Anomaly Detection via Adaptive Traffic Flow Sampling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anomaly detection methods in computer networks face challenges such as lack of ground truth, dynamic network behaviors, and differentiating between noise and anomalies, especially in the context of distributed Denial of Service (DoS) attacks, where malicious behaviors can adapt to appear normal and overwhelm resources.

Innovation Solution

A self-learning network (SLN) infrastructure that selects a subset of reporting devices to provide sampled traffic flow data to an anomaly detection device, utilizing machine learning techniques to identify patterns and differentiate between normal and abnormal behavior, while also employing mechanisms to manage resource constraints and prevent network congestion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If all network devices report traffic flow data to the anomaly detection device, then the detection accuracy improves, but the network congestion and resource overhead increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidnetwork traffic volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent segments the network devices into different groups based on their traffic flow characteristics and anomaly patterns. Instead of having all devices report to a single anomaly detection device, the network is divided into multiple regions or zones, each with its own anomaly detection device. This segmentation reduces the traffic load on individual devices while maintaining comprehensive coverage for anomaly detection across the entire network.

Inventive Principle:
Principle #1Segmentation

2Reliability

If more reporting devices are selected to provide traffic flow data, then the anomaly detection capability improves, but the resource consumption and processing overhead increase

Engineering Contradiction:
Improveanomaly detection reliabilityVSAvoiddevice processing energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent dynamically adjusts the reporting parameters of selected devices based on network conditions, traffic patterns, and anomaly detection needs. Reporting frequency, data granularity, and sampling rates are modified as parameters to optimize the balance between detection reliability and energy consumption. This allows the system to maintain high detection accuracy while adapting resource usage to current network demands.

Inventive Principle:
Principle #35Parameter changes

3Area of stationary object

If traffic flow reporting is implemented across the entire network, then the coverage for detecting distributed DoS attacks improves, but the network performance and legitimate traffic flow deteriorate

Engineering Contradiction:
Improveanomaly detection coverageVSAvoidnetwork throughput
Core Design Contradiction:
Area of stationary objectVSProductivity

Solution Approach 1:

The patent implements partial reporting where only a subset of traffic flow data is reported to anomaly detection devices, rather than complete traffic flow information. By selecting representative samples or reporting only anomalous traffic patterns, the system achieves sufficient detection coverage for distributed DoS attacks while minimizing the impact on network throughput and legitimate traffic performance.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10044741B2Information reporting for anomaly detection
Publication Date: 2018.08.07 CISCO TECHNOLOGY INC
  • US10044741B2 patent drawing
  • US10044741B2 patent drawing
  • US10044741B2 patent drawing

AI summary

In one embodiment, a first device in a network receives traffic flow data from a plurality of devices in the network. The traffic flow data from at least one of the plurality of devices comprises raw packets of a traffic flow. The first device selects a set of reporting devices from among the plurality of devices based on the received traffic flow data. The first device provides traffic flow reporting instructions to the selected set of reporting devices. The traffic flow reporting instructions cause each reporting device to provide sampled traffic flow data to an anomaly detection device.