Network Anomaly Detection via Traffic Feature Distribution Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting network anomalies are limited, as they often rely on volume-based detection, which misses low-rate anomalies, and rule-based methods struggle to identify new or unseen anomalies, while also focusing on single network elements rather than providing a comprehensive solution for the entire network.

Innovation Solution

The technique analyzes the distributional properties of multiple network traffic features across the entire network, using statistical and mathematical methods to classify and localize anomalies, allowing for the detection of novel anomalies without human intervention and providing a general solution for a wide range of anomalous events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If volume-based detection is used, then high-rate anomalies are detected, but low-rate anomalies are missed

Engineering Contradiction:
Improveanomaly detection sensitivityVSAvoiddetection coverage across anomaly rates
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent transforms the detection approach by changing from volume-based parameters to distributional property parameters. Instead of monitoring traffic volume alone, the system analyzes the distribution patterns of multiple traffic features (source/destination addresses, ports, protocols), enabling detection of both high-rate and low-rate anomalies through statistical deviations in feature distributions.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent adds dimensional depth to anomaly detection by moving from single-dimensional volume monitoring to multi-dimensional feature distribution analysis. By simultaneously examining distributions across multiple traffic features and network elements, the system creates a higher-dimensional detection space that captures anomalies regardless of their rate.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If rule-based methods are used, then known anomaly types are detected, but new unseen anomalies cannot be detected

Engineering Contradiction:
Improvedetection accuracy for known anomaliesVSAvoiddetection capability for novel anomalies
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements self-service through unsupervised learning, where the system automatically discovers and adapts to new anomaly patterns without human intervention. The distributional analysis framework enables the system to self-learn normal behavior patterns and automatically identify deviations, providing both reliable detection of known anomalies and adaptability to novel threats.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system transitions from static rule-based detection to dynamic adaptive detection. By continuously analyzing feature distributions and identifying statistical deviations, the system dynamically adjusts to new anomaly types as they emerge, maintaining reliability for known patterns while gaining versatility for unknown threats.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If single network element analysis is used, then element-specific anomalies are detected, but network-wide anomalies spanning multiple elements are missed

Engineering Contradiction:
Improveanomaly localization accuracyVSAvoiddetection scope across network elements
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent merges data from multiple network elements into a unified analysis framework. By collecting and analyzing feature distributions across numerous network elements simultaneously, the system detects both element-specific anomalies and network-wide patterns, enabling comprehensive monitoring that spans the entire network infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The distributional analysis framework serves multiple functions simultaneously: it localizes element-specific anomalies, detects network-wide patterns, and provides both precise localization and broad detection scope through the same multi-element feature distribution analysis mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8869276B2Method and apparatus for whole-network anomaly diagnosis and method to detect and classify network anomalies using traffic feature distributions
Publication Date: 2014.10.21 TRUSTEES OF BOSTON UNIV
  • US8869276B2 patent drawing
  • US8869276B2 patent drawing
  • US8869276B2 patent drawing

AI summary

To improve network reliability and management in today's high-speed communication networks, we propose an intelligent system using adaptive statistical approaches. The system learns the normal behavior of the network. Deviations from the norm are detected and the information is combined in the probabilistic framework of a Bayesian network. The proposed system is thereby able to detect unknown or unseen faults. As demonstrated on real network data, this method can detect abnormal behavior before a fault actually occurs, giving the network management system (human or automated) the ability to avoid a potentially serious problem.