IP Library Granted Patent US 12,726,423
Granted Patent B2
US 12,726,423 · App. 18/131,298 · Granted Sep 1, 2026

Inferring QoE degradation from implicit signals in user behavior

Inventors: Grégory Mermoud (Venthône, CH); Michal Wladyslaw Garcarz (Cracow, PL); Jean-Philippe Vasseur (Combloux, FR)
Assignee: Cisco Technology, Inc.
H04L43/0823H04L43/0852H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,726,423
App. No.
18/131,298
Granted
Sep 1, 2026
Kind
B2
Abstract

In one embodiment, a device obtains interaction data indicative of a flow of interactions performed by a user with an online application accessible via a network. The device detects an anomaly by applying an anomaly detection model to the interaction data. The device determines that the anomaly is attributable to a condition present in the network. The device causes performance of an adjustment to the network, to mitigate the condition.

Claims (44)

1 . A method comprising:

obtaining, by a device, interaction data indicative of a flow of interactions performed by a user with an online application accessible via a network, wherein the interaction data is captured by a web browser or a browser plugin installed to an endpoint operated by the user and used to access the online application via the network;

determining, by the device, a first score indicative of an anomaly associated with the interactions performed by the user by applying an anomaly detection model to the interaction data, wherein the anomaly detection model compares the interaction data to a user activity graph to detect the anomaly;

inputting, by the device, network telemetry and the first score indicative of the anomaly as input to a prediction model;

generating, by the device, through executing the prediction model, and based on the network telemetry and the first score indicative of the anomaly, a second score indicative of a presence of a network performance condition in the network; and

causing, by the device and based on the first score indicative of the anomaly associated with the interactions performed by the user and the second score indicative of the presence of the network performance condition, performance of an adjustment to the network to mitigate the network performance condition.

2 . The method as in claim 1 , wherein the adjustment to the network comprises rerouting application traffic sent between an endpoint of the user and the online application via a first path in the network to a second path in the network.

3 . The method as in claim 1 , wherein the network telemetry is indicative of at least one of path loss, latency, or jitter in the network.

4 . The method as in claim 1 , wherein the interaction data is based on browser waterfall data that is captured by the web browser or the browser plugin.

5 . The method as in claim 4 , wherein the browser waterfall data indicates resource requests sent by the web browser during a session with the online application, protocol information for the resource requests, and timing information for the resource requests.

6 . The method as in claim 1 , wherein the anomaly detection model is specific to a geographic location or employment information associated with the user.

7 . The method as in claim 1 , wherein the anomaly detection model computes a probability of the user performing a particular action within the online application over time as the first score, and the first score indicates a Quality of Experience (QoE) of the user with the online application.

8 . The method as in claim 1 , further comprising:

providing, by the device, the interaction data to a user interface for display.

9 . The method as in claim 1 , wherein the interaction data comprises a graph of user actions within the online application.

10 . An apparatus, comprising:

one or more network interfaces;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process when executed configured to:

obtain interaction data indicative of a flow of interactions performed by a user with an online application accessible via a network, wherein the interaction data is captured by a web browser or a browser plugin installed to an endpoint operated by the user and used to access the online application via the network;

determine a first score indicative of an anomaly associated with the interactions performed by the user, by applying an anomaly detection model to the interaction data, wherein the anomaly detection model compares the interaction data to a user activity graph to detect the anomaly;

input network telemetry and the first score indicative of the anomaly to a prediction model;

generate, through executing the prediction model, and based on the network telemetry and the first score indicative of the anomaly, a second score indicative of a presence of a network performance condition in the network; and

cause, based on the first score indicative of the anomaly associated with the interactions performed by the user and the second score indicative of the presence of the network performance condition, a performance of an adjustment to the network to mitigate the network performance condition.

11 . The apparatus as in claim 10 , wherein the adjustment to the network comprises rerouting application traffic sent between an endpoint of the user and the online application via a first path in the network to a second path in the network.

12 . The apparatus as in claim 10 , wherein the network telemetry is indicative of at least one of path loss, latency, or jitter in the network.

13 . The apparatus as in claim 10 , wherein the interaction data is based on browser waterfall data captured by the web browser or the browser plugin.

14 . The apparatus as in claim 13 , wherein the browser waterfall data indicates resource requests sent by the web browser during a session with the online application, protocol information for the resource requests, and timing information for the resource requests.

15 . The apparatus as in claim 10 , wherein the anomaly detection model is specific to a geographic location or employment information associated with the user.

16 . The apparatus as in claim 10 , wherein the anomaly detection model computes a probability of the user performing a particular action within the online application over time as the first score, and the first score indicates a Quality of Experience (QoE) of the user with the online application.

