Network Anomaly Detection via Master Counter Signal Feature Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network anomaly detection methods require significant effort and equipment, including periodicity analysis and timestamp coordination, which can be cumbersome and prone to manipulation.
Innovation Solution
A method that uses a master device with a counter and trigger to detect signal features and calculate network-specific parameters like propagation time patterns without requiring all devices to actively transmit or receive timestamps, allowing for anomaly detection based on physical boundary conditions with minimal network disruption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If PTP (Precision Time Protocol) is used for anomaly detection, then measurement precision is improved, but device complexity increases because all stations must actively transmit and receive timestamps
Solution Approach 1:
The system divides the anomaly detection function into two parts: a master device that performs the actual measurement by detecting signal features and reading counter values, and slave devices that simply transmit signals. This segmentation allows precise anomaly detection while reducing the complexity burden from all devices to just the master device.
Solution Approach 2:
The master device acts as an intermediary that mediates the anomaly detection process. Instead of requiring all devices to perform complex timestamp operations, the master device receives signals from slave devices, detects their features, reads counter values, and performs the evaluation. This intermediary approach simplifies the overall system while maintaining measurement precision.
2Reliability
If all stations actively transmit and receive timestamps, then reliability of time synchronization is improved, but loss of energy increases due to continuous active transmission
Solution Approach 1:
The system segments the active role in time synchronization, with only the master device performing continuous counter reading and anomaly evaluation. Slave devices can operate with simpler, lower-power transmission since they only need to send signals for feature detection, not maintain complex timestamp exchanges with all other devices.
Solution Approach 2:
The master device performs self-service by autonomously reading its own counter values and evaluating anomalies without requiring active participation from slave devices. This self-service approach allows the master to maintain reliable time synchronization while slave devices conserve energy by performing only simple signal transmission.
3Ease of operation
If periodicity analysis is used for anomaly detection, then ease of operation is improved, but measurement precision deteriorates because it requires expected periodicity assumptions
Solution Approach 1:
The system replaces the mechanical assumption-based periodicity analysis with a physics-based measurement approach. Instead of assuming signals should follow expected periodic patterns, the system uses the master device to directly measure signal feature detection times and counter value differences, which are determined by physical boundary conditions. This substitution eliminates the need for periodicity assumptions while maintaining operational simplicity and improving precision.
Solution Approach 2:
The system changes the measurement parameter from signal periodicity (which requires assumptions) to counter value differences at signal feature detection moments (which are directly measurable). By measuring the difference in counter readings when signal features are detected, the system obtains precise anomaly detection results without relying on periodicity assumptions, while keeping the operation simple through automated master device evaluation.
4Measurement precision
If data content examination is used, then measurement precision is improved, but device complexity increases due to software-based evaluation requirements
Solution Approach 1:
The system replaces complex software-based data content examination with a hardware-based counter reading approach. The master device uses its counter and trigger device to detect signal features and read counter values, which are then evaluated to identify signal sources. This hardware substitution maintains precision by using physically determined counter values while reducing software complexity significantly.
Data Source
Figure 1~2
Figure 3
AI summary
The invention relates to a method (30) for monitoring a data-carrying network (10, 25) comprising multiple devices (12, 12b, 13, 14, 15, 29), which are connected to one another via firmly prescribed signal transmission paths (11), for anomalies, wherein one of the devices (12, 12b, 13, 14, 15, 29) is a master device (12, 12b) that has a counter (20, 27) and a trigger device (18) that captures a prescribed signal feature (SM1, SM2) of a signal (16), and the capture prompts a corresponding master counter reading to be read. The invention provides for an evaluation device, under predetermined conditions, to ascertain a setpoint value for at least one network-specific parameter influenced by a physical property of the network (10, 25) before the actual value of the network-specific parameter is ascertained from a difference between the master counter reading and a further counter reading, and for an anomaly to be signalled if a predetermined difference criterion between the actual value and the setpoint value is met.