IP Library › Granted Patent US 12,237,981
Granted Patent B2
US 12,237,981 · App. 17/669,638 · Granted Feb 25, 2025

Traffic anomaly detection method, and model training method and apparatus

Inventors: Yanfang Zhang (Nanjing, CN); Gang Li (Chengdu, CN); Li Xue (Nanjing, CN); Wei Lin (Shenzhen, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
H04L41/145H04L43/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,237,981
App. No.
17/669,638
Granted
Feb 25, 2025
Kind
B2
Abstract

A traffic anomaly detection method includes obtaining a target time series including N elements; obtaining a target parameter of the target time series, where the target parameter includes at least one of a periodic factor or a jitter density, the periodic factor represents a wave-shaped change that is presented in the target time series and that is about a long-term trend, and the jitter density represents a deviation between an actual value and a target value of the target time series within a target time; determining, from a plurality of types based on the target parameter, a first type to which the target time series belongs, where each of the types corresponds to one parameter set, and the target parameter belongs to a parameter set corresponding to the first type; and detecting an anomaly of the target time series based on a first-type decision model corresponding to the first type.

Claims (194)

1. A method comprising:

obtaining a target time series comprising N elements, wherein the N elements correspond to N moments, and wherein each of the N elements is traffic data received at a corresponding moment;

obtaining a target parameter of the target time series based on the target time series, wherein the target parameter comprises at least one of a periodic factor or a jitter density, wherein the periodic factor represents a wave-shaped change that is presented in the target time series and that is about a trend that represents an overall change of the target time series, and wherein the jitter density represents a deviation between an actual value of the target time series and a target value of the target time series within a target time;

obtaining, based on a first mapping relationship and a first type of the target time series, a first-type decision model, wherein the first mapping relationship comprises correspondences between a plurality of types and a plurality of first-type decision models, wherein the first type of the target time series is based on the plurality of types and on the target parameter, wherein each of the types corresponds to one parameter set and corresponds to a type of decision model, and wherein the target parameter belongs to a parameter set that corresponds to the first type; and

detecting an anomaly of the target time series based on the first-type decision model that corresponds to the first type.

2. The method of claim 1 , further comprising:

decomposing each of the N elements into a trend component, a periodic component, and a residual component;

obtaining a first sub-time series comprising N periodic components and a second sub-time series comprising N residual components; and

further obtaining the target parameter based on the first sub-time series or the second sub-time series.

3. The method of claim 2 , further comprising determining, based on the first sub-time series, whether the target time series has the periodic factor.

4. The method of claim 3 , wherein the target time series has the periodic factor when the N periodic components exist or the target time series does not have the periodic factor when the N periodic components do not exist.

5. The method of claim 2 , further comprising:

obtaining, based on a second mapping relationship and the first type, a second-type decision model that corresponds to the first type, wherein the second mapping relationship comprises correspondences between the plurality of types and a plurality of second-type decision models; and

further detecting the anomaly based on the second sub-time series and the second-type decision model, wherein the second-type decision model corresponds to the first type and is an N-sigma model.

6. The method of claim 2 , wherein the jitter density is based on the second sub-time series.

7. The method of claim 6 , wherein the jitter density is according to the following formula:

R

=

Σ

0

N

-

1

⁢

r

n

N

,

wherein R is the jitter density;

wherein r n is according to the following formula:

r

n

=

{

1

,

Σ

n

nW

-

1

⁢

C

n

2

Σ

n

nW

-

1

⁢

x

n

2

≥

α

0

,

Σ

n

nW

-

1

⁢

C

n

2

Σ

n

nW

-

1

⁢

x

n

2

<

α

,

wherein C n is an n th element in the second sub-time series, wherein x n is an n th element in the target time series; and

wherein N is according to the following formula:

N

=

[

T

W

]

,

wherein T is a length of the target time series, wherein W is a window length of an addition window, and wherein α is a first preset value.

