IP Library › Granted Patent US 12,229,677
Granted Patent B2
US 12,229,677 · App. 18/398,404 · Granted Feb 18, 2025

Network anomaly detection

Inventors: James Peroulas (San Mateo, CA); Poojita Thukral (Mountain View, CA); Dutt Kalapatapu (Santa Clara, CA); Andreas Terzis (Mountain View, CA); Krishna Sayana (Mountain View, CA)
Assignee: GOOGLE LLC
G06N3/08H04W24/08H04W84/042
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,229,677
App. No.
18/398,404
Granted
Feb 18, 2025
Kind
B2
Abstract

A method for detecting network anomalies includes receiving a control message from a cellular network and extracting one or more features from the control message. The method also includes predicting a potential label for the control message using a predictive model configured to receive the one or more extracted features from the control message as feature inputs. Here, the predictive model is trained on a set of training control messages where each training control message includes one or more corresponding features and an actual label. The method further includes determining that a probability of the potential label satisfies a confidence threshold. The method also includes analyzing the control message to determine whether the control message corresponds to a respective network performance issue. When the control message impacts network performance, the method includes communicating the network performance issue to a network entity responsible for the network performance issue.

Claims (47)

1. A computer-implemented method comprising:

extracting one or more first features and an actual label from a first network control message collected from a network;

predicting a predicted label for a second network control message collected from the network based on one or more second features extracted from the second network control message, the one or more second features being input to a predictive model that is trained based on the one or more first features and the actual label; and

determining whether a network anomaly of the network occurs based on the predicted label.

2. The method of claim 1 , wherein the determining determines that the network anomaly of the network occurs in response to the predicted label matching the actual label.

3. The method of claim 1 , wherein the determining determines that the network anomaly of the network occurs in response to a probability of the predicted label satisfying a confidence threshold.

4. The method of claim 1 , further comprising:

in response to a determination that the network anomaly of the network occurs,

determining whether the network anomaly indicates a network performance issue.

5. The method of claim 4 , wherein the determining determines that the network anomaly indicates the network performance issue based on analyzing the second network control message.

6. The method of claim 4 , further comprising:

in response to a determination that the network anomaly indicates the network performance issue,

executing a network performance remediation protocol to resolve the network performance issue.

7. The method of claim 6 , wherein the network performance remediation protocol includes informing a network entity responsible for the network performance issue, or relaying the network performance issue to an entity that knows or communicates with the responsible entity.

8. The method of claim 6 , further comprising:

after the network performance issue is resolved,

removing a filter that is used to prevent redundant analysis of network anomalies similar to the network anomaly indicating the network performance issue.

9. An apparatus, comprising:

processing circuitry configured to

extract one or more first features and an actual label from a first network control message collected from a network,

predict a predicted label for a second network control message collected from the network based on one or more second features extracted from the second network control message, the one or more second features being input to a predictive model that is trained based on the one or more first features and the actual label, and

determine whether a network anomaly of the network occurs based on the predicted label.

10. The apparatus of claim 9 , wherein processing circuitry is configured to:

determine that the network anomaly of the network occurs in response to the predicted label matching the actual label.

11. The apparatus of claim 9 , wherein processing circuitry is configured to:

determine that the network anomaly of the network occurs in response to a probability of the predicted label satisfying a confidence threshold.

12. The apparatus of claim 9 , wherein processing circuitry is configured to:

in response to a determination that the network anomaly of the network occurs,

determine whether the network anomaly indicates a network performance issue.

13. The apparatus of claim 12 , wherein processing circuitry is configured to:

determine that the network anomaly indicates the network performance issue based on analyzing the second network control message.

14. The apparatus of claim 12 , wherein processing circuitry is configured to:

in response to a determination that the network anomaly indicates the network performance issue,

execute a network performance remediation protocol to resolve the network performance issue.

15. The apparatus of claim 14 , wherein the network performance remediation protocol includes informing a network entity responsible for the network performance issue, or relaying the network performance issue to an entity that knows or communicates with the responsible entity.

16. The apparatus of claim 14 , wherein processing circuitry is configured to:

after the network performance issue is resolved,

remove a filter that is used to prevent redundant analysis of network anomalies similar to the network anomaly indicating the network performance issue.

17. A non-transitory computer-readable medium storing instructions that, when executed by a processor, cause the processor to perform a method, the method comprising:

extracting one or more first features and an actual label from a first network control message collected from a network;

predicting a predicted label for a second network control message collected from the network based on one or more second features extracted from the second network control message, the one or more second features being input to a predictive model that is trained based on the one or more first features and the actual label; and

determining whether a network anomaly of the network occurs based on the predicted label.

18. The non-transitory computer-readable medium of claim 17 , wherein the determining determines that the network anomaly of the network occurs in response to the predicted label matching the actual label.

19. The non-transitory computer-readable medium of claim 17 , wherein the determining determines that the network anomaly of the network occurs in response to a probability of the predicted label satisfying a confidence threshold.

20. The non-transitory computer-readable medium of claim 17 , wherein the method comprises:

in response to a determination that the network anomaly of the network occurs,

determining whether the network anomaly indicates a network performance issue.

Continuity (4)
Continuation 17979508 · Nov 2, 2022
Continuation 17145236 · Jan 8, 2021
Continuation 16397082 · Apr 29, 2019
Related Publication 20240127055A1 · Apr 18, 2024
References Cited (16)
US 6836536B2 · Huang et al. · 2004 [cited by applicant]
US 9094444B2 · Baltatu et al. · 2015 [cited by applicant]
US 9342789B2 · Aharoni et al. · 2016 [cited by applicant]
US 10891546B2 · Peroulas · 2021 [cited by applicant]
US 11507837B2 · Peroulas · 2022 [cited by applicant]
US 11861453B2 · Peroulas · 2024 [cited by examiner]
US 20160065444A1 · Schunder et al. · 2016 [cited by applicant]
US 20180097828A1 · Coskun · 2018 [cited by applicant]
JP 201056682A · 2010 [cited by applicant]
JP 2016537906A · 2016 [cited by applicant]
WO WO2015031751A1 · 2015 [cited by applicant]
Japanese Office Action issued Jan. 31, 2023 in Japanese Patent Application No. 2021-564368, 8 pages. [cited by applicant]
Samuel Marchal, et al., “Mitigating Mimicry Attacks Against the Session Initiation Protocol,” IEEE Transactions on Network and Service Management, vol. 12, No. 3, Sep. 2015, pp. 467-482. [cited by applicant]
Korean Office Action issued on Apr. 26, 2023 in Korean Patent Application No. 10-2021-7039075 (with English translation), 6 pages. [cited by applicant]
Lopez-Martin, Manuel et al. “Conditional Variational Autoencoder for Prediction and Feature Recovery Applied to Intrusion Detection in IoT”, Sensors, vol. 17, No. 9, Aug. 26, 2017 (Aug. 26, 2017), p. 1967, https://www.m… [cited by applicant]
European Search Report issued Sep. 5, 2023 in European Application No. 23180415.4, therein. [cited by applicant]