Anomaly Detection via Adaptive Traffic Flow Sampling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current anomaly detection methods in computer networks face challenges such as lack of ground truth, dynamic network behaviors, and differentiating between noise and anomalies, especially in the context of distributed Denial of Service (DoS) attacks, where malicious behaviors can adapt to appear normal and overwhelm resources.
Innovation Solution
A self-learning network (SLN) infrastructure that selects a subset of reporting devices to provide sampled traffic flow data to an anomaly detection device, utilizing machine learning techniques to identify patterns and differentiate between normal and abnormal behavior, while also employing mechanisms to manage resource constraints and prevent network congestion.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If all network devices report traffic flow data to the anomaly detection device, then the detection accuracy improves, but the network congestion and resource overhead increase
Solution Approach 1:
The patent segments the network devices into different groups based on their traffic flow characteristics and anomaly patterns. Instead of having all devices report to a single anomaly detection device, the network is divided into multiple regions or zones, each with its own anomaly detection device. This segmentation reduces the traffic load on individual devices while maintaining comprehensive coverage for anomaly detection across the entire network.
2Reliability
If more reporting devices are selected to provide traffic flow data, then the anomaly detection capability improves, but the resource consumption and processing overhead increase
Solution Approach 1:
The patent dynamically adjusts the reporting parameters of selected devices based on network conditions, traffic patterns, and anomaly detection needs. Reporting frequency, data granularity, and sampling rates are modified as parameters to optimize the balance between detection reliability and energy consumption. This allows the system to maintain high detection accuracy while adapting resource usage to current network demands.
3Area of stationary object
If traffic flow reporting is implemented across the entire network, then the coverage for detecting distributed DoS attacks improves, but the network performance and legitimate traffic flow deteriorate
Solution Approach 1:
The patent implements partial reporting where only a subset of traffic flow data is reported to anomaly detection devices, rather than complete traffic flow information. By selecting representative samples or reporting only anomalous traffic patterns, the system achieves sufficient detection coverage for distributed DoS attacks while minimizing the impact on network throughput and legitimate traffic performance.
Data Source
AI summary
In one embodiment, a first device in a network receives traffic flow data from a plurality of devices in the network. The traffic flow data from at least one of the plurality of devices comprises raw packets of a traffic flow. The first device selects a set of reporting devices from among the plurality of devices based on the received traffic flow data. The first device provides traffic flow reporting instructions to the selected set of reporting devices. The traffic flow reporting instructions cause each reporting device to provide sampled traffic flow data to an anomaly detection device.


