Domain Anomaly Detection via Load Test Normalization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The proliferation of web services has made it difficult to detect and mitigate domain-based anomalies, such as malicious domains and data loading issues, due to the complexity of monitoring and logging data across disparate systems, leading to unnoticed attacks until they are well underway.
Innovation Solution
A device receives results of load tests for a web application, determines a baseline of expected domains through normalizing the results, identifies anomalous domains, and performs mitigation actions, leveraging machine learning techniques to classify and cluster data for effective anomaly detection and response.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If monitoring and logging data are collected across disparate systems, then detection capability is improved, but data complexity and difficulty of analysis increase
Solution Approach 1:
The patent introduces an intermediary system that collects monitoring and logging data from disparate systems, normalizes the data formats, and presents a unified view. This intermediary layer handles the complexity of data integration, allowing detection capabilities to improve without directly increasing the complexity visible to analysts.
Solution Approach 2:
The patent segments the monitoring system into distinct components: data collection agents, normalization layers, analysis modules, and reporting interfaces. Each component handles specific tasks, making the overall complex system manageable through modular architecture where each segment can be independently optimized and maintained.
2Device complexity
If traditional monitoring methods are used, then system simplicity is maintained, but anomaly detection effectiveness deteriorates
Solution Approach 1:
The patent implements self-service anomaly detection through automated baseline establishment and deviation detection. The system automatically learns normal behavior patterns from historical data and independently identifies anomalies without requiring manual configuration or complex rule-setting, maintaining simplicity while improving detection effectiveness.
Solution Approach 2:
The patent incorporates feedback mechanisms where detection results are continuously fed back into the system to refine baseline models and improve future anomaly detection. This closed-loop approach enables the system to automatically learn and adapt, improving reliability without increasing operational complexity.
3Measurement precision
If load testing is performed frequently, then baseline accuracy is improved, but resource consumption increases
Solution Approach 1:
The patent implements periodic load testing at optimized intervals rather than continuous testing. The system determines appropriate testing frequencies based on application characteristics and risk levels, performing tests periodically to establish and update baselines while minimizing resource consumption between test cycles.
Solution Approach 2:
The patent applies partial testing strategies where not all system components are tested at full intensity simultaneously. Instead, testing is distributed across different time periods and targeted at critical paths, achieving sufficient baseline accuracy without the excessive resource consumption of comprehensive full-system testing.
Data Source
AI summary
In one embodiment, a device receives results of a plurality of load tests for a web application, the results comprising information about one or more domains accessed when loading the web application during the plurality of load tests. The device determines a baseline of expected domains that are accessed during loading of the web application based on normalizing the results of the plurality of load tests. The device identifies, based on the baseline of expected domains, an anomalous domain that is loaded during a loading of the web application. The device performs one or more mitigation actions in response to identifying the anomalous domain.


