Anomaly detection and trend tracking system
Patent Information
- Application Number
- PCT/TR2025/051406
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-11-05
- Publication Date
- 2026-08-27
Smart Images

Figure TR2025051406_27082026_PF_FP_ABST
Abstract
Description
[0001] DESCRIPTION
[0002] ANOMALY DETECTION AND TREND TRACKING SYSTEM
[0003] Technical Field
[0004] The present invention relates to a system for performing anomaly and trend analysis by processing traffic data of network points in telecom infrastructure.
[0005] Background of the Invention
[0006] Today, the automation and integration of energy, refining and transportation infrastructures increases cyber security risks and makes industrial control systems communication networks more vulnerable to attacks. In this regard, industrial control systems are developing solutions based on statistical learning and deep learning methods for anomaly detection and event classification through the analysis of network traffic. However, in existing systems, significant deficiencies arise in the form of lack of real-time detection, high false positive rates, algorithmic complexity and low interpretability. In order to ensure the security of national critical infrastructures, there is a need for reliable and rapid solutions developed for more accurate and effective detection of anomalies occurring in industrial control systems communication networks.
[0007] For this reason, considering the studies and deficiencies included in the current technique, it is understood that there is a need for a system which provides shortterm anomaly detection and long-term trend change analysis by analyzing the traffic data of the network points in the telecom infrastructure.
[0008] The United States patent document no. US2022269258A1, an application included in the state of the art, discloses a system for detecting anomalies in ICS networks by integrating SARIMA and LSTM techniques. The said inventiondetermines, based on normal traffic data in the ICS communication network, the dynamic threshold ranges of real-time traffic data by integrating the LSTM deep learning model created by offline training and the distributed short-cycle SARIMA statistical learning models that can run online, and by performing a comparison with background traffic forecast sequences, presents a comprehensive method that performs anomaly detection, classification and source tracking based on numerical differences. In the system, while real-time data collected from components such as industrial switches, PLCs and servers are converted into instantaneous threshold intervals with SARIMA modules, the LSTM model generates background traffic forecast sequences by conducting offline training on large amounts of normal traffic data; the analysis of the differences between the outputs of these two models allows anomaly events occurring in the ICS network to be detected rapidly, accurately and dynamically and resource monitoring and security protection measures to be implemented through detailed digital statistical classification algorithms. In addition, it is aimed to ensure the security of ICS networks effectively by verifying the high detection rate, low false positive rate and real-time status alert capability of the method through experimental analysis conducted on test platforms where virtual and physical devices are present.
[0009] Summary of the Invention
[0010] An object of the present invention is to realize a system which continuously analyzes traffic information received from databases and enables automatic reporting of unusual changes by eliminating the need of manual monitoring in large-scale network infrastructures of telecommunication companies.
[0011] Detailed Description of the Invention
[0012] “Anomaly Detection and Trend Tracking System” realized to fulfil the objective of the present invention is shown in the figure attached, in which:Figure 1 is a schematic view of the inventive system.
[0013] The components illustrated in the figure are individually numbered, where the numbers refer to the following:
[0014] 1. System
[0015] 2. Database
[0016] 3. Server
[0017] The inventive system (1) for performing anomaly and trend analysis by processing traffic data of network points in telecom infrastructure comprises; at least one database (2) which is configured to enable traffic data received from network points to be stored and processed; and
[0018] at least one server (3) which is configured to detect short-term anomalies and long-term trend changes by analyzing traffic data received from the database (2); to identify irregularities in network traffic and to send notifications to the relevant units regarding the detected anomalies.
[0019] The database (2) included in the inventive system (1) is configured to establish communication and exchange data with the server (3) by using any communication protocol. The database (2) is configured to be managed by the server (3). The database (2) is configured to record and update the instantaneous data flow by containing the node code, node location, traffic information passing therethrough and time information of each network point included in the telecom infrastructure. The database (2) is configured to track outages, sudden traffic changes and connection continuity on the network. The database (2) is configured to store historical anomaly records, network outage durations, traffic density change rates, data packet losses, error types and frequencies, seasonal change indicators, threshold values determined by the operational unit, alarm notification history, regional traffic tendencies, infrastructure maintenance and repair records.The server (3) included in the inventive system (1) is configured to establish communication and exchange data with the database (2) by using any communication protocol. The server (3) is configured to enable optimum operating conditions for anomaly detection to be determined with the standard deviation and day variable used in line with the traffic data received from the database (2) in order to identify the sensitivity of the Prophet algorithm. The server (3) is configured to detect anomalies on the network by examining shortterm traffic changes by using the Prophet algorithm when the number of days analyzed is less than 180 and by identifying sudden drops and spikes and to enable automatic notifications to be sent to the relevant operational units. The server (3) is configured to analyze long-term traffic tendencies and to identify unusual trend changes by taking into account seasonal variations with the SARIMA (Seasonal Autoregressive Integrated Moving Average) algorithm, if the number of days is greater than 180. The server (3) is configured to distinguish whether traffic fluctuations are caused by seasonal effects or an anomalous situation by comparing the predicted traffic tendencies with the actual data. The server (3) is configured to enable the relevant units to take early action based on the analysis results. The server (3) is configured to categorize the detected anomaly types by comparing them with historical anomaly records received from the database (2) and to enable possible outages, capacity insufficiencies or unusual traffic behaviors on the network to be managed proactively by performing comparative analysis. The server (3) is configured to increase the accuracy of anomaly detection by minimizing false positive and negative rates by using the threshold values and standard deviation data set by the operational unit, during anomaly detection. The server (3) is configured to increase operational efficiency and to ensure the reliability of the telecommunication infrastructure in order to prevent outages in the event that unusual traffic activities are detected on the network.
