Anomalous Activity Detection via Gradient and Linear Signal Aggregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current automated network anomaly detection systems, such as Boolean detection systems, face challenges in setting thresholds to avoid high false positives or missing attacks due to their linear nature, which limits their ability to detect sophisticated cyber threats and internal unauthorized actions.

Innovation Solution

An aggregated anomalous computer activity detection system that enriches linear detection data with descriptive and gradient-based signals from multiple sources, using machine learning models and rule-based systems to provide a holistic view of account activity, enabling the detection of complex attack patterns and internal threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If linear detection systems with fixed thresholds are used, then the system is simple to implement, but it produces high false positives or misses attacks

Engineering Contradiction:
Improveease of implementationVSAvoiddetection accuracy
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent combines multiple detection systems (linear detection, sequence detection, gradient detection) into a unified anomaly detection system. This merging allows the system to leverage the simplicity of linear detection while adding the sophistication of sequence and gradient analysis to reduce false positives and improve attack detection accuracy.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The detection system is designed to perform multiple functions: it conducts linear threshold-based detection, sequence pattern matching, and gradient-based anomaly detection simultaneously. This multi-functionality allows a single system to address both simple implementation needs and complex detection requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If multiple detection systems are aggregated, then detection precision is improved, but system complexity increases

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the detection system into distinct functional modules: linear detection component, sequence detection component, gradient detection component, and anomaly determination component. Each module performs a specific detection function independently, then their results are aggregated. This segmentation maintains detection precision while making the overall system more manageable and understandable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an anomaly determination component that acts as an intermediary between the various detection systems and the final output. This mediator aggregates signals from linear, sequence, and gradient detections, applies weighting and threshold logic, and produces the final anomaly determination. This intermediary simplifies the complexity by providing a centralized coordination point.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If sophisticated detection models are used to detect complex threats, then detection capability improves, but false positives increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidfalse positives
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies partial action by not relying solely on sophisticated sequence and gradient detection, but rather combining them with simpler linear detection. The system uses gradient-based anomaly scoring and sequence pattern matching to enhance detection capability, while the linear threshold checks provide a baseline that filters out obvious false positives before more complex analysis occurs.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system dynamically adjusts detection parameters including gradient thresholds, sequence matching sensitivity, and anomaly scoring weights. By changing these parameters based on the specific detection context and aggregating results from multiple detection methods, the system maintains high detection capability while reducing false positives through parameter optimization.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12058157B1Anomalous computer activity detection and prevention
Publication Date: 2024.08.06 AMAZON TECH INC
  • US12058157B1 patent drawing
  • US12058157B1 patent drawing
  • US12058157B1 patent drawing

AI summary

Devices and techniques are generally described for anomalous computer activity detection. In various examples, first computer activity data associated with a first account may be determined. A first linear detection event that corresponds to the first computer activity data may be determined. In some examples, a set of gradient-based data associated with the first linear detection event may be determined. The set of gradient-based data may represent comparative analysis of the first computer activity data with computer activity data of other accounts. In some examples, first data representing the first linear detection event and the set of gradient-based data may be generated. In various cases, network access for the first account may be disabled based on the first data.