Dynamic Anomaly Detection for Network Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems are ineffective in detecting and mitigating malicious attacks due to static threshold settings and lack of communication between traffic management devices, leading to delayed defense mechanisms.

Innovation Solution

A network security apparatus that monitors network traffic, generates and updates models with dynamic thresholds, and shares anomalous traffic patterns across storage networks to initiate early mitigation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static thresholds are used for anomaly detection, then the system is simple to implement, but the detection effectiveness is limited when traffic characteristics change over time

Engineering Contradiction:
Improveanomaly detection effectivenessVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic threshold adjustment by continuously learning from historical traffic data. The system automatically adapts thresholds based on observed traffic patterns and characteristics changes, transforming static configuration into a dynamic self-adjusting mechanism that maintains detection effectiveness without manual intervention

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-configuration through automated learning algorithms that analyze traffic data and adjust detection parameters autonomously. This eliminates the need for manual threshold tuning by administrators, allowing the system to adapt to changing traffic characteristics while reducing operational complexity

Inventive Principle:
Principle #25Self-service

2Reliability

If traffic management devices operate in isolation, then each device is independent and simple to manage, but the system cannot share attack information across networks

Engineering Contradiction:
Improvecollective defense capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges isolated traffic management devices into a coordinated networked system that shares anomaly detection data and attack patterns. By combining individual device observations into a collective intelligence framework, the system achieves enhanced detection capability while maintaining manageable complexity through standardized communication protocols

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If manual threshold configuration is used, then the system requires human expertise, but the response time to new attack patterns is delayed

Engineering Contradiction:
Improveattack response speedVSAvoidconfiguration automation
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The system implements continuous feedback loops where detection results and traffic data are fed back into the learning algorithm. This automated feedback mechanism enables the system to rapidly adapt to new attack patterns by continuously refining thresholds based on observed anomalies, eliminating manual reconfiguration delays

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system autonomously performs configuration updates by automatically learning from traffic patterns and adjusting detection parameters without human intervention. This self-service capability accelerates response to emerging threats by enabling real-time adaptation rather than waiting for manual analysis and configuration changes

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10122740B1Methods for establishing anomaly detection configurations and identifying anomalous network traffic and devices thereof
Publication Date: 2018.11.06 F5 NETWORKS INC
  • US10122740B1 patent drawing
  • US10122740B1 patent drawing
  • US10122740B1 patent drawing

AI summary

A method, non-transitory computer readable medium, and network security apparatus that monitors received network traffic to obtain signal data for signals associated with the network traffic in accordance with a stored configuration. A model and configuration update(s) are generated and the stored configuration is updated based on the configuration update(s). The model includes a threshold for at least one of the signals. A determination is made when there is an anomaly in the network traffic based on the application of the model to the signal data or a match of at least a portion of the signal data to an anomalous traffic pattern received from a centralized analytic server computing device. A mitigation action is initiated, when the determining indicates that there is an anomaly in the network traffic. Accordingly, this technology facilitates dynamic and adaptive network traffic analysis and anomaly detection including improvements thereto independent of human intervention.