Anomalous Event Detection Ontology for Security Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in efficiently identifying anomalous computer events from large volumes of data, which can indicate potential security incidents, due to the sheer volume of data and the dynamic nature of threats.
Innovation Solution
A method that involves receiving data from multiple sources, standardizing it, defining vector representations for each event, assigning events to cohorts based on similarity, and generating an ontology using machine learning models to filter and identify anomalous events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all computer events are stored and reviewed, then completeness of security monitoring is improved, but storage cost and computational resources increase significantly
Solution Approach 1:
The patent extracts only the most relevant information from the complete event log by using machine learning models to identify and select anomalous events for storage and review. The system processes all events to understand normal patterns, then extracts only deviations from these patterns as potential security incidents, significantly reducing the quantity of data that needs to be stored and reviewed while maintaining monitoring completeness.
Solution Approach 2:
The patent segments the event data processing into distinct phases: collecting all events, analyzing patterns using machine learning, identifying anomalies, and storing only relevant segments. This segmentation allows the system to handle large volumes of data efficiently by processing and filtering at different stages, separating the complete data set from the subset requiring storage and review.
2Measurement precision
If dynamic anomaly detection is implemented, then threat detection accuracy is improved, but computational complexity increases
Solution Approach 1:
The patent applies preliminary action by training machine learning models in advance to recognize normal event patterns and anomalies. The models are trained on historical data to establish baselines for normal behavior, enabling the system to quickly identify deviations without complex real-time analysis. This pre-training approach maintains high detection accuracy while reducing the computational burden during actual anomaly detection operations.
3Reliability
If event data is retained for compliance, then regulatory compliance is improved, but data utility for security analysis decreases
Solution Approach 1:
The patent extracts only the anomalous events from the complete retained data set for security analysis. By separating the complete compliance data from the subset of potentially relevant events, the system maintains compliance by retaining all data as required, while improving analysis efficiency by focusing computational resources only on the extracted anomalies that require investigation.
Data Source
AI summary
A method includes receiving, from a plurality of sources, data associated with a plurality of events at the plurality of sources, standardizing the data based on a set of predefined standardization rules to define standardized data, and defining a vector representation for each event from the plurality of events based on the standardized data. The method includes assigning each event from the plurality of events to at least one cohort from a plurality of cohorts based on a similarity associated with the vector representation for that event and each cohort from the plurality of cohorts, generating, using at least one machine learning model, an ontology based on a set of cohorts from the plurality of cohorts and associated with the plurality of events, and storing the plurality of events as associated with the ontology such that the plurality of events can be filtered based on the ontology.


