Domain Anomaly Detection via Load Test Normalization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The proliferation of web services has made it difficult to detect and mitigate domain-based anomalies, such as malicious domains and data loading issues, due to the complexity of monitoring and logging data across disparate systems, leading to unnoticed attacks until they are well underway.

Innovation Solution

A device receives results of load tests for a web application, determines a baseline of expected domains through normalizing the results, identifies anomalous domains, and performs mitigation actions, leveraging machine learning techniques to classify and cluster data for effective anomaly detection and response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If monitoring and logging data are collected across disparate systems, then detection capability is improved, but data complexity and difficulty of analysis increase

Engineering Contradiction:
Improvedetection capabilityVSAvoiddata complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that collects monitoring and logging data from disparate systems, normalizes the data formats, and presents a unified view. This intermediary layer handles the complexity of data integration, allowing detection capabilities to improve without directly increasing the complexity visible to analysts.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the monitoring system into distinct components: data collection agents, normalization layers, analysis modules, and reporting interfaces. Each component handles specific tasks, making the overall complex system manageable through modular architecture where each segment can be independently optimized and maintained.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If traditional monitoring methods are used, then system simplicity is maintained, but anomaly detection effectiveness deteriorates

Engineering Contradiction:
Improvesystem simplicityVSAvoidanomaly detection effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements self-service anomaly detection through automated baseline establishment and deviation detection. The system automatically learns normal behavior patterns from historical data and independently identifies anomalies without requiring manual configuration or complex rule-setting, maintaining simplicity while improving detection effectiveness.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where detection results are continuously fed back into the system to refine baseline models and improve future anomaly detection. This closed-loop approach enables the system to automatically learn and adapt, improving reliability without increasing operational complexity.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If load testing is performed frequently, then baseline accuracy is improved, but resource consumption increases

Engineering Contradiction:
Improvebaseline accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent implements periodic load testing at optimized intervals rather than continuous testing. The system determines appropriate testing frequencies based on application characteristics and risk levels, performing tests periodically to establish and update baselines while minimizing resource consumption between test cycles.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent applies partial testing strategies where not all system components are tested at full intensity simultaneously. Instead, testing is distributed across different time periods and targeted at critical paths, achieving sufficient baseline accuracy without the excessive resource consumption of comprehensive full-system testing.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20230102271A1Detection and mitigation of domain-based anomalies
Publication Date: 2023.03.30 CISCO TECHNOLOGY INC
  • US20230102271A1 patent drawing
  • US20230102271A1 patent drawing
  • US20230102271A1 patent drawing

AI summary

In one embodiment, a device receives results of a plurality of load tests for a web application, the results comprising information about one or more domains accessed when loading the web application during the plurality of load tests. The device determines a baseline of expected domains that are accessed during loading of the web application based on normalizing the results of the plurality of load tests. The device identifies, based on the baseline of expected domains, an anomalous domain that is loaded during a loading of the web application. The device performs one or more mitigation actions in response to identifying the anomalous domain.