DETECTION METHOD, CORRESPONDING COMPUTER PROGRAM PRODUCT AND DETECTION SYSTEM
Patent Information
- Application Number
- DE602021031067
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-12-30
- Filing Date
- 2021-12-29
- Publication Date
- 2025-05-21
- Estimated Expiration
- 2041-12-29
Abstract
Description
[0001] The present invention relates to a method for detecting at least one group of abnormal nodes among a plurality of nodes in a communication network. The invention also relates to an associated computer program product.
[0002] The invention also relates to a detection system.
[0003] The invention relates to the field of management and monitoring of communication networks, such as computer networks. Such communication networks comprise a plurality of nodes connected to each other by communication links. The nodes are configured to implement connections via these communication links.
[0004] One or more nodes in the communication network may exhibit anomalies compared to other nodes. By "anomaly," it is understood that the node may establish connections with other nodes that exhibit a stochastic deviation from the connections established by the other nodes.
[0005] To detect anomalies, and in particular to detect nodes exhibiting an anomaly, known as abnormal nodes, it is known to implement detection methods including the analysis of node connections by static modeling, that is to say, in particular without taking into account dynamic characteristics of the connections.
[0006] In such a case, for example the total number of connections is recorded for a predefined period, for each node.
[0007] To identify anomalous nodes, for example, a statistical deviation in the number of recorded connections from a node is identified. This statistical deviation is defined in relation to the connections of other nodes.
[0008] However, such known detection methods are not entirely satisfactory, as the detection of abnormal nodes is not always reliable. In particular, in some cases, abnormal nodes are not detected.
[0009] Thus, one aim of the invention is to obtain a detection method that increases the reliability of detecting abnormal nodes.
[0010] To this end, the invention relates to a method for detecting at least one group of abnormal nodes among a plurality of nodes in a communication network, the nodes of the communication network being interconnected by communication links, each node being configured to establish at least one connection with at least one other node of the communication network via the respective communication link, said detection method comprising the following steps: receiving data relating to each connection between the plurality of nodes during an observation period, each connection being characterized by identifiers of the nodes linked by said connection and by a duration of said connection; determining a set of groups of nodes, each group of nodes being characterized by a group duration and by the nodes, chosen from the plurality of nodes, presenting at least one connection with each other node of the same group of nodes during the group duration; determining, for each group of nodes, at least one parameter characterizing the set of connections implemented within the group of nodes, obtaining said group of anomalous nodes from said parameter using a computational model obtained by machine learning, the computational model comparing the parameter with at least one reference parameter.
[0011] The detection process thus makes it possible to increase the reliability of detection of at least one group of abnormal nodes.
[0012] In particular, determining the set of node groups allows us to divide the nodes into groups of nodes characterized both by the nodes within the respective group and by the group duration. Thus, node groups allow us to account for the dynamic characteristics of the connections between the nodes within a group.
[0013] In particular, when the parameter changes during the observation period, this is detected by the detection process.
[0014] Unlike known detection methods, the detection method according to the present invention thus makes it possible to increase detection reliability by determining, for each group of nodes, the parameter, which is then used by the calculation model.
[0015] According to other advantageous aspects of the invention, the detection method comprises one or more of the following features, taken individually or in all technically possible combinations: the parameter is chosen from the list consisting of: the number of connections in the node group; a statistical parameter of the duration of the connections in the node group; a statistical parameter of a data rate of the connections in the node group; a statistical parameter of a connection density, the connection density of a communication link between two nodes in the node group being a probability of connection by this communication link at a given time during the group duration; and a statistical parameter of a degree of connection associated with each node in the node group, the degree of connection corresponding to the number of nodes connected, during the group duration, by a connection to the node presenting said degree of connection; the parameter is a parameter normalized to the number of nodes in the node group; at least one node is part of two distinct node groups, at distinct times in the observation period; the computational model includes an artificial neural network, with the parameter as an input variable of the artificial neural network and the anomalous node group as an output variable of the artificial neural network; the reference parameter is determined based on the parameter of each node group; at least one connection between two nodes in a node group is an indirect connection, the indirect connection being established through at least one third node in the node group.
[0016] The invention also relates to a computer program product comprising software instructions which, when executed by a computer, implement a detection method as described above.
