Network Anomaly Detection via Segment Aggregation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network anomaly detection methods focus on tracking performance indicators over time, failing to systematically identify significant segments driving anomalies and often produce biased results due to small sample sizes or large outliers, and do not effectively compare network equipment segments to peer populations.
Innovation Solution
The method employs frequent itemset mining and association rule mining to combine small segments into robust segments for statistically valid conclusions, comparing them to peer segments and their own histories, using segment filters to define abnormality and suggest solutions, and aggregates similar segments for actionable insights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network anomaly detection methods track performance indicators over time, then they can monitor network performance, but they fail to systematically identify significant segments driving anomalies and produce biased results due to small sample sizes
Solution Approach 1:
The patent combines multiple small network segments into larger aggregate segments based on shared characteristics (device type, location, configuration). This merging increases the sample size for each segment, enabling statistically valid anomaly detection while maintaining systematic identification of significant segments through the combination of similar units.
2Measurement precision
If network anomaly detection methods track performance indicators over time, then they can monitor network performance, but they do not effectively compare network equipment segments to peer populations
Solution Approach 1:
The patent segments the network population into distinct groups based on shared characteristics such as device type, geographic location, and configuration parameters. This segmentation enables effective comparison of network equipment segments to peer populations by creating homogeneous groups that can be independently analyzed and compared against relevant benchmarks.
3Loss of information
If the system generates detailed segments of network infrastructure items, then it can identify specific segments driving anomalies, but it increases the complexity of managing and deriving insights from large amounts of data
Solution Approach 1:
The patent merges detailed segment information into aggregate segments that maintain the essential characteristics needed for anomaly identification while reducing overall data complexity. By combining segments with similar properties into larger groups, the system preserves information about anomaly sources through the aggregation process while making the data more manageable and easier to derive insights from.
Data Source
AI summary
A processing system may generate segments of network infrastructure items deployed in a communication network, each segment comprising network infrastructure items grouped in accordance with segment filters and a segment size sparsity threshold, and identify anomalous segments comprising at least a subset of the segments having anomalies of an anomaly type regarding a performance indicator. The processing system may next determine segments from the subset that are defined by sets of segment filter values that are different for less than a threshold number of segment filters, merge the segments from the subset that are different for less than the threshold number to create at least one aggregate segment, and generate a ranking of the subset having the anomalies of the anomaly type, wherein the ranking includes the at least one aggregate segment. The processing system may then perform at least one action in the communication network responsive to the ranking.


