Anomaly Detection System for Network Traffic Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in identifying and prioritizing anomalies in network traffic message failures, delays, and trends in real-time, leading to difficulties in monitoring and addressing severe errors.

Innovation Solution

A system that detects anomalies by calculating failure, fluctuation, and sparsity scores based on network traffic message failures, delays, and trends, and assigns a severity bin to each anomaly, generating notifications and recommendations for users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual monitoring of error logs is used to identify anomalies, then users can detect severe errors, but the process becomes time-intensive and difficult to prioritize among thousands of errors

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidtime to monitor and prioritize errors
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual monitoring of error logs with an automated anomaly detection system that uses machine learning models to identify and prioritize anomalies. The system automatically calculates anomaly scores, determines severity levels, and generates notifications, eliminating the need for manual review of thousands of errors while improving detection accuracy through sophisticated algorithms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary anomaly detection system that sits between the error generation process and human users. This intermediary automatically processes errors, identifies anomalies using multiple scoring mechanisms (anomaly score, severity score, trend analysis), and presents prioritized information to users, thereby reducing the time users spend monitoring errors while maintaining high detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If real-time anomaly detection is implemented using multiple scoring mechanisms and machine learning models, then anomaly identification accuracy improves, but system complexity increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidsystem architecture complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the anomaly detection system into distinct modular components: error ingestion module, anomaly score calculation module, severity score calculation module, trend analysis module, machine learning model module, and notification module. Each module performs a specific function and can be independently developed, tested, and maintained, reducing overall system complexity while maintaining high detection accuracy through the coordinated work of specialized sub-components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a multi-functional anomaly detection system where a single platform handles multiple tasks: collecting errors from various sources, calculating anomaly scores using statistical methods, determining severity levels, analyzing trends over time, applying machine learning models, and generating notifications. This universal system reduces complexity by consolidating multiple functions into one integrated platform rather than requiring separate systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250168056A1Intelligent anomaly detection and recommendation systems
Publication Date: 2025.05.22 TWILIO INC
  • US20250168056A1 patent drawing
  • US20250168056A1 patent drawing
  • US20250168056A1 patent drawing

AI summary

A computing device can identify an anomaly based on metadata associated with network traffic messages corresponding to a particular account. After identifying the anomaly, the computing device can determine a failure score for the network traffic messages representing a failure rate for the message traffic. The computing device can determine a fluctuation score by comparing the network traffic messages in a current time period to a previous time period. The computing device can determine a sparsity score by analyzing the message traffic in a previous period of time. The computing device can generate an anomaly impact score based on the failure score, the fluctuation score, and the sparsity score and assign the anomaly to a severity bin based on the anomaly impact score.