IP Library Granted Patent US 12,659,255
Granted Patent B2
US 12,659,255 · App. 18/656,206 · Granted Jun 16, 2026

Detecting network events having adverse user impact

Inventors: Jisheng Wang (Palo Alto, CA); Jing Cheng (San Jose, CA); Abhiram Madhugiri Shamsundar (San Jose, CA); Randall Frei (San Jose, CA)
Assignee: Hewlett Packard Enterprise Development LP
H04L43/0876H04L41/0631H04L43/062H04L45/48
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,659,255
App. No.
18/656,206
Granted
Jun 16, 2026
Kind
B2
Abstract

A method includes receiving, by a network management system, network data from a plurality of network devices configured to provide a network at a site; receiving, by the processing circuitry, user impact data from a plurality of client devices that access the network at the site; determining, based on the network data, a pattern of one or more network events occurring over time; correlating in time the pattern of the one or more network events to an adverse user impact event indicated by the user impact data received from the plurality of client devices; and determining, in response to the correlating, an instance of overwhelming network traffic having an adverse user impact. In some examples, the network data includes network traffic impact data, such as a number of packets dropped at a switch port due to congestion.

Claims (35)

1 . A network management system (NMS) comprising processing circuitry in communication with storage media, the processing circuitry configured to:

determine a pattern of network events within a rolling time window based on network telemetry data obtained from a plurality of network devices that provide network access to one or more client devices;

determine an impact event based on user data obtained from the one or more client devices for one or more users, the user data indicating feedback related to a quality of an application session;

correlate in time the pattern of network events within the rolling time window to the impact event; and

determine, based at least in part on the correlation, that the pattern of network events is indicative of network behavior that is a cause of the impact event, wherein the network behavior comprises an instance of a high volume of discovery messages per unit time exchanged by the one or more client devices.

2 . The NMS of claim 1 , wherein the processing circuitry is further configured to:

identify a root cause of the network behavior that is the cause of the impact event; and

initiate a remedial action to remedy the root cause of the network behavior that is the cause of the impact event.

3 . The NMS of claim 1 , wherein, to determine the pattern of network events based on the network telemetry data, the processing circuitry is configured to apply the network telemetry data as input to a machine learning system trained to perform anomaly detection based on the network telemetry data, the machine learning system configured to output an indication of the pattern of network events.

4 . The NMS of claim 1 , wherein the processing circuitry is further configured to generate, for output to a user, a real-time alert indicating that the pattern of network events is indicative of the network behavior that is the cause of the impact event.

5 . The NMS of claim 1 , wherein the network telemetry data for the plurality of network devices comprises network telemetry data indicating a number of packets dropped at each network device of the plurality of network devices due to congestion.

6 . The NMS of claim 1 , wherein the network telemetry data for the plurality of network devices comprises network telemetry data indicating a number of reflected packets received by each network device of the plurality of network devices.

7 . The NMS of claim 1 , wherein the processing circuitry is further configured to obtain the user data indicating the feedback related to the quality of the application session as a response to a prompt presented to a user of the one or more users by a client device of the one or more client devices.

8 . The NMS of claim 1 ,

wherein to determine that the pattern of network events is indicative of the network behavior that is the cause of the impact event, the processing circuitry is configured to determine that the pattern of network events is indicative of a worsening trend of the network behavior that is the cause of the impact event;

identify a root cause of the worsening trend of the network behavior; and

initiate a remedial action to remedy the root cause of the worsening trend of the network behavior.

9 . A method comprising:

determining, by a network management system (NMS) executed by processing circuitry, a pattern of network events within a rolling time window based on network telemetry data obtained from a plurality of network devices that provide network access to one or more client devices;

determining, by the NMS, an impact event based on user data obtained from the one or more client devices for one or more users, the user data indicating feedback related to a quality of an application session;

correlating, by the NMS, in time the pattern of network events within the rolling time window to the impact event; and

determining, by the NMS, based at least in part on the correlation, that the pattern of network events is indicative of network behavior that is a cause of the impact event, wherein the network behavior comprises an instance of a high volume of discovery messages per unit time exchanged by the one or more client devices.

10 . The method of claim 9 , further comprising:

identifying, by the NMS, a root cause of the network behavior that is the cause of the impact event; and

initiating, by the NMS, a remedial action to remedy the root cause of the network behavior that is the cause of the impact event.

11 . The method of claim 9 , wherein determining the pattern of network events based on the network telemetry data comprises applying, by the NMS, the network telemetry data as input to a machine learning system trained to perform anomaly detection based on the network telemetry data, the machine learning system configured to output an indication of the pattern of network events.

12 . The method of claim 9 , wherein the network telemetry data for the plurality of network devices comprises network telemetry data indicating a number of packets dropped at each network device of the plurality of network devices due to congestion.

