IP Library Granted Patent US 12,199,813
Granted Patent B2
US 12,199,813 · App. 18/345,422 · Granted Jan 14, 2025

Framework for automated application-to-network root cause analysis

Inventors: Rahul Gupta (Kanpur, IN); Tarun Banka (Milpitas, CA); Mithun Chakaravarrti Dharmaraj (Mountain View, CA); Thayumanavan Sridhar (Sunnyvale, CA); Raj Yavatkar (Los Gatos, CA)
Assignee: Juniper Networks, Inc.
H04L41/0631H04L41/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,199,813
App. No.
18/345,422
Granted
Jan 14, 2025
Kind
B2
Abstract

A computing system comprising a memory and processing circuitry may perform the techniques. The memory may store time series data comprising measurements of one or more performance indicators. The processing circuitry may determine, based on the time series data, an anomaly in the performance of the network system, and create, based on the time series data, a knowledge graph. The processing circuitry may determine, in response to detecting the anomaly, and based on the knowledge graph and a machine learning (ML) model trained with previous time series data, a causality graph. The processing circuitry may determine a weighting for each edge in the causality graph, determine, based on the edges in the causality graph, a candidate root cause associated with the anomalies, and determine a ranking of the candidate root cause based on the weighting. The analysis framework system may output at least a portion of the ranking.

Claims (53)

1. A method comprising:

receiving, by an analysis framework system from devices of a network system, time series data comprising measurements of one or more performance indicators;

determining, by the analysis framework system and based on the time series data, one or more anomalies in a performance of the network system;

creating, based on the time series data, a knowledge graph comprising first nodes in the network system referenced in the time series, the first nodes representing elements residing at one or more of a plurality of network service layers associated with the network system;

determining, by the analysis framework system in response to detecting the one or more anomalies, and based on the knowledge graph and a machine learning (ML) model trained with previous time series data, a causality graph, wherein the causality graph includes second nodes associated with the performance indicators, wherein edges between the first nodes and the second nodes indicate relationships between the first nodes and the second nodes, and wherein the knowledge graph and the causality graph each includes edges between one or more of the first nodes and one or more of the second nodes that are associated with elements residing at different network service layers of the plurality of network service layers;

determining a weighting for each of the edges in the causality graph;

determining, based on the edges in the causality graph, one or more candidate root causes associated with the one or more anomalies;

determining a ranking of the one or more candidate root causes based on the weighting of the edges in the causality graph; and

outputting at least a portion of the ranking.

2. The method of claim 1 , wherein outputting comprises outputting, for display, the at least the portion of the ranking.

3. The method of claim 1 , further comprising:

in response to determining the one or more anomalies and prior to determining the causality graph, pruning the knowledge graph to remove first nodes that are more than a threshold distance away from the first nodes of the knowledge graph that are associated with the one or more anomalies,

wherein determining the causality graph comprises determining the causality graph based on the pruned knowledge graph.

4. The method of claim 1 ,

wherein the machine learning model comprises a first machine learning model, and

wherein determining the one or more anomalies comprises determining the one or more anomalies based on passing the time series data through a second machine learning model trained on the previous time series data.

5. The method of claim 1 , wherein determining the one or more anomalies comprises determining the one or more anomalies based on static rules.

6. The method of claim 1 , wherein the network service layers include an application layer, a compute layer, a pod layer, a device layer, and a fabric layer.

7. The method of claim 1 , wherein determining the causality graph comprises determining the causality graph using a Granger causality algorithm.

8. The method of claim 1 , wherein determining the weighting of the edges in the causality graph comprises determining Pearson coefficients of the edges.

9. The method of claim 1 , wherein determining the weighting of an edge of the edges in the causality graph comprises determining the weighting based on an anomaly status of neighbor nodes to a first node associated with the edge.

10. The method of claim 1 , wherein determining the weighting of an edge of the edges in the causality graph comprises determining the weighting of the edge according to a count of persistent events associated with the edge.

11. A computing system comprising:

a memory configured to store time series data comprising measurements of one or more performance indicators received from devices of a network system; and

processing circuitry configured to execute an analysis framework system, the analysis framework system configured to:

determine, based on the time series data, one or more anomalies in a performance of the network system;

create, based on the time series data, a knowledge graph comprising first nodes in the network system referenced in the time series, the first nodes representing elements residing at one or more of a plurality of network service layers associated with the network system;

determine, in response to detecting the one or more anomalies, and based on the knowledge graph and a machine learning (ML) model trained with previous time series data, a causality graph, wherein the causality graph includes second nodes associated with the performance indicators, wherein edges between the first nodes and the second nodes indicate relationships between the first nodes and the second nodes, and wherein the knowledge graph and the causality graph each includes edges between one or more of the first nodes and one or more of the second nodes that are associated with elements residing at different network service layers of the plurality of network service layers;

determine a weighting for each of the edges in the causality graph;

determine, based on the edges in the causality graph, one or more candidate root causes associated with the one or more anomalies;

determine a ranking of the one or more candidate root causes based on the weighting of the edges in the causality graph; and

output at least a portion of the ranking.

