Fog-Based Hybrid Anomaly Detection in Low-Power Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Low-Power and Lossy Networks (LLNs) face challenges in anomaly detection due to limited resources, making traditional distributed and centralized approaches ineffective, as devices lack the necessary resources to perform anomaly detection and remediation without overburdening the network with increased traffic load.
Innovation Solution
A fog-based hybrid system where network devices reserve local resources for anomaly detection, reporting to a supervisory node and receiving rules from both the supervisory node and peer nodes, allowing for efficient distribution and application of anomaly detection and remediation services, optimizing resource use and reducing traffic load.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Use of energy by moving object
If a centralized anomaly detection model is used in LLNs, then devices can perform anomaly detection without requiring extensive local resources, but network traffic load increases as all status data must be transmitted to the centralized node
Solution Approach 1:
The patent segments the anomaly detection function into two parts: status data collection at distributed devices and anomaly detection at the centralized supervisory node. This segmentation allows devices to perform only lightweight status monitoring while the centralized node handles resource-intensive anomaly analysis, resolving the contradiction between device resource constraints and anomaly detection capability.
Solution Approach 2:
The patent introduces an intermediary mechanism where devices transmit only relevant status data to the supervisory node rather than all raw data. This intermediary filtering approach reduces network traffic load while still providing sufficient information for effective anomaly detection at the centralized node.
2Reliability
If distributed anomaly detection is implemented in traditional networks, then each device can independently detect anomalies using local resources, but devices in LLNs lack the necessary resources to perform anomaly detection in addition to their primary functions
Solution Approach 1:
The patent segments the anomaly detection workload by keeping status data collection at the distributed device level (maintaining reliability) while moving the computationally intensive anomaly detection analysis to the centralized supervisory node (preserving device resources). This resolves the contradiction between maintaining anomaly detection capability and preserving device resource availability.
Solution Approach 2:
The centralized supervisory node serves multiple functions: it acts as a data collection point, performs anomaly detection, and provides network management. This multi-functionality consolidates resource-intensive operations at a node designed to handle them, allowing LLN devices to maintain their primary functions while still contributing to network-wide anomaly detection.
Data Source
AI summary
In one embodiment, a device in a network reserves first and second sets of local resources for an anomaly detection mechanism. The device reports the first set of local resources to a supervisory node in the network. The device applies one or more anomaly detection rules from the supervisory node using the first set of reserved resources. The device receives one or more anomaly detection rules from a peer node in the network. The device applies the one or more anomaly detection rules from the peer node using the second set of reserved resources.


