IP Library › Granted Patent US 10,771,488
Granted Patent B2
US 10,771,488 · App. 15/949,198 · Granted Sep 8, 2020

Spatio-temporal anomaly detection in computer networks using graph convolutional recurrent neural networks (GCRNNs)

Inventors: Saurabh Verma (Minneapolis, MN); Manjula Shivanna (San Jose, CA); Gyana Ranjan Dash (San Jose, CA); Antonio Nucci (San Jose, CA)
Assignee: Cisco Technology, Inc.
H04L63/1425G06N3/08H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,771,488
App. No.
15/949,198
Filed
Apr 10, 2018
Granted
Sep 8, 2020
Kind
B2
Art Unit
2435
USPC
726/23
Abstract

In one embodiment, a device receives sensor data from a plurality of nodes in a computer network. The device uses the sensor data and a graph that represents a topology of the nodes in the network as input to a graph convolutional neural network. The device provides an output of the graph convolutional neural network as input to a convolutional long short-term memory recurrent neural network. The device detects an anomaly in the computer network by comparing a reconstruction error associated with an output of the convolutional long short-term memory recurrent neural network to a defined threshold. The device initiates a mitigation action in the computer network for the detected anomaly.

Claims (41)

1. A method comprising:

receiving, at a device, sensor data from a plurality of nodes in a computer network;

using, by the device, the sensor data and a graph that represents a topology of the nodes in the network as input to a graph convolutional neural network;

providing, by the device, an output of the graph convolutional neural network as input to a convolutional long short-term memory recurrent neural network, wherein the graph convolutional neural network is configured to produce its output based in part on a spatial dependency between the nodes in the computer network;

detecting, by the device, an anomaly in the computer network by comparing a reconstruction error associated with an output of the convolutional long short-term memory recurrent neural network to a defined threshold, wherein the convolutional long short-term memory recurrent neural network is configured to produce its output based on a temporal dependency of the sensor data; and

initiating, by the device, a mitigation action in the computer network for the detected anomaly.

2. The method as in claim 1 , wherein the mitigation action comprises one of: blocking or dropping traffic in the computer network, removing one or more of the nodes associated with the detected anomaly from the routing topology, or sending an alert regarding the detected anomaly to a user interface.

3. The method as in claim 1 , wherein the sensor data comprises log data from the plurality of nodes in the computer network regarding operational characteristics of the nodes.

4. The method as in claim 1 , further comprising:

receiving, at the device, the defined threshold from a user interface.

5. The method as in claim 1 , further comprising:

training the graph convolutional neural network and convolutional long short-term memory recurrent neural network using back propagation.

6. The method as in claim 5 , wherein the training uses training data comprising time series of the sensor data indicative of normal operations of the computer network.

7. An apparatus, comprising:

one or more network interfaces to communicate with a computer network;

a processor coupled to the network interfaces and configured to execute one or more processes; and

a memory configured to store a process executable by the processor, the process when executed configured to:

receive sensor data from a plurality of nodes in a computer network;

use the sensor data and a graph that represents a topology of the nodes in the network as input to a graph convolutional neural network;

provide an output of the graph convolutional neural network as input to a convolutional long short-term memory recurrent neural network, wherein the graph convolutional neural network is configured to produce its output based in part on a spatial dependency between the nodes in the computer network;

detect an anomaly in the computer network by comparing a reconstruction error associated with an output of the convolutional long short-term memory recurrent neural network to a defined threshold, wherein the convolutional long short-term memory recurrent neural network is configured to produce its output based on a temporal dependency of the sensor data; and

initiate a mitigation action in the computer network for the detected anomaly.

8. The apparatus as in claim 7 , wherein the mitigation action comprises one of: blocking or dropping traffic in the computer network, removing one or more of the nodes associated with the detected anomaly from the routing topology, or sending an alert regarding the detected anomaly to a user interface.

9. The apparatus as in claim 7 , wherein the sensor data comprises log data from the plurality of nodes in the computer network regarding operational characteristics of the nodes.

10. The apparatus as in claim 7 , wherein the process when executed is further configured to:

receive the defined threshold from a user interface.

11. The apparatus as in claim 7 , wherein the process when executed is further configured to:

train the graph convolutional neural network and convolutional long short-term memory recurrent neural network using back propagation.

