IP Library Granted Patent US 11,108,621
Granted Patent B1
US 11,108,621 · App. 15/929,956 · Granted Aug 31, 2021

Network performance metrics anomaly detection

Inventors: Abdolreza Shirvani (Ottawa, CA); Elizabeth Keddy (Ottawa, CA); Glenda Ann Leonard (Carp, CA); Christopher Daniel Fridgen (Kanata, CA)
Assignee: Accedian Networks Inc.
H04L41/064G06K9/6215H04L41/065H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,108,621
App. No.
15/929,956
Filed
May 29, 2020
Granted
Aug 31, 2021
Kind
B1
Examiner
LING, CHHIAN
Art Unit
2418
USPC
709/224
Abstract

A method for detecting anomalies in one or more network performance metrics stream for one or more monitored object comprising using a discrete window on the stream to extract a motif from said stream for a first of said network performance metric for a first of said monitored object. Maintaining an abnormal and a normal cluster center of historical time series for said first network performance metric for said first monitored object. Classifying said motif based on a distance between said new time series and said abnormal and said normal cluster center. Determining whether an anomaly for said motif occurred based on said distance and a predetermined decision boundary.

Claims (19)

1. A method for detecting anomalies in one or more network performance metrics stream for one or more monitored object comprising:

using, by a processor, a discrete window on the stream to extract a new motif from said stream for a first of said network performance metric for a first of said monitored object;

maintaining, by the processor, a historic abnormal cluster center based on a first cluster, and a historic normal cluster center based on a second cluster with most members, from a binary clustering of historical time series for said first network performance metric for said first monitored object;

classifying, by the processor, said new motif based on a distance between a new normal cluster center and a new abnormal cluster center of said new motif and said historic abnormal cluster center and said historic normal cluster center; and

determining, by the processor, whether an anomaly for said new motif occurred based on said distance and a predetermined decision boundary.

2. The method of claim 1 wherein said distance is computed, by the processor, using a euclidean distance algorithm.

3. The method of claim 1 wherein a cluster member furthest from the normal cluster center or the abnormal cluster center is used as said decision boundary.

4. The method of claim 1 further comprising sending, by the processor, an anomaly notification to a user that the anomaly has occurred.

5. An anomaly detection system for detecting anomalies comprising:

a measurement system configured to collect a plurality of performance data on a monitored object in a network, and transmitting said performance data as a new time series;

a processor; and

a non-volatile memory storing instructions that, when executed by the processor, configure the anomaly detection system to:

maintain a table including a historic abnormal cluster center based on a first cluster, and a historic normal cluster center based on a second cluster with most members from a binary clustering of historical time series for said performance metric for said monitored object;

extract a motif using a discrete window on the new time series;

classify said motif based on a distance between a new normal cluster center and a new abnormal cluster center of said motif and said historic abnormal cluster center and said historic normal cluster center; and

determine whether an anomaly for said performance metric for said monitored object occurred based on said distance and a predetermined decision boundary.

6. The system of claim 5 wherein said distance is computed using a euclidean distance algorithm.

7. The system of claim 5 wherein a furthest cluster member is used as said decision boundary.

8. The system of claim 5 , wherein the instructions that, when executed by the processor, further configure the anomaly detection system to: send a notification to a user that said anomaly has occurred.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Oct 10, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY
To: LES RESEAUX ACCEDIAN INC. / ACCEDIAN NETWORKS INC.
Reel/Frame 065192/0909 →
RELEASE OF SECURITY INTEREST FILED AUGUST 13, 2021 AT REEL/FRAME 057184/0296 Recorded Oct 6, 2023
From: BGC LENDER REP LLC
To: LES RESEAUX ACCEDIAN INC. / ACCEDIAN NETWORKS INC.
Reel/Frame 065178/0452 →
SECURITY INTEREST Recorded Aug 16, 2021
From: LES RESEAUX ACCEDIAN INC. / ACCEDIAN NETWORKS INC.
To: SILICON VALLEY BANK
Reel/Frame 057192/0787 →
SECURITY AGREEMENT Recorded Aug 13, 2021
From: LES RESEAUX ACCEDIAN INC. / ACCEDIAN NETWORKS INC.
To: BGC LENDER REP LLC
Reel/Frame 057184/0296 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2020
From: SHIRVANI, ABDOLREZA; KEDDY, ELIZABETH; LEONARD, GLENDA; FRIDGEN, CHRISTOPHER DANIEL
To: ACCEDIAN NETWORKS INC.
Reel/Frame 052863/0458 →
Cited By (2)
US 12,664,036 US 12,688,282