IP Library Granted Patent US 11,049,033
Granted Patent B2
US 11,049,033 · App. 15/869,639 · Granted Jun 29, 2021

Deriving highly interpretable cognitive patterns for network assurance

Inventors: Vinay Kumar Kolar (San Jose, CA); Vikram Kumaran (Cary, NC); Abhishek Kumar (Vancouver, CA); Santosh Ghanshyam Pandey (Fremont, CA); Jean-Philippe Vasseur (Saint Martin d'uriage, FR); Grégory Mermoud (Veyras, CH)
Assignee: Cisco Technology, Inc.
G06N7/005G06N20/00H04L41/0659H04L41/142H04L41/5067H04L41/16H04L43/0823H04L43/0888H04L43/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,049,033
App. No.
15/869,639
Granted
Jun 29, 2021
Kind
B2
Abstract

In one embodiment, a network assurance system that monitors a network labels time periods with positive labels, based on the network assurance system detecting problems in the network during the time periods. The network assurance system assigns tags to discrete portions of a feature space of measurements from the monitored network, based on whether a particular range of values in the feature space has a threshold probability of occurring during a positively-labeled time period. The network assurance system determines a set of the assigned tags that frequently co-occur with the positively-labeled time periods in which problems are detected in the network. The network assurance system causes performance of a mitigation action in the network based on the set of assigned tags that frequently co-occur with the positively-labeled time periods.

Claims (37)

1. A method comprising:

labeling, by a network assurance system that monitors a network, time periods with positive labels, each positively-labeled time period being indicative of the network assurance system having detected a problem in the network during the corresponding time period;

assigning, by the network assurance system, categorical tags to discrete portions of a feature space comprising an aggregation of network measurements from the monitored network, based on whether a particular range of values in the feature space has a threshold probability of occurring during any of the positively-labeled time periods in which problems are detected in the network by applying a machine learning, decision tree-based classifier to the feature space to determine an association between the particular range of values in the feature space and the detected problems;

determining, by the network assurance system, a set of the assigned categorical tags that frequently co-occur with the positively-labeled time periods in which problems are detected in the network based on one or more predictive strength metrics indicative of a strength of an association between any of the assigned categorical tags and any of the positively-labeled time periods; and

causing, by the network assurance system, performance of a mitigation action in the network based on the set of assigned categorical tags that frequently co-occur with the positively-labeled time periods.

2. The method as in claim 1 , wherein the measurements obtained from the monitored network comprise one or more of: wireless interference, dropped packets, traffic volume, throughput, or an endpoint client count in the network.

3. The method as in claim 1 , wherein the mitigation action comprises providing an indication of the assigned tags that frequently co-occur with the positively-labeled time periods as one or more natural language sentences.

4. The method as in claim 1 , wherein labeling the time periods with positive labels, based on the network assurance system detecting problems in the network during the time periods comprises:

applying a machine learning-based anomaly detection model to one or more of the measurements from the monitored network; and

labeling a given time period with a positive label, when the anomaly detection model determines that the one or more measurements from the monitored network are anomalous.

5. The method as in claim 1 , further comprising:

receiving, at the network assurance system, a definition of a problem condition from a user interface.

6. An apparatus, comprising:

one or more network interfaces to communicate with a network that comprises a plurality of sensors and actuators;

a processor coupled to the network interfaces and configured to execute one or more processes; and

a memory configured to store a process executable by the processor, the process when executed configured to:

label time periods with positive labels, each positively-labeled time period being indicative of the apparatus having detected a problem in the network during the corresponding time period;

assign categorical tags to discrete portions of a feature space comprising an aggregation of network measurements from the network, based on whether a particular range of values in the feature space has a threshold probability of occurring during any of the positively-labeled time periods in which problems are detected in the network by applying a machine learning, decision tree-based classifier to the feature space to determine an association between the particular range of values in the feature space and the detected problems;

determine a set of the assigned categorical tags that frequently co-occur with the positively-labeled time periods in which problems are detected in the network based on one or more predictive strength metrics indicative of a strength of an association between any of the assigned categorical tags and any of the positively-labeled time periods; and

cause performance of a mitigation action in the network based on the set of assigned categorical tags that frequently co-occur with the positively-labeled time periods.

7. The apparatus as in claim 6 , wherein the measurements obtained from the network comprise one or more of: wireless interference, dropped packets, traffic volume, throughput, or an endpoint client count in the network.

8. The apparatus as in claim 6 , wherein the mitigation action comprises providing an indication of the assigned tags that frequently co-occur with the positively-labeled time periods as one or more natural language sentences.

9. The apparatus as in claim 6 , wherein labeling the time periods with positive labels, based on the apparatus detecting problems in the network during the time periods comprises:

applying a machine learning-based anomaly detection model to one or more of the measurements from the network; and

labeling a given time period with a positive label, when the anomaly detection model determines that the one or more measurements from the network are anomalous.

10. The apparatus as in claim 6 , wherein the process when executed is further configured to:

receive a definition of a problem condition from a user interface.

11. A tangible, non-transitory, computer-readable medium storing program instructions that cause a network assurance system that monitors a network to execute a process comprising:

labeling, by the network assurance system, time periods with positive labels, each positively-labeled time period being indicative of the network assurance system having detected a problem in the network during the corresponding time period;

assigning, by the network assurance system, categorical tags to discrete portions of a feature space comprising an aggregation of network measurements from the monitored network, based on whether a particular range of values in the feature space has a threshold probability of occurring during any of the positively-labeled time periods in which problems are detected in the network by applying a machine learning, decision tree-based classifier to the feature space to determine an association between the particular range of values in the feature space and the detected problems;

determining, by the network assurance system, a set of the assigned categorical tags that frequently co-occur with the positively-labeled time periods in which problems are detected in the network based on one or more predictive strength metrics indicative of a strength of an association between any of the assigned categorical tags and any of the positively-labeled time periods; and

causing, by the network assurance system, performance of a mitigation action in the network based on the set of assigned categorical tags that frequently co-occur with the positively-labeled time periods.

12. The computer-readable medium as in claim 11 , wherein the measurements obtained from the monitored network comprise one or more of: wireless interference, dropped packets, traffic volume, throughput, or an endpoint client count in the network.

13. The computer-readable medium as in claim 11 , wherein the mitigation action comprises providing an indication of the assigned tags that frequently co-occur with the positively-labeled time periods as one or more natural language sentences.

14. The computer-readable medium as in claim 11 , wherein labeling the time periods with positive labels, based on the network assurance system detecting problems in the network during the time periods comprises:

applying a machine learning-based anomaly detection model to one or more of the measurements from the monitored network; and

labeling a given time period with a positive label, when the anomaly detection model determines that the one or more measurements from the monitored network are anomalous.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2020
From: PANDEY, SANTOSH GHANSHYAM
To: CISCO TECHNOLOGY, INC.
Reel/Frame 052798/0462 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2018
From: KOLAR, VINAY KUMAR; KUMARAN, VIKRAM; KUMAR, ABHISHEK; PANDEY, SANTOSH GHANSHYAM; VASSEUR, JEAN-PHILIPPE; MERMOUD, GRÉGORY
To: CISCO TECHNOLOGY, INC.
Reel/Frame 044608/0671 →
Continuity (1)
Related Publication 20190220760A1 · Jul 18, 2019