8. The method of claim 1 , wherein a first parameter set from a plurality of parameter sets of the target parameter is based on the target parameter, and

wherein the first type is based on a second mapping relationship and the first parameter set, wherein the second mapping relationship comprises correspondences between the parameter sets and the plurality of types.

9. The method of claim 2 , wherein a third sub-time series comprises N trend components, and wherein the method further comprises:

dividing a second time series into M sub-series of a target length, wherein M is a positive integer, wherein the second time series is the third sub-time series or is formed based on the third sub-time series and a linear segmentation algorithm;

calculating matrix profile (MP) values of the M sub-series, wherein the MP values constitute an MP time series; and

further detecting the anomaly based on the MP time series and an N-sigma algorithm.

10. A method comprising:

obtaining a target time series comprising N elements, wherein the N elements correspond to N moments, and wherein each of the N elements is traffic data received at a corresponding moment;

decomposing each of the N elements into a trend component, a periodic component, and a residual component;

obtaining a first sub-time series comprising N periodic components and a second sub-time series comprising N residual components;

obtaining a target parameter of the target time series based on the first sub-time series or the second sub-time series, wherein the target parameter comprises at least one of a periodic factor or a jitter density, wherein the periodic factor represents a wave-shaped change that is presented in the target time series and that is about a trend that represents an overall change of the target time series, and wherein the jitter density is based on the second sub-time series and represents a deviation between an actual value of the target time series and a target value of the target time series within a target time; and

classifying the target time series based on the target parameter.

11. The method of claim 10 , further comprising determining, based on the first sub-time series, whether the target time series has the periodic factor.

12. The method of claim 11 , wherein the target time series has the periodic factor when the N periodic components exist or the target time series does not have the periodic factor when the N periodic components do not exist.

13. The method of claim 12 , wherein the target time series is periodic when the periodic factor exists or the target time series is aperiodic when the periodic factor does not exist.

14. The method of claim 10 , wherein

the jitter density is according to the following formula:

R

=

Σ

0

N

-

1

⁢

r

n

N

,

wherein R is the jitter density,

wherein r n is according to the following formula:

r

n

=

{

1

,

Σ

n

nW

-

1

⁢

C

n

2

Σ

n

nW

-

1

⁢

x

n

2

≥

α

0

,

Σ

n

nW

-

1

⁢

C

n

2

Σ

n

nW

-

1

⁢

x

n

2

<

α

,

wherein C n is an n th element in the second sub-time series, wherein x n is an n th element in the target time series,

wherein N is according to the following formula:

N

=

[

T

W

]

,

wherein T is a length of the target time series, wherein W is a window length of an addition window, and wherein a is a first preset value.

15. The method of claim 10 , wherein the target time series is spiky when the jitter density is greater than a second preset value or the target time series is stationary when the jitter density is less than or equal to the second preset value.

16. An apparatus comprising:

a processor; and

a memory coupled to the processor and configured to store instructions that when executed by the processor, cause the apparatus to be configured to:

obtain a target time series comprising N elements, wherein the N elements correspond to N moments, and wherein each of the N elements is traffic data received at a corresponding moment;

obtain a target parameter of the target time series based on the target time series, wherein the target parameter comprises at least one of a periodic factor or a jitter density, wherein the periodic factor represents a wave-shaped change that is presented in the target time series and that is about a trend that represents an overall change of the target time series, and wherein the jitter density is used to represent a deviation between an actual value of the target time series and a target value of the target time series within a target time;

obtain, based on a first mapping relationship and a first type of the target time series, a first-type decision model, and wherein the first mapping relationship comprises correspondences between a plurality of types and a plurality of first-type decision models, wherein the first type of the target time series is based on the plurality of types and on the target parameter, wherein each of the types corresponds to one parameter set and corresponds to a type of decision model, and wherein the target parameter belongs to a parameter set that corresponds to the first type; and

detect an anomaly of the target time series based on the first-type decision model that corresponds to the first type.

