IP Library Granted Patent US 11,483,213
Granted Patent B2
US 11,483,213 · App. 16/924,489 · Granted Oct 25, 2022

Enterprise process discovery through network traffic patterns

Inventors: Gal Engelberg (Pardes-hana, IL); Eitan Hadar (Nesher, IL); Avraham Dayan (Bnei Brak, IL); Moshe Hadad (Rosh HaAyim, IL)
Assignee: Accenture Global Solutions Limited
H04L41/16G06K9/6219G06K9/6256G06N20/00H04L67/14H04L67/535
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,483,213
App. No.
16/924,489
Granted
Oct 25, 2022
Kind
B2
Abstract

Implementations of the present disclosure include executing, within a computer network, multiple instances of a process, each instance including a simulation of execution of the process within the computer network, receiving session datasets representative of sessions performed during execution of each instance of the process, generating a set of session traces, each session trace representing a sequence of sessions performed during an instance of the process within the computer network, processing the set of session traces using a clustering algorithm to cluster sessions of each session trace into two or more clusters, each cluster having an associated label, and providing a process model that generically represents multiple executions of the process within the computer network, the process model comprising a sequence of labels of the two or more clusters corresponding to session traces in the set of session traces.

Claims (40)

1. A computer-implemented method for process discovery in a computer network based on session traffic, the method being executed by one or more processors and comprising:

executing, within a computer network, multiple instances of a process, each instance comprising a simulation of execution of the process within the computer network;

receiving session datasets representative of sessions performed during execution of each instance of the process;

generating a set of session traces, each session trace representing a sequence of sessions performed during an instance of the process within the computer network;

processing the set of session traces using a clustering algorithm to cluster sessions of each session trace into two or more clusters, each cluster having an associated label;

providing a process model that generically represents multiple executions of the process within the computer network, the process model comprising a sequence of labels of the two or more clusters corresponding to session traces in the set of session traces;

comparing network traffic of actual execution of processes within the computer network to a set of process models, the set of process models comprising the process model; and

identifying the process as having been actually executed in the computer network based on the comparing.

2. The method of claim 1 , wherein the clustering algorithm comprises a hierarchical clustering algorithm.

3. The method of claim 1 , further comprising generating a set of activity traces based on the set of session traces and labels of the two or more clusters.

4. The method of claim 1 , wherein the process model is provided based on a process discovery technique that is executed on the set of activity traces.

5. The method of claim 1 , further comprising training a machine-learning (ML) model at least partially based on the process model.

6. The method of claim 1 , wherein the computer network assets comprise information technology (IT) components and operational technology (OT) components, each session being associated with communication between multiple IT components.

7. A non-transitory computer-readable storage medium coupled to one or more processors and having instructions stored thereon which, when executed by the one or more processors, cause the one or more processors to perform operations for process discovery in a computer network based on session traffic, the operations comprising:

executing, within a computer network, multiple instances of a process, each instance comprising a simulation of execution of the process within the computer network;

receiving session datasets representative of sessions performed during execution of each instance of the process;

generating a set of session traces, each session trace representing a sequence of sessions performed during an instance of the process within the computer network;

processing the set of session traces using a clustering algorithm to cluster sessions of each session trace into two or more clusters, each cluster having an associated label;

providing a process model that generically represents multiple executions of the process within the computer network, the process model comprising a sequence of labels of the two or more clusters corresponding to session traces in the set of session traces;

comparing network traffic of actual execution of processes within the computer network to a set of process models, the set of process models comprising the process model; and

identifying the process as having been actually executed in the computer network based on the comparing.

8. The computer-readable storage medium of claim 7 , wherein the clustering algorithm comprises a hierarchical clustering algorithm.

9. The computer-readable storage medium of claim 7 , wherein operations further comprise generating a set of activity traces based on the set of session traces and labels of the two or more clusters.

10. The computer-readable storage medium of claim 7 , wherein the process model is provided based on a process discovery technique that is executed on the set of activity traces.

11. The computer-readable storage medium of claim 7 , wherein operations further comprise training a machine-learning (ML) model at least partially based on the process model.

12. The computer-readable storage medium of claim 7 , wherein the computer network assets comprise information technology (IT) components and operational technology (OT) components, each session being associated with communication between multiple IT components.

13. A system, comprising:

one or more computers; and

a computer-readable storage device coupled to the computing device and having instructions stored thereon which, when executed by the computing device, cause the computing device to perform operations for process discovery in a computer network based on session traffic, the operations comprising:

executing, within a computer network, multiple instances of a process, each instance comprising a simulation of execution of the process within the computer network;

receiving session datasets representative of sessions performed during execution of each instance of the process;

generating a set of session traces, each session trace representing a sequence of sessions performed during an instance of the process within the computer network;

processing the set of session traces using a clustering algorithm to cluster sessions of each session trace into two or more clusters, each cluster having an associated label;

providing a process model that generically represents multiple executions of the process within the computer network, the process model comprising a sequence of labels of the two or more clusters corresponding to session traces in the set of session traces;

comparing network traffic of actual execution of processes within the computer network to a set of process models, the set of process models comprising the process model; and

identifying the process as having been actually executed in the computer network based on the comparing.

14. The system of claim 13 , wherein the clustering algorithm comprises a hierarchical clustering algorithm.

15. The system of claim 13 , wherein operations further comprise generating a set of activity traces based on the set of session traces and labels of the two or more clusters.

16. The system of claim 13 , wherein the process model is provided based on a process discovery technique that is executed on the set of activity traces.

17. The system of claim 13 , wherein operations further comprise training a machine-learning (ML) model at least partially based on the process model.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2020
From: ENGELBERG, GAL; HADAR, EITAN; DAYAN, AVRAHAM; HADAD, MOSHE
To: ACCENTURE GLOBAL SOLUTIONS LIMITED
Reel/Frame 053164/0811 →
Continuity (1)
Related Publication 20220014445A1 · Jan 13, 2022
Cited By (8)
US 12,231,461 US 12,284,200 US 12,289,336 US 12,335,296 US 12,348,552 US 12,355,798 US 12,470,591 US 12,476,994