[0017] The invention also relates to a system for detecting at least one group of abnormal nodes among a plurality of nodes in a communication network, the nodes of the communication network being interconnected by communication links, each node being configured to establish at least one connection with at least one other node of the communication network via the respective communication link, the detection system comprising: a receiving module configured to receive data relating to each connection between the plurality of nodes during an observation period, each connection being characterized by identifiers of the nodes linked by said connection and by a duration of said connection; a first determination module configured to determine a set of groups of nodes, each group of nodes being characterized by a group duration and by the nodes, chosen from the plurality of nodes, presenting at least one connection with each other node of the same group of nodes during the group duration;a second determination module configured to determine, for each group of nodes, at least one parameter characterizing the set of connections implemented within the group of nodes, and a retrieval module configured to obtain said group of anomalous nodes from said parameter using a computational model obtained by machine learning, the computational model being configured to compare the parameter with at least one reference parameter. ;
[0018] The invention also relates to an assembly comprising the detection system as described above and a communication network.
[0019] These features and advantages of the invention will become clearer upon reading the following description, given solely by way of non-limiting example, and made with reference to the accompanying drawings, in which: [ Fig 1 ] there figure 1 is a schematic representation of an assembly comprising a communication network and a detection system configured to implement the detection method according to the invention; [ Fig 2 ] there figure 2 is a schematic representation showing time-varying connections between nodes in the communication network, the connections being detected by the detection system of the figure 1 ; Fig 3 ] there figure 3 is a schematic representation comprising a plurality of graphs representing groups of nodes defined according to the connections shown on the figure 2 , And [ Fig 4 ] there figure 4 is a schematic representation showing the degrees of connection of the nodes as a function of time.
[0020] On the figure 1 , a set 1 includes a communication network 2 and a control system 4.
[0021] The communication network 2 comprises a plurality of nodes N, labeled N1, N2, N3, N4, N5, and N6 in the examples in the figures. The nodes N are connected to each other by communication links 6.
[0022] By "communication link", we mean the possibility of establishing a connection C between two nodes N.
[0023] Only certain communication links (6) are represented on the figure 1 for visibility reasons.
[0024] In particular, each node N has a communication link 6 with each other node N of the communication network 2.
[0025] Alternatively, some nodes N have communication links 6 only with a subset of the nodes N in the plurality of nodes.
[0026] Each node N is configured to establish at least one connection C with at least one other node N of the communication network 2 via the respective communication link 6.
[0027] By "connection" we mean an exchange and / or transmission of data between two nodes N.
[0028] Communication network 2, for example, is configured to implement the internet protocol or IP (from the English "internet protocol"). In this case, each node N has, among other things, an IP address.
[0029] Communication network 2 is, for example, a company network or a network of a public body.
[0030] The detection system 4 includes a receiving module 8, a first determination module 10, a second determination module 12 and an acquisition module 14.
[0031] The receiving module 8 is configured to receive data relating to each connection C between the plurality of nodes N during an observation period.
[0032] The first determination module 10 is configured to determine a set of node groups G. Each node group G is characterized by a group duration and by the nodes N, chosen from the plurality of nodes N, exhibiting at least one connection C with each other node N in the same node group G during the group duration.
[0033] The second determination module 12 is configured to determine, for each group of nodes G, at least one parameter characterizing the set of connections C implemented within the group of nodes G.
[0034] The acquisition module 14 is configured to obtain the group of abnormal nodes from the parameter using a computation model 20 obtained by machine learning.
[0035] The receiving module 8, the first determining module 10, the second determining module 12 and the obtaining module 14 are each, for example, integrated into at least one computer 16.
[0036] In this case, each of the modules among the receiving module 8, the first determining module 10, the second determining module 12 and the obtaining module 14 is at least partially in the form of software executable by a processor and stored in a memory of the computer 16.
[0037] Alternatively or in addition, each of the modules among the receiving module 8, the first determining module 10, the second determining module 12 and the obtaining module 14 is integrated, at least partially, into a physical device, such as for example a programmable logic circuit, such as an FPGA (from the English "Field Programmable Gate Array"), or in the form of a dedicated integrated circuit, such as an ASIC (from the English "Application Specific Integrated Circuit").
[0038] In addition, the detection system 4 also includes a display module 18.
[0039] A detection method will now be described, this method being implemented by detection system 4.
[0040] The detection process includes a reception step, a first determination step, a second determination step and a retrieval step.
[0041] During the reception stage, the reception module 8 receives data relating to each connection between the plurality of nodes during an observation period. In the examples of figures 2 à 4 , the observation period is 5 time units t, for example 5 seconds.
[0042] The data includes identifiers of the N nodes connected by the connection. Each identifier is, for example, an IP address according to the internet protocol.
[0043] The data also includes a connection duration. Each connection C is thus characterized by the identifiers of the nodes N connected by said connection C and by the connection duration.
[0044] THE figure 2 is a schematic representation showing the time-varying connections between the nodes N, called nodes N1 to N6.
