Network Anomaly Detection via Dynamic Baselines and Fuzzy Logic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network anomaly detection systems rely on historical baselines and upfront assumptions, which become outdated quickly due to the dynamic nature of network traffic, leading to high false positive rates and inefficiencies in detecting DoS and DDoS attacks.

Innovation Solution

A novel approach that computes trends in network traffic characteristics and applies fuzzy logic to classify anomalies in real-time, eliminating the need for historical baselines and allowing for timely detection and classification of network anomalies, including DoS and DDoS attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If historical baselines and upfront assumptions are used for anomaly detection, then the system can detect anomalies using traditional methods, but the detection accuracy deteriorates over time due to dynamic network traffic changes

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidbaseline obsolescence time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements dynamic baseline computation that continuously adapts to changing network traffic patterns. Instead of using static historical baselines, the system computes baselines dynamically from recent traffic data, allowing the detection system to remain accurate as network conditions evolve over time.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of baseline computation from fixed historical periods to adaptive recent periods. By adjusting the time window and computation parameters based on current traffic characteristics, the system maintains detection accuracy without relying on outdated assumptions.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If traditional anomaly detection methods are used, then the system can identify potential anomalies, but the false positive rate increases due to outdated baselines

Engineering Contradiction:
Improveanomaly detection rateVSAvoidfalse positive rate
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system incorporates feedback mechanisms where detection results and traffic pattern changes continuously inform baseline adjustments. This feedback loop allows the system to learn from false positives and refine its detection thresholds, reducing false alarms while maintaining high detection rates.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The detection thresholds and parameters are made dynamic rather than static. The system adapts its sensitivity and baseline values in response to changing network conditions, preventing both false positives and missed detections that occur with fixed parameters.

Inventive Principle:
Principle #15Dynamics

3Speed

If real-time anomaly detection is implemented, then the system can detect DoS and DDoS attacks timely, but the computational complexity increases

Engineering Contradiction:
Improvedetection speedVSAvoidcomputational complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent divides the anomaly detection process into multiple independent stages: traffic feature extraction, baseline comparison, anomaly scoring, and classification. Each stage processes data independently and can be optimized separately, reducing overall computational complexity while maintaining real-time detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different detection algorithms and complexity levels to different types of traffic or different anomaly categories. By tailoring the computational approach to local requirements rather than using a uniform high-complexity method everywhere, the system achieves real-time detection with reduced overall computational burden.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11805143B2Method and system for confident anomaly detection in computer network traffic
Publication Date: 2023.10.31 NETFLOW LOGIC CORP
  • US11805143B2 patent drawing
  • US11805143B2 patent drawing
  • US11805143B2 patent drawing

AI summary

The present invention relates to systems and methods for detecting anomalies in computer network traffic with fewer false positives and without the need for time-consuming and unreliable historical baselines. Upon detection, traffic anomalies can be processed to determine valuable network insights, including health of interfaces, devices and network services, as well as to provide timely alerts in the event of attack.