Network Anomaly Detection Using Confidence Scores

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As network environments grow in size and complexity, detecting anomalies becomes increasingly difficult due to the large amount of data generated, making it challenging for administrators to correctly diagnose and fix problems in a timely manner, especially since network states often change quickly after an anomaly occurs.

Innovation Solution

A system that determines confidence scores for network events to identify anomalies and presents the relevant network state, allowing for automated detection and reporting of anomalies, even when the user is not actively monitoring the environment, using confidence scores and Gaussian distributions to identify deviations from normal behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If network environments increase in size and complexity to collect more data for monitoring, then the amount of data collected and generated increases, but it becomes more difficult to analyze the data and determine anomalies

Engineering Contradiction:
Improveamount of data collectedVSAvoiddifficulty to analyze data
Core Design Contradiction:
Quantity of substanceVSDifficulty of detecting and measuring

Solution Approach 1:

The system extracts only the most relevant data elements and anomaly indicators from the large volume of collected network data, rather than attempting to analyze all data. This is achieved through automated anomaly detection algorithms that identify and extract only the critical deviations from normal network behavior, reducing the analysis burden while maintaining detection effectiveness

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary automated analysis system that acts as a mediator between data collection and administrator review. This intermediary system processes the large volume of collected data, applies anomaly detection algorithms, and presents only the detected anomalies to administrators, thereby reducing the direct analysis burden on human operators

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If administrators manually monitor network environments to detect anomalies, then they can identify problems, but it takes time and administrators may not be actively monitoring when anomalies occur

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidtime to diagnose and fix problems
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary automated anomaly detection and analysis before administrators need to review the data. By continuously monitoring and pre-identifying anomalies through automated algorithms, the system ensures that when administrators do review the data, the anomalies are already detected and flagged, reducing their analysis time while maintaining detection accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements automated feedback mechanisms where the system continuously monitors network data, compares it against baseline behavior, and automatically feeds back anomaly detections to administrators. This closed-loop feedback system ensures timely detection and notification of anomalies without requiring continuous active monitoring by administrators

Inventive Principle:
Principle #23Feedback

3Measurement precision

If administrators review network data to determine anomalies, then they can diagnose problems, but network states change quickly making it difficult to correctly diagnose issues

Engineering Contradiction:
Improvediagnosis accuracyVSAvoidrate of network state change
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The system captures and preserves network state information at the time anomalies are detected, creating a timestamped snapshot of the network condition. This preliminary capture of state data ensures that administrators can review the exact network configuration and conditions when the anomaly occurred, even if the network state has since changed, thereby maintaining diagnosis accuracy

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11716265B2Anomaly detection and reporting in a network assurance appliance
Publication Date: 2023.08.01 CISCO TECHNOLOGY INC
  • US11716265B2 patent drawing
  • US11716265B2 patent drawing
  • US11716265B2 patent drawing

AI summary

Systems, methods, and computer-readable media for detecting and reporting anomalies in a network environment for providing network assurance. In some embodiments, a system can determine confidence scores for at least one value of parameters of a network environment defining network events occurring in the network environment. The confidences scores can indicate a frequency that the defined network events have a specific event state. The confidence scores can be monitored to detect an anomaly in the network environment. In response to detecting the anomaly in the network environment, the system can determine a relevant network state of the network environment. The relevant network state of the network environment and the anomaly in the network environment can be presented to a user.