [cited by applicant]
US 5390297A · Barber · 1995 [cited by applicant]
US 5442791A · Wrabetz · 1995 [cited by applicant]
US 5452415A · Hotka · 1995 [cited by applicant]
US 5522042A · Fee · 1996 [cited by applicant]
US 5533116A · Vesterinen · 1996 [cited by applicant]
US 5655081A · Bonnell · 1997 [cited by applicant]
US 5659736A · Hasegawa · 1997 [cited by applicant]
US 5671412A · Christiano · 1997 [cited by applicant]
US 5696701A · Burgess · 1997 [cited by applicant]
US 5715463A · Merkin · 1998 [cited by applicant]
US 5745879A · Wyman · 1998 [cited by applicant]
US 5761502A · Jacobs · 1998 [cited by applicant]
US 5764913A · Jancke · 1998 [cited by applicant]
US 5887139A · Madison, Jr. · 1999 [cited by applicant]
US 5909217A · Bereiter · 1999 [cited by applicant]
US 5937165A · Schwaller · 1999 [cited by applicant]
US 5949976A · Chappelle · 1999 [cited by applicant]
US 5978594A · Bonnell · 1999 [cited by applicant]
US 6021437A · Chen · 2000 [cited by applicant]
US 6041347A · Harsham · 2000 [cited by applicant]
US 6088717A · Reed · 2000 [cited by applicant]
US 6101500A · Lau · 2000 [cited by applicant]
US 6128016A · Coelho · 2000 [cited by applicant]
US 6131118A · Stupek, Jr. · 2000 [cited by applicant]
US 6134581A · Ismael · 2000 [cited by applicant]
US 6138122A · Smith · 2000 [cited by applicant]
US 6148335A · Haggard · 2000 [cited by applicant]
US 6166732A · Mitchell · 2000 [cited by applicant]
US 6167448A · Hemphill · 2000 [cited by applicant]
US 6175866B1 · Holloway et al. · 2001 [cited by applicant]
US 6175878B1 · Seaman · 2001 [cited by applicant]
US 6260050B1 · Yost · 2001 [cited by applicant]
US 6263457B1 · Anderson · 2001 [cited by applicant]
US 6272150B1 · Hrastar · 2001 [cited by applicant]
US 6336138B1 · Caswell · 2002 [cited by applicant]
US 6363421B2 · Barker · 2002 [cited by applicant]
US 6393386B1 · Zager · 2002 [cited by applicant]
US 6397245B1 · Johnson, II · 2002 [cited by applicant]
US 6434626B1 · Prakash · 2002 [cited by applicant]
US 6438592B1 · Killian · 2002 [cited by applicant]
US 6456306B1 · Chin · 2002 [cited by applicant]
US 6466932B1 · Dennis · 2002 [cited by applicant]
US 6487590B1 · Foley · 2002 [cited by applicant]
US 6505248B1 · Casper · 2003 [cited by applicant]
US 6526442B1 · Stupek, Jr. · 2003 [cited by applicant]
US 6621823B1 · Mellquist · 2003 [cited by applicant]
US 6707795B1 · Noorhosseini · 2004 [cited by applicant]
US 6742015B1 · Bowman-Amuah · 2004 [cited by applicant]
US 6763380B1 · Mayton · 2004 [cited by applicant]
US 6816898B1 · Scarpelli · 2004 [cited by applicant]
US 6895586B1 · Brasher · 2005 [cited by applicant]
US 6948175B1 · Fong · 2005 [cited by applicant]
US 6985901B1 · Sachse · 2006 [cited by applicant]
US 7003564B2 · Greuel · 2006 [cited by applicant]
US 7028228B1 · Lovy · 2006 [cited by applicant]
US 7043537B1 · Pratt · 2006 [cited by applicant]
US 7043661B2 · Valadarsky · 2006 [cited by applicant]
US 7062683B2 · Warpenburg · 2006 [cited by applicant]
US 7096459B2 · Keller · 2006 [cited by applicant]
US 7146574B2 · Goldthwaite · 2006 [cited by applicant]
US 7197466B1 · Peterson · 2007 [cited by applicant]
US 7215360B2 · Gupta · 2007 [cited by applicant]
US 7216304B1 · Gourdol · 2007 [cited by applicant]
