Application-Centric Anomaly Detection in Network Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security measures are inadequate in detecting and mitigating application-centric anomalies, particularly in distributed Denial of Service (DoS) attacks, as they struggle to differentiate between legitimate and malicious traffic and lack effective coordination between network devices and applications for proactive mitigation.

Innovation Solution

Implementing an application-centric approach within the network, where devices monitor specific metrics and detect anomalies using machine learning techniques, allowing for proactive mitigation actions to be taken by network devices in collaboration with application hosts to prevent the spread of anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current network security measures are used to monitor network traffic, then network traffic can be monitored, but application-centric anomalies cannot be effectively detected and differentiated from legitimate traffic

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidnetwork security system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the anomaly detection process by introducing application-centric metrics that focus on specific application behavior patterns rather than generic network traffic analysis. This segmentation allows the system to detect anomalies at the application level with higher precision while maintaining manageable system complexity through targeted monitoring.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to anomaly detection by implementing coordination between network devices and application hosts. This multi-dimensional approach combines network-level monitoring with application-level insights, enabling precise differentiation of anomalies from legitimate traffic without proportionally increasing system complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If network devices monitor more metrics to detect anomalies, then detection capability improves, but coordination overhead between network devices and applications increases

Engineering Contradiction:
Improveanomaly detection reliabilityVSAvoidcoordination complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a coordination mechanism that serves multiple functions: exchanging metrics, detecting anomalies, and executing mitigation actions. This multi-functional approach improves anomaly detection reliability while managing coordination complexity by consolidating multiple operations into a unified framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent establishes preliminary coordination frameworks and metric definitions before anomaly detection begins. By pre-defining application-centric metrics and coordination protocols, the system achieves reliable anomaly detection without incurring excessive coordination overhead during actual threat response.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If traditional DoS attack detection methods are used, then network flooding can be detected, but distributed attacks from multiple sources cannot be effectively distinguished from legitimate traffic

Engineering Contradiction:
Improveattack detection precisionVSAvoidattack differentiation difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the detection approach by focusing on application-centric metrics that capture behavioral patterns specific to legitimate applications. This segmentation enables precise detection of distributed attacks by identifying deviations from expected application behavior, even when traffic originates from multiple sources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements feedback mechanisms where network devices and application hosts continuously exchange information about traffic patterns and anomalies. This feedback loop improves attack detection precision by allowing the system to learn and adapt to legitimate traffic patterns, making it easier to distinguish attacks from legitimate traffic.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9813432B2Tracking anomaly propagation at the network level
Publication Date: 2017.11.07 CISCO TECHNOLOGY INC
  • US9813432B2 patent drawing
  • US9813432B2 patent drawing
  • US9813432B2 patent drawing

AI summary

In one embodiment, a device in a network monitors one or more metrics regarding network traffic associated with a particular application. The device detects an application-centric anomaly based on the monitored one or more metrics. The device causes an anomaly mitigation action to be performed in the network, in response to detecting the application-centric anomaly.