Inbound Call Traffic Anomaly Detection in Telecommunications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Telecommunication networks face challenges in detecting anomalies that affect the quality of service, leading to unforeseen problems and potential customer dissatisfaction, as existing methods are inadequate in identifying deviations in call traffic patterns.
Innovation Solution
A method for identifying inbound call traffic anomalies by receiving expected values from call detail records, determining residuals, computing an anomaly score, and declaring anomalies based on predefined thresholds and alerting windows, with the option to create alerts and initiate remedial processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing anomaly detection methods are used in telecommunications networks, then the system operation continues without interruption, but the quality of service deteriorates due to undetected anomalies in call traffic patterns
Solution Approach 1:
The system pre-calculates and stores expected values for multiple metrics (call attempt volume, success rate, duration, etc.) based on historical data before anomalies occur. These expected values serve as baseline thresholds for future anomaly detection, enabling the system to quickly identify deviations without complex real-time analysis
Solution Approach 2:
The patent introduces an intermediary anomaly detection system that sits between the call traffic flow and the network operations. This intermediary continuously monitors call detail records, compares actual metrics against expected values, and generates alerts when anomalies are detected, without interfering with the normal call processing
2Measurement precision
If multiple metrics are monitored with strict thresholds for anomaly detection, then the detection precision improves, but the number of false alerts increases
Solution Approach 1:
The system monitors multiple metrics simultaneously (call attempt volume, success rate, duration, billing information) with predefined thresholds, applying partial action by only triggering alerts when specific combinations of metrics deviate from expected values. This selective approach reduces false alerts while maintaining detection precision for genuine anomalies
Solution Approach 2:
The system dynamically adjusts detection parameters by comparing multiple related metrics against each other rather than using fixed absolute thresholds. When one metric shows deviation, the system cross-validates with other metrics to confirm whether the change represents a genuine anomaly or normal variation, thereby reducing false alerts
3Loss of time
If real-time anomaly detection is implemented in call traffic, then the response time to service quality issues improves, but the system complexity increases
Solution Approach 1:
The anomaly detection system is segmented into independent modular components: data collection module, metric calculation module, threshold comparison module, and alert generation module. Each component handles a specific aspect of anomaly detection, making the overall system manageable despite its complexity while enabling real-time operation through parallel processing
Data Source
AI summary
Methods identifying inbound call traffic anomalies in a telecommunications system are provided. The method includes receiving expected values for data related to the telecommunications system, the data being associated with call detail records; for each metric in the received data, determining if an observed value is outside defined upper and lower thresholds; selecting a set of residuals based on an aggregation of data in the call detail records if the observed value is outside the defined upper and lower thresholds; computing an anomaly score based the selected set of residuals; determining if multiple, serial anomalous alerting windows are needed to create an alert if the computed anomaly score is greater than a minimum anomaly score; and declaring that the data supports an anomaly in the inbound call traffic if it is determined that multiple, serial anomalous alerting windows are not needed to create an alert.