[0045] Each node N is present in the communication network 2 for one or more periods of presence.
[0046] When a node N is present, it implements at least one connection C with another node N. For example, node N1 is present in the period from t=0 to t=5, as is node N2. Node N3 is present in the period from t=0 to t=1. Node N4 is present in the period from t=0 to t=1 and in the period from t=2 to t=3. Node N5 is present in the period from t=1 to t=5. Node N6 is present in the period from t=0 to t=3.
[0047] Each node N implements connections C during its presence with at least one other node N. Each connection C has a connection duration D.
[0048] With reference to the figure 2 , the C connections are named C1, C2, C3, C4 and C5 in this example.
[0049] Node N1, for example, establishes a C1 connection with node N2 for a duration D extending from t=0 to t=4. Node N3, for example, establishes a C2 connection with node N4 for a duration D extending from t=0 to t=1. Node N4, for example, establishes a C3 connection with node N5 for a duration D extending from t=2 to t=3. Node N2, for example, establishes a C4 connection with node N5 for a duration D converging to 0. For example, connection C4 transmits a single data packet between node N2 and node N5. Node N5, for example, establishes a C5 connection with node N6 for a duration D extending from t=0 to t=3.
[0050] Each connection C is, in particular, a bidirectional connection. For example, data is exchanged between the two nodes N connected by the connection. Alternatively, at least one connection is a unidirectional connection.
[0051] During the first determination step, the first determination module 10 determines a set of node groups G, for example visible on the figure 3 .
[0052] Each group of nodes G is characterized by a group duration and by the nodes N, chosen from the plurality of nodes N that are part of the group of nodes G.
[0053] Each node in the node group G has at least one connection with each other node N in the same node group G during the group duration.
[0054] The nodes N of the same group of nodes G are also called strongly connected nodes.
[0055] Nodes N that are not part of a respective group of nodes G during the group duration are also called weakly connected nodes with respect to the nodes N of that group of nodes G.
[0056] In particular, weakly connected nodes do not implement a connection with the N nodes of the node group during the group duration.
[0057] In particular, the N nodes of the same group of nodes have a connection C to the other N nodes of the group for the entire duration of the group.
[0058] For example, each node N of a respective group of nodes G implements a connection C with every other node in that group of nodes G, in particular directly or through at least one other node N in that group of nodes G.
[0059] For example, at least one connection C between two nodes N of a group of nodes G is an indirect connection. The indirect connection is established through at least one third node N of the group of nodes G to which the two nodes N belong.
[0060] The group duration is in particular the period during which each node N of the group of nodes G has a connection with each other node N of the group of nodes G.
[0061] In particular, the group duration defines the period of time of the existence of a group of nodes G. All the nodes of this group are connected to each other during this period.
[0062] According to one example, at least some nodes are likely to continue to exist in smaller or larger groups after this period.
[0063] The connection between the nodes of the node group G is in particular either a direct connection or an indirect connection during the duration of this group.
[0064] By "direct connection" it is understood that at least one communication link 6 connects for example two nodes directly, without passing through another node.
[0065] By "indirect connection", it is understood in particular that two nodes N are not connected by a direct connection, but are connected by communication links 6 via at least one intermediate node N.
[0066] Preferably, there is a connection between two nodes N from the plurality of nodes for a given duration if and only if there are communication links 6 allowing by successive hops to reach one of the considered nodes from the other.
[0067] According to an example not shown, for a group of nodes G comprising nodes A, B, C, D, the connection between nodes A and C is ensured during the first half of the group duration by the communication links AB and BC and then during the second half by the links AD and DC (the communication link AC having been interrupted).
[0068] Preferably, the connection structure is likely to change during the group duration between the nodes of the group, but these nodes of the group are connected directly or indirectly to each other throughout the group duration.
[0069] In the example of the figure 3 , groups of nodes G, called groups of nodes G0 to G8 in this figure, are represented.
[0070] The node group G0 includes nodes N3 and N4 during the group duration extending from t=0 to t=1. As seen on the figure 2 , nodes N3 and N4 are directly connected to each other via connection C2 during the group duration.
[0071] The node group G2 includes nodes N4, N5 and N6 during the group duration extending from t=2 to t=3.
[0072] As seen on the figure 2 , node N4 is connected to node N5 by connection C3 during the group duration, and node N4 is connected to node N6 via node N5, and via connections C3 and C5 during the group duration of the node group G2.
[0073] Thus, nodes N4, N5 and N6 of the node group G2 are, in particular throughout the duration of the group of group G2, connected to each other.
