Network Anomaly Detection via External Platform Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network administrators face challenges in identifying and addressing significant network anomalies due to an overwhelming number of alerts, many of which are false positives, leading to delays in resolving critical issues affecting users.

Innovation Solution

A method that monitors both internal network events and external public Internet platforms to gather volumetric problem report data, identifies anomalies, and generates reports, which can trigger automatic remediation if a known solution exists, and notifies administrators of critical issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If internal network monitoring tools are used to detect anomalies, then network problems can be identified, but the number of false positive alerts increases significantly

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidnumber of alerts
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent combines internal network monitoring data with external public Internet platform data to create a correlated anomaly detection system. By merging these two independent data sources, the system validates alerts through multiple perspectives, reducing false positives while maintaining comprehensive coverage of network issues.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback by continuously monitoring external platforms for user-reported problems and comparing them with internal network events. This feedback loop allows the system to adjust alert generation based on actual user impact, filtering out false positives that don't correlate with external observations.

Inventive Principle:
Principle #23Feedback

2Reliability

If administrators attend to all alerts, then comprehensive monitoring is achieved, but critical problems are overlooked due to alert overload

Engineering Contradiction:
Improveproblem detection completenessVSAvoidtime to resolve critical issues
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts and prioritizes critical anomalies by correlating internal alerts with external user impact data. By taking out only the most significant problems that are confirmed by multiple sources, the system reduces administrator workload while ensuring critical issues receive immediate attention.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies different levels of attention to different alerts based on their correlation strength and impact. Critical anomalies with strong external corroboration receive immediate focus, while low-priority alerts are handled separately, creating a differentiated response strategy that optimizes administrator time.

Inventive Principle:
Principle #3Local quality

3Productivity

If internal monitoring tools are used alone, then network events are captured, but false positives cannot be distinguished from real problems

Engineering Contradiction:
Improvealert processing efficiencyVSAvoidanomaly validation accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent merges internal network event data with external public Internet platform data to create a validation mechanism. By combining these independent data sources, the system achieves both efficient processing and high precision in distinguishing real problems from false positives through correlation analysis.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12244455B2Detecting network anomalies by correlating multiple information sources
Publication Date: 2025.03.04 ROYAL BANK OF CANADA
  • US12244455B2 patent drawing
  • US12244455B2 patent drawing
  • US12244455B2 patent drawing

AI summary

A method for detecting network anomalies comprises monitoring a network that provides public-facing application services and monitoring at least one external public Internet platform outside of the network to obtain volumetric problem report data about the application services. The external public Internet platform is nonspecific to the application services. Responsive to the volumetric problem report data from the external public Internet platform(s) exceeding a threshold, at least one internal network event logging tool is queried for alerts, and from the alerts, at least one anomaly associated with the volumetric problem report data is identified and an anomaly report about the at least one anomaly is generated. Responsive to generating the anomaly report, it may be determined whether the at least one anomaly has a known remediation, and if so, the known remediation may be initiated automatically. Network administrator(s) may also be automatically notified.