Dynamic Application Degrouping for Anomaly Detection Accuracy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current anomaly detection systems in computer networks face challenges such as lack of ground truth, dynamic network behaviors, and resource constraints, making it difficult to differentiate between noise and relevant anomalies, especially in high-dimensional spaces and with limited computational resources.
Innovation Solution
The system dynamically forms and deforms application clusters to generate anomaly detection models, optimizing resource usage by grouping applications with similar behavior and testing models for efficacy, allowing for real-time feedback and threat intelligence-driven adjustments to select the most effective models for analyzing traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Use of energy by moving object
If applications are grouped into clusters for anomaly detection, then resource usage is reduced, but model accuracy deteriorates
Solution Approach 1:
The patent implements dynamic application degrouping where the system continuously monitors detection efficacy and reorganizes application clusters in real-time. Applications are dynamically moved between grouped and ungrouped states based on their anomaly detection performance, allowing the system to adapt cluster configurations dynamically to maintain accuracy while managing resources efficiently.
Solution Approach 2:
The system changes the parameter of application grouping by testing multiple cluster configurations and selecting the optimal grouping based on detection efficacy metrics. By adjusting the grouping parameters and monitoring their impact on anomaly detection, the system finds the optimal balance between resource efficiency and detection accuracy.
2Measurement precision
If more application clusters are created to improve detection accuracy, then model accuracy improves, but device complexity increases
Solution Approach 1:
The patent segments applications into multiple clusters based on their behavioral characteristics and anomaly detection requirements. By dividing the application set into meaningful segments or clusters, the system can apply targeted detection strategies to each segment, improving overall detection accuracy while managing complexity through organized segmentation.
Solution Approach 2:
The system creates a universal framework for anomaly detection that can handle both grouped and ungrouped applications within the same architecture. This multi-functional approach allows the system to process different application types through a unified detection mechanism, reducing the need for separate complex systems for each application type.
3Measurement precision
If applications are analyzed individually rather than in groups, then detection accuracy improves, but resource consumption increases
Solution Approach 1:
The patent applies partial action by analyzing only the most critical applications individually while grouping less critical applications together. The system performs selective degrouping where only applications that benefit from individual analysis are separated from clusters, applying detection effort partially rather than uniformly across all applications, thus optimizing the balance between accuracy and resource usage.
Data Source
AI summary
In one embodiment, a device in a network identifies a plurality of applications from observed traffic in the network. The device forms two or more application clusters from the plurality of applications. Each of the application clusters includes one or more of the applications, and wherein a particular application in the plurality of applications is included in each of the application clusters. The device generates anomaly detection models for each of the application clusters. The device tests the anomaly detection models, to determine a measure of efficacy for each of the models with respect to traffic associated with the particular application. The device selects a particular anomaly detection model to analyze the traffic associated with the particular application based on the measures of efficacy for each of the models.


