Network Trend Line Correlation for Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network management platforms fail to effectively detect network anomalies and potential faults by not considering the correlation between trend lines, particularly higher-order derivatives and temporal correlations, which can reveal significant patterns or events that lower-order trends may miss.

Innovation Solution

The implementation of systems and methods that analyze network operation data to identify trends and patterns by using higher-order derivatives, such as acceleration and jerk, and correlating these with other trend lines and their derivatives to detect anomalies and potential events, enabling more sensitive detection of network conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing network management platforms examine data only on trends showing increase or decrease over unit time, then the examination process is simple, but significant patterns and events are missed that could be revealed by analyzing higher-order derivatives and temporal correlations

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transitions from analyzing only first-order trends (increase/decrease over time) to incorporating higher-order derivatives (acceleration, jerk) and temporal correlations between multiple trend lines. This dimensional expansion in the analysis space enables detection of patterns that were previously invisible, directly resolving the contradiction between detection accuracy and analysis complexity by adding necessary analytical dimensions.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system dynamically changes the order of derivatives being analyzed (from first-order to second-order acceleration, third-order jerk, etc.) and adjusts temporal correlation windows to optimize detection sensitivity. This parameter adaptation allows the system to achieve high detection accuracy while managing complexity through selective application of higher-order analysis only when needed.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If higher-order derivatives and temporal correlations are analyzed to detect network anomalies, then detection sensitivity improves, but computational requirements and system complexity increase

Engineering Contradiction:
Improveanomaly detection reliabilityVSAvoidprocessing system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the analysis process into distinct stages: collecting network operation data, generating initial trend lines, calculating higher-order derivatives, computing temporal correlations, and generating alerts. This segmentation allows each component to be optimized independently and enables parallel processing, improving reliability while managing system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces intermediate representations (trend lines and their derivatives) as mediators between raw network data and final anomaly detection. These intermediaries simplify the computational burden by pre-processing data into meaningful patterns before correlation analysis, thereby improving detection reliability without proportionally increasing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If multiple trend lines and their derivatives are correlated in time sequence, then network event detection capability improves, but data processing time and computational load increase

Engineering Contradiction:
Improveevent detection precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary calculations of trend lines and their derivatives continuously in the background before correlation analysis is needed. This preliminary action ensures that when anomaly detection is triggered, the higher-order derivative data is already prepared, reducing real-time processing time while maintaining high event detection precision.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements periodic sampling and analysis of trend line correlations at optimized intervals rather than continuously. This periodic action maintains high detection precision for critical events while significantly reducing overall computational load and processing time by analyzing data only at strategically chosen moments.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9967169B2Detecting network conditions based on correlation between trend lines
Publication Date: 2018.05.08 RED HAT INC

AI summary

Embodiments relate systems and methods for detecting network conditions based on a correlation between trend lines. In embodiments, a network management server can monitor the status and operation of network machines, such as servers or targets, as well as network transmission hardware (e.g. routers). Streams of network operation data from those sources can be captured and stored. The management server or other logic can examine the network operation data to identify trend lines for network conditions, such as application faults, attempted intrusions, or other events or conditions. Trend line data can be treated to generate second or other higher-order derivatives, such as third-order derivatives or others. A time correlation between two or more trend lines and/or their higher order derivatives, for instance, the occurrence of a peak value in the same time window, can be used to identify an event, state or condition.