Packet Flow Video Representation for Network Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge in building machine learning models for cybersecurity and network management lies in manually engineering features from voluminous and heterogeneous network traffic data, which is dynamic and involves continuous flows between hosts.
Innovation Solution
Convert captured packets into individual videos, applying machine learning algorithms to classify these videos for anomaly detection and identification within or between packet flows.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If manual feature engineering is used to extract information from network traffic data, then the model can be built with traditional methods, but the process becomes time-consuming and complex due to the voluminous and heterogeneous nature of the data
Solution Approach 1:
The patent replaces manual feature engineering with automated video processing techniques. Network traffic packets are converted into video frames, and pre-trained video classification models automatically extract features and classify traffic patterns, eliminating the need for manual feature extraction while reducing processing time and complexity
Solution Approach 2:
The patent creates a visual representation (copy) of network traffic data by converting packets into video frames. This visual copy can then be processed by existing video classification models, allowing the system to leverage pre-trained models for network traffic analysis without requiring custom feature engineering
2Reliability
If network traffic data is processed as-is, then the original data structure is preserved, but the heterogeneous and dynamic nature of the data makes it difficult to apply machine learning models
Solution Approach 1:
The patent transforms network traffic data by changing its representation parameters. Packets are converted into video frames with specific visual parameters (color, shape, position) that correspond to network characteristics. This parameter transformation makes the data compatible with video classification models while preserving the essential traffic patterns
Solution Approach 2:
The patent introduces video frames as an intermediary representation between raw network packets and machine learning models. This intermediary format bridges the gap between heterogeneous network data and standard ML model inputs, allowing existing video processing models to be applied to network traffic analysis
3Quantity of substance
If the system processes all network traffic data, then comprehensive analysis is achieved, but the voluminous data creates computational complexity and scalability issues
Solution Approach 1:
The patent creates a visual representation of network traffic that can be processed by efficient video models. By converting packets to video frames, the system leverages optimized computer vision algorithms that can handle large datasets more efficiently than traditional network analysis methods, reducing computational complexity while maintaining comprehensive analysis
Solution Approach 2:
The patent segments network traffic into individual packets and then into video frames. This segmentation allows the system to process data in manageable units that can be efficiently handled by video classification models, reducing the computational burden compared to processing raw packet data as a whole
Data Source
AI summary
A plurality of captured packets are received. The plurality of captured packets are from a plurality of packet flows. A packet flow is a communication session between two devices. For example, a packet flow may be a communication session between a client and a server. The plurality of captured packets are sorted into individual packet flows. The individual packet flows are converted into individual videos. For example, each packet from each packet flow is stored as a separate video frame in an individual video. A machine learning algorithm is applied to the individual videos to perform analytic tasks on the individual videos. For example, the machine learning algorithm may be used to identify anomalies within a packet flow and/or between packet flows.


