IP Library Granted Patent US 11,637,740
Granted Patent B2
US 11,637,740 · App. 17/175,061 · Granted Apr 25, 2023

Intelligent anomaly detection and root cause analysis in mobile networks

Inventors: Manu Sharma (Palo Alto, CA); Deepak Khurana (Palo Alto, CA); Sarabjot Singh (Palo Alto, CA); Adnan Raja (Palo Alto, CA); Srikanth Hariharan (Sunnyvale, CA); Aditya Gudipati (Los Angeles, CA); Manu Bansal (Palo Alto, CA); Duyen Riggs (Palo Alto, CA); Rakesh Misra (Palo Alto, CA)
Assignee: VMware, Inc.
H04L41/0631H04L41/16H04L43/0817H04W24/04H04W24/08H04W24/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,637,740
App. No.
17/175,061
Granted
Apr 25, 2023
Kind
B2
Abstract

A method for automated root cause analysis in mobile radio access networks, including: determining mobile radio access network data (e.g., RAN data); detecting an anomaly for a set of user sessions and/or cells from the RAN data; and classifying the detected anomalies using a set of root cause classifiers.

Claims (52)

1. A method comprising:

receiving radio access network data generated by a set of base stations;

determining a plurality of user sessions from the radio access network data;

detecting an anomalous user session from the plurality of user sessions;

detecting an anomalous cell associated with the anomalous user session based on the radio access network data;

determining a root cause of the anomalous user session;

determining additional anomalous user sessions associated with the root cause and additional cell identifiers associated with the additional anomalous user sessions; and

displaying an alert that comprises:

a severity score based on a percentage of user sessions impacted by the root cause;

a number of user sessions impacted by the root cause; and

an indication of the root cause.

2. The method of claim 1 , wherein the alert further comprises a number of cells impacted by the root cause.

3. The method of claim 1 , wherein the alert further comprises a start and end time for the root cause.

4. The method of claim 1 , wherein the severity score is further based on multiple performance factors that are selected and weighted by an administrator.

5. The method of claim 1 , further comprising displaying a second alert with a second severity score, wherein the alerts are ordered based on their respective severity scores.

6. The method of claim 1 , further comprising displaying a map with numbers corresponding to a number of alerts within an associated geographic area.

7. The method of claim 1 , further comprising, in response to selecting the displayed alert, displaying a map with a location indication corresponding to the alert.

8. A non-transitory, computer-readable medium comprising instructions that, when executed by a hardware-based processor, perform stages for anomaly detection, the stages comprising:

receiving radio access network data generated by a set of base stations;

determining a plurality of user sessions from the radio access network data;

detecting an anomalous user session from the plurality of user sessions;

detecting an anomalous cell associated with the anomalous user session based on the radio access network data;

determining a root cause of the anomalous user session;

determining additional anomalous user sessions associated with the root cause and additional cell identifiers associated with the additional anomalous user sessions; and

displaying an alert that comprises:

a severity score based on a percentage of user sessions impacted by the root cause;

a number of user sessions impacted by the root cause; and

an indication of the root cause.

9. The non-transitory, computer-readable medium of claim 8 , wherein the alert further comprises a number of cells impacted by the root cause.

10. The non-transitory, computer-readable medium of claim 8 , wherein the alert further comprises a start and end time for the root cause.

11. The non-transitory, computer-readable medium of claim 8 , wherein the severity score is further based on multiple performance factors that are selected and weighted by an administrator.

12. The non-transitory, computer-readable medium of claim 8 , further comprising displaying a second alert with a second severity score, wherein the alerts are ordered based on their respective severity scores.

13. The non-transitory, computer-readable medium of claim 8 , further comprising displaying a map with numbers corresponding to a number of alerts within an associated geographic area.

14. The non-transitory, computer-readable medium of claim 8 , further comprising, in response to selecting the displayed alert, displaying a map with a location indication corresponding to the alert.

15. A system for anomaly detection, the system comprising:

a hardware-based processor; and

a non-transitory, computer-readable medium comprising instructions that, when executed by the processor, perform stages comprising:

receiving radio access network data generated by a set of base stations;

determining a plurality of user sessions from the radio access network data;

detecting an anomalous user session from the plurality of user sessions;

detecting an anomalous cell associated with the anomalous user session based on the radio access network data;

determining a root cause of the anomalous user session;

determining additional anomalous user sessions associated with the root cause and additional cell identifiers associated with the additional anomalous user sessions; and

displaying an alert that comprises:

a severity score based on a percentage of user sessions impacted by the root cause;

a number of user sessions impacted by the root cause; and

an indication of the root cause.

16. The system of claim 15 , wherein the alert further comprises a number of cells impacted by the root cause.

17. The system of claim 15 , wherein the alert further comprises a start and end time for the root cause.

18. The system of claim 15 , wherein the severity score is further based on multiple performance factors that are selected and weighted by an administrator.

19. The system of claim 15 , further comprising displaying a second alert with a second severity score, wherein the alerts are ordered based on their respective severity scores.

20. The system of claim 15 , further comprising displaying a map with numbers corresponding to a number of alerts within an associated geographic area.

Assignments (1)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
Continuity (4)
Continuation 16563830 · Sep 7, 2019
Provisional Application 62834773 · Apr 16, 2019
Provisional Application 62728345 · Sep 7, 2018
Related Publication 20210176116A1 · Jun 10, 2021
Cited By (2)
US 12,450,519 US 12,530,616