IP Library › Granted Patent US 11,956,117
Granted Patent B1
US 11,956,117 · App. 18/199,997 · Granted Apr 9, 2024

Network monitoring and healing based on a behavior model

Inventors: Arivudainambi Appachi gounder (San Jose, CA); Parthasarathi Palanisamy (San Jose, CA)
Assignee: Google LLC
H04L41/0631H04L41/0627H04L41/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,956,117
App. No.
18/199,997
Granted
Apr 9, 2024
Kind
B1
Abstract

Aspects of the disclosure are directed to monitoring, alerting, and/or root causing network problems based on current network behavior and network events at any instant in time using a network behavior model. The network behavior model can learn and be updated with network states and events to correlate network problems and determine root causes of the network problems for alerting and/or automatic correction.

Claims (42)

1. A method for managing a network using a behavior model, comprising:

receiving, by one or more processors, first network metadata;

comparing, by the one or more processors, the first network metadata to test network metadata;

determining, by the one or more processors, that the first network metadata does not match the test network metadata;

identifying, by the one or more processors, second network metadata that match the test network metadata;

computing, by the one or more processors, a plurality of network events based on possible transitions from the first network metadata to the second network metadata;

identifying, by the one or more processors, a root cause for the first network metadata not matching the test network metadata based on the plurality of network events; and

outputting, by the one or more processors, instructions based on the root cause.

2. The method of claim 1 , wherein the first network metadata comprises at least one of network states or behaviors at a point in time and the test network metadata comprises at least one of desired network states or behaviors for the network.

3. The method of claim 1 , wherein outputting instructions further comprises at least one of sending an alert or notification to validate the root cause or automatically correcting the root cause.

4. The method of claim 1 , wherein the second network metadata comprises at least one of network states or behaviors that are affecting the first network metadata.

5. The method of claim 1 , wherein the behavior model comprises at least one of a finite state machine or a machine learning model.

6. The method of claim 1 , further comprising generating, by the one or more processors, a directed graph for the behavior model, the directed graph comprising a plurality of nodes and a plurality of edges connecting the plurality of nodes, the plurality of nodes representing network metadata and the plurality of edges representing network events.

7. The method of claim 6 , wherein computing the plurality of network events further comprises parsing edges from the node comprising the second network metadata to the node comprising the first network metadata.

8. The method of claim 6 , wherein identifying the root cause further comprises filtering the plurality of network events based on changes to the network or predicting the root cause based on previous network metadata or network events.

9. The method of claim 1 , further comprising training, by the one or more processors, the behavior model on previous network events, previous network metadata, and network objectives.

10. A system comprising:

one or more processors; and

one or more storage devices coupled to the one or more processors and storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations for managing a network using a behavior model, the operations comprising:

receiving first network metadata;

comparing the first network metadata to test network metadata;

determining that the first network metadata does not match the test network metadata;

identifying second network metadata that match the test network metadata;

computing plurality of network events based on possible transitions from the first network metadata to the second network metadata;

identifying a root cause for the first network metadata not matching the test network metadata based on the plurality of network events; and

outputting instructions based on the root cause.

11. The system of claim 10 , wherein outputting instructions further comprises at least one of sending an alert or notification to validate the root cause or automatically correcting the root cause.

12. The system of claim 10 , wherein the operations further comprise generating a directed graph for the behavior model, the directed graph comprising a plurality of nodes and a plurality of edges connecting the plurality of nodes, the plurality of nodes representing network metadata and the plurality of edges representing network events.

13. The system of claim 12 , wherein computing the plurality of network events further comprises parsing edges from the node comprising the second network metadata to the node comprising the first network metadata.

14. The system of claim 12 , wherein identifying the root cause further comprises filtering the plurality of network events based on changes to the network or predicting the root cause based on previous network metadata or network events.

15. A non-transitory computer readable medium for storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations for managing a network using a behavior model, the operations comprising:

receiving first network metadata;

comparing the first network metadata to test network metadata;

determining that the first network metadata does not match the test network metadata;

identifying second network metadata that match the test network metadata;

computing a plurality of network events based on possible transitions from the first network metadata to the second network metadata;

identifying a root cause for the first network metadata not matching the test network metadata based on the plurality of network events; and

outputting instructions based on the root cause.

16. The non-transitory computer readable medium of claim 15 , wherein outputting instructions further comprises at least one of sending an alert or notification to validate the root cause or automatically correcting the root cause.

17. The non-transitory computer readable medium of claim 15 , wherein the operations further comprise generating a directed graph for the behavior model, the directed graph comprising a plurality of nodes and a plurality of edges connecting the plurality of nodes, the plurality of nodes representing network metadata and the plurality of edges representing network events.

18. The non-transitory computer readable medium of claim 17 , wherein computing the plurality of network events further comprises parsing edges from the node comprising the second network metadata to the node comprising the first network metadata.

19. The non-transitory computer readable medium of claim 17 , wherein identifying the root cause further comprises filtering the plurality of network events based on changes to the network or predicting the root cause based on previous network metadata or network events.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2023
From: APPACHI GOUNDER, ARIVUDAINAMBI; PALANISAMY, PARTHASARATHI
To: GOOGLE LLC
Reel/Frame 063712/0492 →
Cited By (2)
US 12,244,452 US 12,706,816