IP Library Granted Patent US 12,524,713
Granted Patent B2
US 12,524,713 · App. 18/636,756 · Granted Jan 13, 2026

Forecasting recurring anomalies in time series data

Inventors: Saurabh Dinesh Brahmankar (Nagpur, IN); Christopher Ryan Barber (Ottawa, CA); Minming Ni (Kanata, CA)
Assignee: Ciena Corporation
G06Q10/04G06F16/2477
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,524,713
App. No.
18/636,756
Granted
Jan 13, 2026
Kind
B2
Abstract

Systems and methods for forecasting recurring anomalies in time series data include determining forecast data from historical data of time series data where the forecast data is for a desired future time span; combining the forecast data with the historical data to form a combined time series; determining a normal operating range using the combined time series; detecting anomalies in the forecast data based on the normal operating range; and providing an output including the detected anomalies in the forecast data.

Claims (46)

1 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to implement steps of:

determining forecast data from historical data of time series data where the forecast data is for a desired future time span, wherein the time series data relates to a network and describes network traffic therein, wherein the forecast data includes recurring anomalies predicted for the desired future time span and the time series data comprises Performance Monitoring (PM) data collected from network elements in the network;

combining the forecast data with the historical data to form a combined time series;

determining a normal operating range using the combined time series such that the normal operating range is determined based on both the historical data and the forecast data, wherein the normal operating range is defined by a fixed, predefined sensitivity boundary interval width explicitly configured in advance and applied uniformly regardless of statistical variance, and wherein the normal operating range is determined without computing statistical confidence intervals or error variance estimates;

detecting anomalies in the forecast data based on the normal operating range, wherein the normal operating range includes sensitivity boundaries defined by a predefined interval width on the combined time series, and wherein the detecting anomalies includes determining forecast data points including forecasted recurring anomalies in seasonal or periodic patterns that lie outside the sensitivity boundaries;

providing an output including the detected anomalies in the forecast data; and

triggering a workflow based on the output, wherein the workflow includes scaling up or down network resources in the network through network-specific actions comprising bandwidth scaling, routing adjustments or Quality of Service (QoS) parameter modifications based on the detected anomalies and their corresponding times.

2 . The non-transitory computer-readable medium of claim 1 , wherein the steps further include

providing the output as an alert in a graphical user interface.

3 . The non-transitory computer-readable medium of claim 2 , wherein the graphical user interface includes a dashboard that displays one or more of the detected anomalies in the forecast data and their corresponding times, associated equipment related to the detected anomalies, aggregate data for a plurality of time series and any detected anomalies, a number of forecasts, and a percentage of forecasts that came true.

4 . The non-transitory computer-readable medium of claim 1 , wherein the time series data is for Performance Monitoring (PM) data for packet layer data, and wherein the PM data includes any of latency, jitter, error rate, RX bytes/packets, TX bytes/packets, or dropped packet bytes.

5 . The non-transitory computer-readable medium of claim 4 , wherein the PM data is used to derive values for network traffic including one of a Committed Information Rate (CIR) and an Excess Information Rate (EIR).

6 . The non-transitory computer-readable medium of claim 1 , wherein the normal operating range is determined using a forecast envelope that incorporate sonality analysis to account for recurring traffic patterns, and the detecting anomalies includes determining any of the forecast data outside a sensitivity boundary of the predefined interval width.

7 . The non-transitory computer-readable medium of claim 1 , wherein the time series data comprises multi-layer Performance Monitoring (PM) data selected from optical layer data, packet layer data, and service layer data, and wherein anomalies are detected by correlating deviations across at least two layers of PM data.

8 . The non-transitory computer-readable medium of claim 7 , wherein the steps further include

performing the determining the forecast data, the combining, the determining the normal operating range, the detecting, and the providing for one or more additional time series that are each different PM data in the network.

9 . A computer-implemented method comprising steps of:

determining forecast data from historical data of time series data where the forecast data is for a desired future time span, wherein the time series data relates to a network and describes network traffic therein, wherein the forecast data includes recurring anomalies predicted for the desired future time span and the time series data comprises network telemetry Performance Monitoring (PM) data including packet transmission, routing, or switching metrics;

combining the forecast data with the historical data to form a combined time series;

determining a normal operating range using the combined time series such that the normal operating range is determined based on both the historical data and the forecast data, wherein the normal operating range is defined by a fixed, predefined sensitivity boundary interval width explicitly configured in advance and independent of statistical confidence calculations, and wherein no statistical confidence bounds are computed for the time series;

detecting anomalies in the forecast data based on the normal operating range, wherein the normal operating range includes sensitivity boundaries defined by a predefined interval width on the combined time series, and wherein the detecting anomalies includes determining forecast data points including forecasted recurring anomalies in periodic or seasonal cycles that lie outside the sensitivity boundaries;

providing an output including the detected anomalies in the forecast data; and

triggering a workflow based on the output, wherein the workflow includes scaling up or down network resources in the network through automated actions comprising reallocating traffic across links, adjusting routing configurations, or scaling bandwidth based on the detected anomalies and their corresponding times based on the detected anomalies and their corresponding times.

10 . The computer-implemented method of claim 9 , wherein the steps further include

providing the output as an alert in a graphical user interface.

11 . The computer-implemented method of claim 10 , wherein the graphical user interface includes a dashboard that displays one or more of the detected anomalies in the forecast data and their corresponding times, associated equipment related to the detected anomalies, aggregate data for a plurality of time series and any detected anomalies, a number of forecasts, and a percentage of forecasts that came true.