12. The apparatus as in claim 11 , wherein the training uses training data comprising time series of the sensor data indicative of normal operations of the computer network.

13. A tangible, non-transitory, computer-readable medium storing program instructions that cause a processor of a device to execute a process comprising:

receiving, at the device, sensor data from a plurality of nodes in a computer network;

using, by the device, the sensor data and a graph that represents a topology of the nodes in the network as input to a graph convolutional neural network;

providing, by the device, an output of the graph convolutional neural network as input to a convolutional long short-term memory recurrent neural network, wherein the graph convolutional neural network is configured to produce its output based in part on a spatial dependency between the nodes in the computer network;

detecting, by the device, an anomaly in the computer network by comparing a reconstruction error associated with an output of the convolutional long short-term memory recurrent neural network to a defined threshold, wherein the convolutional long short-term memory recurrent neural network is configured to produce its output based on a temporal dependency of the sensor data; and

initiating, by the device, a mitigation action in the computer network for the detected anomaly.

14. The computer-readable medium as in claim 13 , wherein the mitigation action comprises one of: blocking or dropping traffic in the computer network, removing one or more of the nodes associated with the detected anomaly from the routing topology, or sending an alert regarding the detected anomaly to a user interface.

15. The computer-readable medium as in claim 13 , wherein the sensor data comprises log data from the plurality of nodes in the computer network regarding operational characteristics of the nodes.

16. The computer-readable medium as in claim 13 , wherein the process further comprises:

receiving, at the device, the defined threshold from a user interface.

17. The computer-readable medium as in claim 13 , wherein the process further comprises:

training the graph convolutional neural network and convolutional long short-term memory recurrent neural network using back propagation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2018
From: VERMA, SAURABH; SHIVANNA, MANJULA; DASH, GYANA RANJAN; NUCCI, ANTONIO
To: CISCO TECHNOLOGY, INC.
Reel/Frame 046998/0971 →
Continuity (1)
Related Publication 20190312898A1 · Oct 10, 2019
Cited By (113)
US 12,206,696 US 12,244,452 US 12,244,621 US 12,261,866 US 12,267,345 US 12,284,197 US 12,293,320 US 12,309,181 US 12,309,182 US 12,309,185 US 12,309,236 US 12,323,449 US 12,335,286 US 12,335,348 US 12,341,797 US 12,348,545 US 12,355,626 US 12,355,787 US 12,355,793 US 12,363,148 US 12,368,745 US 12,368,746 US 12,368,747 US 12,375,363 US 12,375,573 US 12,381,901 US 12,395,573 US 12,401,669 US 12,405,849 US 12,407,701 US 12,407,702 US 12,418,552 US 12,418,555 US 12,425,428 US 12,425,430 US 12,444,181 US 12,445,474 US 12,452,272 US 12,452,279 US 12,457,231 US 12,463,994 US 12,463,995 US 12,463,996 US 12,463,997 US 12,464,003 US 12,470,577 US 12,470,578 US 12,483,576 US 12,489,770 US 12,489,771 US 12,495,052 US 12,500,910 US 12,500,911 US 12,500,912 US 12,505,126 US 12,506,762 US 12,511,110 US 12,513,221 US 12,526,297 US 12,537,836 US 12,537,837 US 12,537,839 US 12,537,840 US 12,537,884 US 12,549,575 US 12,549,577 US 12,556,548 US 12,556,559 US 12,563,060 US 12,563,064 US 12,563,071 US 12,563,072 US 12,580,932 US 12,580,934 US 12,580,935 US 12,580,936 US 12,580,937 US 12,587,553 US 12,592,950 US 12,598,205 US 12,613,930 US 12,615,271 US 12,621,324 US 12,621,329 US 12,627,686 US 12,627,687 US 12,627,690 US 12,634,312 US 12,634,376 US 12,652,302 US 12,659,325 US 12,659,326 US 12,659,327 US 12,659,333 US 12,676,874 US 12,689,638 US 12,689,640 US 12,695,768 US 12,706,931 US 12,706,932 US 12,706,933 US 12,706,980 US 12,712,897 US 12,719,896 US 12,726,495 US 12,730,899 US 12,739,266 US 12,739,267 US 12,744,799 US 12,744,800 US 12,744,802 US 12,750,382 US 12,750,383