Anomaly Detection Model Validation via Network State Information
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current anomaly detection systems in computer networks face challenges in distinguishing between legitimate traffic and distributed Denial of Service (DoS) attacks, particularly in highly distributed scenarios, as they fail to effectively utilize local state information to confirm or refute machine learning outputs, leading to false positives, false negatives, and model confusion.
Innovation Solution
The integration of state information from network devices with machine learning outputs allows for the validation of anomaly detection model outputs, enabling the adjustment of the model based on local and network state data, thereby improving detection accuracy and retraining the model to enhance performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If machine learning models are used for anomaly detection in distributed networks, then detection capability is improved, but false positives and false negatives increase due to inability to distinguish legitimate traffic from coordinated attacks
Solution Approach 1:
The patent combines multiple data sources including network traffic data, device state information, and contextual data from multiple devices into a unified analysis framework. This merging allows the system to cross-validate anomalies across devices and distinguish coordinated attacks from legitimate traffic patterns, thereby reducing false positives and negatives while maintaining detection accuracy
Solution Approach 2:
The system implements feedback mechanisms where detection results and device state information are continuously fed back to refine the machine learning models. This feedback loop enables the system to learn from false positives and negatives, adjusting detection thresholds and model parameters to improve reliability over time while maintaining high detection accuracy
2Productivity
If distributed devices are monitored individually, then local anomaly detection is achieved, but coordinated attacks remain undetected due to lack of correlation between devices
Solution Approach 1:
The patent adds a new dimension of analysis by correlating data across multiple devices and time periods. Instead of analyzing each device in isolation, the system creates multi-dimensional views of network behavior that reveal coordinated attack patterns spanning multiple devices, thereby improving detection accuracy without sacrificing local detection speed
3Measurement precision
If more data is collected from network devices, then detection accuracy is improved, but system complexity increases due to data management and processing requirements
Solution Approach 1:
The system extracts and focuses on specific critical features and state information from the collected data, rather than processing all raw data. By identifying and extracting only the most relevant features for anomaly detection, the system maintains high detection precision while reducing the computational complexity of data management and processing
Data Source
AI summary
In one embodiment, a device in a network receives an output of an anomaly detection model. The device receives state information surrounding the output of the anomaly detection model. The device determines whether the state information supports the output of the anomaly detection model. The device causes the anomaly detection model to be adjusted based on a determination that the state information does not support the output of the anomaly detection model.


