Network Anomaly Classification Using External Event Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In communication networks, distinguishing between normal behavior and network anomalies is complex due to varying operation conditions, leading to potential false alarms from detected anomalies that may correspond to expected behavior, such as increased data traffic during events.

Innovation Solution

A two-stage process for analyzing network anomalies, where the first stage detects anomalies through monitoring and the second stage classifies them using additional external data, such as weather or event information, to determine if the anomaly is expected or unexpected, thereby preventing unnecessary reporting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network anomaly detection is performed using only network data, then detection sensitivity is improved, but false alarm rate increases due to inability to distinguish expected from unexpected anomalies

Engineering Contradiction:
Improveanomaly detection sensitivityVSAvoidfalse alarm rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces additional data (mediator) from external sources as an intermediary element between the network anomaly detector and the classification process. This additional data serves as a reference against which detected anomalies are compared to determine whether they represent expected or unexpected behavior, thereby reducing false alarms while maintaining detection sensitivity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the anomaly analysis process into two distinct stages: (1) anomaly detection based on network data, and (2) anomaly classification based on both network data and additional data. This segmentation allows each stage to focus on its specific function, improving overall system reliability by separating detection from classification

Inventive Principle:
Principle #1Segmentation

2Reliability

If additional external data is used for anomaly classification, then false alarm reduction is improved, but system complexity increases

Engineering Contradiction:
Improvefalse alarm reductionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal classification mechanism that can handle multiple types of anomalies (data traffic anomalies, voice call anomalies, etc.) using the same additional data and classification process. This multi-functionality approach reduces system complexity by avoiding the need for separate specialized systems for each anomaly type

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If comprehensive anomaly analysis is performed, then classification accuracy is improved, but processing time increases

Engineering Contradiction:
Improveclassification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-acquiring and storing additional data from external sources before anomaly detection occurs. This allows the classification process to quickly compare detected anomalies against pre-available reference data, reducing processing time while maintaining high classification accuracy

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10404525B2Classification of detected network anomalies using additional data
Publication Date: 2019.09.03 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US10404525B2 patent drawing
  • US10404525B2 patent drawing
  • US10404525B2 patent drawing

AI summary

A network anomaly detector detects a network anomaly by monitoring a communication network and provides an indication of the detected network anomaly to a network anomaly analyzer. The network anomaly analyzer receives the indication of the detected network anomaly and, on the basis of data representing the detected network anomaly and additional data, e.g., from outside the communication network, performs classification of the detected network anomaly. Depending on the classification of the detected network anomaly, the network anomaly analyzer provides a report of the detected network anomaly to another node. If for example the detected network anomaly is classified as expected behavior, reporting of the detected network anomaly may be suppressed.