Adaptive Behavioral Profiles for Network Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions are inadequate in detecting internal threats and zero-day attacks, as they rely on signature-based approaches that are time-consuming, resource-intensive, and ineffective for insider threats, leading to high false positive alerts and inability to adapt to quickly evolving threats.

Innovation Solution

A system and method for creating adaptive behavioral profiles using machine learning to detect anomalies by analyzing time series of observable events and network resource states, employing statistical analysis and adaptive profile aging to identify potential malicious activity, and using anomaly probability functions to evaluate deviations from normal behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If signature-based approaches are used to detect threats, then detection accuracy for known attacks is improved, but the system becomes ineffective against zero-day attacks and insider threats while requiring time-consuming signature development

Engineering Contradiction:
Improvedetection accuracyVSAvoidadaptability to new threats
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic behavioral profiles that automatically adapt to changing user behavior patterns over time. The system continuously updates baseline behavior metrics and anomaly thresholds based on observed user activities, enabling it to detect both known and unknown threats including zero-day attacks and insider threats without requiring manual signature updates.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-learning by automatically analyzing user behavior patterns and generating anomaly detection rules without external intervention. The behavioral profiles are continuously refined through machine learning algorithms that process user activities, automatically adapting to new threat vectors and reducing the need for manual security analysis.

Inventive Principle:
Principle #25Self-service

2Extent of automation

If statistical approaches are used to construct behavioral profiles, then profile creation is automated, but false positive alerts increase when data distributions are incorrectly assumed

Engineering Contradiction:
Improveprofile creation automationVSAvoidfalse positive rate
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The system dynamically adjusts statistical parameters and thresholds based on actual data distribution characteristics rather than assuming fixed distributions. The anomaly detection thresholds are adapted according to observed behavioral patterns and variability, allowing the system to maintain high automation while reducing false positives by matching statistical models to actual data characteristics.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If high confidence levels are used for anomaly detection, then false positives are minimized, but actual threats may be missed due to overly strict detection criteria

Engineering Contradiction:
Improvefalse positive reductionVSAvoidthreat detection sensitivity
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system applies different confidence thresholds and detection criteria to different types of anomalies and user contexts. Rather than using a single global threshold, the system tailors detection sensitivity to specific user roles, time periods, and behavioral patterns, allowing high confidence for critical threats while maintaining lower thresholds for less severe anomalies.

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If an overly permissive approach is used for anomaly detection, then all potential threats are flagged, but security analysts are overwhelmed with alerts

Engineering Contradiction:
Improvethreat coverageVSAvoidalert volume
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements a tiered alerting approach where only anomalies exceeding specific confidence thresholds are flagged for analyst review. Less severe anomalies are monitored but not immediately alerted, allowing the system to maintain comprehensive threat coverage while filtering out low-priority events that would overwhelm analysts.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9544321B2Anomaly detection using adaptive behavioral profiles
Publication Date: 2017.01.10 SECURONIX INC
  • US9544321B2 patent drawing
  • US9544321B2 patent drawing
  • US9544321B2 patent drawing

AI summary

Anomalous activities in a computer network are detected using adaptive behavioral profiles that are created by measuring at a plurality of points and over a period of time observables corresponding to behavioral indicators related to an activity. Normal kernel distributions are created about each point, and the behavioral profiles are created automatically by combining the distributions using the measured values and a Gaussian kernel density estimation process that estimates values between measurement points. Behavioral profiles are adapted periodically using data aging to de-emphasize older data in favor of current data. The process creates behavioral profiles without regard to the data distribution. An anomaly probability profile is created as a normalized inverse of the behavioral profile, and is used to determine the probability that a behavior indicator is indicative of a threat. The anomaly detection process has a low false positive rate.