IP Library › Granted Patent US 11,792,217
Granted Patent B2
US 11,792,217 · App. 17/694,222 · Granted Oct 17, 2023

Systems and methods to detect abnormal behavior in networks

Inventors: David Côté (Gatineau, CA); Merlin Davies (Montréal, CA); Olivier Simard (Montréal, CA); Emil Janulewicz (Ottawa, CA); Thomas Triplet (Manotick, CA)
Assignee: Ciena Corporation
H04L63/1425G06F15/76G06F17/18G06F18/2411G06F18/2413G06N3/08G06N5/01G06N20/00G06N20/10G06N20/20H04L41/0677H04L41/145H04L43/045H04L63/1441G06N3/02G06N5/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,792,217
App. No.
17/694,222
Filed
Mar 14, 2022
Granted
Oct 17, 2023
Kind
B2
Art Unit
2431
USPC
726/22
Abstract

Systems and methods include receiving a machine learning model that is configured to detect anomalies in network devices operating in a multi-layer network, wherein the machine learning model is trained via unsupervised learning that includes training the machine learning model with unlabeled data that describes an operational status of the network devices over time; receiving live data related to a current operational status of the network devices; analyzing the live data with the machine learning model; and detecting an anomaly related to any of the network device based on the analyzing.

Claims (37)

1. A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform the steps of:

receiving a machine learning model that is configured to detect anomalies in network devices operating in a multi-layer network, wherein the machine learning model is trained via unsupervised learning that includes training the machine learning model with unlabeled data that describes an operational status of the network devices over time, wherein the training builds a set of Probability Density Functions (PDFs), a likelihood function for each PDF, and a global likelihood function based on a product of each individual likelihood function, wherein the global likelihood function is a single multivariate function to describe a network component;

receiving live data related to a current operational status of the network devices;

analyzing the live data with the machine learning model; and

detecting an anomaly related to any of the network device based on the analyzing.

2. The non-transitory computer-readable medium of claim 1 , wherein the unlabeled data does not include an indication of whether a particular network device is operating normally.

3. The non-transitory computer-readable medium of claim 2 , wherein the unlabeled data further includes a training dataset representative of a normal function in the network such that the machine learning model detects departures from expectations.

4. The non-transitory computer-readable medium of claim 1 , wherein the steps further include

causing an action based on the anomaly.

5. The non-transitory computer-readable medium of claim 4 , wherein the action is one or more of a notification to a network operator, a replacement of a network device associated with the anomaly, and configuration changes of the network device associated with the anomaly.

6. The non-transitory computer-readable medium of claim 1 , wherein the multi-layer network includes any of optical, Time Division Multiplexing (TDM), and packet.

7. The non-transitory computer-readable medium of claim 1 , wherein the detecting the anomaly provides a single probability output of the anomaly based on the live data, the single probability output provides an indication of a departure from a normally functioning network.

8. The non-transitory computer-readable medium of claim 7 , wherein the single probability output is a p-value from multiple different Performance Monitoring (PM) types, wherein the global likelihood function is used to calculate the p-value and the anomaly is detected based on the p-value.

9. A method comprising steps of:

receiving a machine learning model that is configured to detect anomalies in network devices operating in a multi-layer network, wherein the machine learning model is trained via unsupervised learning that includes training the machine learning model with unlabeled data that describes an operational status of the network devices over time, wherein the training builds a set of Probability Density Functions (PDFs), a likelihood function for each PDF, and a global likelihood function based on a product of each individual likelihood function, wherein the global likelihood function is a single multivariate function to describe a network component;

receiving live data related to a current operational status of the network devices;

analyzing the live data with the machine learning model; and

detecting an anomaly related to any of the network device based on the analyzing.

10. The method of claim 9 , wherein the unlabeled data does not include an indication of whether a particular network device is operating normally.

11. The method of claim 10 , wherein the unlabeled data further includes a training dataset representative of a normal function in the network such that the machine learning model detects departures from expectations.

12. The method of claim 9 , wherein the steps further include

causing an action based on the anomaly.

13. The method of claim 12 , wherein the action is one or more of a notification to a network operator, a replacement of a network device associated with the anomaly, and configuration changes of the network device associated with the anomaly.

14. The method of claim 9 , wherein the detecting the anomaly provides a single probability output of the anomaly based on the live data, the single probability output provides an indication of a departure from a normally functioning network.

15. The method of claim 14 , wherein the single probability output is a p-value from multiple different Performance Monitoring (PM) types, wherein the global likelihood function is used to calculate the p-value and the anomaly is detected based on the p-value.

16. An apparatus configured to detect abnormal behavior in a network, the apparatus comprising:

a processor; and

memory storing instructions that, when executed, cause the processor to

receive a machine learning model that is configured to detect anomalies in network devices operating in a multi-layer network, wherein the machine learning model is trained via unsupervised learning that includes training the machine learning model with unlabeled data that describes an operational status of the network devices over time, wherein the training builds a set of Probability Density Functions (PDFs), a likelihood function for each PDF, and a global likelihood function based on a product of each individual likelihood function, wherein the global likelihood function is a single multivariate function to describe a network component,

receive live data related to a current operational status of the network devices,

analyze the live data with the machine learning model, and

detect an anomaly related to any of the network device based on the analyzing.

17. The apparatus of claim 16 , wherein the unlabeled data does not include an indication of whether a particular network device is operating normally.

18. The apparatus of claim 17 , wherein the unlabeled data further includes a training dataset representative of a normal function in the network such that the machine learning model detects departures from expectations.

19. The apparatus of claim 16 , wherein the instructions that, when executed, cause the processor to

cause an action based on the anomaly.

20. The apparatus of claim 16 , wherein the detecting the anomaly provides a single probability output of the anomaly based on the live data, the single probability output provides an indication of a departure from a normally functioning network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2022
From: CÔTÉ, DAVID; DAVIES, MERLIN; SIMARD, OLIVIER; JANULEWICZ, EMIL; TRIPLET, THOMAS
To: CIENA CORPORATION
Reel/Frame 059263/0388 →
Continuity (3)
Continuation 15896380 · Feb 14, 2018
Provisional Application 62463060 · Feb 24, 2017
Related Publication 20220210176A1 · Jun 30, 2022
Cited By (2)
US 12,353,399 US 12,367,088