Dynamic Node Grouping for Abnormal Detection in Communication Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting abnormal nodes in communication networks are not entirely reliable, often failing to detect nodes that exhibit anomalies due to their static modeling approach, which does not account for dynamic characteristics of connections.
Innovation Solution
A detection method that divides nodes into groups based on dynamic characteristics of their connections, using a set of node groups to account for parameter changes during an observation period, and employing a computational model obtained by machine learning to identify abnormal node groups.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static modeling is used to detect abnormal nodes, then the detection method is simple to implement, but the reliability of detection is low and abnormal nodes are not always detected
Solution Approach 1:
The patent applies dynamics by transitioning from static modeling to dynamic modeling of node connections. The system continuously monitors connection parameters over time, capturing temporal variations in node behavior. This allows the detection method to adapt to changing network conditions and accurately identify abnormal nodes that exhibit dynamic anomalies, thereby improving detection reliability while managing complexity through systematic approaches.
Solution Approach 2:
The patent utilizes parameter changes by monitoring multiple connection parameters (such as connection frequency, duration, and data volume) over time. The system detects anomalies by identifying significant deviations in these parameters from established baselines. This multi-parameter approach enables more reliable detection of abnormal nodes compared to single-parameter static methods, addressing the reliability-complexity contradiction.
2Reliability
If dynamic characteristics of connections are taken into account, then detection reliability increases, but the complexity of the detection method increases
Solution Approach 1:
The patent applies segmentation by dividing the network into node groups based on their connection characteristics and behavior patterns. This grouping allows the system to analyze dynamic characteristics within smaller, more manageable subsets rather than treating the entire network as a single unit. The segmentation reduces computational complexity while maintaining high detection reliability by enabling focused analysis of abnormal behaviors within specific groups.
Solution Approach 2:
The system implements dynamic monitoring of connection characteristics including temporal patterns, connection frequency, and data transmission rates. By continuously tracking these dynamic parameters and comparing them against learned normal behavior patterns, the system achieves high detection reliability. The complexity is managed through efficient data structures and algorithms that process dynamic information in a systematic manner.
3Measurement precision
If node groups are determined with group duration characteristics, then dynamic connection characteristics are captured, but the complexity of analysis increases
Solution Approach 1:
The patent segments the observation period into multiple time intervals and determines node groups for each interval with specific group duration characteristics. This temporal segmentation allows precise measurement of how node relationships evolve over time, capturing dynamic connection characteristics with high precision. The analysis complexity is managed by processing segmented data in manageable chunks rather than analyzing the entire time period simultaneously.
Solution Approach 2:
The system applies partial action by focusing analysis on specific time intervals and node groups that exhibit interesting or abnormal characteristics, rather than uniformly analyzing all nodes throughout the entire observation period. This approach achieves high measurement precision for critical periods while reducing overall analysis complexity by avoiding unnecessary processing of normal, unchanging node behaviors.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Method for detecting at least one group of abnormal nodes among a plurality of nodes (N1, ... N6) of a communication network (2), the nodes (N1, ... N6) of the communication network (2) being connected to each other by communication links (6), each node (N1, ... N6) being configured to establish at least one connection with at least one other node (N1, ... N6) of the communication network (2) by the respective communication link (6), said detection method comprising the following steps: - receiving data relating to each connection between the plurality of nodes (N1, ... N6) during an observation period, - determining a set of groups of nodes, - determining, for each group of nodes, at least one parameter characterizing the set of connections implemented within the group of nodes, - obtaining said group of abnormal nodes.