Anomaly Graphs Aggregate Network Traffic Records

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Anomaly detection systems in computer networks generate a large number of anomalous records during network attacks or events, making it cumbersome for users to assess and identify meaningful anomalies from the data.

Innovation Solution

A device in the network uses anomaly graphs to match and order traffic records, aggregating them into consistent anomaly messages by representing hosts as vertices and communications as edges, applying specific ordering rules to associate each record with an anomaly and sending notifications based on these associations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If anomaly detection systems collect and analyze traffic records at different granularities, then detection accuracy is improved, but the quantity of records increases making assessment cumbersome

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidnumber of anomaly records
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent merges multiple anomalous traffic records into consolidated anomaly messages by identifying common characteristics and grouping related records. This aggregation process combines individual record details into unified messages that represent clusters of similar anomalies, reducing the total number of records while preserving detection accuracy through maintained characteristic analysis.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the large set of anomaly records into meaningful groups based on shared characteristics such as source/destination hosts, anomaly types, and temporal patterns. By dividing the comprehensive record set into segmented categories, the system maintains detailed detection capabilities while organizing records into manageable segments for assessment.

Inventive Principle:
Principle #1Segmentation

2Reliability

If detailed traffic records are generated for each anomaly, then detection completeness is improved, but ease of operation deteriorates due to cumbersome assessment

Engineering Contradiction:
Improveanomaly detection completenessVSAvoiduser assessment ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces anomaly messages as intermediary representations between detailed traffic records and user assessment. These messages serve as mediators that condense complex record information into standardized formats with key characteristics highlighted, making the data more accessible and easier to evaluate while maintaining complete anomaly detection coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of presenting raw detailed records directly to users, the patent inverts the presentation approach by generating summarized anomaly messages that contain essential information in a user-friendly format. This inversion transforms the data presentation from detailed-and-complex to condensed-and-accessible while preserving detection completeness.

Inventive Principle:
Principle #13The other way round (Inversion)

3Loss of information

If multiple anomaly records are reported individually, then information completeness is improved, but bandwidth requirements increase

Engineering Contradiction:
Improveanomaly information completenessVSAvoidbandwidth consumption
Core Design Contradiction:
Loss of informationVSLoss of energy

Solution Approach 1:

The patent merges multiple individual anomaly records into consolidated anomaly messages that convey the same information complete set in fewer transmissions. By combining records with similar characteristics into single messages, the system maintains information completeness while significantly reducing the total number of data transmissions required.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10389606B2Merging of scored records into consistent aggregated anomaly messages
Publication Date: 2019.08.20 CISCO TECHNOLOGY INC
  • US10389606B2 patent drawing
  • US10389606B2 patent drawing
  • US10389606B2 patent drawing

AI summary

In one embodiment, a device in a network identifies a plurality of traffic records as anomalous. The device matches each of the plurality of traffic records to one or more anomalies using one or more anomaly graphs. A particular anomaly graph represents hosts in the network as vertices in the graph and communications between hosts as edges in the graph. The device applies one or more ordering rules to the traffic records, to uniquely associate each traffic record to an anomaly in the one or more anomalies. The device sends an anomaly notification for a particular anomaly that is based on the traffic records associated with the particular anomaly.