12 . The computer-implemented method of claim 9 , wherein the time series data is for Performing Monitoring (PM) data for packet layer data, and wherein the PM data includes any of latency, jitter, error rate, RX bytes/packets, TX bytes/packets, or dropped packet bytes.

13 . The computer-implemented method of claim 12 , wherein the PM data is used to derive values for network traffic including one of a Committed Information Rate (CIR) and an Excess Information Rate (EIR).

14 . The computer-implemented method of claim 9 , wherein the normal operating range is determined using a forecast envelope that incorporates seasonality analysis to account for recurring traffic patterns, and the detecting anomalies includes determining any of the forecast data outside a sensitivity boundary of the predefined interval width.

15 . The computer-implemented method of claim 9 , wherein the time series data comprises multi-layer Performance Monitoring (PM) data selected from optical layer data, packet layer data, and service layer data, and wherein anomalies are detected by correlating deviations across at least two layers of PM data.

16 . The computer-implemented method of claim 15 , wherein the steps further include

performing the determining the forecast data, the combining, the determining the normal operating range, the detecting, and the providing for one or more additional time series that are each different PM data in the network.

17 . A processing device comprising:

one or more processors; and

memory storing instructions that, when executed, cause the one or more processors to

determine forecast data from historical data of time series data where the forecast data is for a desired future time span, wherein the time series data relates to a network and describes network traffic therein, wherein the forecast data includes recurring anomalies predicted for the desired future time span and the time series data represents telecommunications network traffic metrics including at least one of latency, jitter packet delay, throughput, or error rate

combine the forecast data with the historical data to form a combined time series,

determine a normal operating range using the combined time series such that the normal operating range is determined based on both the historical data and the forecast data, wherein the normal operating range is defined by a fixed, predefined sensitivity boundary interval width explicitly configured in advance and applied uniformly regardless of statistical variance, and wherein no statistica confidence intervals or residual error distributions are computed;

detect anomalies in the forecast data based on the normal operating range, wherein the normal operating range includes sensitivity boundaries defined by a predefined interval width on the combined time series, and wherein the anomalies are detected by determining forecast data points including forecasted recurring anomalies in periodic or seasonal patterns that lie outside the sensitivity boundaries,

provide an output including the detected anomalies in the forecast data, and

trigger a workflow based on the output, wherein the workflow includes scaling up or down network resources in the network through network control actions including scaling bandwidth, reallocating traffic, or adjusting routing parameters based on the detected anomalies and their corresponding times.

18 . The processing device of claim 17 , wherein the instructions that, when executed, cause the one or more processors to

provide the output as an alert in a graphical user interface.

19 . The processing device of claim 17 , wherein

time series data is for Performance Monitoring (PM) data for packet layer data, and wherein the PM data includes any of bandwidth, throughput, latency, jitter, error rate, RX bytes/packets, TX bytes/packets, or dropped packet bytes.

20 . The processing device of claim 17 , wherein the normal operating range is determined using a forecast envelope that incorpora easonality analysis to account for recurring traffic patterns, and the detecting anomalies includes determining any of the forecast data outside a sensitivity boundary of the predefined interval width.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2024
From: BRAHMANKAR, SAURABH DINESH; BARBER, CHRISTOPHER RYAN; NI, MINMING
To: CIENA CORPORATION
Reel/Frame 067120/0047 →
Priority Claims (1)
IN 202411015405 · Mar 1, 2024 · national
Continuity (1)
Related Publication 20250278678A1 · Sep 4, 2025
References Cited (24)
US 10015057B2 · Djukic et al. · 2018 [cited by applicant]
US 10129168B2 · Kaminski · 2018 [cited by examiner]
US 11356320B2 · Côté et al. · 2022 [cited by applicant]
US 11620528B2 · Ryan et al. · 2023 [cited by applicant]
US 11704539B2 · Amiri et al. · 2023 [cited by applicant]
US 11706100B2 · Poteat · 2023 [cited by examiner]
US 11726982B1 · Azam · 2023 [cited by examiner]
US 20120278051A1 · Jiang · 2012 [cited by examiner]
US 20150029847A1 · Puleri · 2015 [cited by examiner]
US 20160062950A1 · Brodersen · 2016 [cited by examiner]
US 20190222491A1 · Tomkins et al. · 2019 [cited by applicant]
US 20190280942A1 · Côté et al. · 2019 [cited by applicant]
US 20190303726A1 · Côté et al. · 2019 [cited by applicant]
US 20200065213A1 · Poghosyan · 2020 [cited by examiner]
US 20200387797A1 · Ryan et al. · 2020 [cited by applicant]
US 20210150305A1 · Amiri et al. · 2021 [cited by applicant]
US 20220335347A1 · Doan Huu · 2022 [cited by examiner]
US 20230011452A1 · Barber et al. · 2023 [cited by applicant]
US 20230022401A1 · Amiri et al. · 2023 [cited by applicant]
US 20230047781A1 · Narayanan · 2023 [cited by examiner]
US 20230057444A1 · Djukic et al. · 2023 [cited by applicant]
US 20230216747A1 · Barber et al. · 2023 [cited by applicant]
US 20230409875A1 · Djukic et al. · 2023 [cited by applicant]
US 20240242159A1 · Parthasarathy · 2024 [cited by examiner]
Cited By (1)
US 12,659,257