Network Anomaly Detection With Ensemble Machine Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security appliances and software products in computer networks face scalability and network visibility limitations, struggling to detect malicious activities effectively due to localized monitoring and inability to utilize context information from other network segments.

Innovation Solution

A distributed data processing system employing machine learning techniques for real-time and batch processing of network events, enabling scalable and comprehensive anomaly detection across the network, using machine learning models to analyze user and entity behaviors without relying on pre-existing signatures or rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security appliances are deployed to monitor network traffic, then malware detection capability is improved, but scalability is worsened due to appliance swap requirements when traffic increases

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network into multiple monitored segments with appliances deployed at strategic locations. Each appliance monitors its local segment while a central server aggregates data from all segments, enabling scalable deployment without requiring appliance swaps when traffic increases.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent combines localized appliance monitoring with centralized server analysis. The central server merges data from multiple appliances across different network segments, providing comprehensive malware detection while maintaining scalability through distributed architecture.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If security appliances are deployed to monitor network traffic, then intrusion detection capability is improved, but network visibility is worsened due to limited view of other network segments

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidnetwork visibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent merges localized appliance data with centralized server data to create a comprehensive network-wide view. The central server aggregates information from multiple appliances monitoring different segments, eliminating blind spots and providing complete network visibility for intrusion detection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The central server acts as an intermediary that collects, correlates, and analyzes data from multiple appliances. This intermediary role enables appliances with limited local visibility to benefit from comprehensive network-wide context for detecting sophisticated malware.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If installed software products are deployed on terminal devices to monitor data, then malware detection is improved, but scalability is worsened due to hardware upgrade limitations

Engineering Contradiction:
Improvemalware detectionVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments detection functions between lightweight terminal software and a powerful centralized server. Terminal devices perform local monitoring while the central server handles complex analysis, allowing scalability without upgrading terminal hardware.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The central server acts as an intermediary that receives data from terminal devices and performs sophisticated malware analysis. This architecture enables scalable deployment where terminal hardware remains simple while detection capability scales with server resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12438891B1Anomaly detection based on ensemble machine learning model
Publication Date: 2025.10.07 CISCO TECHNOLOGY INC
  • US12438891B1 patent drawing
  • US12438891B1 patent drawing
  • US12438891B1 patent drawing

AI summary

A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.