Network Anomaly Detection Using Sequence Frequency Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing volume of network traffic in IoT and enterprise networks makes it difficult to accurately distinguish between benign and malicious activity, leading to a high rate of false alarms and inefficiencies in identifying potential threats.

Innovation Solution

A method that combines the probability of a sequence of network events, obtained using a trained statistical model like a Markov model, with a frequency characteristic to determine the likelihood of anomalous activity, allowing differentiation between benign and malicious network behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network monitoring methods are used to analyze all network traffic, then comprehensive threat detection is achieved, but false alarms increase and analysis efficiency decreases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidbenign vs malicious differentiation accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments network events into sequences and analyzes them collectively rather than individually. By grouping related events into sequences and evaluating their combined probability and frequency characteristics, the system achieves better differentiation between benign and malicious activity, reducing false alarms while maintaining comprehensive threat detection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms the analysis approach by changing parameters from individual event analysis to sequence-level probability and frequency analysis. It uses probability of sequence occurrence and frequency characteristics as new parameters to evaluate network activity, enabling more accurate distinction between benign and malicious behavior.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If detailed analysis of each network event is performed, then detection accuracy improves, but computational load and time consumption increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-calculating probability values for event sequences based on historical data and storing them for quick reference. During real-time analysis, the system retrieves pre-computed probabilities and combines them with frequency characteristics, avoiding the need for complex real-time calculations and reducing analysis time while maintaining high detection accuracy.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If all network events are monitored individually, then complete threat coverage is achieved, but false alarm rate increases

Engineering Contradiction:
Improvethreat detection coverageVSAvoidfalse alarms
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent merges multiple individual event analyses into a unified sequence evaluation. By combining events into sequences and assessing their joint probability and frequency characteristics together, the system maintains complete threat coverage while reducing false alarms. The merging approach allows benign events that individually appear suspicious to be correctly identified when viewed in context with their sequence counterparts.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12438765B2Network anomaly detection
Publication Date: 2025.10.07 BRITISH TELECOM PLC
  • US12438765B2 patent drawing
  • US12438765B2 patent drawing
  • US12438765B2 patent drawing

AI summary

A method of identifying anomalous network activity. The method includes identifying, based on network data representative of network activity within a network, at least one instance of a sequence of events that occurred within the network. A probability of the sequence of events occurring during non-anomalous network activity is obtained based on transition probabilities between events in the sequence of events. A frequency characteristic dependent on a frequency at which the sequence of events occurred within the network is determined. A likelihood of the sequence of events occurring within the network at the frequency is determined based on a combination of the probability and the frequency characteristic. It is identified, based on the likelihood, that at least a portion of the network data is anomalous.