Distributed Anomaly Detection via Node Offloading

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anomaly detection systems in computer networks face challenges in distinguishing distributed Denial of Service (DoS) attacks, particularly due to the difficulty in differentiating between malicious and legitimate traffic, especially in highly distributed attacks where individual requests appear non-malicious but collectively overwhelm resources.

Innovation Solution

The implementation of a self-learning network (SLN) infrastructure that utilizes distributed learning agents (DLAs) and supervisory devices to perform machine learning-based anomaly detection, where nodes capable of performing anomaly detection functions are identified and instructed to capture and assess traffic data, enabling the offloading of computational tasks and distributed packet capture to optimize resource utilization and detection efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If distributed anomaly detection is implemented using multiple network nodes, then detection precision and resource utilization improve, but device complexity and coordination overhead increase

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent divides the anomaly detection system into multiple independent learning agents deployed across different network nodes. Each agent independently monitors and analyzes traffic patterns at its local node, segmenting the overall detection task into distributed units. This segmentation improves detection precision by capturing node-specific anomalies while reducing central coordination complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a spatial dimension to anomaly detection by distributing detection capabilities across multiple network nodes rather than relying on a single centralized system. This dimensional transformation allows parallel detection operations at different network locations, improving overall detection precision without proportionally increasing coordination overhead.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If machine learning-based anomaly detection is deployed, then anomaly detection capability improves, but computational resource consumption increases

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent implements machine learning models with local adaptability, where each learning agent at a network node is trained to recognize anomalies specific to its local traffic patterns and characteristics. This local quality approach enables effective anomaly detection at each node while reducing the computational burden on centralized systems, as each agent handles only its local detection tasks independently.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If centralized anomaly detection is used, then coordination is simplified, but detection efficiency and resource utilization decrease

Engineering Contradiction:
Improvecoordination simplicityVSAvoiddetection efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent segments the centralized detection function into distributed learning agents at multiple network nodes. Each agent independently performs anomaly detection on local traffic, eliminating the coordination bottleneck of centralized systems. This segmentation dramatically improves detection efficiency and resource utilization while maintaining operational simplicity through standardized agent deployment.

Inventive Principle:
Principle #1Segmentation

4Measurement precision

If more network nodes are involved in anomaly detection, then detection coverage and precision improve, but system complexity and management difficulty increase

Engineering Contradiction:
Improvedetection coverageVSAvoidmanagement complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates universal learning agents that can be deployed at any network node to perform anomaly detection functions. These multi-functional agents handle traffic monitoring, pattern recognition, and anomaly identification across diverse network environments, enabling expanded detection coverage without proportionally increasing management complexity through standardized deployment procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10757121B2Distributed anomaly detection management
Publication Date: 2020.08.25 CISCO TECHNOLOGY INC
  • US10757121B2 patent drawing
  • US10757121B2 patent drawing
  • US10757121B2 patent drawing

AI summary

In one embodiment, a device in a network performs anomaly detection functions using a machine learning-based anomaly detector to detect anomalous traffic in the network. The device identifies an ability of one or more nodes in the network to perform at least one of the anomaly detection functions. The device selects a particular one of the anomaly detection functions to offload to a particular one of the nodes, based on the ability of the particular node to perform the particular anomaly detection function. The device instructs the particular node to perform the selected anomaly detection function.