17 . The apparatus as in claim 10 , wherein the process when executed is further configured to:

provide the interaction data to a user interface for display.

18 . A tangible, non-transitory, computer-readable medium storing program instructions that cause a device to execute a process comprising:

obtaining, by the device, interaction data indicative of a flow of interactions performed by a user with an online application accessible via a network, wherein the interaction data is captured by a web browser or a browser plugin installed to an endpoint operated by the user and used to access the online application via the network;

determining, by the device, a first score indicative of an anomaly associated with the interactions performed by the user, by applying an anomaly detection model to the interaction data, wherein the anomaly detection model compares the interaction data to a user activity graph to detect the anomaly;

inputting, by the device, network telemetry and the first score indicative of the anomaly to a prediction model;

generating, by the device, through executing the prediction model, and based on the network telemetry and the first score indicative of the anomaly, a second score indicative of a presence of a network performance condition in the network; and

causing, by the device and based on the first score indicative of the anomaly associated with the interactions performed by the user and the second score indicative of the presence of the network performance condition, performance of an adjustment to the network to mitigate the network performance condition.

19 . The method of claim 1 , wherein causing, by the device and based on the first score indicative of the anomaly associated with the interactions performed by the user and the second score indicative of the presence of the network performance condition, performance of an adjustment to the network to mitigate the network performance condition, further comprises:

comparing, by the device, the first score with the second score; and

determining, by the device and based on a difference between the first score and the second score, that the anomaly is caused by the network performance condition.

20 . The method of claim 1 , wherein the anomaly detection model includes a machine learning model that is trained by performing:

classifying training data into classes based at least in part on labels associated with the training data; and

minimizing a cost function associated with the machine learning model.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 5, 2023
From: MERMOUD, GRÉGORY; GARCARZ, MICHAL WLADYSLAW; VASSEUR, JEAN-PHILIPPE
To: CISCO TECHNOLOGY, INC.
Reel/Frame 063235/0596 →
Continuity (1)
Related Publication 20240340228A1 · Oct 10, 2024
References Cited (32)
US 10333958B2 · Huang et al. · 2019 [cited by applicant]
US 10862771B2 · Tomkins et al. · 2020 [cited by applicant]
US 11856014B2 · Kare · 2023 [cited by examiner]
US 12212470B2 · Donthireddy · 2025 [cited by examiner]
US 12238129B2 · Huang · 2025 [cited by examiner]
US 12323452B1 · Tsironis · 2025 [cited by examiner]
US 20140137246A1 · Baluda · 2014 [cited by examiner]
US 20170126475A1 · Mahkonen · 2017 [cited by examiner]
US 20170250855A1 · Patil · 2017 [cited by examiner]
US 20170318043A1 · Shin · 2017 [cited by examiner]
US 20170325120A1 · Szilagyi et al. · 2017 [cited by applicant]
US 20180124082A1 · Siadati · 2018 [cited by examiner]
US 20180124114A1 · Woods · 2018 [cited by examiner]
US 20180302272A1 · Makovsky · 2018 [cited by examiner]
US 20180316713A1 · Tsironis · 2018 [cited by examiner]
US 20190116131A1 · Patil · 2019 [cited by examiner]
US 20210211347A1 · Vasseur · 2021 [cited by examiner]
US 20220027431A1 · Zheng et al. · 2022 [cited by applicant]
US 20220059619A1 · Kubota · 2022 [cited by examiner]
US 20220131886A1 · Smelov et al. · 2022 [cited by applicant]
US 20220165432A1 · Pickus · 2022 [cited by examiner]
US 20220345473A1 · Kare · 2022 [cited by examiner]
US 20230029794A1 · Huang · 2023 [cited by examiner]
US 20230262072A1 · Cambric · 2023 [cited by examiner]
US 20240015076A1 · Donthireddy · 2024 [cited by examiner]
US 20240161076A1 · Raiskin · 2024 [cited by examiner]
WO WO2021141674A1 · 2021 [cited by examiner]
“Endpoint Views Reference”, online: https://docs.thousandeyes.com/product-documentation/end-user-monitoring/viewing-data/endpoint-agent-views-reference, accessed Mar. 27, 2023, 21 pages. [cited by applicant]
“XMLHttpRequest”, online: https://en.wikipedia.org/wiki/XMLHttpRequest, accessed Mar. 27, 2023, 7 pages. [cited by applicant]
“Workday”, online: https://www.workday.com/, accessed Mar. 27, 2023, 5 pages. [cited by applicant]
“Github”, online: https://github.com/, accessed Mar. 27, 2023, 16 pages. [cited by applicant]
Huang, et al., “User See, User Point: Gaze and Cursor Alignment in Web Search”, CHI '12: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, May 2012, pp. 1341-1350, Association for Computing Mac… [cited by applicant]