IP Library Granted Patent US 12,401,563
Granted Patent B2
US 12,401,563 · App. 18/109,826 · Granted Aug 26, 2025

Methods, systems, and computer readable media for detecting network service anomalies

Inventors: Marc Owen Magnuson (Austin, TX); Stefan Jan Johansson (Round Rock, TX); Deep Datta (Austin, TX); George Lache (Cedar Park, TX); Ethan Paul Spurlock (Cedar Park, TX); Gregory Lane Singleton (Liberty Hill, TX)
Assignee: KEYSIGHT TECHNOLOGIES, INC.
H04L41/0631H04L41/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,563
App. No.
18/109,826
Granted
Aug 26, 2025
Kind
B2
Abstract

Methods, systems, and computer readable media for detecting network service anomalies. An example method includes, during a learning phase, detecting a client initiating a first network interaction with an application and recording a start time for the first network interaction with the application; determining that the first network interaction with the application has ceased and recording an end time for the first network interaction; and determining, based on the start time and the end time, an application interaction rate for the first network interaction with the application. The method includes, during a detection phase, detecting the client initiating a second network interaction with the application; determining a second application interaction rate for the second network interaction; and determining that a network service anomaly occurred during the second network interaction based on the first application interaction rate and the second application interaction rate.

Claims (36)

1. A method for detecting network service anomalies, the method comprising:

during a learning phase:

detecting a client initiating a first network interaction with an application and recording a start time for the first network interaction with the application;

determining that the first network interaction with the application has ceased and recording an end time for the first network interaction; and

determining, based on the start time and the end time, a first application interaction rate for the first network interaction with the application; and

during a detection phase:

detecting the client initiating a second network interaction with the application;

determining a second application interaction rate for the second network interaction; and

determining that a network service anomaly occurred during the second network interaction based on the first application interaction rate and the second application interaction rate, wherein determining that the network service anomaly occurred comprises determining that the second network interaction has ceased, building a feature vector comprising the second application interaction rate and one or more other metrics observed during the second network interaction, supplying the feature vector to a machine learning model trained on one or more previous interactions with the application, and using an output of the machine learning model to determine that the network service anomaly occurred during the second network interaction.

2. The method of claim 1 , wherein the first network interaction with the application comprises a plurality of different encrypted connections between the client and a plurality of application servers within a network domain for the application.

3. The method of claim 1 , wherein determining that the first network interaction with the application has ceased comprises determining that all connections to the application have ceased for at least a threshold amount of time.

4. The method of claim 1 , wherein detecting a client initiating a first network interaction with an application comprises performing transport layer security (TLS) parsing to identify an application name for the application from an encrypted connection.

5. The method of claim 1 , wherein the machine learning model is trained on one or more previous interactions with the application for a first geographic region, and wherein the method comprises determining that the client is located with the first geographic region.

6. The method of claim 1 , wherein the machine learning model is trained on one or more previous interactions with the application for a day of the week, and wherein the method comprises determining that the second client interaction occurred during the day of the week.

7. The method of claim 1 , wherein building the feature vector comprises measuring one or more of: application response time, connection lifetime, bitrate, total bytes, number of packets, a packet size distribution, and a number of connections.

8. The method of claim 1 , wherein building the feature vector comprises including one or more feature time window metrics characterizing a window of time at an end of the second network interaction.

9. The method of claim 1 , comprising outputting a total mean squared error (MSE) score for the feature vector and one or more feature-specific MSE scores.

10. A system for detecting network service anomalies, the system comprising:

one or more processors and memory storing executable instructions for the one or more processors;

a visibility behavior analysis system (VBAS) implemented on the one or more processors and configured for:

during a learning phase:

detecting a client initiating a first network interaction with an application and recording a start time for the first network interaction with the application;

determining that the first network interaction with the application has ceased and recording an end time for the first network interaction; and

determining, based on the start time and the end time, a first application interaction rate for the first network interaction with the application; and

during a detection phase:

detecting the client initiating a second network interaction with the application;

determining a second application interaction rate for the second network interaction; and

determining that a network service anomaly occurred during the second network interaction based on the first application interaction rate and the second application interaction rate, wherein determining that the network service anomaly occurred comprises determining that the second network interaction has ceased, building a feature vector comprising the second application interaction rate and one or more other metrics observed during the second network interaction, supplying the feature vector to a machine learning model trained on one or more previous interactions with the application, and using an output of the machine learning model to determine that the network service anomaly occurred during the second network interaction.

11. The system of claim 10 , wherein the first network interaction with the application comprises a plurality of different encrypted connections between the client and a plurality of application servers within a network domain for the application.

12. The system of claim 10 , wherein determining that the first network interaction with the application has ceased comprises determining that all connections to the application have ceased for at least a threshold amount of time.

13. The system of claim 10 , wherein detecting a client initiating a first network interaction with an application comprises performing transport layer security (TLS) parsing to identify an application name for the application from an encrypted connection.

14. The system of claim 10 , wherein the machine learning model is trained on one or more previous interactions with the application for a first geographic region, and wherein the VBAS is configured for determining that the client is located with the first geographic region.

15. The system of claim 10 , wherein the machine learning model is trained on one or more previous interactions with the application for a day of the week, and wherein the VBAS is configured for determining that the second client interaction occurred during the day of the week.

