IP Library › Granted Patent US 10,951,461
Granted Patent B2
US 10,951,461 · App. 16/264,480 · Granted Mar 16, 2021

Anomaly-driven packet capture and spectrum capture in an access point

Inventors: Sachin Ganu (Santa Clara, CA); Ahmad Kholaif (Santa Clara, CA); Karthik Srinivasa Murthy (Santa Clara, CA)
Assignee: Hewlett Packard Enterprise Development LP
H04L41/0631H04L41/069H04L43/0811H04W24/04H04W24/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,951,461
App. No.
16/264,480
Granted
Mar 16, 2021
Kind
B2
Abstract

An access point providing a client device with access to a communication network detects an anomaly in packet traffic being transmitted to or received from the client device. In response, the access point performs a packet capture by triggering the release of stored packets. The access point determines an anomaly type representing a root cause of the anomaly and annotates the packet capture with the anomaly type. The access point also detects radio frequency interference exceeding a prescribed threshold and, in response, performs a spectrum capture. The packet capture, annotated with the anomaly type, and the spectrum capture are reported either automatically or in response to a request.

Claims (42)

1. A method comprising:

detecting, by an access point providing a client device with access to a communication network, an anomaly in packet traffic, wherein the access point is configured to detect anomalies in packet traffic and anomalies in connectivity due to radio frequency interference;

upon detecting the anomaly in the packet traffic, triggering, by the access point, a packet capture process of packets being transmitted to or received from the client device, wherein triggering the packet capture process releases the packets stored in a buffer at the access point responsive to detecting the anomaly;

determining, by the access point, an anomaly type representing a root cause of the anomaly in the packets released from the buffer at the access point;

annotating, by the access point, the packets with the anomaly type;

detecting a radio frequency interference associated with the anomalies in connectivity, wherein the radio frequency interference exceeds a prescribed threshold; and

responsive to detecting that the radio frequency interference exceeds the prescribed threshold, performing a spectrum capture process in addition to the packet capture process.

2. The method of claim 1 , further comprising reporting at least one of the anomaly in packet traffic and the anomaly in connectivity automatically or upon request.

3. The method of claim 1 , further comprising identifying a corrective action.

4. The method of claim 3 , further comprising annotating the packets with an identifier of the corrective action.

5. The method of claim 4 , further comprising initiating the corrective action.

6. The method of claim 1 , further comprising determining whether to collect a debugging log based on the anomaly type.

7. The method of claim 1 , wherein the spectrum capture process uses a Fast Fourier Transform snapshot of an interfering signal.

8. The method of claim 1 , wherein the spectrum capture process continually stores snapshots in a ring buffer in a spectrum capture storage.

9. The method of claim 8 , wherein performing the spectrum capture process releases the snapshots stored in the ring buffer.

10. The method of claim 8 , further comprising: receiving reports from the packet capture process and the spectrum capture process in a continuous stream.

11. An access point providing a client device with access to a communication network, comprising:

a buffer to store packets;

a wireless radio transceiver to transmit or receive the packets to or from a client device;

an anomaly detector to:

detect an anomaly in packet traffic being transmitted to or received from the client device, wherein the access point is configured to detect anomalies in the packet traffic and anomalies in connectivity due to radio frequency interference; and

upon detecting the anomaly in the packet traffic, triggering a packet capture process of the packets being transmitted to or received from the client device responsive to detecting the anomaly, wherein triggering the packet capture process releases the packets stored in the buffer;

a radio frequency interference detector to:

detecting a radio frequency interference associated with the anomalies in connectivity, wherein the radio frequency interference exceeds a prescribed threshold; and

responsive to detecting that the radio frequency interference exceeds the prescribed threshold, performing a spectrum capture in addition to the packet capture process;

an anomaly type identifier to determine an anomaly type representing a root cause of the anomaly in the packets released from the buffer; and

an annotator to annotate the packets with the anomaly type.

12. The access point of claim 11 , further comprising a wired interface to report the packet capture annotated with the anomaly type.

13. The access point of claim 11 , further comprising a corrective action identifier to identify a corrective action for the anomaly based on the anomaly type.

14. The access point of claim 13 , wherein the annotator is to annotate the packets with an identity of the corrective action identified by the corrective action identifier.

15. The access point of claim 11 , wherein the buffer is a ring buffer, and wherein the anomaly detector triggers release of the packets from the ring buffer responsive to detecting the anomaly.

16. A non-transitory computer readable medium comprising computer executable instructions stored thereon that, when executed by a processor in an access point of a communication network, cause the processor to:

detect an anomaly in packets being transmitted to or received from a client device by the access point, wherein the access point is configured to detect anomalies in packet traffic and anomalies in connectivity due to radio frequency interference;

upon detecting the anomaly in the packet traffic, triggering a packet capture process of the packets being transmitted to or received from the client device by the access point, wherein triggering the packet capture process releases the packets stored in a buffer at the access point responsive to detecting the anomaly;

determine an anomaly type representing a root cause of the anomaly in the packets released from the buffer at the access point;

annotate the packets with the anomaly type;

report the packets annotated with the anomaly type;

detect a radio frequency interference associated with the anomalies in connectivity, wherein the radio frequency interference exceeds a prescribed threshold; and

responsive to detecting that the radio frequency interference exceeds the prescribed threshold, perform a spectrum capture in addition to the packet capture process.

17. The non-transitory computer readable medium of claim 16 , further comprising instructions stored thereon that, when executed by the processor, cause the processor to identify a corrective action based on the anomaly type.

18. The non-transitory computer readable medium of claim 17 , further comprising instructions stored thereon that, when executed by the processor, cause the processor to annotate the packets with an identity of the corrective action.

19. The non-transitory computer readable medium of claim 17 , further comprising instructions stored thereon that, when executed by the processor, cause the processor to initiate the corrective action.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2019
From: GANU, SACHIN; KHOLAIF, AHMAD; MURTHY, KARTHIK SRINIVASA
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 048226/0474 →
Continuity (1)
Related Publication 20200252265A1 · Aug 6, 2020
Cited By (4)
US 12,212,583 US 12,224,984 US 12,309,178 US 12,726,825