Network Anomaly Detection via Motif Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network performance anomaly detection is manual and unable to react in real-time, requiring ultra-granular and accurate performance measurements to address rapid performance issues in high-speed networks effectively.

Innovation Solution

An automated anomaly detection system that uses a discrete window to extract motifs from network performance metrics, maintains abnormal and normal cluster centers, and classifies anomalies based on distance from these centers using a predetermined decision boundary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If manual anomaly detection process is used, then system complexity is reduced, but detection speed and real-time response capability deteriorate

Engineering Contradiction:
Improveanomaly detection speedVSAvoiddetection system complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent replaces manual anomaly detection (mechanical human operation) with an automated system using machine learning models and algorithms. The system automatically collects performance data, processes it through trained models, and generates anomaly detections without human intervention, thereby dramatically increasing detection speed while accepting the trade-off of increased system complexity through automated infrastructure.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements self-service anomaly detection by automatically monitoring its own network performance metrics, collecting data, processing it through embedded machine learning models, and generating anomaly alerts without requiring external manual analysis. This self-monitoring capability enables real-time detection while maintaining operational autonomy.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If automated anomaly detection system is implemented, then detection accuracy and real-time response improve, but system complexity increases

Engineering Contradiction:
Improveperformance measurement accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-training machine learning models offline using historical network performance data before deployment. These pre-trained models capture normal and anomalous patterns in advance, enabling the system to quickly and accurately detect anomalies in real-time without requiring complex real-time training computations, thus improving measurement precision while managing system complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the anomaly detection task into distinct components: data collection module, model training module (using synthetic and real data), inference module, and alert generation module. This segmentation allows each component to be optimized independently, improving overall measurement accuracy while making the complex system more manageable and maintainable through modular architecture.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If ultra-granular performance measurements are collected, then anomaly detection accuracy improves, but data processing complexity and computational requirements increase

Engineering Contradiction:
Improveperformance measurement granularityVSAvoidcomputational processing power
Core Design Contradiction:
Measurement precisionVSPower

Solution Approach 1:

The system extracts only the most relevant features and metrics from ultra-granular performance measurements for anomaly detection. Instead of processing all raw data points, the machine learning models identify and extract key discriminative features that are most indicative of anomalies, thereby maintaining high detection accuracy while reducing computational processing requirements and power consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11924049B2Network performance metrics anomaly detection
Publication Date: 2024.03.05 ACCEDIAN NETWORKS
  • US11924049B2 patent drawing
  • US11924049B2 patent drawing
  • US11924049B2 patent drawing

AI summary

A method for detecting anomalies in one or more network performance metrics stream for one or more monitored object comprising using a discrete window on the stream to extract a motif from said stream for a first of said network performance metric for a first of said monitored object. Maintaining an abnormal and a normal cluster center of historical time series for said first network performance metric for said first monitored object. Classifying said motif based on a distance between said new time series and said abnormal and said normal cluster center. Determining whether an anomaly for said motif occurred based on said distance and a predetermined decision boundary.