16. The system of claim 10 , wherein building the feature vector comprises measuring one or more of: application response time, connection lifetime, bitrate, total bytes, number of packets, a packet size distribution, and a number of connections.

17. The system of claim 10 , wherein building the feature vector comprises including one or more feature time window metrics characterizing a window of time at an end of the second network interaction.

18. The system of claim 10 , wherein the VBAS is configured for outputting a total mean squared error (MSE) score for the feature vector and one or more feature-specific MSE scores.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2023
From: MAGNUSON, MARC OWEN; JOHANSSON, STEFAN JAN; LACHE, GEORGE; SPURLOCK, ETHAN PAUL; SINGLETON, GREGORY LANE; DATTA, DEEP
To: KEYSIGHT TECHNOLOGIES, INC.
Reel/Frame 063104/0743 →
Continuity (2)
Provisional Application 63437708 · Jan 8, 2023
Related Publication 20240235923A1 · Jul 11, 2024
References Cited (36)
US 9094444B2 · Baltatu et al. · 2015 [cited by applicant]
US 9386103B2 · Clifton et al. · 2016 [cited by applicant]
US 9609009B2 · Muddu et al. · 2017 [cited by applicant]
US 10009364B2 · Dasgupta et al. · 2018 [cited by applicant]
US 10404732B2 · Munro et al. · 2019 [cited by applicant]
US 10459827B1 · Aghdaie et al. · 2019 [cited by applicant]
US 10574512B1 · Mermoud et al. · 2020 [cited by applicant]
US 10716017B2 · Lyon et al. · 2020 [cited by applicant]
US 10887786B2 · Vedam et al. · 2021 [cited by applicant]
US 11190417B2 · Raney et al. · 2021 [cited by applicant]
US 11265337B2 · Smelov et al. · 2022 [cited by applicant]
US 11507488B2 · Orzell et al. · 2022 [cited by applicant]
US 11949570B2 · Pandey et al. · 2024 [cited by applicant]
US 20100153316A1 · Duffield et al. · 2010 [cited by applicant]
US 20150113133A1 · Srinivas et al. · 2015 [cited by applicant]
US 20160014152A1 · Buruganahalli · 2016 [cited by examiner]
US 20170332256A1 · Gupta · 2017 [cited by examiner]
US 20170339022A1 · Hegde et al. · 2017 [cited by applicant]
US 20190222591A1 · Kislitsin et al. · 2019 [cited by applicant]
US 20200106795A1 · Servajean et al. · 2020 [cited by applicant]
US 20200314128A1 · Hild · 2020 [cited by applicant]
US 20200364561A1 · Ananthanarayanan et al. · 2020 [cited by applicant]
US 20220239720A1 · Madanapalli et al. · 2022 [cited by applicant]
US 20230031654A1 · Pandey et al. · 2023 [cited by applicant]
Orsolic and Skorin-Kapov, “A Framework for In-Network QoE Monitoring of Encrypted Video Streaming”, IEEE Access, vol. 8, pp. 74691-74706 (2020). [cited by applicant]
Bartolec, et al. “Impact of User Playback Interactions on In-Network Estimation of Video Streaming Performance”, IEEE Transaction On Network And Service Management, vol. 19, No. 3, pp. 3547-3561 (2022). [cited by applicant]
Commonly-Assigned, co-pending U.S. Appl. No. 17/390,860 for “Methods, Systems, and Computer Readable Media for Utilizing Machine Learning to Automatically Configure Filters at a Net” (Unpublished, filed Jul. 30, 2021). [cited by applicant]
Nguyen et al., “GEE: A Gradient-based Explainable Variational Autoencoder for Network Anomaly Detection,” arXiv:1903.06661v1, pp. 1-10 (Mar. 15, 2019). [cited by applicant]
Sanjuas, “Application of Machine Learning to Flow-based Network Monitoring,” Polygraph.io, pp. 1-13 (2016). [cited by applicant]
Saboori et al., “Automatic firewall rules generator for anomaly detection systems with Apriori algorithm,” 2010 3rd International Conference on Advanced Computer Theory and Engineering (ICACTE), pp. 1-4 (2010). [cited by applicant]
Pranschke et al., “Automated Firewall Rule Set Generation Through Passive Traffic Inspection,” Conference: Information Security South Africa Conference, pp. 1-10 (Jan. 2009). [cited by applicant]
Mahoney et al., “PHAD: Packet Header Anomaly Detection for Identifying Hostile Network Traffic,” Florida Institute of Technology Technical Report CS-2001-04, pp. 1-17 (2001). [cited by applicant]
Balakrishnan, et al., “A Study of the Classification Capabilities of Neural Networks Using Unsupervised Learning: A Comparison with K-Means Clustering”, the Psychometric Society, 17 pages (1994). [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/390,860 (Jun. 29, 2023). [cited by applicant]
Shabtai, et al., “F-Sign: Automatic, Function-Based Signature Generation for Malware” in IEEE Transactions on Systems, Man, and Cybernetics, Part C (Applications and Reviews), vol. 41, No. 4, pp. 494-508, Jul. 2011, doi… [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/390,860 (Dec. 5, 2023). [cited by applicant]