Anomalous Activity Detection via Gradient and Linear Signal Aggregation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current automated network anomaly detection systems, such as Boolean detection systems, face challenges in setting thresholds to avoid high false positives or missing attacks due to their linear nature, which limits their ability to detect sophisticated cyber threats and internal unauthorized actions.
Innovation Solution
An aggregated anomalous computer activity detection system that enriches linear detection data with descriptive and gradient-based signals from multiple sources, using machine learning models and rule-based systems to provide a holistic view of account activity, enabling the detection of complex attack patterns and internal threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If linear detection systems with fixed thresholds are used, then the system is simple to implement, but it produces high false positives or misses attacks
Solution Approach 1:
The patent combines multiple detection systems (linear detection, sequence detection, gradient detection) into a unified anomaly detection system. This merging allows the system to leverage the simplicity of linear detection while adding the sophistication of sequence and gradient analysis to reduce false positives and improve attack detection accuracy.
Solution Approach 2:
The detection system is designed to perform multiple functions: it conducts linear threshold-based detection, sequence pattern matching, and gradient-based anomaly detection simultaneously. This multi-functionality allows a single system to address both simple implementation needs and complex detection requirements.
2Measurement precision
If multiple detection systems are aggregated, then detection precision is improved, but system complexity increases
Solution Approach 1:
The patent segments the detection system into distinct functional modules: linear detection component, sequence detection component, gradient detection component, and anomaly determination component. Each module performs a specific detection function independently, then their results are aggregated. This segmentation maintains detection precision while making the overall system more manageable and understandable.
Solution Approach 2:
The patent introduces an anomaly determination component that acts as an intermediary between the various detection systems and the final output. This mediator aggregates signals from linear, sequence, and gradient detections, applies weighting and threshold logic, and produces the final anomaly determination. This intermediary simplifies the complexity by providing a centralized coordination point.
3Adaptability or versatility
If sophisticated detection models are used to detect complex threats, then detection capability improves, but false positives increase
Solution Approach 1:
The patent applies partial action by not relying solely on sophisticated sequence and gradient detection, but rather combining them with simpler linear detection. The system uses gradient-based anomaly scoring and sequence pattern matching to enhance detection capability, while the linear threshold checks provide a baseline that filters out obvious false positives before more complex analysis occurs.
Solution Approach 2:
The system dynamically adjusts detection parameters including gradient thresholds, sequence matching sensitivity, and anomaly scoring weights. By changing these parameters based on the specific detection context and aggregating results from multiple detection methods, the system maintains high detection capability while reducing false positives through parameter optimization.
Data Source
AI summary
Devices and techniques are generally described for anomalous computer activity detection. In various examples, first computer activity data associated with a first account may be determined. A first linear detection event that corresponds to the first computer activity data may be determined. In some examples, a set of gradient-based data associated with the first linear detection event may be determined. The set of gradient-based data may represent comparative analysis of the first computer activity data with computer activity data of other accounts. In some examples, first data representing the first linear detection event and the set of gradient-based data may be generated. In various cases, network access for the first account may be disabled based on the first data.


