Virtual Traffic Hub Anomaly Detection via Segmented Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large-scale provider networks face challenges in scaling network packet processing and detecting anomalies in traffic patterns due to the complexity of managing hundreds of thousands of virtual or physical machines, where ad-hoc solutions fail to efficiently handle customized packet transformation requirements and detect anomalous traffic patterns.

Innovation Solution

Implementing scalable virtual traffic hubs with a multi-layer cell-based packet processing service that uses action implementation nodes and decision master nodes to manage network packets based on customer-provided metadata, enabling anomaly detection and reporting through customizable anomaly metrics collection and machine learning models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If ad-hoc solutions are used for packet transformation requirements, then customization flexibility is improved, but scalability deteriorates in large provider networks

Engineering Contradiction:
Improvecustomization flexibilityVSAvoidscalability
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system segments packet processing into separate functional components: virtual traffic hubs handle packet transformation and forwarding, while anomaly detection systems monitor traffic patterns. This segmentation allows each component to be independently scaled and optimized, resolving the contradiction between customization flexibility and scalability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Virtual traffic hubs are designed as universal networking components that can handle multiple types of packet transformations and forwarding scenarios through configurable policies. This multi-functionality allows a single infrastructure to serve diverse customization needs without requiring separate ad-hoc solutions for each scenario, thereby improving both adaptability and scalability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If comprehensive anomaly detection is implemented across large provider networks, then detection precision is improved, but system complexity worsens

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces virtual traffic hubs as intermediary components between network traffic sources and anomaly detection systems. These hubs aggregate and normalize traffic data, providing a simplified interface for anomaly detection algorithms to analyze comprehensive network patterns without directly handling the full complexity of raw network traffic from hundreds of thousands of devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transforms anomaly detection from a distributed complex task across numerous network devices to a centralized analysis performed on aggregated traffic data at virtual traffic hubs. This dimensional change moves the detection problem from the network device level to the virtualization layer, reducing system complexity while maintaining or improving detection precision through broader traffic pattern analysis.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If virtualization technologies are deployed to share hardware resources, then hardware utilization is improved, but managing network packet processing complexity increases

Engineering Contradiction:
Improvehardware utilizationVSAvoidpacket processing management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Virtual traffic hubs serve as intermediary components between virtualized network functions and physical hardware resources. They abstract packet processing management from the complexity of underlying virtualization infrastructure, providing a standardized interface for managing network traffic across multiple virtual machines while maintaining efficient hardware utilization through consolidated processing at the hub level.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10893004B2Configurable detection of network traffic anomalies at scalable virtual traffic hubs
Publication Date: 2021.01.12 AMAZON TECH INC
  • US10893004B2 patent drawing
  • US10893004B2 patent drawing
  • US10893004B2 patent drawing

AI summary

Packets of a network flow are received at a virtual traffic hub, which includes an action implementation layer at which routing actions generated at a decisions layer are performed. One or more properties of one or more packets of the flow are analyzed at the virtual traffic hub. An indication of an anomaly of the flow, detected based at least in part on the analysis, is provided to one or more destinations.