Anomaly Detection Using Statistical Dispersion Variation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anomaly detection methods in communication networks face high false-negative and false-positive rates, along with high computational complexity and memory requirements, making them unsuitable for high-speed and high-volume networks, especially due to the difficulty in describing normal traffic with stable probability distributions.

Innovation Solution

A method that monitors the statistical behavior of numerical packet features across moving time windows, computing statistical dispersion quantities and comparing variation between these windows to detect anomalies, using features like packet size, packet rate, and byte rate, with a focus on reduced computational complexity and improved reliability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing anomaly detection methods use complex statistical models to improve detection accuracy, then detection reliability improves, but computational complexity and memory requirements increase

Engineering Contradiction:
Improvedetection reliabilityVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts only the essential statistical dispersion quantity (variance) from packet flow portions, rather than using complex comprehensive statistical models. By focusing solely on variance calculation and comparison between time windows, the method achieves reliable anomaly detection while significantly reducing computational complexity and memory requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If existing anomaly detection methods use comprehensive statistical models to reduce false-positive and false-negative rates, then detection accuracy improves, but processing time and computational resources increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts only the essential statistical dispersion quantity (variance) from packet flow portions, rather than using complex comprehensive statistical models. By focusing solely on variance calculation and comparison between time windows, the method achieves reliable anomaly detection while significantly reducing computational complexity and memory requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If existing anomaly detection methods use stable probability distributions to describe normal traffic, then detection reliability improves, but the difficulty of accurately describing normal traffic increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoiddifficulty of describing normal traffic
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent changes the approach from trying to model the entire probability distribution of normal traffic to monitoring only the statistical dispersion (variance) parameter. This parameter transformation simplifies the problem significantly, as variance is easier to compute and compare across time windows than full probability distributions, yet still provides reliable anomaly detection capability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8503302B2Method of detecting anomalies in a communication system using numerical packet features
Publication Date: 2013.08.06 TELECOM ITALIA SPA
  • US8503302B2 patent drawing
  • US8503302B2 patent drawing
  • US8503302B2 patent drawing

AI summary

A method of detecting anomalies in a communication system, includes: providing a first packet flow portion and a second packet flow portion; extracting samples of a numerical feature associated with a traffic status of the first and second packet flow portions; computing from said extracted samples a first statistical dispersion quantity and a second statistical dispersion quantity of the numerical feature associated with the first and second packet flow portions, respectively; computing from the dispersion quantities a variation quantity representing a dispersion change from the first packet flow portion to the second packet flow portion; comparing the variation quantity with a comparison value; and detecting an anomaly in the system in response to said comparison.