Distributed Anomaly Detection in Hierarchical Network Bridges

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional anomaly detection methods in hierarchical networks, such as VoIP, are centralized, leading to biased detection of user behavior anomalies, scalability issues, and high data traffic, which can result in undetected outliers and privacy concerns.

Innovation Solution

A method where each bridge in the network determines common user behaviors, transmits these to a profiling entity to create an overall profile, which is then used to detect anomalies, reducing data exchange and preserving privacy by focusing on aggregated information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a centralized anomaly detection method is used where a central node collects information from all users, then the system can perform comprehensive anomaly detection, but the data traffic increases significantly and scalability is reduced

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddata traffic volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent segments the centralized anomaly detection system into distributed components at each bridge. Each bridge independently performs anomaly detection for its connected users using locally determined behavioral profiles, eliminating the need to transfer all user data to a central node. This segmentation reduces data traffic while maintaining detection capability at the edge of the network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a vertical centralized architecture to a horizontal distributed architecture where anomaly detection capabilities are distributed across multiple bridges. Each bridge operates in its own dimension/scope, determining profiles and detecting anomalies for its local users independently, thereby reducing the dimensional concentration of data traffic at a single central node.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If a centralized anomaly detection method is used where a central node collects information from all users, then comprehensive anomaly detection can be performed, but the system scalability is reduced

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidnetwork scalability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system segments anomaly detection functionality across multiple independent bridges, allowing each bridge to serve its local users autonomously. This segmentation enables the network to scale horizontally by simply adding more bridges without requiring a proportionally larger centralized processing node, thus maintaining scalability while preserving detection accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each bridge performs self-service anomaly detection for its connected users by determining behavioral profiles locally and detecting anomalies independently. This self-service capability eliminates the need for centralized processing, allowing the network to scale freely by adding more self-sufficient bridges without increasing central node complexity or data traffic requirements.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If conventional anomaly detection methods are used, then anomalies can be detected, but localized anomalies may be missed when aggregated at the central node

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidlocalized anomaly information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent segments anomaly detection to occur at the local bridge level rather than aggregating all data centrally. Each bridge maintains sensitivity to localized anomalies in its own user group by determining and applying behavioral profiles locally, preventing information loss that would occur through central aggregation and normalization of diverse user behaviors.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies local quality by allowing each bridge to determine behavioral profiles and detect anomalies specific to its local user group. This localized approach preserves the unique characteristics and anomaly patterns of each bridge's user base, preventing the loss of localized information that occurs when all data is aggregated and processed uniformly at a central node.

Inventive Principle:
Principle #3Local quality

4Measurement precision

If a centralized system collects raw data from all users, then anomaly detection can be performed, but privacy concerns increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidprivacy risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent segments user data processing to occur locally at each bridge rather than centralizing raw user data collection. Each bridge determines behavioral profiles and detects anomalies for its own users without transferring detailed user information to a central node, thereby segmenting privacy risk containment to local levels while maintaining detection accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces behavioral profiles as an intermediary representation that mediates between raw user data and anomaly detection. Instead of transferring or storing sensitive raw user data centrally, the system uses aggregated behavioral profiles as intermediaries that capture essential patterns for detection while preserving user privacy, thus reducing privacy risks associated with centralized data collection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9203857B2Method and system for detecting anomaly of user behavior in a network
Publication Date: 2015.12.01 NEC CORP
  • US9203857B2 patent drawing
  • US9203857B2 patent drawing
  • US9203857B2 patent drawing

AI summary

A method and system for detecting anomaly of user behavior in a network with a hierarchical topology, including a plurality of users, at least two bridges to each of which at least one user is connected to and wherein the bridges are configured to be operable to connect the corresponding users to the network, and at least one predetermined profiling network entity, the method includes the steps of:a) determining common behaviors of the users connected to the respective bridges;b) transmitting the determined common behaviors to the profiling network entity;c) determining an overall profile based on the transmitted common behaviors;d) transmitting back the determined overall profile to the bridges; ande) detecting anomaly of user behavior of the users connected to the corresponding bridges based on the overall profile.