Virtual Traffic Hub Anomaly Detection via Segmented Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large-scale provider networks face challenges in scaling network packet processing and detecting anomalies in traffic patterns due to the complexity of managing hundreds of thousands of virtual or physical machines, where ad-hoc solutions fail to efficiently handle customized packet transformation requirements and detect anomalous traffic patterns.
Innovation Solution
Implementing scalable virtual traffic hubs with a multi-layer cell-based packet processing service that uses action implementation nodes and decision master nodes to manage network packets based on customer-provided metadata, enabling anomaly detection and reporting through customizable anomaly metrics collection and machine learning models.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If ad-hoc solutions are used for packet transformation requirements, then customization flexibility is improved, but scalability deteriorates in large provider networks
Solution Approach 1:
The system segments packet processing into separate functional components: virtual traffic hubs handle packet transformation and forwarding, while anomaly detection systems monitor traffic patterns. This segmentation allows each component to be independently scaled and optimized, resolving the contradiction between customization flexibility and scalability.
Solution Approach 2:
Virtual traffic hubs are designed as universal networking components that can handle multiple types of packet transformations and forwarding scenarios through configurable policies. This multi-functionality allows a single infrastructure to serve diverse customization needs without requiring separate ad-hoc solutions for each scenario, thereby improving both adaptability and scalability.
2Measurement precision
If comprehensive anomaly detection is implemented across large provider networks, then detection precision is improved, but system complexity worsens
Solution Approach 1:
The patent introduces virtual traffic hubs as intermediary components between network traffic sources and anomaly detection systems. These hubs aggregate and normalize traffic data, providing a simplified interface for anomaly detection algorithms to analyze comprehensive network patterns without directly handling the full complexity of raw network traffic from hundreds of thousands of devices.
Solution Approach 2:
The system transforms anomaly detection from a distributed complex task across numerous network devices to a centralized analysis performed on aggregated traffic data at virtual traffic hubs. This dimensional change moves the detection problem from the network device level to the virtualization layer, reducing system complexity while maintaining or improving detection precision through broader traffic pattern analysis.
3Productivity
If virtualization technologies are deployed to share hardware resources, then hardware utilization is improved, but managing network packet processing complexity increases
Solution Approach 1:
Virtual traffic hubs serve as intermediary components between virtualized network functions and physical hardware resources. They abstract packet processing management from the complexity of underlying virtualization infrastructure, providing a standardized interface for managing network traffic across multiple virtual machines while maintaining efficient hardware utilization through consolidated processing at the hub level.
Data Source
AI summary
Packets of a network flow are received at a virtual traffic hub, which includes an action implementation layer at which routing actions generated at a decisions layer are performed. One or more properties of one or more packets of the flow are analyzed at the virtual traffic hub. An indication of an anomaly of the flow, detected based at least in part on the analysis, is provided to one or more destinations.


