Multi-layer Distributed Analytics for Network Anomaly Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network anomaly detection systems face challenges in distinguishing between legitimate and malicious traffic, especially in distributed Denial of Service (DoS) attacks, due to a lack of ground truth, dynamic network behaviors, and the ability to differentiate between noise and relevant anomalies, which complicates the detection of anomalies such as malware and misconfigured devices.

Innovation Solution

Implementing a multi-layered distributed analytics approach with self-learning network (SLN) infrastructure, where primary networking devices aggregate and correlate anomalies detected by secondary devices, using machine learning techniques and graph-based models to identify patterns and associate anomalies with specific locations in the network, enabling more granular detection and mitigation of network threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If distributed anomaly detection is implemented across multiple network devices, then detection coverage and granularity are improved, but system complexity and difficulty of correlating anomalies increase

Engineering Contradiction:
Improveanomaly detection granularityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the anomaly detection system into multiple independent detection agents deployed across different network devices (routers, switches, firewalls). Each agent independently monitors its local network segment, generating anomaly detections that are then correlated centrally. This segmentation enables fine-grained detection coverage while managing complexity through modular deployment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a central correlation server as an intermediary that receives anomaly detections from multiple distributed agents and performs correlation analysis. This intermediary consolidates the complexity of cross-device anomaly correlation, allowing individual agents to remain simple while achieving sophisticated distributed detection through the mediating correlation layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If multiple anomaly detection agents are deployed distributedly, then detection coverage is improved, but the ability to differentiate between noise and relevant anomalies deteriorates

Engineering Contradiction:
Improvedetection coverageVSAvoidsignal-to-noise differentiation
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent merges anomaly detections from multiple distributed agents through central correlation. By combining observations from multiple independent sources, the system distinguishes true anomalies (which appear across multiple agents) from local noise (which appears only at single agents). This merging approach enhances reliability through statistical validation across the distributed network.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements feedback mechanisms where the central correlation server analyzes patterns across multiple agent reports and adjusts detection thresholds and parameters accordingly. This feedback loop enables the system to learn from false positives and negatives, continuously improving its ability to differentiate signal from noise across the distributed detection network.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If centralized anomaly aggregation is implemented, then correlation capability is improved, but information loss and reduced granularity occur

Engineering Contradiction:
Improveanomaly correlation capabilityVSAvoidlocation granularity
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent implements a nested structure where detailed local anomaly information is maintained within individual detection agents (inner layer), while central correlation provides high-level pattern analysis (outer layer). This nested architecture allows correlation capabilities at the central level while preserving granular location information at the distributed agent level, preventing information loss through hierarchical information preservation.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS10581901B2Increased granularity and anomaly correlation using multi-layer distributed analytics in the network
Publication Date: 2020.03.03 CISCO TECHNOLOGY INC
  • US10581901B2 patent drawing
  • US10581901B2 patent drawing
  • US10581901B2 patent drawing

AI summary

In one embodiment, a primary networking device in a branch network receives a notification of an anomaly detected by a secondary networking device in the branch network. The primary networking device is located at an edge of the network. The primary networking device aggregates the anomaly detected by the secondary networking device and a second anomaly detected in the network into an aggregated anomaly. The primary networking device associates the aggregated anomaly with a location of the secondary networking device in the branch network. The primary networking device reports the aggregated anomaly and the associated location of the secondary networking device to a supervisory device.