Network Anomaly Detection Using Multi-Location Load Consistency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network anomaly detection technologies require pre-acquisition of load information during normal times and re-acquisition after network configuration changes, making them inefficient and unstable.
Innovation Solution
A detection device and system that detects network anomalies based on consistency between load information from multiple locations, eliminating the need for load information during normal times and post-change acquisitions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If load information is acquired during normal times and re-acquired after network configuration changes, then detection reliability is improved, but detection efficiency and stability deteriorate due to continuous data collection requirements
Solution Approach 1:
The patent applies preliminary action by pre-calculating expected load values at multiple network locations based on message transmission patterns before anomalies occur. These expected values are stored and used for comparison during detection, eliminating the need for continuous re-acquisition of load information after configuration changes. This prepares the system in advance with reference data that remains valid across configuration changes.
Solution Approach 2:
The patent creates copies of load information by generating expected load values at multiple network locations that mirror the actual load distribution. These copied expected values serve as reference standards for anomaly detection without requiring continuous monitoring of actual loads. The detection device compares actual load information against these pre-created copies to identify deviations indicating anomalies.
2Measurement precision
If load information is continuously collected and re-acquired after configuration changes, then detection accuracy is improved, but system complexity and data processing burden increase
Solution Approach 1:
The patent segments the network into multiple observation points and segments the load information into expected values at each segment. By dividing the detection task into independent segments (each location having its own expected load value), the system achieves comprehensive coverage without requiring complex centralized processing. Each segment can be independently calculated and compared, simplifying the overall system architecture.
Solution Approach 2:
The system applies self-service by automatically generating expected load values at multiple network locations based on message transmission patterns without requiring manual configuration or continuous external input. The detection device autonomously compares actual loads against these self-generated expected values, eliminating the need for complex external data collection infrastructure and reducing system complexity.
3Reliability
If load information from multiple locations is analyzed, then anomaly detection capability is improved, but information processing requirements and time consumption increase
Solution Approach 1:
The patent applies preliminary action by pre-calculating and storing expected load values at multiple network locations before detection is needed. This eliminates the time-consuming process of collecting and analyzing actual load data from multiple locations during detection. The system only needs to retrieve pre-computed expected values and compare them with current measurements, dramatically reducing detection time while maintaining multi-location analysis capability.
Data Source
AI summary
This detection device is a detection device configured to detect an abnormality in a network. In the network, transmission and reception of a plurality of messages including a response message are performed by a plurality of communication apparatuses. The detection device includes: an acquisition unit configured to acquire a plurality of pieces of load information respectively indicating communication loads at a plurality of locations in the network, the plurality of pieces of load information respectively indicating communication loads due to the messages whose transmission sources are corresponding ones of the communication apparatuses; and a detection unit configured to detect an abnormality in the network, based on consistency between the plurality of pieces of load information acquired by the acquisition unit.


