Network Entropy Metrics for Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in understanding and managing the complex behavior of networks, particularly in large and dynamic systems like the internet, where malicious processes and attacks can occur, and maintaining secure communication is crucial for national and global stability, but existing methods struggle with the sheer volume of data and the need for intuitive, hierarchical analysis of network topology.

Innovation Solution

The development of generalized entropy functions based on the Markov monoid matrix, which generates metrics that can quickly compute and intuitively interpret the state and time evolution of network nodes, allowing for dynamic monitoring and identification of changes in network connectivity patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional network analysis methods are used to monitor network status and behavior, then comprehensive data collection is achieved, but the computational complexity and time required for analysis increases significantly

Engineering Contradiction:
Improvenetwork status monitoring accuracyVSAvoidcomputation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts only the essential features needed for network analysis by using entropy metrics that summarize network topology and behavior into compact representations. Instead of analyzing all raw network data, the system computes entropy values that capture the essential structural and dynamic properties of the network, thereby reducing computational burden while maintaining monitoring accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms network data from traditional representation formats into entropy-based parameters. By computing entropy metrics (such as Shannon entropy or Renyi entropy) from network adjacency matrices or flow data, the system changes the parameter space to one that is both informative and computationally efficient, enabling fast comparison and anomaly detection.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If detailed network data analysis is performed to understand complex network behavior, then comprehensive understanding is achieved, but the difficulty of detecting and measuring network patterns increases

Engineering Contradiction:
Improvenetwork behavior understandingVSAvoidnetwork pattern analysis complexity
Core Design Contradiction:
Loss of informationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces entropy metrics as intermediary representations between raw network data and human interpretation. These entropy values serve as mediators that translate complex network structures and dynamics into intuitive scalar or spectral representations, making it easier to detect and measure network patterns without losing essential behavioral information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms network analysis from examining individual edge or node properties to analyzing the spectral dimension of entropy values. By computing entropy spectra or using eigenvalue decompositions of entropy-based matrices, the system elevates the analysis to a different dimensional space where network patterns become more discernible and interpretable.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If comprehensive network monitoring is implemented to detect malicious activities, then security coverage is improved, but the device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal monitoring framework based on entropy metrics that can be applied to various types of networks and security threats through a single unified approach. The entropy-based analysis method serves multiple functions including anomaly detection, topology analysis, and behavior monitoring, thereby reducing the need for multiple specialized systems and lowering overall device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8271412B2Methods and systems for determining entropy metrics for networks
Publication Date: 2012.09.18 UNIVERSITY OF SOUTH CAROLINA
  • US8271412B2 patent drawing
  • US8271412B2 patent drawing
  • US8271412B2 patent drawing

AI summary

Methods and systems for network monitoring using network metrics which are generalized entropy functions of the Markov monoid matrix M generated by an altered connection matrix C.