Network Traffic Anomaly Detection via Local and Remote Model Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In computer networks, distinguishing and optimizing traffic flows for specific applications is challenging due to the use of shared protocols like HTTP and HTTPS, and detecting Denial of Service (DoS) attacks, especially distributed ones, is difficult because they can mimic legitimate traffic, overwhelming network resources.
Innovation Solution
A self-learning network (SLN) infrastructure that uses local and remote anomaly detection models to analyze network data, comparing outputs to identify peculiar traffic patterns and score network metrics, allowing for network-centric visualization of normal and anomalous traffic patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If shared protocols like HTTP and HTTPS are used for both business and non-business critical traffic, then network protocol compatibility and ease of operation are improved, but traffic flow differentiation and measurement precision deteriorate
Solution Approach 1:
The patent segments traffic analysis by deploying multiple specialized anomaly detection models (local models for specific network portions, remote models for other portions) that each specialize in detecting anomalies within their domain. This segmentation allows precise traffic differentiation while maintaining overall protocol compatibility, as each model focuses on specific traffic patterns without requiring protocol changes.
2Quantity of substance
If distributed DoS attacks are allowed to mimic legitimate traffic, then network traffic volume increases, but attack detection precision and reliability deteriorate
Solution Approach 1:
The patent merges multiple anomaly detection models (local and remote) to collectively analyze traffic patterns. By combining their outputs and comparing results, the system achieves more reliable attack detection even when attacks mimic legitimate traffic, as the ensemble approach reduces false positives and improves detection precision across varied traffic volumes.
Solution Approach 2:
The system implements feedback mechanisms where anomaly detection models continuously learn from detected patterns and adjust their detection thresholds. This feedback loop enables the system to adapt to evolving attack patterns while maintaining high detection precision, even as traffic volume fluctuates between legitimate and malicious flows.
3Ease of operation
If local anomaly detection models are used independently, then device autonomy and ease of operation are improved, but detection reliability and measurement precision deteriorate
Solution Approach 1:
The patent introduces remote anomaly detection models as intermediaries that provide additional detection perspectives. Local models maintain autonomy by continuing to analyze local traffic independently, while remote models analyze traffic from other network portions and provide complementary detection results, thereby enhancing overall reliability without compromising device autonomy.
Data Source
AI summary
In one embodiment, a device in a network analyzes local network data regarding a portion of the network that is local to the device using a first anomaly detection model. The device analyzes the local network data using a second anomaly detection model that was trained in part using remote network data regarding a portion of the network that is remote to the device. The device compares outputs of the first and second anomaly detection models. The device identifies the local network data as peculiar, in response to the first anomaly detection model determining the local network data to be normal and the second anomaly detection model determining the local network data to be anomalous.


