IP Library › Granted Patent US 12,587,557
Granted Patent B2
US 12,587,557 · App. 18/511,860 · Granted Mar 24, 2026

Detection method of network anomaly and anomaly detection apparatus

Inventor: Yuan Fu Huang (New Taipei City, TW)
Assignee: Wistron Corporation
H04L63/1425H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,587,557
App. No.
18/511,860
Filed
Nov 16, 2023
Granted
Mar 24, 2026
Kind
B2
Art Unit
2435
USPC
726/22
Abstract

A detection method of network anomaly and an anomaly detection apparatus are disclosed. In the detection method, one or more request intervals within a detection period are determined, where each of the request intervals is a time interval of two network requests from a network source. A network request anomaly from the network source is determined according to the request interval within the detection period.

Claims (50)

1 . A detection method of network anomaly, adapted to be executed by a processor, the detection method comprising:

determining at least one request interval within a detection period, wherein each of the request intervals is a time interval of two network requests from a network source; and

determining a network request anomaly from the network source according to the at least one request interval within the detection period, wherein determining the network request anomaly from the network source according to the at least one request interval within the detection period comprises:

determining a number of occurrences of an anomalous interval where the at least one request interval is determined as the anomalous interval within the detection period; and

determining the network request anomaly from the network source in response to the number of occurrences of the anomalous interval within a statistical period does not meet normal conditions, wherein the statistical period includes a plurality of the detection periods.

2 . The detection method of network anomaly according to claim 1 , wherein determining the network request anomaly from the network source according to the at least one request interval within the detection period comprises:

determining that the at least one request interval is the anomalous interval through a detection model, wherein the detection model is trained using at least one request interval of at least one normal interval.

3 . The detection method of network anomaly according to claim 1 , wherein determining the network request anomaly from the network source according to the number of occurrences of the anomalous interval within the detection periods within the statistical period comprises:

determining whether the number of occurrences of the anomalous interval within the detection periods within the statistical period conforms to a statistical distribution to produce a compliance result, wherein the compliance result comprises that the number of occurrences within the statistical period conforms to the statistical distribution, and that the number of occurrences within the statistical period does not conform to the statistical distribution; and

determining the network request anomaly from the network source according to the compliance result of the statistical distribution.

4 . The detection method of network anomaly according to claim 3 , wherein determining whether the number of occurrences of the anomalous interval within the detection periods within the statistical period conforms to the statistical distribution comprises:

determining a test statistic according to a number of observation and a number of expectation, wherein the number of observation is a number of occurrences in each of the detection periods, and the number of expectation is an expected value of the number of occurrences of the anomalous interval in the each of the detection periods in the statistical distribution; and

determining the compliance result according to the test statistic.

5 . The detection method of network anomaly according to claim 4 , wherein determining the compliance result according to the test statistic comprises:

determining whether the test statistic lies within an anomalous range of the statistical distribution;

in response to the test statistic not lying within the anomalous range, determining that the compliance result is that the number of occurrences of the anomalous interval within the statistical period conforms to the statistical distribution; and

in response to the test statistic lying within the anomalous range, determining that the compliance result is that the number of occurrences of the anomalous interval within the statistical period does not conform to the statistical distribution.

6 . The detection method of network anomaly according to claim 5 , wherein determining whether the test statistic lies within the anomalous range of the statistical distribution comprises:

comparing the test statistic with a threshold value, wherein the threshold value is at a beginning of the anomalous range.

7 . The detection method of network anomaly according to claim 1 , wherein determining the network request anomaly from the network source according to the at least one request interval within the detection period comprises:

blocking the network requests from the network source.

8 . The detection method of network anomaly according to claim 4 , wherein the test statistic is defined by a chi-square test.

9 . The detection method of network anomaly according to claim 3 , wherein the statistical distribution is Poisson distribution.