17. The apparatus of claim 16 , wherein the instructions that when executed by the processor further cause the apparatus to be configured to:

decompose each of the N elements into a trend component, a periodic component, and a residual component;

obtain a first sub-time series comprising N periodic components and a second sub-time series comprising N residual components; and

further obtain the target parameter based on the first sub-time series or the second sub-time series.

18. The apparatus of claim 17 , wherein the instructions that when executed by the processor further cause the apparatus to be configured to determine, based on the first sub-time series, whether the target time series has the periodic factor.

19. The apparatus of claim 18 , wherein the target time series has the periodic factor when the N periodic components exist or the target time series does not have the periodic factor when the N periodic components do not exist.

20. The apparatus of claim 17 , wherein the jitter density is based on the second sub-time series.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 7, 2025
From: ZHANG, YANFANG; LI, GANG; XUE, LI; LIN, WEI
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 069766/0047 →
Priority Claims (1)
CN 201910752193.9 · Aug 15, 2019 · national
Continuity (2)
Continuation PCTCN2020107627 · Aug 7, 2020
Related Publication 20220166681A1 · May 26, 2022
References Cited (93)
US 6137283A · Williams · 2000 [cited by examiner]
US 6263290B1 · Williams · 2001 [cited by examiner]
US 6493169B1 · Ferris · 2002 [cited by examiner]
US 6529842B1 · Williams · 2003 [cited by examiner]
US 6832172B2 · Ward · 2004 [cited by examiner]
US 6898535B2 · Draving · 2005 [cited by examiner]
US 7010444B2 · Nishikobara · 2006 [cited by examiner]
US 7254168B2 · Guenther · 2007 [cited by examiner]
US 7388937B1 · Rodger · 2008 [cited by examiner]
US 7400988B2 · Tabatabaei · 2008 [cited by examiner]
US 7512196B2 · Tabatabaei · 2009 [cited by examiner]
US 7623977B2 · Tabatabaei · 2009 [cited by examiner]
US 7899638B2 · Miller · 2011 [cited by examiner]
US 7941287B2 · Tabatabaei · 2011 [cited by examiner]
US 8065141B2 · Maeda · 2011 [cited by examiner]
US 8594169B2 · Zivny · 2013 [cited by examiner]
US 9363045B2 · Agoston · 2016 [cited by examiner]
US 9506951B2 · Taratorin · 2016 [cited by examiner]
US 9787416B2 · Shiva · 2017 [cited by examiner]
US 9954546B2 · Laquai · 2018 [cited by examiner]
US 10530422B2 · Chen · 2020 [cited by examiner]
US 10942219B2 · Wong · 2021 [cited by examiner]
US 10958551B2 · Nitsch · 2021 [cited by examiner]
US 11243249B2 · Wong · 2022 [cited by examiner]
US 11620528B2 · Ryan · 2023 [cited by examiner]
US 11624781B2 · Guenther · 2023 [cited by examiner]
US 11777966B2 · Jiang · 2023 [cited by examiner]
US 20030004664A1 · Ward · 2003 [cited by examiner]
US 20040136450A1 · Guenther · 2004 [cited by examiner]
US 20040143406A1 · Nishikobara · 2004 [cited by examiner]
US 20050080574A1 · Draving · 2005 [cited by examiner]
US 20050232345A1 · Ward · 2005 [cited by examiner]
US 20050286627A1 · Tabatabaei · 2005 [cited by examiner]
US 20080319691A1 · Tabatabaei · 2008 [cited by examiner]
US 20090106839A1 · Cha et al. · 2009 [cited by applicant]
US 20110292987A1 · Zivny · 2011 [cited by examiner]
