Network Anomaly Detection Using Confidence Scores
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As network environments grow in size and complexity, detecting anomalies becomes increasingly difficult due to the large amount of data generated, making it challenging for administrators to correctly diagnose and fix problems in a timely manner, especially since network states often change quickly after an anomaly occurs.
Innovation Solution
A system that determines confidence scores for network events to identify anomalies and presents the relevant network state, allowing for automated detection and reporting of anomalies, even when the user is not actively monitoring the environment, using confidence scores and Gaussian distributions to identify deviations from normal behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If network environments increase in size and complexity to collect more data for monitoring, then the amount of data collected and generated increases, but it becomes more difficult to analyze the data and determine anomalies
Solution Approach 1:
The system extracts only the most relevant data elements and anomaly indicators from the large volume of collected network data, rather than attempting to analyze all data. This is achieved through automated anomaly detection algorithms that identify and extract only the critical deviations from normal network behavior, reducing the analysis burden while maintaining detection effectiveness
Solution Approach 2:
The patent introduces an intermediary automated analysis system that acts as a mediator between data collection and administrator review. This intermediary system processes the large volume of collected data, applies anomaly detection algorithms, and presents only the detected anomalies to administrators, thereby reducing the direct analysis burden on human operators
2Reliability
If administrators manually monitor network environments to detect anomalies, then they can identify problems, but it takes time and administrators may not be actively monitoring when anomalies occur
Solution Approach 1:
The system performs preliminary automated anomaly detection and analysis before administrators need to review the data. By continuously monitoring and pre-identifying anomalies through automated algorithms, the system ensures that when administrators do review the data, the anomalies are already detected and flagged, reducing their analysis time while maintaining detection accuracy
Solution Approach 2:
The patent implements automated feedback mechanisms where the system continuously monitors network data, compares it against baseline behavior, and automatically feeds back anomaly detections to administrators. This closed-loop feedback system ensures timely detection and notification of anomalies without requiring continuous active monitoring by administrators
3Measurement precision
If administrators review network data to determine anomalies, then they can diagnose problems, but network states change quickly making it difficult to correctly diagnose issues
Solution Approach 1:
The system captures and preserves network state information at the time anomalies are detected, creating a timestamped snapshot of the network condition. This preliminary capture of state data ensures that administrators can review the exact network configuration and conditions when the anomaly occurred, even if the network state has since changed, thereby maintaining diagnosis accuracy
Data Source
AI summary
Systems, methods, and computer-readable media for detecting and reporting anomalies in a network environment for providing network assurance. In some embodiments, a system can determine confidence scores for at least one value of parameters of a network environment defining network events occurring in the network environment. The confidences scores can indicate a frequency that the defined network events have a specific event state. The confidence scores can be monitored to detect an anomaly in the network environment. In response to detecting the anomaly in the network environment, the system can determine a relevant network state of the network environment. The relevant network state of the network environment and the anomaly in the network environment can be presented to a user.


