Anomaly Detector for Network Terminals in Distributed Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack a comprehensive solution for detecting and predicting anomalies in network terminals within distributed networks, particularly in wide area networks, intranets, or local area networks, and do not effectively optimize system behavior to counter malicious attacks or performance deviations.

Innovation Solution

A computer-implemented method and system that collects behavioral data from network terminals, compares it with pre-stored behavior profiles in a distributed knowledge database, and uses an intelligent agent algorithm to detect anomalies and optimize system behavior, incorporating a hardware platform module and retraining mechanism for continuous learning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If behavioral data is collected and compared with pre-stored behavior profiles to detect anomalies, then anomaly detection capability is improved, but system complexity increases

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is divided into multiple independent modules: data collection module, behavior profile storage module (distributed knowledge database), anomaly detection module, and optimization module. Each module performs a specific function, making the complex anomaly detection system manageable and maintainable while improving detection capability through specialized components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A behavior profile acts as an intermediary between raw behavioral data and anomaly detection. The system stores pre-established behavior profiles in a distributed knowledge database, which serve as reference standards for comparing actual system behavior, thereby simplifying the detection process while maintaining high reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If an intelligent agent algorithm is used to optimize network terminal behavior, then system optimization capability is improved, but computational requirements increase

Engineering Contradiction:
Improvesystem optimization capabilityVSAvoidcomputational requirements
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The system pre-establishes behavior profiles and stores them in the distributed knowledge database before actual anomaly detection occurs. This preliminary preparation allows the intelligent agent to work with pre-processed reference data rather than raw data, reducing real-time computational requirements while maintaining optimization capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback mechanism where detected anomalies and optimization results are used to update and refine behavior profiles in the distributed knowledge database. This continuous learning process improves optimization capability over time while the feedback loop efficiently processes only relevant deviation information rather than all raw data.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10218722B2Method and system for developing an anomaly detector for detecting an anomaly parameter on network terminals in a distributed network
Publication Date: 2019.02.26 PEREZ RAMOS YANDY
  • US10218722B2 patent drawing
  • US10218722B2 patent drawing
  • US10218722B2 patent drawing

AI summary

The present invention discloses a computer implemented method for developing an anomaly detector which is adapted to detect/predict anomaly in one or more network terminals and optimize the behavior of the network terminals. The said method is adapted to collect and monitor the behavior of the network terminals and compare it with the behavior profile of the network terminals in order to detect the anomaly parameter. The behavior profile is the normal interaction of the software and hardware components of the network terminals. A system for implementation and execution of such anomaly detector is also disclosed.