US 12,316,518 B2
Network anomaly detection
Mikhal Shemer, Tel Aviv (IL); Roee Engelberg, Tel Aviv (IL); Yonit Tova Halperin Worzel, Tel Aviv (IL); Alex Gontmakher, Holon (IL); Alexander Goldshtein, Tel Aviv (IL); Gal Elidan, Modiin (IL); and Benjamin Dov Kessler, Jerusalem (IL)
Assigned to Google LLC, Mountain View, CA (US)
Filed by Google LLC, Mountain View, CA (US)
Filed on Jan. 22, 2024, as Appl. No. 18/419,024.
Application 18/419,024 is a continuation of application No. 18/158,623, filed on Jan. 24, 2023, granted, now 11,929,900.
Application 18/158,623 is a continuation of application No. 17/381,909, filed on Jul. 21, 2021, granted, now 11,595,282, issued on Feb. 28, 2023.
Claims priority of provisional application 63/054,493, filed on Jul. 21, 2020.
Prior Publication US 2024/0163193 A1, May 16, 2024
This patent is subject to a terminal disclaimer.
Int. Cl. G06F 15/173 (2006.01); G06F 9/455 (2018.01); G06F 18/214 (2023.01); H04L 41/0604 (2022.01); H04L 41/0631 (2022.01); H04L 43/065 (2022.01); H04L 43/0817 (2022.01)
CPC H04L 43/0817 (2013.01) [G06F 9/45558 (2013.01); G06F 18/214 (2023.01); H04L 41/0627 (2013.01); H04L 41/0631 (2013.01); H04L 43/065 (2013.01); G06F 2009/45575 (2013.01); G06F 2009/45595 (2013.01)] 16 Claims
OG exemplary drawing
 
1. A method of detecting states of a network, the method comprising:
generating, by one or more processors, at least a first model for detecting a current state of the network based on characteristics of a given virtual machine;
obtaining, by the one or more processors, time series data related to network parameters associated with the current state of the network based on the given virtual machine;
determining, by the one or more processors, that the current state of the network meets a predetermined state differing from a normal state of the network using at least the first model based on the time series data;
providing, by the one or more processors, an actionable notification in response to determining that the current state of the network meets the predetermined state differing from the normal state of the network; and
performing, by the one or more processors, an action in response to determining that the current state of the network meets the predetermined state differing from the normal state of the network, wherein the action comprises at least one of: restarting the network, changing security protocols, changing firewall rules, or stopping or slowing egress or ingress of traffic.