Iterative Origin Tracing for Anomalous Network Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network solutions struggle to effectively identify and mitigate anomalous network traffic in IoT networks, particularly due to limited visibility of the origin, cause, and extent of the anomalies, which can lead to compromised devices and rapid propagation of malicious attacks.

Innovation Solution

A computer-implemented method that utilizes a security analyser to receive and analyse network communications, identify anomalous communications, and iteratively request origin information from preceding network entities to trace the source of the anomaly, ultimately applying a security policy to the identified source entity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If remote security solutions are deployed to analyse anomalous traffic, then security monitoring capability is improved, but visibility of the origin and cause of anomalies deteriorates

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidvisibility of origin and cause of anomalies
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces intermediary components (security agents, network taps, and analysis modules) deployed at strategic points within the network infrastructure. These intermediaries capture and forward traffic metadata and anomaly information to the remote security analysis system, enabling comprehensive monitoring while preserving contextual information about traffic origins and causes that would otherwise be lost in pure endpoint monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If iterative tracing of origin information is performed across multiple network entities, then identification precision of the source entity is improved, but analysis time and computational resources increase

Engineering Contradiction:
Improveidentification precision of source entityVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary actions by pre-configuring network entities with identification capabilities and caching mechanisms. When an anomaly is detected, the system leverages pre-established routing information and cached entity identifiers to accelerate the iterative tracing process, reducing the time required to identify the source entity while maintaining high precision through the systematic propagation of origin information requests across the network.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12225032B2Method of analysing anomalous network traffic
Publication Date: 2025.02.11 BRITISH TELECOM PLC
  • US12225032B2 patent drawing
  • US12225032B2 patent drawing
  • US12225032B2 patent drawing

AI summary

A computer-implemented method of analysing anomalous network traffic in a telecommunications network, said telecommunications network comprising a plurality of network entities (120, 110) and a security analyser (130-3), wherein the method comprises the steps of: receiving at the security analyser a network communication from a first network entity; identifying the first network entity; by means of the security analyser: analysing the network communication and/or a performance of the first network entity thereby to identify the network communication as an anomalous communication (310); in response to identifying the network communication as an anomalous communication, communicating an instruction to the identified first network entity to respond with origin information regarding the anomalous communication, wherein the origin information identifies a preceding network entity from which the anomalous communication was directly received by the first network entity (320, 330); and commencing with the preceding network entity, iteratively communicating an instruction to a preceding network entity to respond with origin information for identifying another preceding network entity from which the anomalous communication was directly received until a source network entity from which the anomalous communication originated is identified (380, 390; and applying a security policy to the identified source network entity (370).