Network Hop Model Anomaly Detection for Secure Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in providing improved network security against sophisticated network threats and risks, such as hacking attempts and data breaches, due to increasing connectivity and the evolving nature of cybersecurity threats, which existing technologies struggle to detect and control effectively.

Innovation Solution

A method that utilizes network traffic data to monitor and analyze user behavior, generating a network hop model to identify normal behavior patterns and adjust data transmission operations, employing machine learning algorithms to detect anomalies, and employing IP tunneling and layered encryptions to secure data transmission, thereby controlling communications and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network monitoring and analysis systems are implemented to detect sophisticated threats, then network security detection capability is improved, but system complexity and computational resources increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments network traffic analysis into multiple components: flow data collection, hop model generation, anomaly detection, and response actions. Each component processes specific aspects of network traffic independently, reducing overall system complexity while maintaining comprehensive threat detection capability through coordinated operation of these segmented modules.

Inventive Principle:
Principle #1Segmentation

2Speed

If real-time network traffic analysis is performed to detect anomalies, then response time to threats is improved, but computational energy consumption increases

Engineering Contradiction:
Improvethreat response speedVSAvoidcomputational energy consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary actions by pre-generating hop models from historical flow data and establishing baseline network behavior patterns before threats occur. This allows the anomaly detection component to quickly compare real-time traffic against pre-established models, achieving fast threat response without requiring intensive real-time computational analysis of all traffic parameters.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If comprehensive network hop modeling is implemented to track data packets, then network visibility and control are improved, but data processing requirements increase

Engineering Contradiction:
Improvenetwork visibilityVSAvoiddata processing volume
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The system extracts only the essential hop information from complete network flow data to create condensed hop models. Instead of processing and storing all raw flow data, the system extracts key routing information (source, destination, intermediate hops, timestamps) to build simplified representations that maintain network visibility while significantly reducing data processing and storage requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12113815B1Systems and methods of using network traffic data to control data transmission
Publication Date: 2024.10.08 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US12113815B1 patent drawing
  • US12113815B1 patent drawing
  • US12113815B1 patent drawing

AI summary

A method may include receiving, via a processor, a first set of data packets from a first computing device associated with a user over a first period of time. The method may then involve generating a network hop model indicative of one or more network hops traversed by the first set of data packets. The method may also include receiving a second set of data packets from the first computing device over a second period of time, determining whether the second set of data packets corresponds to the network hop model, and adjusting one or more operations associated with transmitting a third set of data packets to the first computing device in response to determining that the second set of data packets does not match the network hop model.