12. The computing system of claim 11 , wherein the processing circuitry is configured to output, for display, the at least the portion of the ranking.

13. The computing system of claim 11 ,

wherein the processing circuitry is further configured to, in response to determining the one or more anomalies and prior to determining the causality graph, prune the knowledge graph to remove first nodes that are more than a threshold distance away from the first nodes of the knowledge graph that are associated with the one or more anomalies, and

wherein the processing circuitry is configured to determine the causality graph based on the pruned knowledge graph.

14. The computing system of claim 11 ,

wherein the machine learning model comprises a first machine learning model, and

wherein the processing circuitry is configured to determine the one or more anomalies based on passing the time series data through a second machine learning model trained on the previous time series data.

15. The computing system of claim 11 , wherein the processing circuitry is configured to determine the one or more anomalies based on static rules.

16. The computing system of claim 11 , wherein the network service layers include an application layer, a compute layer, a pod layer, a device layer, and a fabric layer.

17. The computing system of claim 11 , wherein the processing circuitry is configured to determine the causality graph using a Granger causality algorithm.

18. The computing system of claim 11 , wherein the processing circuitry is configured to determine Pearson coefficients of the edges.

19. The computing system of claim 11 , wherein the processing circuitry is configured to determine the weighting based on an anomaly status of neighbor nodes to a first node associated with the edge.

20. Non-transitory computer-readable storage media having instructions stored thereon that, when executed, cause one or more processors to execute a framework analysis system, wherein the framework analysis system is configured to:

receive, from one or more devices of a network system, time series data comprising measurements of one or more performance indicators;

determine, based on the time series data, one or more anomalies in a performance of the network system;

create, based on the time series data, a knowledge graph comprising first nodes in the network system referenced in the time series, the first nodes representing elements residing at one or more of a plurality of network service layers associated with the network system;

determine, in response to detecting the one or more anomalies, and based on the knowledge graph and a machine learning (ML) model trained with previous time series data, a causality graph, wherein the causality graph includes second nodes associated with the performance indicators, wherein edges between the first nodes and the second nodes indicate relationships between the first nodes and the second nodes, and wherein the knowledge graph and the causality graph each includes edges between one or more of the first nodes and one or more of the second nodes that are associated with elements residing at different network service layers of the plurality of network service layers;

determine a weighting for each of the edges in the causality graph;

determine, based on the edges in the causality graph, one or more candidate root causes associated with the one or more anomalies;

determine a ranking of the one or more candidate root causes based on the weighting of the edges in the causality graph; and

