Packet Flow Video Representation for Network Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge in building machine learning models for cybersecurity and network management lies in manually engineering features from voluminous and heterogeneous network traffic data, which is dynamic and involves continuous flows between hosts.

Innovation Solution

Convert captured packets into individual videos, applying machine learning algorithms to classify these videos for anomaly detection and identification within or between packet flows.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If manual feature engineering is used to extract information from network traffic data, then the model can be built with traditional methods, but the process becomes time-consuming and complex due to the voluminous and heterogeneous nature of the data

Engineering Contradiction:
Improveease of feature extractionVSAvoidtime for manual feature engineering
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

The patent replaces manual feature engineering with automated video processing techniques. Network traffic packets are converted into video frames, and pre-trained video classification models automatically extract features and classify traffic patterns, eliminating the need for manual feature extraction while reducing processing time and complexity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a visual representation (copy) of network traffic data by converting packets into video frames. This visual copy can then be processed by existing video classification models, allowing the system to leverage pre-trained models for network traffic analysis without requiring custom feature engineering

Inventive Principle:
Principle #26Copying

2Reliability

If network traffic data is processed as-is, then the original data structure is preserved, but the heterogeneous and dynamic nature of the data makes it difficult to apply machine learning models

Engineering Contradiction:
Improvedata structure preservationVSAvoidadaptability to machine learning models
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms network traffic data by changing its representation parameters. Packets are converted into video frames with specific visual parameters (color, shape, position) that correspond to network characteristics. This parameter transformation makes the data compatible with video classification models while preserving the essential traffic patterns

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces video frames as an intermediary representation between raw network packets and machine learning models. This intermediary format bridges the gap between heterogeneous network data and standard ML model inputs, allowing existing video processing models to be applied to network traffic analysis

Inventive Principle:
Principle #24Intermediary (Mediator)

3Quantity of substance

If the system processes all network traffic data, then comprehensive analysis is achieved, but the voluminous data creates computational complexity and scalability issues

Engineering Contradiction:
Improvecompleteness of traffic analysisVSAvoidcomputational complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent creates a visual representation of network traffic that can be processed by efficient video models. By converting packets to video frames, the system leverages optimized computer vision algorithms that can handle large datasets more efficiently than traditional network analysis methods, reducing computational complexity while maintaining comprehensive analysis

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent segments network traffic into individual packets and then into video frames. This segmentation allows the system to process data in manageable units that can be efficiently handled by video classification models, reducing the computational burden compared to processing raw packet data as a whole

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12621224B2Abstracting network traffic as video for representation learning
Publication Date: 2026.05.05 MICRO FOCUS LLC
  • US12621224B2 patent drawing
  • US12621224B2 patent drawing
  • US12621224B2 patent drawing

AI summary

A plurality of captured packets are received. The plurality of captured packets are from a plurality of packet flows. A packet flow is a communication session between two devices. For example, a packet flow may be a communication session between a client and a server. The plurality of captured packets are sorted into individual packet flows. The individual packet flows are converted into individual videos. For example, each packet from each packet flow is stored as a separate video frame in an individual video. A machine learning algorithm is applied to the individual videos to perform analytic tasks on the individual videos. For example, the machine learning algorithm may be used to identify anomalies within a packet flow and/or between packet flows.