[0020] Industrial Application of the InventionThe inventive system (1) provides service continuity by detecting the outages that may occur in the network infrastructures of telecom companies in advance, while enabling to increase operational efficiency by minimizing manual tracking processes.
[0021] Within these basic concepts; it is possible to develop various embodiments of the inventive “Anomaly Detection and Trend Tracking System (1)”; the invention cannot be limited to examples disclosed herein and it is essentially according to claims.
Claims
CLAIMS1. A system (1) for performing anomaly and trend analysis by processing traffic data of network points in telecom infrastructure; characterized byat least one database (2) which is configured to enable traffic data received from network points to be stored and processed; andat least one server (3) which is configured to detect short-term anomalies and long-term trend changes by analyzing traffic data received from the database (2); to identify irregularities in network traffic and to send notifications to the relevant units regarding the detected anomalies.
2. A system (1) according to Claim 1; characterized by the database (2) which is configured to establish communication and exchange data with the server (3) by using any communication protocol.
3. A system (1) according to Claim 1 or 2; characterized by the database (2) which is configured to be managed by the server (3).
4. A system (1) according to any one of the preceding claims; characterized by the database (2) which is configured to record and update the instantaneous data flow by containing the node code, node location, traffic information passing therethrough and time information of each network point included in the telecom infrastructure.
5. A system (1) according to any one of the preceding claims; characterized by the database (2) which is configured to track outages, sudden traffic changes and connection continuity on the network.
6. A system (1) according to any one of the preceding claims; characterized by the database (2) which is configured to store historical anomaly records, network outage durations, traffic density change rates, data packet losses, error types andfrequencies, seasonal change indicators, threshold values determined by the operational unit, alarm notification history, regional traffic tendencies, infrastructure maintenance and repair records.
7. A system (1) according to any one of the preceding claims; characterized by the server (3) which is configured to establish communication and exchange data with the database (2) by using any communication protocol.
8. A system (1) according to any one of the preceding claims; characterized by the server (3) which is configured to enable optimum operating conditions for anomaly detection to be determined with the standard deviation and day variable used in line with the traffic data received from the database (2) in order to identify the sensitivity of the Prophet algorithm.
9. A system (1) according to any one of the preceding claims; characterized by the server (3) which is configured to detect anomalies on the network by examining short-term traffic changes by using the Prophet algorithm when the number of days analyzed is less than 180 and by identifying sudden drops and spikes and to enable automatic notifications to be sent to the relevant operational units.
10. A system (1) according to any one of the preceding claims; characterized by the server (3) which is configured to analyze long-term traffic tendencies and to identify unusual trend changes by taking into account seasonal variations with the SARIMA algorithm, if the number of days is greater than 180.
11. A system (1) according to any one of the preceding claims; characterized by the server (3) which is configured to distinguish whether traffic fluctuations are caused by seasonal effects or an anomalous situation by comparing the predicted traffic tendencies with the actual data.
12. A system (1) according to any one of the preceding claims; characterized by the server (3) which is configured to enable the relevant units to take early action based on the analysis results.
13. A system (1) according to any one of the preceding claims; characterized by the server (3) which is configured to categorize the detected anomaly types by comparing them with historical anomaly records received from the database (2) and to enable possible outages, capacity insufficiencies or unusual traffic behaviors on the network to be managed proactively by performing comparative analysis.
14. A system (1) according to any one of the preceding claims; characterized by the server (3) which is configured to increase the accuracy of anomaly detection by minimizing false positive and negative rates by using the threshold values and standard deviation data set by the operational unit, during anomaly detection.
15. A system (1) according to any one of the preceding claims; characterized by the server (3) which is configured to increase operational efficiency and to ensure the reliability of the telecommunication infrastructure in order to prevent outages in the event that unusual traffic activities are detected on the network.