Network Anomaly Detection via Sketching and PCA

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network administrators face challenges in diagnosing and defending against network anomalies in real-time, particularly in large-scale enterprise networks with high data rates and complex configurations, requiring effective monitoring and anomaly localization.

Innovation Solution

A network management station employs sketching and principal component analysis (PCA) to actively monitor administrator-configurable parameters, mathematically identify network anomalies, and automatically mitigate their causes by utilizing sketching for random projections and PCA for eigenvalue decomposition to detect variability and isolate anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional network monitoring methods are used to monitor network parameters in real-time, then network administrators can detect anomalies, but the system cannot effectively localize the root cause of anomalies in large-scale networks with high data rates

Engineering Contradiction:
Improveanomaly localization precisionVSAvoidnetwork scale complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the network monitoring problem by dividing the network into multiple regions or zones, and applies independent monitoring and analysis to each segment. This allows the system to handle large-scale networks by breaking them down into manageable parts, improving anomaly localization precision without being overwhelmed by overall network complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of analysis by applying principal component analysis (PCA) to transform network parameter data into a different dimensional space. This dimensional transformation enables the system to identify patterns and anomalies that are not apparent in the original parameter space, improving detection precision while managing the complexity of high-data-rate networks.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If comprehensive network parameter monitoring is implemented to detect all types of anomalies, then network security is improved, but the computational complexity and processing time increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidanomaly detection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-calculating baseline network behavior patterns and establishing normal parameter ranges before anomalies occur. This allows the monitoring system to quickly compare current parameters against pre-established baselines, enabling rapid anomaly detection without requiring complex real-time analysis of all network parameters, thus improving security while reducing detection time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical/manual anomaly detection methods with automated statistical analysis and machine learning algorithms. By substituting manual monitoring with automated PCA-based analysis, the system can process comprehensive network parameters in real-time, improving both security coverage and detection speed without proportional increases in computational burden.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If real-time anomaly detection and mitigation is implemented, then network security and optimization are improved, but the system complexity and resource requirements increase

Engineering Contradiction:
Improvenetwork optimization efficiencyVSAvoidmonitoring system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the network monitoring system to automatically detect anomalies, diagnose root causes, and initiate mitigation actions without human intervention. The system uses automated rule engines and decision algorithms to respond to detected anomalies, improving network optimization efficiency while managing complexity through automation rather than requiring complex manual intervention procedures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the results of anomaly detection and mitigation actions are fed back into the monitoring system to continuously refine detection algorithms and update baseline parameters. This feedback loop improves productivity over time by making the system increasingly accurate and efficient, while the automated nature of the feedback process manages system complexity through iterative learning rather than requiring complex manual tuning.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8474041B2Autonomous diagnosis and mitigation of network anomalies
Publication Date: 2013.06.25 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8474041B2 patent drawing
  • US8474041B2 patent drawing
  • US8474041B2 patent drawing

AI summary

Autonomous diagnosis and mitigation of network anomalies may include creating a plurality of sketch matrices wherein each sketch matrix corresponds to an individual hashing function and each row in each sketch matrix corresponds to an array of hashed parameters of interest from multiple network devices for a given period of time, the parameters of interest being configurable by an administrator. A principal components analysis (PCA) input matrix is created for each of the sketch matrices by computing an entropy value for each element in the sketch matrices, and principal components analysis (PCA) is performed on each of the PCA input matrices to heuristically detect a network anomaly in real time.