Network Link Detection via Bayesian Probability Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network link analysis methods fail to effectively identify communication links between nodes in communications networks, especially when communications traffic is encrypted or obscured, limiting their ability to determine who is communicating with whom.

Innovation Solution

A method and system that uses a hypothesis test based on Bayesian probability calculations to estimate network links by analyzing the relationships between events in time windows, identifying associated nodes through the calculation of posterior probabilities and applying statistical tests like the Neyman-Pearson test, even in encrypted or obscured communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network link analysis methods are used, then the analysis process is simple, but the ability to identify communication links in encrypted or obscured communications fails

Engineering Contradiction:
Improvelink detection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical/link-based analysis methods with a Bayesian probability calculation system. Instead of directly observing communication links, the system uses statistical probability models to infer the existence and strength of links between network nodes based on observed communication events, thereby achieving reliable detection in encrypted environments without requiring direct access to communication content.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent transforms the link detection problem from a binary presence/absence determination to a continuous probability assessment. By calculating posterior probabilities P(Lij|E) for each potential link, the system can dynamically adjust detection thresholds and prioritize high-probability links, enabling flexible and adaptive link identification in complex encrypted communication scenarios.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If Bayesian probability calculations are used to detect network links, then the ability to identify communication partners in encrypted communications is improved, but the computational complexity increases

Engineering Contradiction:
Improvenode association probabilityVSAvoidcalculation system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the network into discrete nodes and evaluates link probabilities between node pairs independently. By calculating posterior probabilities for each potential link Lij separately based on observed events E, the system breaks down the complex global link detection problem into manageable local probability assessments, reducing overall computational complexity while maintaining measurement precision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses observed communication events E as copies or proxies for the actual encrypted communications. Instead of attempting to decrypt or directly analyze encrypted traffic, the system creates a probabilistic model based on observable metadata (timing, frequency, patterns of communication events), thereby achieving precise link identification without the computational burden of breaking encryption.

Inventive Principle:
Principle #26Copying

3Reliability

If network link analysis is performed on encrypted communications, then the ability to determine communication partners is improved, but the loss of information due to encryption increases

Engineering Contradiction:
Improvecommunication link identificationVSAvoidencrypted traffic information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces Bayesian probability calculations as an intermediary layer between observed communication events and link identification. Instead of attempting to access the actual encrypted communication content, the system uses probability theory to bridge the gap between observable event patterns and the hidden link structure, thereby recovering link information without needing to decrypt the actual traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces direct observation of communication content with statistical inference based on event patterns. By substituting the need to access encrypted payload information with probability-based link detection methods, the system maintains reliable link identification while accepting the information loss inherent in encrypted communications.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8682836B2Detection of network links in a communications network
Publication Date: 2014.03.25 SOUTHWEST RES INST
  • US8682836B2 patent drawing
  • US8682836B2 patent drawing
  • US8682836B2 patent drawing

AI summary

A method or system for detecting associations between nodes of a communications network. “Node events”are defined as being communications from one node to another, each event having an origination time. For a given node, and for a number of time windows, event originations from other nodes after the occurrence of an event from that node are counted. Then for that node, these counts may be used to determine the probability that any other node is in a time window of that node. The probability data may then be used to determine the likelihood of a communications link with that node. The process may be repeated for a number of nodes to determine links within the network.