Intermediary Node Anomaly Detection in Split Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods and systems for managing communication in split computer networks are inadequate in analyzing anomalies, particularly in nodes that are not directly connected or have limited access, and fail to utilize message payload information for identifying transaction issues.

Innovation Solution

A method involving a processor at an intermediary node that monitors transactions, analyzes patterns, probes communication, and identifies anomalies by comparing actual data to expected templates, prompting corrective actions such as routing adjustments or notifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If currently available methods and systems monitor transactions only via their own network, then they can analyze communication within their network, but they cannot detect anomalies in nodes that communicate through other networks (logically disconnected nodes)

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidnetwork topology adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a gateway node as an intermediary that bridges logically disconnected subnets. This gateway monitors transactions between requestor nodes in one subnet and approver nodes in another subnet, enabling anomaly detection across network boundaries without requiring direct connectivity between all nodes. The gateway acts as a mediator that collects and analyzes transaction data from multiple subnets, solving the problem of detecting anomalies in nodes that are not directly connected to the monitoring system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If currently available systems manage communication without utilizing message payload information, then they can maintain simple monitoring processes, but they cannot identify specific transaction anomalies through payload analysis

Engineering Contradiction:
Improveanomaly identification precisionVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by creating expected message templates that define the correct structure, format, and content requirements for valid transactions before actual monitoring occurs. These templates are established in advance based on knowledge of legitimate transaction types. During monitoring, actual messages are compared against these pre-defined templates to quickly identify anomalies. This approach enables precise anomaly detection by checking whether messages conform to expected patterns, without requiring complex real-time analysis of every message detail.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If currently available methods probe communication between all nodes, then they can detect anomalies comprehensively, but they accumulate excessive information and increase processing overhead

Engineering Contradiction:
Improveanomaly detection coverageVSAvoidinformation processing efficiency
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts and monitors only the essential and relevant information from transaction messages, rather than collecting and processing all communication data. The monitoring system focuses on extracting key elements such as message structure, required fields, and critical payload information that are necessary for anomaly detection. By selectively extracting only the most important data elements needed for template matching and anomaly identification, the system achieves comprehensive anomaly detection coverage while minimizing information processing overhead and avoiding accumulation of excessive data.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10986116B1System and method for analyzing and correcting an anomaly in split computer networks
Publication Date: 2021.04.20 SHIFT4 TECHNOLOGY LTD
  • US10986116B1 patent drawing
  • US10986116B1 patent drawing
  • US10986116B1 patent drawing

AI summary

A system and method of correcting an anomaly in a split computer network, where the split computer network includes a first subnet, connecting one or more requestor nodes to a first intermediary node, and a second subnet, connecting the first intermediary node to one or more approver nodes may include performing, by at least one processor associated with the first intermediary node: monitoring transactions between the one or more requestor nodes and the one or more approver nodes, via the first intermediary node; analyzing the monitored transactions, to obtain a transaction pattern; probing communication between an examined requestor node and at least one approver node; analyzing the probed communication, in view of the transaction pattern, to identify a suspected transaction anomaly; and producing a suggestion of at least one corrective action, based on the suspected transaction anomaly.