IP Library › Granted Patent US 10,944,636
Granted Patent B2
US 10,944,636 · App. 15/278,275 · Granted Mar 9, 2021

Dynamically identifying criticality of services and data sources

Inventors: Thiago J. Macieira (Portland, OR); Ned M. Smith (Beaverton, OR); Zheng Zhang (Portland, OR); John Teddy (Butte, MT); Arthur S. Zeigler (Santa Clara, CA)
Assignee: McAfee, LLC
H04L41/12H04L41/065H04L41/0853H04L41/5009H04L43/08H04L67/16H04L41/0659
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,944,636
App. No.
15/278,275
Filed
Sep 28, 2016
Granted
Mar 9, 2021
Kind
B2
Art Unit
2465
USPC
370/255
Abstract

A method, a computer-readable medium, and a device for dynamically identifying criticality of services and data sources. Service-related metrics are received from all IoT network elements in a network. The service-related metrics are parsed to extrapolate a network topology. From the topology, a set of critical service delivery points are determined based on data extracted from the service-related metrics. The critical service delivery points may be monitored for service interruptions and alerts may be generated in response to interruptions. Additionally the extrapolated network topology may be compared to a previously recorded topology of the network, and based on the delta, alerts may be generated when the delta meets a threshold.

Claims (62)

1. At least one computer readable storage device or storage disk comprising instructions which, when executed, cause a programmable device to at least:

determine, based on a plurality of service-related metrics from a network node, upstream network nodes and downstream network nodes in a network;

query the upstream network nodes and the downstream network nodes with a multicast request for an additional plurality of service-related metrics;

extrapolate a current network topology based on the plurality of service-related metrics from the network node and the additional plurality of service-related metrics from the upstream network nodes and the downstream network nodes;

determine whether or not an upstream backup server is present for the network node;

determine a set of critical service delivery points in the network based on (A) the network topology, (B) the plurality of service-related metrics, (C) the additional plurality of service-related metrics, and (D) the determination of the upstream backup server, wherein the plurality of service-related metrics includes a first count of packets in data, a second count of errors in the data, and a third count of a volume of the data;

monitor the set of critical service delivery points for a service interruption;

generate a first network service alert responsive to the service interruption;

compare the current network topology to a previous network topology to identify first network elements that have been added to the network and second network elements have been removed from the network between a time corresponding to the previous network topology and a time corresponding to the extrapolation of the current network topology;

translate the addition of the first network elements and the removal of the second network elements into a delta value based on the current network topology and the previous network topology; and

generate a second network service alert responsive to the delta value satisfying a threshold.

2. The at least one computer readable storage device or storage disk of claim 1 , wherein the instructions which, when executed, cause the programmable device to translate the addition of the first network elements and the removal of the second network elements into the delta value by applying a machine learning algorithm to the current network topology and the previous network topology.

3. The at least one computer readable storage device or storage disk of claim 2 , wherein the machine learning algorithm includes a hidden Markov model.

4. The at least one computer readable storage device or storage disk of claim 1 , wherein the instructions which, when executed, cause the programmable device to extrapolate the current network topology by extracting network topology information from the service-related metrics and the additional plurality of service-related metrics utilizing base stack layer application programming interfaces.

5. The at least one computer readable storage device or storage disk of claim 1 , wherein the previous network topology includes a seeded network topology.

6. The at least one computer readable storage device or storage disk of claim 1 , wherein the instructions which, when executed, cause the programmable device to extrapolate by:

parsing the plurality of service-related metrics and the additional plurality of service-related metrics;

extracting a plurality of network element identifiers from the parsed plurality of service-related metrics and the additional plurality of service-related metrics; and

determining a relationship between each of the extracted plurality of network element identifiers.

7. A method comprising:

determining, based on a plurality of service-related metrics from a network node and by executing an instruction with a processor, upstream network nodes and downstream network nodes in a network;

querying, by executing an instruction with the processor, the upstream network nodes and the downstream network nodes for an additional plurality of service-related metrics;

accessing, by executing an instruction with the processor, the additional plurality of service-related metrics from the upstream network nodes and the downstream network nodes; and

extrapolating, by executing an instruction with the processor, a current network topology based on the plurality of service-related metrics and the additional plurality of service-related metrics;

determining, by executing an instruction with the processor, whether or not an upstream backup server is present for the network node;

determining, by executing an instruction with the processor, a set of critical service delivery points in the network, based on the network topology, the plurality of service-related metrics, the additional plurality of service-related metrics, and the determination of the upstream backup server, wherein the plurality of service-related metrics includes a first count of packets in data, a second count of errors in the data, and a third count of a volume of the data;

