Dynamic SNA Anomaly Detection via Self-Learning Baselines

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Social Network Analysis (SNA) techniques lack a convenient method for determining functional roles of individuals and organizations within social networks and diagnosing network-wide conditions, especially when there is no pre-established norm for comparison, and they fail to detect anomalies effectively without labeled training data or accurate models.

Innovation Solution

A computer-based method combining SNA and statistical pattern classification, which dynamically detects anomalies by computing SNA metrics and updating normal ranges based on observed data, allowing for automated identification of abnormal behavior without requiring prior models of normal or abnormal behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If conventional SNA techniques are used for visual analysis of social networks, then analysts can reason about individual actors or network structure, but the method lacks automation and cannot effectively detect anomalies without labeled training data

Engineering Contradiction:
Improveanomaly detection automationVSAvoidanomaly detection accuracy
Core Design Contradiction:
Extent of automationVSMeasurement precision

Solution Approach 1:

The system performs self-learning by automatically establishing normal behavior baselines from observed data without requiring external labeled training data. The anomaly detection system serves itself by dynamically adapting to new patterns and updating its understanding of normal behavior continuously, eliminating the need for manual annotation of training datasets.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes parameters dynamically by adjusting anomaly thresholds and baseline definitions based on observed data characteristics. Instead of using fixed thresholds, the system adapts parameters such as standard deviation multiples and baseline time windows to match the specific characteristics of the social network being analyzed, improving detection accuracy across different scenarios.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If manual visual analysis is used to determine functional roles and diagnose network conditions, then detailed insights can be obtained, but the process is time-consuming and not scalable

Engineering Contradiction:
Improveanalysis throughputVSAvoiddetection complexity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent replaces manual visual analysis with automated computational methods. Instead of analysts manually examining network graphs and computing SNA metrics, the system automatically calculates centrality measures, clustering coefficients, and other structural indicators, then applies statistical anomaly detection algorithms to identify unusual patterns, significantly increasing analysis throughput.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system introduces an intermediary layer of automated processing that bridges raw social network data and actionable anomaly insights. This intermediary automatically performs data preprocessing, metric computation, baseline establishment, and anomaly scoring, simplifying the overall process while maintaining analytical depth.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If pre-established norms and models are used for anomaly detection, then detection speed can be improved, but the system lacks adaptability when no pre-defined models exist

Engineering Contradiction:
Improvemodel adaptabilityVSAvoiddetection time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically establishing normal behavior baselines from historical data before actual anomaly detection begins. This preliminary baseline establishment phase captures the characteristic patterns of normal social network behavior, enabling rapid anomaly detection in subsequent operations without requiring pre-defined models for each specific scenario.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements dynamic adaptation by continuously updating baseline definitions and anomaly thresholds based on newly observed data. Instead of relying on static pre-defined models, the system dynamically adjusts its understanding of normal behavior to accommodate evolving social network patterns, maintaining both adaptability and detection speed.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7739211B2Dynamic SNA-based anomaly detection using unsupervised learning
Publication Date: 2010.06.15 NORTHROP GRUMMAN SYSTEMS CORP
  • US7739211B2 patent drawing
  • US7739211B2 patent drawing
  • US7739211B2 patent drawing

AI summary

A method, system, and computer program product for enabling dynamic detection of anomalies occurring within an input graph representing a social network. More specifically, the invention provides an automated computer simulation technique that implements the combination of Social Network Analysis (SNA) and statistical pattern classification for detecting abnormal social patterns or events through the expanded use of SNA Metrics. The simulation technique further updates the result sets generated, based on observed occurrences, to dynamically determine what constitutes abnormal behavior, within the overall context of observed patterns of behavior.