Network Traffic Model Event Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting events of interest in network traffic lack efficiency in identifying significant events from a vast number of entities and are hindered by noise and spam, requiring large data sets and infrequent analysis.

Innovation Solution

A computer-implemented method generates a network traffic model using forecasted time series data with confidence intervals, identifying events of interest by comparing actual data to forecasted values, and assigns scores based on temporal displacement and excess value, while filtering out noise and spam to produce detailed reports.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional methods are used to detect events of interest in network traffic, then the system can operate with simpler architecture, but it cannot efficiently identify significant events from a vast number of entities and is hindered by noise and spam

Engineering Contradiction:
Improveevent detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the network traffic analysis by treating each entity independently, creating separate time series models for each entity rather than analyzing all entities together. This segmentation allows the system to handle a theoretically infinite number of entities efficiently while maintaining high detection accuracy through individualized forecasting models.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary actions by generating time series models and forecasted values in advance for each entity before actual event detection is needed. The system continuously updates forecasts based on historic data, preparing the analytical framework ahead of time so that when events occur, they can be quickly identified by comparing actual values against pre-computed forecasts and confidence intervals.

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If the system analyzes network traffic frequently to detect events, then event detection timeliness improves, but computational resources and processing time increase

Engineering Contradiction:
Improveevent detection delayVSAvoidcomputational resources
Core Design Contradiction:
Loss of timeVSPower

Solution Approach 1:

The patent implements periodic action by updating time series models and forecasts at regular intervals based on the availability of new data. The system performs analysis multiple times during given time segments rather than continuously, achieving frequent event detection capability while managing computational resources through structured periodic updates rather than continuous processing.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent changes parameters dynamically by adjusting the frequency and intensity of analysis based on the noisiness of time series data and the volume of traffic. The system adapts its analytical behavior to the characteristics of the data it processes, performing more intensive analysis when needed and reducing computational effort when data is stable or low-volume, thus optimizing the balance between detection timeliness and resource consumption.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If the system processes large amounts of data to improve detection accuracy, then event identification improves, but the system becomes more vulnerable to noise and spam

Engineering Contradiction:
Improveevent detection accuracyVSAvoidnoise and spam impact
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by tailoring the analysis parameters and model characteristics to the specific properties of each entity's time series data. The system adjusts forecasting methods, confidence interval calculations, and anomaly detection thresholds according to the individual patterns and noise characteristics of each entity, allowing accurate event detection while filtering out noise and spam through entity-specific analysis rather than applying uniform processing to all data.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7970934B1Detecting events of interest
Publication Date: 2011.06.28 GOOGLE LLC
  • US7970934B1 patent drawing
  • US7970934B1 patent drawing
  • US7970934B1 patent drawing

AI summary

Methods, systems, and apparatus, including computer program products, for detecting events of interest. In one aspect, a method includes generating a network traffic model that includes forecasted time series data representative of a frequency of actions related to a network traffic entity, and identifying that an event of interest has occurred based on a comparison of actual time series data related to the network traffic entity with the forecasted time series data.