Anomaly Detection Using Weighted Directed Graphs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In complex systems or networks, pinpointing the root cause of anomalous behavior is challenging due to numerous interrelated factors, especially when the inner workings of the system are unknown.
Innovation Solution
A method using weighted directed graphs to detect and analyze anomalous behavior by processing data subsets through a set of rules, generating activation values, forming activation patterns, and creating a predictive model to identify outliers based on these patterns, allowing for the identification of impactful rules even in masked systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional analysis methods are used to detect anomalous behavior in complex systems, then the system can process data through known relationships, but the ability to detect anomalies in systems with unknown inner workings is limited
Solution Approach 1:
The patent introduces activation patterns as an intermediary representation that captures system behavior without requiring knowledge of internal relationships. These patterns serve as mediators between raw system data and anomaly detection, allowing the system to analyze complex interrelationships through simplified activation signatures that can be compared against learned norms.
Solution Approach 2:
The patent creates copies of system behavior in the form of activation patterns that replicate essential characteristics without requiring the actual system structure. By copying and analyzing these behavioral signatures separately, the system can detect anomalies in unknown systems by comparing pattern deviations rather than analyzing the complex original system directly.
2Measurement precision
If all factors and interrelationships in a complex system are analyzed to pinpoint root causes, then comprehensive anomaly detection is achieved, but the time and computational resources required increase significantly
Solution Approach 1:
The patent segments the complex system analysis into distinct activation patterns for different system components or time periods. By dividing the overall system behavior into manageable pattern segments, the system can analyze each segment independently for anomalies, reducing the computational burden of analyzing all factors simultaneously while maintaining precision through pattern comparison.
Solution Approach 2:
The patent performs preliminary analysis by learning normal activation patterns from historical data before actual anomaly detection occurs. This preliminary action creates a baseline of expected behavior that enables faster real-time anomaly detection, as the system only needs to compare current patterns against the pre-established baseline rather than analyzing all factors from scratch during anomaly events.
3Reliability
If the system processes complete data sets through multiple rules to generate activation values, then accurate anomaly detection is achieved, but the computational complexity and processing time increase
Solution Approach 1:
The patent extracts only the essential features needed for anomaly detection by focusing on activation patterns rather than processing complete raw data sets through all possible rules. By taking out and analyzing only the relevant activation signatures, the system maintains detection accuracy while reducing computational overhead by eliminating unnecessary data processing steps.
Solution Approach 2:
The patent applies partial action by processing data through a subset of rules that are most relevant to detecting the specific type of anomaly being sought, rather than exhaustively applying all possible rules. This selective approach maintains sufficient detection accuracy by focusing on the most impactful analysis steps while improving processing speed by avoiding redundant computations.
Data Source
AI summary
A method includes receiving a data set. The data set includes a plurality of data subsets wherein each data subset is associated with one transaction in a fully or partially masked network. The method further includes processing each data subset according to a plurality of rules to generate a plurality of activation values and an output for the each data subset. The plurality of activation values and the output for the each data subset form an activation pattern for the each data subset. The method also includes generating a predictive model based on the activation patterns. The method further includes identifying a subset of transactions as outliers based on the predictive model.