[0074] The node group G3 includes nodes N1 and N2 during the group duration extending from t=0 to t=4. As seen on the figure 2 , these nodes are connected to each other by the C1 connection.
[0075] The node group G4 includes nodes N5 and N2 during the group duration converging to 0 at time t=4.
[0076] The node groups G5, G6, G7 and G8 each comprise a single node N5, N5, N2 and N1 during their respective group duration.
[0077] For example, with respect to node group G5, node N5 is present during the group duration extending from t=3 to t=4 and has no connection with another node N during the group duration of group G5. Thus, no other node N is present in the node group G5 of the example.
[0078] Specifically, at least one node N belongs to two distinct groups of nodes G, at distinct times during the observation period. For example, node N5 belongs to the groups of nodes G1, G2, G5, and G6 for their respective group durations.
[0079] During the second determination step, the second determination module 12 determines, for each group of nodes G, at least one parameter characterizing the set of connections implemented within the group of nodes.
[0080] The parameter is notably a parameter characterizing the behavior of a node N with respect to the connections established by this node N during the group duration.
[0081] For example, the parameter includes the number of C connections in the node group G. The node groups G0, G1, G3 and G4 in the example figures each include one C connection, the node group G2 includes two C connections and the other node groups in the example include no C connections.
[0082] For example, the parameter includes at least one statistical parameter of the connection duration C of the node group G, such as an average, for example an arithmetic mean, or a variance of the connection duration of the node group G.
[0083] For example, the parameter includes at least one statistical parameter of a data rate of the C connections of the node group, such as an average, for example an arithmetic mean, or a variance of the data rate of the C connections.
[0084] For example, the parameter includes at least one statistical parameter of a connection density, such as a mean, for example an arithmetic mean, or a variance of the connection density.
[0085] The connection density of a communication link 6 between two nodes N of the group of nodes G is the probability of connection through this communication link 6 at a given time during the group's duration. The connection density can, for example, have a value between 0 and 1.
[0086] For example, the parameter includes at least one statistical parameter of a degree of connection associated with each node N of the group of nodes G, such as a mean, for example an arithmetic mean, or a variance of the degrees of connection.
[0087] The degree of connection corresponds to the number of nodes N linked, during the group duration, by a connection C to the node N exhibiting said degree of connection.
[0088] There figure 3 is a schematic representation of an example of the degree of connection for each node N during the observation period.
[0089] Node N5 has a degree of connection of 2 during the period from t=2 to t=3. Specifically, node N5 is connected to both node N4 and node N6 during this period. Therefore, node N5 has a degree of connection of 2 for the duration of group G2.
[0090] Following the example of the figure 3, nodes N1 to N4 and N6 exhibit, during the observation period, a degree of connection equal to 1, when they are connected to another node N.
[0091] Node N5 also has a degree of connection equal to 1 during the group duration of node group G1, i.e. from t=0 to t=2.
[0092] For example, the parameter includes at least one statistical parameter related to another parameter of graph theory, such as a k-core, a k-clique, a proximity (or "closeness" in English), an intermediate centrality, an intermediate centrality or betweenness.
[0093] In particular, the parameter is a normalized parameter on the number of nodes N in the group of nodes G.
[0094] According to one example, the parameter is a normalized parameter on a number of possible connections between the nodes N of the group of nodes G.
[0095] During the acquisition step, the acquisition module 14 obtains the group of abnormal nodes from the parameter using the computational model 20 obtained through machine learning. The computational model 20 compares the parameter with at least one reference parameter.
[0096] For example, the acquisition module 14 calculates the reference parameter based on the parameter of each node group G. For example, the reference parameter is an average of the parameters of each node group G, such as an arithmetic mean, a harmonic mean, a geometric mean, or a quadratic mean.
[0097] The computational model 20 includes, for example, an artificial neural network 22, an input variable of the artificial neural network 22 being the parameter, and an output variable of the artificial neural network 22 being the group of abnormal nodes.
[0098] As an example, calculation model 20 implements an anomaly detection algorithm called "Isolation Forest".
[0099] The detection process also includes, for example, a display step, during which information relating to the group of abnormal nodes is displayed on the display module 18.
[0100] The detection process includes, in particular, a training phase, implemented prior to the implementation of the reception step, the first determination step, the second determination step and the obtaining step.
[0101] During the training phase, the computing model 20 is trained by a machine learning device 24. For example, the machine learning device 24 provides the computing model 20 with the input parameter, and teaches the computing model 20 the abnormal node group(s) when the connections C of the node groups G have the input parameter.
