Outlier Classification for Network Traffic Flows

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional traffic flow analytics methods lack refinement in outlier detection and are delayed in identifying malicious or problematic activity due to their reliance on bulk data exports over long time intervals, leading to delayed precautionary actions.

Innovation Solution

Implementing a multiple sub-time window sampling architecture with outlier detection at the network device level, allowing for real-time analysis of traffic flow data in short intervals to reduce average value convergence and false positives, and enabling quicker identification of malicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If traffic flow analytics are performed over long time intervals using bulk data exports, then network resources are conserved, but outlier detection refinement and real-time identification of malicious activity are compromised

Engineering Contradiction:
Improvenetwork resourcesVSAvoidoutlier detection refinement
Core Design Contradiction:
Loss of energyVSMeasurement precision

Solution Approach 1:

The patent segments the long time interval into multiple sub-time windows, allowing outlier detection to be performed on shorter intervals while still conserving network resources through selective bulk exports. This segmentation enables refined outlier detection without requiring continuous real-time analysis of all traffic data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by performing outlier detection only on sampled traffic flows rather than all traffic flows. This selective approach maintains measurement precision for outlier detection while reducing the overall processing load and network resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

2Loss of energy

If traffic flow analytics are performed over long time intervals, then network resources are conserved, but the speed of identifying malicious activity is reduced

Engineering Contradiction:
Improvenetwork resourcesVSAvoididentification speed of malicious activity
Core Design Contradiction:
Loss of energyVSSpeed

Solution Approach 1:

By dividing the analysis into multiple sub-time windows within the bulk export interval, the system can identify malicious activity more quickly within each sub-window while still exporting data in bulk at longer intervals to conserve network resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary outlier detection analysis on sampled traffic flows during the bulk export interval, identifying potential malicious activity before the actual bulk export occurs. This preliminary action enables faster identification and response to threats.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If multiple sub-time window sampling is implemented with outlier detection at network device level, then outlier detection accuracy is enhanced, but device complexity increases

Engineering Contradiction:
Improveoutlier detection accuracyVSAvoidnetwork device complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only sampled traffic flows for outlier detection analysis rather than processing all traffic flows. This extraction approach enhances detection accuracy for the sampled subset while limiting the processing complexity to only the necessary portion of traffic data.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network device performs outlier detection on its own sampled traffic flows without requiring external analytics services. This self-service capability enhances detection accuracy by keeping analysis local while avoiding the complexity of integrated external analytics systems.

Inventive Principle:
Principle #25Self-service

4Reliability

If outlier detection is performed on sampled traffic flows using multiple sub-time windows, then false positives are reduced through aggregation, but processing time increases

Engineering Contradiction:
Improvefalse positive reductionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments outlier detection into multiple sub-time windows that process traffic flows in smaller batches. Aggregation of results across these segments reduces false positives while the segmented approach limits the processing time required for each individual segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by performing outlier detection only on sampled traffic flows rather than all traffic flows. This selective processing reduces the total processing time while still achieving reliable false positive reduction through aggregation across multiple sub-time windows.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12027044B2Assigning outlier-related classifications to traffic flows across multiple time windows
Publication Date: 2024.07.02 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12027044B2 patent drawing
  • US12027044B2 patent drawing
  • US12027044B2 patent drawing

AI summary

Systems and methods are provided for combining a multiple sub-time window sampling architecture with machine learning to detect outlier traffic flow behavior which may indicate malicious/problematic network activity. For example, a network device may obtain a sample of traffic flow data during a defined time window. The sample of traffic flow data may comprise information associated with a sampled subset of traffic flows transferred by a network device in the defined time window. The network device may partition the defined time window into two or more sub-time windows. In each sub-time window, using machine learning, the network device may assign an outlier-related classification to each sampled traffic flow based on the relative behavioral characteristics of all the sampled traffic flows. The network device may aggregate the outlier-related classifications for each sampled traffic flow across multiple sub-time windows, and process traffic flows based on the aggregated outlier-related classifications.