10 . An anomaly detection apparatus, comprising:

a communication transceiver;

a storage, storing a program code; and

a processor, coupled to the communication transceiver and the storage, loading the program code to execute:

determining at least one request interval within a detection period, wherein each of the request intervals is a time interval of two network requests from a network source received from the communication transceiver; and

determining the network request anomaly from the network source according to the at least one request interval within the detection period,

wherein the processor further executes:

determining a number of occurrences of an anomalous interval where the at least one request interval is determined as the anomalous interval within the detection period; and

determining the network request anomaly from the network source in response to the number of occurrences of the anomalous interval within a statistical period does not meet normal conditions, wherein the statistical period includes a plurality of the detection periods.

11 . The anomaly detection apparatus according to claim 10 , wherein the processor further executes:

determining that the at least one request interval is the anomalous interval through a detection model, wherein the detection model is trained using at least one request interval of at least one normal interval.

12 . The anomaly detection apparatus according to claim 10 , wherein the processor further executes:

determining whether the number of occurrences of the anomalous interval within the detection periods within the statistical period conforms to a statistical distribution to produce a compliance result, wherein the compliance result comprises that the number of occurrences of the anomalous interval within the statistical period conforms to the statistical distribution, and that the number of occurrences of the anomalous interval within the statistical period does not conform to the statistical distribution; and

determining the network request anomaly from the network source according to the compliance result of the statistical distribution.

13 . The anomaly detection apparatus according to claim 12 , wherein the processor further executes:

determining a test statistic according to a number of observation and a number of expectation, wherein the number of observation is a number of occurrences in each of the detection periods, and the number of expectation is an expected value of the number of occurrences in the each of the detection periods in the statistical distribution; and

determining the compliance result according to the test statistic.

14 . The anomaly detection apparatus according to claim 13 , wherein the processor further executes:

determining whether the test statistic lies within an anomalous range of the statistical distribution;

in response to the test statistic not lying within the anomalous range, determining that the compliance result is that the number of occurrences of the anomalous interval within the statistical period conforms to the statistical distribution; and

in response to the test statistic lying within the anomalous range, determining that the compliance result is that the number of occurrences of the anomalous interval within the statistical period does not conform to the statistical distribution.

15 . The anomaly detection apparatus according to claim 14 , wherein the processor further executes:

comparing the test statistic with a threshold value, wherein the threshold value is at a beginning of the anomalous range.

16 . The anomaly detection apparatus according to claim 10 , wherein the processor further executes:

blocking the network requests from the network source through the communication transceiver.

17 . The anomaly detection apparatus according to claim 13 , wherein the test statistic is defined by a chi-square test.

18 . The anomaly detection apparatus according to claim 12 , wherein the statistical distribution is Poisson distribution.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2023
From: HUANG, YUAN FU
To: WISTRON CORPORATION
Reel/Frame 065626/0123 →
Priority Claims (1)
TW 112135433 · Sep 18, 2023 · national
Continuity (1)
Related Publication 20250097243A1 · Mar 20, 2025
References Cited (16)
US 10158658B1 · Sharifi Mehr · 2018 [cited by applicant]
US 10623429B1 · Vines · 2020 [cited by examiner]
US 10673880B1 · Pratt · 2020 [cited by examiner]
US 11470096B2 · Muddu · 2022 [cited by examiner]
US 20110214187A1 · Wittenstein · 2011 [cited by examiner]
US 20120079101A1 · Muppala · 2012 [cited by examiner]
US 20140041032A1 · Scheper · 2014 [cited by examiner]
US 20140082730A1 · Vashist · 2014 [cited by examiner]
US 20140101763A1 · Harlacher · 2014 [cited by examiner]
US 20140325649A1 · Zhang · 2014 [cited by examiner]
US 20150229662A1 · Hitt · 2015 [cited by examiner]
US 20220035721A1 · Iyengar · 2022 [cited by examiner]
CN 108737406 · 2020 [cited by applicant]
CN 111783883 · 2020 [cited by applicant]
TW 201818289 · 2018 [cited by applicant]
Mark Steel. “Bayesian Time Series Analysis” (pp. 1-12) https://warwick.ac.uk/fac/sci/statistics/staff/academic-research/steel/steel_homepage/bayesiantsrev.pdf (Year: 2008). [cited by examiner]