Network Packet Broker Auto-Configuring Filters via ML Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Manual configuration of filters in network packet brokers for identifying and addressing anomalous network traffic conditions is labor-intensive and time-consuming, necessitating a more efficient method for automating filter configuration.
Innovation Solution
Utilizing machine learning to receive and aggregate network traffic flow data, generate IP flow feature vectors, and automatically configure filter elements within the network packet broker to detect anomalies and generate filtering rules without user intervention, employing techniques such as autoencoders, decision trees, or K-means clustering for unsupervised learning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual configuration methods are used to set up filters in network packet brokers, then network operators can identify and address anomalous traffic conditions, but the process becomes extremely labor intensive and time consuming
Solution Approach 1:
The system enables self-service through automated filter configuration using machine learning. The network packet broker automatically analyzes traffic patterns, identifies anomalies, and configures filters without human intervention. The machine learning element processes network traffic flow data, generates IP flow feature vectors, and automatically adjusts filter settings based on detected anomalies, eliminating the need for manual operator analysis and configuration.
Solution Approach 2:
The patent replaces the mechanical manual process of filter configuration with an automated machine learning system. Instead of operators manually analyzing traffic data and creating filter rules, a machine learning element processes network traffic flow data, generates feature vectors, identifies anomalies through pattern recognition, and automatically configures filters. This substitution of manual mechanical operations with automated intelligent systems resolves the contradiction between reliable anomaly detection and time-consuming configuration.
2Adaptability or versatility
If manual filter configuration is performed by network operators, then filters can be tuned to address specific network conditions, but the process requires extensive expert analysis and creation of filter rules
Solution Approach 1:
The system performs self-service by automatically analyzing network traffic patterns and configuring appropriate filters without requiring operator expertise. The machine learning element autonomously processes network traffic flow data, generates IP flow feature vectors, identifies anomalies, and creates filter rules based on learned patterns. This eliminates the need for operators to manually analyze and tune filters, making the system easy to operate while maintaining high adaptability to various network conditions.
Solution Approach 2:
The patent utilizes parameter changes through machine learning to dynamically adjust filter configuration parameters based on network conditions. The system analyzes network traffic flow data and automatically modifies filter parameters such as traffic thresholds, anomaly detection sensitivity, and filter rule priorities. This automated parameter adjustment maintains filter adaptability to different network scenarios while eliminating the complexity of manual parameter tuning and filter rule creation.
3Productivity
If automated machine learning systems are implemented for filter configuration, then manual labor and time are reduced, but the system complexity increases with machine learning elements and processing requirements
Solution Approach 1:
The patent applies universality by designing a multi-functional machine learning element that handles multiple tasks within a single integrated component. The machine learning element simultaneously performs data aggregation, feature vector generation, anomaly detection, and filter configuration. This consolidation of multiple functions into one universal component increases productivity by automating the entire filter configuration process while managing system complexity through functional integration rather than proliferation of separate systems.
Solution Approach 2:
The patent uses an intermediary approach by introducing a machine learning element as a mediator between network traffic data and filter configuration. The machine learning element receives network traffic flow data as input, processes it through unsupervised learning algorithms, and outputs automated filter configuration decisions. This intermediary component simplifies the overall system architecture by providing a single point of intelligence that translates raw network data into actionable filter rules, thereby increasing productivity while containing complexity within a well-defined intermediary layer.
Data Source
AI summary
A method for network flow metadata processing at a network packet broker is described herein. The method includes, receiving, as input at a network packet broker, network traffic flow data, aggregating the network traffic flow data over a predefined time period to generate Internet protocol (IP) flow feature vectors containing metadata parameters associated with one or more particular endpoint devices, and providing the IP flow feature vectors to a machine learning element in the network packet broker. The method further includes identifying, by the machine learning element, anomalies existing in the metadata parameters included in the IP flow feature vectors, and automatically configuring one or more filter elements in the network packet broker in response to detecting the identified anomalies of the IP flow feature vectors.