output at least a portion of the ranking.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2025
From: YAVATKAR, RAJENDRA SHIVARAM
To: JUNIPER NETWORKS, INC.
Reel/Frame 073226/0029 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2023
From: GUPTA, RAHUL; BANKA, TARUN; DHARMARAJ, MITHUN CHAKARAVARRTI; SRIDHAR, THAYUMANAVAN; YAVATKAR, RAJ
To: JUNIPER NETWORKS, INC.
Reel/Frame 064131/0885 →
Continuity (4)
Provisional Application 63367456 · Jun 30, 2022
Provisional Application 63367452 · Jun 30, 2022
Provisional Application 63367457 · Jun 30, 2022
Related Publication 20240007342A1 · Jan 4, 2024
References Cited (109)
US 7363203B2 · Hines · 2008 [cited by applicant]
US 9424121B2 · Kushnir · 2016 [cited by examiner]
US 9571394B1 · Sivaramakrishnan et al. · 2017 [cited by applicant]
US 9961571B2 · Yang · 2018 [cited by examiner]
US 10171335B2 · Maheshwari · 2019 [cited by examiner]
US 10235231B2 · Zhang · 2019 [cited by examiner]
US 10257055B2 · Li et al. · 2019 [cited by applicant]
US 10263833B2 · Maheshwari · 2019 [cited by examiner]
US 10289473B2 · Mendes · 2019 [cited by examiner]
US 10373094B2 · Naous · 2019 [cited by examiner]
US 10574512B1 · Mermoud · 2020 [cited by examiner]
US 10616043B2 · Wang · 2020 [cited by examiner]
US 10855548B2 · Garvey · 2020 [cited by examiner]
US 10897389B2 · Thampy · 2021 [cited by examiner]
US 11061393B2 · Abe · 2021 [cited by examiner]
US 11082439B2 · Salunke · 2021 [cited by examiner]
US 11138163B2 · Mdini · 2021 [cited by examiner]
US 11165631B1 · Chitalia · 2021 [cited by examiner]
US 11238129B2 · Jalal · 2022 [cited by examiner]
US 11265336B2 · Hild · 2022 [cited by examiner]
US 11323312B1 · Banka · 2022 [cited by examiner]
US 11323327B1 · Chitalia · 2022 [cited by examiner]
US 11422882B1 · Chhabra · 2022 [cited by applicant]
US 11500757B2 · Ambichl et al. · 2022 [cited by applicant]
US 11616682B2 · Thampy · 2023 [cited by examiner]
US 11636090B2 · Li · 2023 [cited by examiner]
US 11645293B2 · Pelloin · 2023 [cited by examiner]
US 11658874B2 · Banka · 2023 [cited by examiner]
US 11675799B2 · Pierri · 2023 [cited by examiner]
US 11765014B2 · Banka · 2023 [cited by examiner]
US 11809267B2 · Gusat · 2023 [cited by examiner]
US 11816178B2 · Jalal · 2023 [cited by examiner]
US 11887015B2 · Fahmy · 2024 [cited by examiner]
US 20040088730A1 · Gopalan · 2004 [cited by examiner]
US 20040268149A1 · Aaron · 2004 [cited by applicant]
US 20050276228A1 · Yavatkar et al. · 2005 [cited by applicant]
US 20080262990A1 · Kapoor et al. · 2008 [cited by applicant]
US 20090055684A1 · Jamjoom et al. · 2009 [cited by applicant]
US 20110214157A1 · Korsunsky et al. · 2011 [cited by applicant]
US 20130298184A1 · Ermagan et al. · 2013 [cited by applicant]
US 20140157405A1 · Joll et al. · 2014 [cited by applicant]
US 20160112443A1 · Grossman et al. · 2016 [cited by applicant]
US 20160182373A1 · Wang et al. · 2016 [cited by applicant]
US 20160308734A1 · Feller et al. · 2016 [cited by applicant]
US 20170075749A1 · Ambichl et al. · 2017 [cited by applicant]
US 20170288991A1 · Ganesh · 2017 [cited by applicant]
US 20170330096A1 · Das Gupta · 2017 [cited by examiner]
US 20180103052A1 · Choudhury et al. · 2018 [cited by applicant]
US 20180115470A1 · Huang et al. · 2018 [cited by applicant]
US 20180131675A1 · Sengupta et al. · 2018 [cited by applicant]
US 20190068693A1 · Bernat · 2019 [cited by applicant]
US 20190141015A1 · Nellen · 2019 [cited by applicant]
US 20190196894A1 · Cherbakov · 2019 [cited by examiner]
US 20200028771A1 · Wong et al. · 2020 [cited by applicant]
US 20200136973A1 · Rahman et al. · 2020 [cited by applicant]
US 20200272973A1 · Hongtan et al. · 2020 [cited by applicant]
US 20200278892A1 · Nainar et al. · 2020 [cited by applicant]
US 20210044623A1 · Bosch et al. · 2021 [cited by applicant]
US 20210117242A1 · Van De Groenendaal et al. · 2021 [cited by applicant]
US 20210135967A1 · Iorga et al. · 2021 [cited by applicant]
US 20210160262A1 · Bynum et al. · 2021 [cited by applicant]
US 20210320875A1 · Guim Bernat et al. · 2021 [cited by applicant]
US 20210367830A1 · Jain et al. · 2021 [cited by applicant]
US 20210390423A1 · Latapie · 2021 [cited by examiner]
US 20210406091A1 · Thyagaturu et al. · 2021 [cited by applicant]
US 20220006783A1 · Hassanzadeh et al. · 2022 [cited by applicant]
US 20220029929A1 · Jain et al. · 2022 [cited by applicant]
US 20220038471A1 · Sugarbaker et al. · 2022 [cited by applicant]
US 20220058042A1 · Vanjare · 2022 [cited by examiner]
