Network Abnormality Detection via Dynamic Rule Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network monitoring systems face challenges in detecting communication abnormalities without increasing the processing load on network apparatuses, which can lead to unreliable monitoring data and longer detection times, especially when monitoring high-layer communications or unfamiliar network configurations.
Innovation Solution
A network abnormality detection system that includes network signal copy apparatuses, measurement apparatuses, and analysis apparatuses, which dynamically calculate communication statistics and create correlation models to detect abnormalities without pre-defined monitoring rules, thereby reducing processing load and improving detection speed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network monitoring systems acquire route information from routers to detect communication abnormalities, then abnormality detection capability is improved, but processing load on network apparatus increases
Solution Approach 1:
The patent extracts the monitoring function from the network apparatus (routers) itself and places it in an external monitoring system. The monitoring system acquires route information from routers without requiring the routers to perform monitoring operations, thereby improving abnormality detection capability while avoiding increased processing load on the network apparatus.
Solution Approach 2:
The patent introduces an external monitoring system as an intermediary between the network apparatus and the monitoring function. This intermediary acquires route information from routers and performs analysis, allowing the routers to maintain their primary communication functions without additional monitoring processing load.
2Adaptability or versatility
If network monitoring systems monitor multiple network apparatuses and high-layer communications, then monitoring coverage is improved, but time necessary for monitoring information collection and abnormality determination increases
Solution Approach 1:
The patent segments the monitoring process into distinct components: route information acquisition from multiple routers, communication statistics calculation from copied packets, and abnormality determination through correlation analysis. This segmentation allows parallel processing of monitoring data from multiple sources, improving monitoring coverage while reducing the time required for information collection and analysis.
3Productivity
If network monitoring systems use pre-defined monitoring rules to reduce information monitoring, then processing speed is improved, but adaptability to unfamiliar network configurations deteriorates
Solution Approach 1:
The patent implements dynamic monitoring rules that automatically adapt to different network configurations. Instead of using static pre-defined rules, the system dynamically determines which route information and communication statistics to monitor based on the actual network topology and traffic patterns, maintaining both processing speed and adaptability to unfamiliar configurations.
Solution Approach 2:
The patent incorporates feedback mechanisms where the monitoring system analyzes acquired route information and communication statistics to automatically adjust monitoring parameters and rules. This feedback loop enables the system to adapt to unfamiliar network configurations while maintaining efficient processing speeds through learned optimization patterns.
Data Source
AI summary
In a communication system in which a plurality of communication apparatuses perform communication via a communication network, a network abnormality detection system dynamically creates a monitoring rule during operation without defining information (monitoring rule) regarding communication to be monitored in advance and perform a collection process and an abnormality determination process quickly even when an amount of information to be monitored is vast. The network abnormality detection system copies packets transmitted at predetermined measurement positions in the communication network, calculates communication statistics information at each measurement position from the copied packets, analyzes one or more pieces of communication statistics information, and detects occurrence of communication abnormality.


