Network Traffic Model Event Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting events of interest in network traffic lack efficiency in identifying significant events from a vast number of entities and are hindered by noise and spam, requiring large data sets and infrequent analysis.
Innovation Solution
A computer-implemented method generates a network traffic model using forecasted time series data with confidence intervals, identifying events of interest by comparing actual data to forecasted values, and assigns scores based on temporal displacement and excess value, while filtering out noise and spam to produce detailed reports.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional methods are used to detect events of interest in network traffic, then the system can operate with simpler architecture, but it cannot efficiently identify significant events from a vast number of entities and is hindered by noise and spam
Solution Approach 1:
The patent segments the network traffic analysis by treating each entity independently, creating separate time series models for each entity rather than analyzing all entities together. This segmentation allows the system to handle a theoretically infinite number of entities efficiently while maintaining high detection accuracy through individualized forecasting models.
Solution Approach 2:
The patent performs preliminary actions by generating time series models and forecasted values in advance for each entity before actual event detection is needed. The system continuously updates forecasts based on historic data, preparing the analytical framework ahead of time so that when events occur, they can be quickly identified by comparing actual values against pre-computed forecasts and confidence intervals.
2Loss of time
If the system analyzes network traffic frequently to detect events, then event detection timeliness improves, but computational resources and processing time increase
Solution Approach 1:
The patent implements periodic action by updating time series models and forecasts at regular intervals based on the availability of new data. The system performs analysis multiple times during given time segments rather than continuously, achieving frequent event detection capability while managing computational resources through structured periodic updates rather than continuous processing.
Solution Approach 2:
The patent changes parameters dynamically by adjusting the frequency and intensity of analysis based on the noisiness of time series data and the volume of traffic. The system adapts its analytical behavior to the characteristics of the data it processes, performing more intensive analysis when needed and reducing computational effort when data is stable or low-volume, thus optimizing the balance between detection timeliness and resource consumption.
3Measurement precision
If the system processes large amounts of data to improve detection accuracy, then event identification improves, but the system becomes more vulnerable to noise and spam
Solution Approach 1:
The patent applies local quality by tailoring the analysis parameters and model characteristics to the specific properties of each entity's time series data. The system adjusts forecasting methods, confidence interval calculations, and anomaly detection thresholds according to the individual patterns and noise characteristics of each entity, allowing accurate event detection while filtering out noise and spam through entity-specific analysis rather than applying uniform processing to all data.
Data Source
AI summary
Methods, systems, and apparatus, including computer program products, for detecting events of interest. In one aspect, a method includes generating a network traffic model that includes forecasted time series data representative of a frequency of actions related to a network traffic entity, and identifying that an event of interest has occurred based on a comparison of actual time series data related to the network traffic entity with the forecasted time series data.