US 20130142242A1 · Agoston · 2013 [cited by examiner]
US 20160217022A1 · Velipasaoglu et al. · 2016 [cited by applicant]
US 20160231357A1 · Taratorin · 2016 [cited by examiner]
US 20160292196A1 · Yan · 2016 [cited by examiner]
US 20170011299A1 · Ebert et al. · 2017 [cited by applicant]
US 20170244504A1 · Chen · 2017 [cited by examiner]
US 20170257107A1 · Laquai · 2017 [cited by examiner]
US 20180053111A1 · Yan · 2018 [cited by examiner]
US 20190006937A1 · Wong · 2019 [cited by examiner]
US 20190064264A1 · Wong · 2019 [cited by examiner]
US 20190102276A1 · Dang et al. · 2019 [cited by applicant]
US 20190138643A1 · Saini et al. · 2019 [cited by applicant]
US 20190228296A1 · Gefen et al. · 2019 [cited by applicant]
US 20200387797A1 · Ryan · 2020 [cited by examiner]
US 20210042382A1 · Freeman · 2021 [cited by examiner]
US 20210160263A1 · Jiang · 2021 [cited by examiner]
US 20210374864A1 · Kchouk · 2021 [cited by examiner]
US 20220166681A1 · Zhang et al. · 2022 [cited by applicant]
US 20220382857A1 · Liu · 2022 [cited by examiner]
CN 102111312A · 2011 [cited by applicant]
CN 102288840A · 2011 [cited by examiner]
CN 102288840B · 2015 [cited by examiner]
CN 106095655A · 2016 [cited by applicant]
CN 106685750A · 2017 [cited by applicant]
CN 107528722A · 2017 [cited by applicant]
CN 108804731A · 2018 [cited by applicant]
CN 109783876A · 2019 [cited by applicant]
CN 109784042A · 2019 [cited by applicant]
CN 109862129A · 2019 [cited by applicant]
CN 109871401A · 2019 [cited by applicant]
CN 109902703A · 2019 [cited by applicant]
CN 110266552A · 2019 [cited by applicant]
CN 109565239B · 2021 [cited by examiner]
CN 117397204A · 2024 [cited by examiner]
EP 1431770A1 · 2004 [cited by examiner]
EP 2390789A1 · 2011 [cited by examiner]
EP 1431770B1 · 2012 [cited by examiner]
EP 3451232A1 · 2019 [cited by applicant]
EP 3916667A1 · 2021 [cited by examiner]
JP 2004200868A · 2004 [cited by examiner]
JP 3790741B2 · 2006 [cited by examiner]
JP 2011247887A · 2011 [cited by examiner]
JP 2022176136A · 2022 [cited by examiner]
TW 201633721A · 2016 [cited by examiner]
WO WO2016082899A1 · 2016 [cited by examiner]
WO WO2019019255A1 · 2019 [cited by examiner]
WO WO2021026243A1 · 2021 [cited by examiner]
WO WO2021189845A1 · 2021 [cited by examiner]
WO WO2022251837A1 · 2022 [cited by examiner]
WO WO2023175232A1 · 2023 [cited by examiner]
WO WO2023221701A1 · 2023 [cited by examiner]
WO WO2024057063A1 · 2024 [cited by examiner]
Anton, S.D., et al., “Time is of the Essence:Machine Learning-based Intrusion Detection in Industrial Time Series Data”, 2018 IEEE International Conference on Data Mining Workshops (ICDMW), 6 pages. [cited by applicant]
Chandola, V., et al., “Anomaly Detection: A Survey,” ACM Computing Surveys, Jul. 2009, 75 pages. [cited by applicant]
Li Yan, et al., “Network traffic anomaly detection based on time series analysis,” Jan. 4, 2017, 4 pages. [cited by applicant]
Shangzhen Lin, et al., “Research On Real-Time Network Traffic Anomaly Detection Algorithm and System Realization,” Nov. 25, 2017, 68 pages. [cited by applicant]
Liao Jun et al.,“Time series piecewise linear representation based on trend transition point,” Computer Engineering and Applications, Computer Engineering and Applications, vol. 46, Issue 30, 2010, 5 pages. [cited by applicant]