monitoring, by executing an instruction with the processor, the set of critical service delivery points for a service interruption;

generating, by executing an instruction with the processor, a first alert responsive to the service interruption;

comparing, by executing an instruction with the processor, the current network topology to a previous network topology to identify first network elements that have been added to the network and second network elements have been removed from the network between a time corresponding to the previous network topology and a time corresponding to the extrapolation of the current network topology;

translating, by executing an instruction with the processor, the addition of the first network elements and the removal of the second network elements into a delta value; and

generating, by executing an instruction with the processor, a second alert responsive to the delta value satisfying a threshold.

8. The method of claim 7 , wherein the determining of the set of critical service delivery points includes examining the data passing through the upstream network nodes and the downstream network nodes.

9. The method of claim 7 , wherein the extrapolating of the current network topology includes extracting network topology information from the service-related metrics and the additional plurality of service-related metrics utilizing base layer application programming interfaces.

10. The method of claim 7 , wherein the extrapolating of the current network topology includes:

parsing the plurality of service-related metrics and the additional plurality of service-related metrics;

extracting a plurality of network element identifiers from the parsed plurality of service-related metrics and the additional plurality of service-related metrics; and

determining relationships between the plurality of network element identifiers.

11. The method of claim 7 , wherein the determining of the set of critical service delivery points includes detecting upstream network node isolation and downstream network node isolation.

12. A device for monitoring a network topology, the device comprising:

one or more processors;

a network adapter, communicatively coupled to the one or more processors; and

memory coupled to the one or more processors, the memory including instructions, the instructions, when executed, to cause the one or more processors to at least:

determine, based on a plurality of service-related metrics from a network node, upstream network nodes and downstream network nodes in a network;

query the upstream network nodes and the downstream network nodes for an additional plurality of service-related metrics;

extrapolate a current network topology based on the plurality of service-related metrics from the network node and the additional plurality of service-related metrics from the upstream network nodes and the downstream network nodes;

determine whether or not an upstream backup server is present for the network node;

determine a set of critical service delivery points in the network based on (A) the network topology, (B) the plurality of service-related metrics, (C) the additional plurality of service-related metrics, and (D) the determination of the upstream backup server, wherein the plurality of service-related metrics includes a first count of packets in data, a second count of errors in the data, and a third count of a volume of the data;

monitor the set of critical service delivery points for a service interruption;

compare the current network topology to a previous network topology to identify first network elements that have been added to the network and second network elements have been removed from the network between a time corresponding to the previous network topology and a time corresponding to the extrapolation of the current network topology;

translate the addition of the first network elements and the removal of the second network elements into a delta value representing an amount of change between the current network topology and the previous network topology; and

generate at least one of a first alert responsive to the service interruption or a second service alert responsive to a comparison of the delta value to a threshold.

13. The device of claim 12 , wherein the one or more processors are to determine the delta value by applying a machine learning algorithm to the current network topology and the previous network topology.

14. The device of claim 13 , wherein the machine learning algorithm includes a hidden Markov model.

15. The device of claim 12 , wherein the one or more processors are to extrapolate the current network topology by extracting network topology information from the service-related metrics and the additional plurality of service-related metrics utilizing base layer APIs.

16. The device of claim 12 , wherein the previous network topology includes a seeded network topology.

17. The device of claim 12 , wherein the one or more processors are to extrapolate the current network topology by:

parsing the plurality of service-related metrics and the additional plurality of service-related metrics;

extracting a plurality of network element identifiers from the parsed plurality of service-related metrics and the additional plurality of service-related metrics; and

determining a relationship between the plurality of network element identifiers.

18. The at least one computer readable storage device or storage disk of claim 1 , wherein a service delivery point is less critical if there is a built in backup in the upstream backup server.

19. The method of claim 7 , wherein a service delivery point is less critical if there is a built in backup in the upstream backup server.

20. The device of claim 12 , wherein a service delivery point is less critical if there is a built in backup in the upstream backup server.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Sep 15, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043969/0057 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2016
From: MACIEIRA, THIAGO; SMITH, NED; ZHANG, ZHENG; TEDDY, JOHN; ZEIGLER, ARTHUR S.
To: MCAFEE, INC.
Reel/Frame 039877/0665 →
Continuity (1)
Related Publication 20180091374A1 · Mar 29, 2018
Cited By (1)
US 12,450,126