IP Library › Granted Patent US 11,595,282
Granted Patent B2
US 11,595,282 · App. 17/381,909 · Granted Feb 28, 2023

Network anomaly detection

Inventors: Mikhal Shemer (Tel Aviv, IL); Roee Engelberg (Tel Aviv, IL); Yonit Tova Halperin Worzel (Tel Aviv, IL); Alex Gontmakher (Holon, IL); Alexander Goldshtein (Tel Aviv, IL); Gal Elidan (Modiin, IL); Benjamin Dov Kessler (Jerusalem, IL)
Assignee: Google LLC
H04L43/0817G06F9/45558G06K9/6256H04L41/0627H04L41/0631H04L43/065G06F2009/45575G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,595,282
App. No.
17/381,909
Granted
Feb 28, 2023
Kind
B2
Abstract

A cloud network is a complex environment in which hundreds and thousands of users or entities can each host, create, modify, and develop multiple virtual machines. Each virtual machine can have complex behavior unknown to the provider or maintainer of the cloud. Technologies disclosed include methods, systems, and apparatuses to monitor the complex environment to detect network anomalies using machine learning techniques. In addition, techniques to modify and adapt to user feedback are provided allowing the developed models to be tuned for specific use cases, virtual machine types, and users.

Claims (32)

1. A method of detecting states of a network, the method comprising:

selecting at least a first model for detecting a current state of the network based on a given virtual machine;

obtaining data related to network parameters based on at least the first model;

evaluating a current state of the network, based on the obtained data, by using at least the first model; and

providing to a user device, an actionable notification, upon determining that the evaluated current state of the network meets a predetermined state differing from a normal state of the network;

wherein the actionable notification indicates the current state of the network; and

wherein the first model is a trained machine learning model, the first model having been trained on prior network data to enable the first model to evaluate at least a normal state of the network, the prior network data including a dataset of underlying software being used on theft given virtual machine.

2. The method of claim 1 further comprising selecting multiple models for detecting the current state of the network based on the given virtual machine.

3. The method of claim 1 wherein selecting at least the first model for detecting the current state of the network is further based on a machine learning model configured to match at least the first model to the given virtual machine.

4. The method of claim 1 wherein evaluating the current state of the network comprises at least one of determining a presence of an event impacting the given virtual machine that is indicative of the current state of the network differing from the normal state of the network.

5. The method of claim 1 wherein the predetermined state is an anomalous state or a user defined state.

6. The method of claim 1 further comprising automatically taking an action upon determining the current state of the network meets a particular predetermined state.

7. The method of claim 1 wherein the prior network data comprises prior data related to the network parameters.

8. The method of claim 1 wherein the first model is re-trained upon a change in the given virtual machine.

9. The method of claim 1 wherein obtaining network parameters comprises obtaining network parameters in real-time.

10. The method of claim 1 wherein the actionable notification causes an action to be performed on the network.

11. The method of claim 10 wherein the action comprises at least one of: restarting the network, changing security protocols, changing firewall rules, or stopping or slowing egress or ingress of traffic.

12. The method of claim 1 wherein the training of the first model comprises generating weights for network parameters of the prior network data.

13. The method of claim 1 wherein a cause for the current state of the network differing from the normal state of the network can be determined using the evaluated current state of the network and the obtained data related to the network parameters.

14. The method of claim 1 wherein the evaluation of the current state of the network distinguishes between an anomalous condition for the network and a malfunction within the given virtual machine.

15. The method of claim 1 wherein feedback to the actionable notification is used to adjust a threshold used in evaluating the current state of the network or to retrain the first model.

16. A non-transient computer readable medium containing program instructions that, when executed, perform steps for detecting states of a network, the steps comprising:

selecting at least a first model for detecting a current state of the network based on a given virtual machine;

obtaining data related to network parameters based on at least the first model;

evaluating the current state of the network, based on the obtained data, by using at least the first model; and

providing to a user device, an actionable notification, upon determining that the evaluated current state of the network meets a predetermined state differing from a normal state of the network;

wherein the actionable notification indicates the current state of the network; and

wherein the first model is trained using machine learning, the first model having been trained on prior network data to enable the first model to evaluate at least a normal state of the network, the prior network data including a dataset of underlying software being used on the given virtual machine.

17. The non-transient computer readable medium of claim 16 wherein the steps further comprise selecting multiple models for detecting the current state of the network based on the given virtual machine.

18. The non-transient computer readable medium of claim 16 wherein selecting at least the first model for detecting the current state of the network is further based on a machine learning model configured to match at least the first model to the given virtual machine.

19. The non-transient computer readable medium of claim 16 wherein the training of the first model comprises generating weights for network parameters of the prior network data.

20. The non-transient computer readable medium of claim 16 wherein the predetermined state is an anomalous state.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE 4TH INVENTOR'S EXECUTION DATE PREVIOUSLY RECORDED AT REEL: 57029 FRAME: 617. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 30, 2021
From: SHEMER, MIKHAL; ENGELBERG, ROEE; WORZEL, YONIT TOVA HALPERIN; GONTMAKHER, ALEX; GOLDSHTEIN, ALEXANDER; ELIDAN, GAL; KESSLER, BENJAMIN DOV
To: GOOGLE LLC
Reel/Frame 057678/0392 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2021
From: SHEMER, MIKHAL; ENGELBERG, ROEE; WORZEL, YONIT TOVA HALPERIN; GONTMAKHER, ALEX; GOLDSHTEIN, ALEXANDER; ELIDAN, GAL; KESSLER, BENJAMIN DOV
To: GOOGLE LLC
Reel/Frame 057029/0617 →
Continuity (2)
Provisional Application 63054493 · Jul 21, 2020
Related Publication 20220029902A1 · Jan 27, 2022
Cited By (1)
US 12,316,518