Network Event Detection via Lattice Vector Summaries

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for network event detection and analysis are manual, tedious, and inaccurate, lacking an effective automated system for identifying and addressing network anomalies, attacks, and overloads based on historical network activity.

Innovation Solution

A method involving a data structure with a lattice representation of network activity, partitioning interfaces into groups, and defining a vector to summarize network activity, allowing for the identification of events by comparing distances to known event sub-vectors, enabling automated detection and prediction of network events across multiple temporal, topological, and categorical scales.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual methods are used to analyze network history and identify events, then network managers can use accumulated experience to address network problems, but the process becomes tedious, inaccurate, and not effective

Engineering Contradiction:
Improveaccuracy of network event identificationVSAvoidmanual process complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces manual mechanical analysis of network history with an automated computational system. The system automatically processes network logs, constructs vectors representing network states, and uses algorithms to identify events without human intervention, thereby eliminating the tedious and inaccurate manual process while maintaining high reliability in event identification

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs self-service by automatically analyzing its own operational data. The network management system processes its own network history, constructs representations of network states, and identifies events autonomously without requiring external manual analysis, making the system both reliable and easy to operate

Inventive Principle:
Principle #25Self-service

2Productivity

If automated methods are implemented to search network history, then efficiency and accuracy improve, but device complexity increases due to data structures and algorithms required

Engineering Contradiction:
Improveautomated event detection efficiencyVSAvoiddata structure and algorithm complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the complex network state into manageable components by partitioning network interfaces into groups and representing them as vectors with specific dimensions. This segmentation allows the system to handle complex network data through simpler, standardized vector representations, reducing the perceived complexity while maintaining high productivity in automated event detection

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The vector representation system serves multiple functions simultaneously: it represents network states, enables comparison with historical data, facilitates event identification, and supports both corrective and preventive measures. This multi-functionality reduces the need for separate complex systems, thereby improving productivity without proportionally increasing device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If extensive network history is maintained and analyzed, then more accurate event identification is possible, but the volume of data and processing requirements increase

Engineering Contradiction:
Improvenetwork activity summary accuracyVSAvoidnetwork history data volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts essential information from extensive network history by constructing vectors that capture the most important characteristics of network states. Instead of processing raw historical data directly, the system extracts and represents only the critical features needed for event identification, thereby maintaining measurement precision while reducing the effective data volume that requires processing

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7649853B1Method for keeping and searching network history for corrective and preventive measures
Publication Date: 2010.01.19 THE BOEING CO
  • US7649853B1 patent drawing
  • US7649853B1 patent drawing
  • US7649853B1 patent drawing

AI summary

A method is provided for identifying an event of network activity associated with a network where the network includes a plurality of interfaces and the method includes providing a first data structure comprising a node, partitioning the plurality of interfaces into a plurality of groups, associating the plurality of groups with the node, providing a vector corresponding to a group of the plurality of groups for representing a summary of the network activity, and identifying an event of network activity according to the vector. Experimental results are shown to demonstrate the effectiveness and robustness of the invention.