Customizable Anomaly Action Rules for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security tools rely on rigid, hard-coded logic to detect unusual activities, leading to either under-inclusion or over-inclusion of security threats, resulting in unreliable and ineffective threat identification, as the same rules are applied across different organizations despite varying concerns.

Innovation Solution

A network security platform that allows users to customize anomaly action rules and threat rules through a user-friendly interface, enabling organizations to define specific scenarios and conditions for identifying security threats, using machine learning for behavioral analysis and real-time anomaly detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Stability of the object's composition

If rigid, hard-coded logic is used to detect unusual activities, then consistency in rule application is improved, but adaptability to different organizational needs deteriorates

Engineering Contradiction:
Improveconsistency in rule applicationVSAvoidadaptability to different organizational needs
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The patent transforms static, hard-coded security rules into dynamic, customizable rules that can be modified by users. The system allows organizations to define their own anomaly criteria and response actions through a configuration interface, enabling the security logic to adapt to specific organizational needs while maintaining consistent application of the customized rules.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables customization of security detection parameters by allowing users to modify anomaly thresholds, detection criteria, and response actions. This parameter flexibility allows the same security platform to adapt to different organizational requirements without sacrificing the consistency of rule enforcement within each organization.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If security rules are made customizable to reduce false positives, then detection precision is improved, but system complexity increases

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a self-service configuration interface that guides users through the process of customizing security rules. The system provides pre-defined templates and automated recommendations, allowing organizations to achieve high detection precision without requiring complex manual configuration. The interface handles the complexity internally while presenting a simplified user experience.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent provides pre-configured security rules and anomaly detection templates that organizations can deploy immediately. These preliminary configurations reduce false positives out of the box, and organizations can later customize them as needed. This approach achieves high detection precision without initially exposing users to system complexity.

Inventive Principle:
Principle #10Preliminary action

3Ease of manufacture

If pre-configured security rules are applied across all organizations, then ease of deployment is improved, but effectiveness in identifying legitimate threats deteriorates

Engineering Contradiction:
Improveease of deploymentVSAvoideffectiveness in identifying legitimate threats
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent enables security rules to transition from static pre-configured templates to dynamic customized rules. Organizations start with easy-to-deploy pre-configured rules and can progressively customize them to match their specific threat landscape, thereby maintaining both ease of initial deployment and ongoing effectiveness in identifying legitimate threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent designs a universal security platform that can serve multiple organizations with different requirements. The system provides a common base of pre-configured rules that work across organizations, while simultaneously allowing each organization to customize rules for their specific needs, achieving both ease of deployment and threat-specific effectiveness.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10958674B2User interface for defining anomaly action rules in a network security system
Publication Date: 2021.03.23 CISCO TECHNOLOGY INC
  • US10958674B2 patent drawing
  • US10958674B2 patent drawing
  • US10958674B2 patent drawing

AI summary

The disclosed embodiments include a method performed by a computer system. The method includes causing display of one or more first graphical controls enabling a user to define a filter of an anomaly action rule, the filter defining at least one of an attribute of an anomaly or an attribute of a computer network entity. The method also includes causing display of one or more second graphical controls enabling a user to define an action to take with respect to the anomaly action rule. The method further includes generating the anomaly action rule based on interaction by a user with the one or more first and second graphical controls, wherein the anomaly action rule causes performance of the action upon detecting an anomaly that satisfies the anomaly action rule.