Network Anomaly Detection via Dynamic Behavioral Indicators

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As the number of network-connected devices increases, especially with the advancement of IoT, networks become more vulnerable to security attacks due to the lack of hardware and software capabilities in IoT devices, and static security rules fail to effectively identify anomalies.

Innovation Solution

Implementing a method in network nodes with processors and memory to generate characteristic indicators for device types based on communications, determine performance indicators, and synthesize anomaly indicators to detect and prevent security threats by grouping devices, generating characteristic indicators for device types, determining performance indicators, and synthesizing anomaly indicators based on these indicators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static security rules are used for network protection, then the security system is simple to implement, but it fails to identify anomalies in networks with diverse device types

Engineering Contradiction:
Improveanomaly identification capabilityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic anomaly detection by continuously learning device behavior patterns and adapting security rules based on observed communications. The system transitions from static predefined rules to dynamic rules that evolve with network conditions, enabling reliable anomaly identification while managing complexity through automated adaptation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security parameters dynamically by adjusting detection thresholds, rule weights, and analysis depths based on network context. This allows the security system to maintain high reliability across diverse device types while managing computational complexity through adaptive parameter adjustment rather than fixed complex rules.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If the number of network-connected devices increases, then network coverage and functionality improve, but network vulnerability to security attacks increases

Engineering Contradiction:
Improvenetwork device compatibilityVSAvoidnetwork security vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements self-service security where each device learns its own normal behavior patterns and contributes to collective anomaly detection. Devices autonomously monitor their own communications and help identify threats in the network, enabling security protection that scales with device count without proportionally increasing central system complexity or vulnerability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses feedback mechanisms where detected anomalies and attack patterns are fed back into the learning model to improve future detection. This continuous feedback loop enables the network to adapt to new threat types as devices are added, maintaining security effectiveness while supporting growing network diversity.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If IoT devices are deployed to expand network functionality, then network versatility improves, but hardware and software capability to prevent security attacks decreases

Engineering Contradiction:
Improvenetwork functionalityVSAvoidsecurity defense capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary behavioral analysis layer that sits between IoT devices and the network. This intermediary monitors device communications and identifies anomalies without requiring direct security capabilities in the IoT devices themselves, enabling versatile device deployment while maintaining security through external behavioral analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces traditional hardware-based security mechanisms (firewalls, intrusion prevention systems) with software-based behavioral analysis. This substitution allows IoT devices with limited hardware capabilities to be secured through cloud-based or network-based behavioral monitoring that analyzes communication patterns rather than requiring strong local security hardware.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10911475B2Identifying anomalies in a network
Publication Date: 2021.02.02 CISCO TECHNOLOGY INC
  • US10911475B2 patent drawing
  • US10911475B2 patent drawing
  • US10911475B2 patent drawing

AI summary

Various implementations disclosed herein enable identifying anomalies in a network. For example, in various implementations, a method of identifying anomalies in a network is performed by a network node. In various implementations, the network node includes one or more processors, and a non-transitory memory. In various implementations, the method includes generating a characteristic indicator that characterizes a device type based on communications associated with a first device of the device type. In various implementations, the method includes determining, based on communications associated with the first device, a performance indicator that indicates a performance of the first device. In various implementations, the method includes synthesizing an anomaly indicator as a function of the performance indicator in relation to the characteristic indicator.