Dynamic Application Degrouping for Anomaly Detection Accuracy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anomaly detection systems in computer networks face challenges such as lack of ground truth, dynamic network behaviors, and resource constraints, making it difficult to differentiate between noise and relevant anomalies, especially in high-dimensional spaces and with limited computational resources.

Innovation Solution

The system dynamically forms and deforms application clusters to generate anomaly detection models, optimizing resource usage by grouping applications with similar behavior and testing models for efficacy, allowing for real-time feedback and threat intelligence-driven adjustments to select the most effective models for analyzing traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Use of energy by moving object

If applications are grouped into clusters for anomaly detection, then resource usage is reduced, but model accuracy deteriorates

Engineering Contradiction:
Improvecomputational resourcesVSAvoidanomaly detection accuracy
Core Design Contradiction:
Use of energy by moving objectVSMeasurement precision

Solution Approach 1:

The patent implements dynamic application degrouping where the system continuously monitors detection efficacy and reorganizes application clusters in real-time. Applications are dynamically moved between grouped and ungrouped states based on their anomaly detection performance, allowing the system to adapt cluster configurations dynamically to maintain accuracy while managing resources efficiently.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of application grouping by testing multiple cluster configurations and selecting the optimal grouping based on detection efficacy metrics. By adjusting the grouping parameters and monitoring their impact on anomaly detection, the system finds the optimal balance between resource efficiency and detection accuracy.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If more application clusters are created to improve detection accuracy, then model accuracy improves, but device complexity increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments applications into multiple clusters based on their behavioral characteristics and anomaly detection requirements. By dividing the application set into meaningful segments or clusters, the system can apply targeted detection strategies to each segment, improving overall detection accuracy while managing complexity through organized segmentation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a universal framework for anomaly detection that can handle both grouped and ungrouped applications within the same architecture. This multi-functional approach allows the system to process different application types through a unified detection mechanism, reducing the need for separate complex systems for each application type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If applications are analyzed individually rather than in groups, then detection accuracy improves, but resource consumption increases

Engineering Contradiction:
Improvedetection efficacyVSAvoidcomputational resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by analyzing only the most critical applications individually while grouping less critical applications together. The system performs selective degrouping where only applications that benefit from individual analysis are separated from clusters, applying detection effort partially rather than uniformly across all applications, thus optimizing the balance between accuracy and resource usage.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10318887B2Dynamic application degrouping to optimize machine learning model accuracy
Publication Date: 2019.06.11 CISCO TECHNOLOGY INC
  • US10318887B2 patent drawing
  • US10318887B2 patent drawing
  • US10318887B2 patent drawing

AI summary

In one embodiment, a device in a network identifies a plurality of applications from observed traffic in the network. The device forms two or more application clusters from the plurality of applications. Each of the application clusters includes one or more of the applications, and wherein a particular application in the plurality of applications is included in each of the application clusters. The device generates anomaly detection models for each of the application clusters. The device tests the anomaly detection models, to determine a measure of efficacy for each of the models with respect to traffic associated with the particular application. The device selects a particular anomaly detection model to analyze the traffic associated with the particular application based on the measures of efficacy for each of the models.