US 20220103431A1 · Singh · 2022 [cited by examiner]
US 20220114032A1 · Bernat et al. · 2022 [cited by applicant]
US 20220116478A1 · Biederman et al. · 2022 [cited by applicant]
US 20220210028A1 · Chen et al. · 2022 [cited by applicant]
US 20220224121A1 · Jha et al. · 2022 [cited by applicant]
US 20220337555A1 · Gol et al. · 2022 [cited by applicant]
US 20220417117A1 · Tayeb et al. · 2022 [cited by applicant]
US 20220417323A1 · Julien et al. · 2022 [cited by applicant]
US 20230262093A1 · Gupta et al. · 2023 [cited by applicant]
US 20230300059A1 · Rodriguez Natal et al. · 2023 [cited by applicant]
US 20230388346A1 · Kulshreshtha et al. · 2023 [cited by applicant]
US 20240007342A1 · Gupta · 2024 [cited by examiner]
CN 113206761B · 2021 [cited by applicant]
EP 3889777A1 · 2021 [cited by applicant]
WO 2013184846A1 · 2013 [cited by applicant]
WO 2022020336A1 · 2022 [cited by applicant]
“Granger Causality,” Wikipedia, Last Updated Sep. 28, 2023, 14 pp. [cited by applicant]
“PageRank,” Wikipedia, Last Updated Oct. 19, 2023, 22 pp. [cited by applicant]
Liu et al., “MicroHECL: High-Efficient Root Cause Localization in Large-Scale Microservice Systems,” 2021 IEEE/ACM 43rd International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP), May… [cited by applicant]
Meng et al., “Localizing Failure Root Causes in a Microservice through Causality Inference,” 2020 IEEE/ACM 28th International Symposium on Quality of Service (IWQoS), Jun. 2020, 10 pp. [cited by applicant]
U.S. Appl. No. 18/472,042, filed Sep. 21, 2023, by Kommula et al. [cited by applicant]
U.S. Appl. No. 18/472,050, filed Sep. 21, 2023, by Kommula et al. [cited by applicant]
U.S. Appl. No. 18/472,059, filed Sep. 21, 2023, by Kommula et al. [cited by applicant]
U.S. Appl. No. 18/472,092, filed Sep. 21, 2023, by Kommula et al. [cited by applicant]
U.S. Appl. No. 18/472,111, filed Sep. 21, 2023, by Kommula et al. [cited by applicant]
U.S. Appl. No. 18/472,123, filed Sep. 21, 2023, by Kommula et al. [cited by applicant]
Wu et al., “MicroRCA: Root Cause Localization of Performance Issues in Microservices,” IEEE/IFIP Network Operations and Management Symposium (NOMS), Apr. 2020, 10 pp. [cited by applicant]
PCT Application No. PCT/US2023/069485, filed Jun. 30, 2023, naming inventors Gupta et al. [cited by applicant]
International Search Report and Written Opinion of International Application No. PCT/US2023/069485 dated Oct. 30, 2023, 12 pp. [cited by applicant]
“Amazon SageMaker—Developer Guide,” retrieved from https://docs.aws.amazon.com/sagemaker/latest/dg/randomcutforest.html on Feb. 15, 2024, 6167 pp. [cited by applicant]
“cSRX Container Firewall,” retrieved from https://www.juniper.net/us/en/products/security/srx-series/csrx-containerized-firewall.html, on Feb. 15, 2024, 2 pp. [cited by applicant]
“Emerging Technologies: Adoption Growth Insights—Function Accelerator Cards Cards(Next-Gen SmartNICs, DPUs, IPUs),” Gartner Research, Sep. 14, 2021, 6 pp. [cited by applicant]
“NVIDIA BlueField Networking Platform,” retrieved from https://www.nvidia.com/en-us/networking/products/data-processing-unit/, on Feb. 15, 2024, 7 pp. [cited by applicant]
“The Istio Service Mesh,” retrieved from https://istio.io/latest/about/service-mesh/, on Feb. 15, 2024, 5 pp. [cited by applicant]
Kim et al., “A Case for SmartNIC-accelerated Private Communication,” APNet '20: Proceedings of the 4th Asia-Pacific Workshop on Networking, Aug. 2020, 8 pp. [cited by applicant]
Liu et al., “Offloading Distributed Applications onto SmartNICs using iPipe,” In Proceedings of the ACM Special Interest Group on Data Communication (SIGCOMM '19), Aug. 19-23, 2019, 16 pp. [cited by applicant]
Liu et al., “Performance Characteristics of the BlueField-2 SmartNIC,” arXiv:2105.06619, May 14, 2021, 13 pp. [cited by applicant]
Moro et al., “FOP4: Function Offloading Prototyping in Heterogeneous and Programmable Network Scenarios,” 2019 IEEE Conference on Network Function Virtualization and Software Defined Network, Nov. 2019, 6 pp. [cited by applicant]
Soldani et al., “Anomaly Detection and Failure Root Cause Analysis in (Micro) Service-Based Cloud Applications: A Survey,” arXiv:2105.12378, May 26, 2021, 36 pp. [cited by applicant]
Tanenbaum et al., “Distributed Systems: Principles and Paradigms,” Second Edition, Prentice-Hall, (Applicant points out, in accordance with MPEP 609.04(a), that the year of publication, 2007, is sufficiently earlier tha… [cited by applicant]
Cited By (2)
US 12,294,492 US 12,568,397