IP Library › Granted Patent US 12,069,069
Granted Patent B2
US 12,069,069 · App. 17/347,353 · Granted Aug 20, 2024

Network devices assisted by machine learning

Inventors: Yair Chasdai (Tel Aviv, IL); David Daniel Pilnik (Rishon LeTsiyon, IL); Liran Daniel (Holon, IL); Gary Mataev (Haifa, IL)
Assignee: MELLANOX TECHNOLOGIES LTD.
H04L63/1416G06N5/04G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,069,069
App. No.
17/347,353
Granted
Aug 20, 2024
Kind
B2
Abstract

Devices and methods to identify malicious usage of a network device. In at least one embodiment, a network device comprises circuitry for performing a networking function and collecting telemetry data indicative of the performance of the networking function. The network device obtains an inference of a network traffic pattern using a machine learning model, and responds to the inference.

Claims (57)

1. A system, comprising:

at least one processor; and

at least one memory storing instructions that, in response to execution by the at least one processor, cause the system to at least:

perform at least one networking function;

collect data associated with the performing of the at least one networking function as the system performs the at least one networking function;

obtain an inference using a machine learning model, the inference obtained based, at least in part, on the data; and

respond to the inference.

2. The system of claim 1 , wherein the processor comprises an integrated circuit.

3. The system of claim 1 , wherein a data processing unit (“DPU”) comprises the at least one processor and an integrated network interface.

4. The system of claim 1 , wherein the inference is of a network traffic pattern, and

responding to the inference comprises adjusting operation of the system based, at least in part, on the inference of the network traffic pattern.

5. The system of claim 1 , wherein

responding to the inference comprises sending data indicative of a proposed change to operation of the system.

6. The system of claim 1 , wherein the inference is of a network traffic pattern, and

the machine learning model is trained to infer the network traffic pattern based at least in part on training data indicating an association of a sample in the training data with the network traffic pattern.

7. The system of claim 1 , wherein the inference is of a network traffic pattern, and the at least one memory stores further instructions that, in response to execution by the at least one processor, cause the system to at least:

determine that one or more units of network data received by the system are associated with the network traffic pattern; and

train the machine learning model to infer the network traffic pattern based, at least in part, on the one or more units of network data.

8. The system of claim 1 , wherein the inference is of a network traffic pattern,

the at least one memory stores further instructions that, in response to execution by the at least one processor, cause the system to at least determine that the inference of the network traffic pattern is associated with undesired usage of the system, and

responding to the inference comprises limiting processing of data originating from a source associated with the network traffic pattern.

9. The system of claim 1 , wherein the data is associated with at least one of open systems interconnect (“OSI”) levels one or two.

10. The system of claim 1 , wherein the system is comprised in at least one of an access point, router, switch, hub, bridge, modem, data processing unit (“DPU”), SmartNIC, or active cable.

11. The system of claim 1 , wherein the data comprises at least one of a latency histogram, receive counter, transaction counter, queue length indicator, queue occupancy indicator, or power-level usage indicator.

12. A non-transitory computer-readable storage medium comprising instructions that, in response to execution by at least one processor of a network device, cause the network device to at least:

cause the at least one processor to collect data indicative of operation of the network device as the at least one processor performs at least one networking function;

obtain, from the at least one processor, the data indicative of the operation of the network device; and

train a machine learning model to obtain an inference from a network traffic pattern, the inference obtained based, at least in part, on the data indicative of the operation of the network device.

13. The non-transitory computer-readable storage medium of claim 12 , wherein the machine learning model is trained based, at least in part, on data obtained by the at least one processor in association with performance of the at least one network function.

14. The non-transitory computer-readable storage medium of claim 12 , comprising further instructions that, in response to execution by at least one processor of a computing device, cause the computing device to at least:

respond to the inference by at least adjusting operation of the network device, the adjustment determined based, at least in part, on the inference.

15. The non-transitory computer-readable storage medium of claim 12 , comprising further instructions that, in response to execution by at least one processor of a computing device, cause the computing device to at least:

determine, based at least in part on the inference, an adjustment to operation of the network device;

obtain authorization to adjust the operation of the network device; and

update the machine learning model using information obtained from the authorization.

16. The non-transitory computer-readable storage medium of claim 12 , comprising further instructions that, in response to execution by at least one processor of a computing device, cause the computing device to at least:

determine that the network traffic pattern is associated with undesired usage of a networking device; and

prevent processing of data originating from a source associated with the network traffic pattern.

17. The non-transitory computer-readable storage medium of claim 12 , comprising further instructions that, in response to execution by at least one processor of a computing device, cause the computing device to at least:

identify a condition of operation of the network device;

store telemetry data associated with the condition; and

train the machine learning model based, at least in part, on the stored telemetry data associated with the condition.

18. A method, comprising:

performing, by an integrated circuit of a network device, at least one networking function;

collecting, by the integrated circuit, data associated with the performing of the at least one networking function as the integrated circuit performs the at least one networking function;

obtaining, by the network device, an inference using a machine learning model, the inference obtained based, at least in part, on the data; and

responding to the inference.

19. The method of claim 18 , wherein the inference is performed by the integrated circuit, and the integrated circuit comprises at least one processor and a network interface.

20. The method of claim 18 , further comprising:

responding to the inference by adjusting operation of the network device.

21. The method of claim 18 , further comprising:

obtaining information indicating that operation of the network device is anomalous; and

training the machine learning model to infer a characteristic of a network traffic pattern based, at least in part, on the obtained information.

22. The method of claim 18 , wherein the integrated circuit reads the data associated with the performing of the at least one networking function from a memory of a network component of the network device.

23. The method of claim 18 , wherein the at least one networking function is performed on at least one of open systems interconnect (“OSI”) levels one or two.

24. The method of claim 18 , wherein input to the machine learning model comprises at least one of a latency histogram, receive counter, transaction counter, or power-level usage indicator.

25. The method of claim 18 , wherein responding to the inference comprises limiting network traffic associated with an inferred undesired usage of the network device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2021
From: CHASDAI, YAIR; PILNIK, DAVID DANIEL; DANIEL, LIRAN; MATAEV, GARY
To: MELLANOX TECHNOLOGIES LTD.
Reel/Frame 056537/0669 →
Continuity (1)
Related Publication 20220400124A1 · Dec 15, 2022
Cited By (1)
US 12,689,579