13 . The method of claim 9 , wherein the network telemetry data for the plurality of network devices comprises network telemetry data indicating a number of reflected packets received by each network device of the plurality of network devices.

14 . The method of claim 9 , further comprising obtaining, by the NMS, the user data indicating the feedback related to the quality of the application session as a response to a prompt presented to a user of the one or more users by a client device of the one or more client devices.

15 . Non-transitory, computer-readable media comprising instructions that, when executed, cause processing circuitry to:

execute a network management system (NMS) configured to:

determine a pattern of network events within a rolling time window based on network telemetry data obtained from a plurality of network devices that provide network access to one or more client devices;

determine an impact event based on user data obtained from the one or more client devices for one or more users, the user data indicating feedback related to a quality of an application session;

correlate in time the pattern of network events within the rolling time window to the impact event; and

determine, based at least in part on the correlation, that the pattern of network events is indicative of network behavior that is a cause of the impact event, wherein the network behavior comprises an instance of a high volume of discovery messages per unit time exchanged by the one or more client devices.

Assignments (2)
NUNC PRO TUNC ASSIGNMENT Recorded May 6, 2026
From: JUNIPER NETWORKS, INC.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 075513/0034 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2026
From: WANG, JISHENG; CHENG, JING; SHAMSUNDAR, ABHIRAM MADHUGIRI; FREI, RANDALL
To: JUNIPER NETWORKS, INC.
Reel/Frame 074090/0865 →
Continuity (3)
Continuation 17812676 · Jul 14, 2022
Provisional Application 63322545 · Mar 22, 2022
Related Publication 20240291743A1 · Aug 29, 2024
References Cited (34)
US 9729439B2 · MeLampy et al. · 2017 [cited by applicant]
US 9729682B2 · Kumar et al. · 2017 [cited by applicant]
US 9762485B2 · Kaplan et al. · 2017 [cited by applicant]
US 9832082B2 · Dade · 2017 [cited by applicant]
US 9871748B2 · Gosselin et al. · 2018 [cited by applicant]
US 9985883B2 · MeLampy et al. · 2018 [cited by applicant]
US 10200264B2 · Menon et al. · 2019 [cited by applicant]
US 10277506B2 · Timmons et al. · 2019 [cited by applicant]
US 10432522B2 · Kaplan et al. · 2019 [cited by applicant]
US 10862742B2 · Singh · 2020 [cited by applicant]
US 10958537B2 · Safavi · 2021 [cited by applicant]
US 10958585B2 · Safavi · 2021 [cited by applicant]
US 10985969B2 · Safavi · 2021 [cited by applicant]
US 11075824B2 · McCulley et al. · 2021 [cited by applicant]
US 11743151B2 · Safavi · 2023 [cited by applicant]
US 20110126054A1 · Hayward · 2011 [cited by examiner]
US 20130094361A1 · Kulkarni · 2013 [cited by applicant]
US 20160065419A1 · Szilagyi et al. · 2016 [cited by applicant]
US 20160285717A1 · Kim · 2016 [cited by applicant]
US 20170065892A1 · Loeb · 2017 [cited by applicant]
US 20190196894A1 · Cherbakov et al. · 2019 [cited by applicant]
US 20210028973A1 · Côté · 2021 [cited by examiner]
US 20210250222A1 · Boussac · 2021 [cited by applicant]
US 20210306201A1 · Wang et al. · 2021 [cited by applicant]
US 20210306877A1 · Blake · 2021 [cited by examiner]
US 20220174503A1 · Kounev · 2022 [cited by applicant]
US 20230231785A1 · Kumar · 2023 [cited by applicant]
US 20230308374A1 · Wang et al. · 2023 [cited by applicant]
Extended Search Report from counterpart European Application No. 22214651.6 dated Jul. 11, 2023, 10 pp. [cited by applicant]
Juniper Networks, Inc., “Resolution Guide—EX—Troubleshoot Spanning Tree Protocol (STP)”, Feb. 20, 2012, 9 pp., Retrieved from URL: https://kb.juniper.net/InfoCenter/index?page=content&id=KB22774&actp=METADATA. [cited by applicant]
Prosecution History from U.S. Appl. No. 17/812,676, dated Mar. 6, 2023 through Feb. 12, 2024, 107 pp. [cited by applicant]
Response to Extended Search Report dated Jul. 11, 2023, from counterpart European Application No. 22214651.6 filed Mar. 25, 2024, 28 pp. [cited by applicant]
U.S. Appl. No. 63/299,733, filed Jan. 14, 2022, naming inventors Wang et al. [cited by applicant]
Corrected Notice of Allowance from U.S. Appl. No. 17/812,676 dated May 20, 2024, 5 pp. [cited by applicant]