Claims
1. A method for detecting at least one group of abnormal nodes among a plurality of nodes (N1, ... N6) of a communication network (2), the nodes (N1, ... N6) of the communication network (2) being interconnected by communication links (6), each node (N1, ... N6) being configured to establish at least one connection (C1, ... C6) with at least one other node (N1, ... N6) of the communication network (2) via the respective communication link (6), said detection method comprising the following steps: - receiving data relating to each connection (C1, ... C6) between the plurality of nodes (N1, ... N6) during an observation period, each connection (C1, ... C6) being characterized by identifiers of the nodes (N1, ... N6) connected by said connection (C1, ... C6) and by a duration of said connection (C1, ... C6); - determination of a set of node groups (G1, ... G8), each node group (G1, ... G8) being characterized bya group duration and by the nodes (N1, ... N6), chosen from the plurality of nodes (N1, ... N6), presenting at least one connection (C1, ... C6) with each other node (N1, ... N6) of the same group of nodes (G1, ... G8) during the group duration; - determination, for each group of nodes (G1, ... G8), of at least one parameter characterizing the set of connections (C1, ... C6) implemented within the group of nodes (G1, ... G8), - obtaining said group of abnormal nodes from said parameter using a calculation model (20) obtained by machine learning, the calculation model (20) comparing the parameter with at least one reference parameter.
2. A detection method according to claim 1, wherein the parameter is chosen from the list consisting of: - the number of connections (C1, ... C6) of the node group (G1, ... G8); - a statistical parameter of the duration of the connections (C1, ... C6) of the node group (G1, ... G8); - a statistical parameter of a data rate of the connections (C1, ... C6) of the node group (G1, ... G8); - a statistical parameter of a connection density, the connection density of a communication link (6) between two nodes (N1, ... N6) of the node group (G1, ... G8) being a probability of connection by this communication link (6) at a given time during the group duration; and - a statistical parameter of a degree of connection associated with each node (N1, ... N6) of the group of nodes (G1, ... G8), the degree of connection corresponding to the number of nodes (N1, ... N6) linked, during the duration of the group, by a connection (C1, ... C6) to the node (N1, ...N6) exhibiting said degree of connection.
3. Detection method according to claim 1 or 2, wherein the parameter is a parameter normalized to the number of nodes (N1, ... N6) of the node group (G1, ... G8).
4. A detection method according to any one of the preceding claims, wherein at least one node (N1, ... N6) is part of two distinct groups of nodes (G1, ... G8), at distinct times in the observation period.
5. A detection method according to any one of the preceding claims, wherein the computational model (20) comprises an artificial neural network (22), an input variable of the artificial neural network (22) being the parameter, and an output variable of the artificial neural network (22) being the group of abnormal nodes.
6. A detection method according to any one of the preceding claims, wherein the reference parameter is determined as a function of the parameter of each group of nodes (G1, ... G8).
7. A detection method according to any one of the preceding claims, wherein at least one connection (C1, ... C6) between two nodes (N1, ... N6) of a group of nodes (G1, ... G8) is an indirect connection, the indirect connection being established via at least one third node (N1, ... N6) of the group of nodes (G1, ... G8).
8. Product computer program comprising software instructions which, when executed by a computer, implement a detection method according to any one of the preceding claims.
9. A detection system (4) for at least one group of abnormal nodes among a plurality of nodes (N1, ... N6) of a communication network (2), the nodes (N1, ... N6) of the communication network (2) being interconnected by communication links (6), each node (N1, ... N6) being configured to establish at least one connection (C1, ... C6) with at least one other node (N1, ... N6) of the communication network (2) via the respective communication link (6), the detection system (4) comprising: - a receiving module (8) configured to receive data relating to each connection (C1, ... C6) between the plurality of nodes (N1, ... N6) during an observation period, each connection (C1, ... C6) being characterized byidentifiers of the nodes (N1, ... N6) connected by said connection (C1, ... C6) and by a duration of said connection (C1, ... C6); - a first determination module (10) configured to determine a set of node groups (G1, ... G8), each node group (G1, ... G8) being characterized bya group duration and by the nodes (N1, ... N6), chosen from the plurality of nodes (N1, ... N6), presenting at least one connection (C1, ... C6) with each other node (N1, ... N6) of the same group of nodes (G1, ... G8) during the group duration; - a second determination module (12) configured to determine, for each group of nodes (G1, ... G8), at least one parameter characterizing the set of connections (C1, ... C6) implemented within the group of nodes (G1, ... G8), and - a obtaining module (14) configured to obtain said group of anomalous nodes from said parameter using a computation model (20) obtained by machine learning, the computation model (20) being configured to compare the parameter with at least one reference parameter.
10. Assembly (1) comprising a detection system according to the preceding claim and a communication network (2).