US 7222147B1 · Black · 2007 [cited by applicant]
US 7281170B2 · Taylor · 2007 [cited by applicant]
US 7328260B1 · Muthiyan · 2008 [cited by applicant]
US 7412502B2 · Fearn · 2008 [cited by applicant]
US 7505872B2 · Keller · 2009 [cited by applicant]
US 7593013B2 · Agutter · 2009 [cited by applicant]
US 7596716B2 · Frost · 2009 [cited by applicant]
US 7617073B2 · Trinon · 2009 [cited by applicant]
US 7660731B2 · Chaddha · 2010 [cited by applicant]
US 7676294B2 · Baier · 2010 [cited by applicant]
US 7676437B2 · Satkunanathan · 2010 [cited by applicant]
US 7840490B1 · Sellers · 2010 [cited by applicant]
US 7877783B1 · Cline · 2011 [cited by applicant]
US 7890869B1 · Mayer · 2011 [cited by applicant]
US 7966398B2 · Wiles, Jr. · 2011 [cited by applicant]
US 8060396B1 · Bessler · 2011 [cited by applicant]
US 8196210B2 · Sterin · 2012 [cited by applicant]
US 8321948B2 · Robinson · 2012 [cited by applicant]
US 8407669B2 · Yee · 2013 [cited by applicant]
US 8554750B2 · Rangarajan · 2013 [cited by applicant]
US 8595647B2 · Sabin · 2013 [cited by applicant]
US 8620818B2 · Hughes · 2013 [cited by applicant]
US 8646093B2 · Myers · 2014 [cited by applicant]
US 8674992B2 · Poston · 2014 [cited by applicant]
US 8725647B2 · Disciascio · 2014 [cited by applicant]
US 9053460B2 · Gilbert · 2015 [cited by applicant]
US 9069737B1 · Kimotho · 2015 [cited by applicant]
US 9231834B2 · Carmel · 2016 [cited by applicant]
US 9971826B1 · Belmar · 2018 [cited by applicant]
US 10305738B2 · Kaluza · 2019 [cited by applicant]
US 10673963B1 · Feiguine · 2020 [cited by applicant]
US 10749943B1 · Feiguine · 2020 [cited by applicant]
US 10771344B2 · Bitterfeld · 2020 [cited by applicant]
US 10824650B2 · Bar Oz · 2020 [cited by applicant]
US 10944654B2 · Rimar · 2021 [cited by applicant]
US 10999152B1 · Bar Oz · 2021 [cited by applicant]
US 11025481B1 · Louca · 2021 [cited by applicant]
US 11037080B2 · Widanapathirana · 2021 [cited by examiner]
US 11089115B2 · Garty · 2021 [cited by applicant]
US 11095506B1 · Erblat · 2021 [cited by applicant]
US 11108635B2 · Tero · 2021 [cited by applicant]
US 11216502B2 · Levy · 2022 [cited by applicant]
US 11275580B2 · Tamir · 2022 [cited by applicant]
US 11277475B1 · Tal · 2022 [cited by applicant]
US 11281442B1 · Tal · 2022 [cited by applicant]
US 11294666B1 · Look · 2022 [cited by applicant]
US 11296922B2 · Leibkowiz · 2022 [cited by applicant]
US 11301503B2 · Burli · 2022 [cited by applicant]
US 11379089B2 · Goswami · 2022 [cited by applicant]
US 11418526B2 · Bertiger et al. · 2022 [cited by applicant]
US 11451573B2 · Waplington · 2022 [cited by applicant]
US 11470107B2 · Waplington · 2022 [cited by applicant]
US 11582106B2 · Hameiri · 2023 [cited by applicant]
US 11604896B2 · Walters · 2023 [cited by applicant]
US 11616690B2 · Feiguine · 2023 [cited by applicant]
US 11630717B2 · Vutukuru · 2023 [cited by applicant]
US 11632303B2 · Bitterfeld · 2023 [cited by applicant]
US 11640369B2 · Bhogle · 2023 [cited by applicant]
US 11651032B2 · Baskar · 2023 [cited by applicant]
US 11671444B2 · Waplington · 2023 [cited by applicant]
US 11695641B2 · Bar Oz · 2023 [cited by applicant]
US 20020116340A1 · Hellberg · 2002 [cited by applicant]
