Temporal Behavior Analysis for Network Traffic Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current deep learning methods face challenges in efficiently detecting anomalous network traffic, especially in scenarios with limited training data, as they struggle to capture key temporal behaviors hidden in network traffic data.

Innovation Solution

The implementation of sequence data-based temporal behavior analysis (SDTBA) that extracts features by processing communication and profile data to generate temporal features, which are then used in an anomaly detection process to identify anomalous network traffic, utilizing a point process-based model to capture behaviors like short-term usage, long gaps, and cluster patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep learning methods are used to detect anomalous network traffic, then detection accuracy can be improved, but the requirement for large amounts of training data increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidtraining data volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts temporal behavior features from network traffic data using sequence data-based temporal behavior analysis (SDTBA). This extraction approach isolates the essential temporal patterns (short-term usage, long gaps, cluster patterns) from the raw data, enabling effective anomaly detection without requiring large volumes of training data. The feature extraction process transforms raw network traffic into meaningful temporal representations that capture anomalous behaviors.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary feature extraction and temporal behavior analysis before the actual anomaly detection process. By pre-processing the network traffic data to extract temporal features and model normal behavior patterns in advance, the system prepares the detection mechanism with sufficient information, reducing the need for extensive training data during the detection phase.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If traditional anomaly detection methods are used, then implementation is simpler, but the ability to capture temporal behaviors is insufficient

Engineering Contradiction:
Improvedetection system complexityVSAvoidtemporal behavior information
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent introduces temporal behavior features as an intermediary between raw network traffic data and anomaly detection. These features act as a mediator that captures and represents temporal patterns (short-term usage, long gaps, cluster patterns) in a structured form, bridging the gap between complex temporal data and the anomaly detection process while preserving essential temporal information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms network traffic data by changing parameters to temporal behavior features. This transformation converts raw data into meaningful representations that highlight temporal patterns, enabling the detection system to capture temporal behaviors effectively. The parameter change from raw data to temporal features preserves critical information while making it more suitable for anomaly detection.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If more features are extracted to improve detection accuracy, then anomaly detection performance improves, but processing time increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies local quality by focusing feature extraction on specific temporal patterns that are most relevant to anomaly detection. Instead of extracting all possible features from the data, the system concentrates on three key temporal behaviors (short-term usage, long gaps, cluster patterns) that locally capture the essential characteristics of anomalous network traffic, reducing processing overhead while maintaining detection accuracy.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11323465B2Temporal behavior analysis of network traffic
Publication Date: 2022.05.03 NEC CORP
  • US11323465B2 patent drawing
  • US11323465B2 patent drawing
  • US11323465B2 patent drawing

AI summary

Systems and methods for implementing sequence data based temporal behavior analysis (SDTBA) to extract features for characterizing temporal behavior of network traffic are provided. The method includes extracting communication and profile data associated with one or more devices to determine sequences of data associated with the devices. The method includes generating temporal features to model anomalous network traffic. The method also includes inputting, into an anomaly detection process for anomalous network traffic, the temporal features and the sequences of data associated with the devices and formulating a list of prediction results of anomalous network traffic associated with the devices.