US 20020133584A1 · Greuel · 2002 [cited by applicant]
US 20020158969A1 · Gupta · 2002 [cited by applicant]
US 20030118087A1 · Goldthwaite · 2003 [cited by applicant]
US 20030200293A1 · Fearn · 2003 [cited by applicant]
US 20050015217A1 · Weidl · 2005 [cited by applicant]
US 20050091356A1 · Izzo · 2005 [cited by applicant]
US 20060026453A1 · Frost · 2006 [cited by applicant]
US 20060095461A1 · Raymond · 2006 [cited by applicant]
US 20060179058A1 · Bram · 2006 [cited by applicant]
US 20060288053A1 · Holt · 2006 [cited by applicant]
US 20060293942A1 · Chaddha · 2006 [cited by applicant]
US 20070033279A1 · Battat · 2007 [cited by applicant]
US 20070188494A1 · Agutter · 2007 [cited by applicant]
US 20070288389A1 · Vaughan · 2007 [cited by applicant]
US 20080133289A1 · Armour · 2008 [cited by applicant]
US 20080148253A1 · Badwe · 2008 [cited by applicant]
US 20080319779A1 · Hughes · 2008 [cited by applicant]
US 20090088875A1 · Baier · 2009 [cited by applicant]
US 20090228984A1 · Sterin · 2009 [cited by applicant]
US 20100110932A1 · Doran · 2010 [cited by applicant]
US 20130073496A1 · Szatmary et al. · 2013 [cited by applicant]
US 20130283273A1 · Miyazaki · 2013 [cited by applicant]
US 20140122427A1 · Dary · 2014 [cited by applicant]
US 20180123940A1 · Rimar · 2018 [cited by applicant]
US 20190073257A1 · Dasgupta · 2019 [cited by applicant]
US 20190073416A1 · Wang · 2019 [cited by applicant]
US 20190104398A1 · Owen · 2019 [cited by applicant]
US 20190129739A1 · Al Reza · 2019 [cited by applicant]
US 20190149515A1 · Sharma · 2019 [cited by applicant]
US 20190165957A1 · Abbott · 2019 [cited by applicant]
US 20190342162A1 · Bendre · 2019 [cited by applicant]
US 20200034462A1 · Narayanasamy · 2020 [cited by applicant]
US 20200050689A1 · Tal · 2020 [cited by applicant]
US 20200204443A1 · Bar Oz · 2020 [cited by applicant]
US 20200301678A1 · Burman · 2020 [cited by applicant]
US 20210067527A1 · Chen et al. · 2021 [cited by applicant]
US 20210067549A1 · Chen et al. · 2021 [cited by applicant]
US 20210097168A1 · Patel · 2021 [cited by applicant]
US 20210124981A1 · Kim · 2021 [cited by examiner]
US 20210194764A1 · Badyan · 2021 [cited by applicant]
US 20210374601A1 · Liu et al. · 2021 [cited by applicant]
US 20220138621A1 · Patil et al. · 2022 [cited by applicant]
US 20220327108A1 · Manolache et al. · 2022 [cited by applicant]
US 20230419402A1 · Ghelichi · 2023 [cited by examiner]
EP 0433979A2 · 1991 [cited by applicant]
EP 1607824A2 · 2005 [cited by applicant]
WO 9934285A1 · 1999 [cited by applicant]
WO 0052559A1 · 2000 [cited by applicant]
WO 0179970A2 · 2001 [cited by applicant]
You et al., “Graph Contrastive Learning with Augmentations,” 34th Conference on Neural Information Processing Systems (NeurIPS 2020), Vancouver, Canada, 2020, 12 pages. [cited by applicant]
Zhang et al., “STAR-GCN: Stacked and Reconstructed Graph Convolutional Networks for Recommender Systems,” Proceedings of the Twenty-Eighth International Joint Conference on Artificial Intelligence (IJCAI-19), 2019, pp. … [cited by applicant]
Zhu et al., “Deep Graph Contrastive Representation Learning,” arXiv:2006.04131v2, Jul. 13, 2020, 17 pages. [cited by applicant]
Cited By (1)
US 12,568,144