Anomaly Alert Fidelity via Control and Data Plane Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current threat detection systems face challenges in accurately differentiating between rare legitimate events and malicious events, leading to false positives and reduced credibility due to the reactive nature of countermeasures against evolving exploits in computer networks.

Innovation Solution

The integration of data plane and control plane signals to enhance anomaly detection, using a probabilistic model that correlates {resource, entity, time-window} tuples to differentiate between legitimate and malicious access anomalies, thereby improving precision and recall of security alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If anomaly detection is used to identify attacks by alerting on rare events, then recall is improved, but precision deteriorates due to false positives from legitimate rare events

Engineering Contradiction:
ImproverecallVSAvoidprecision
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent combines control plane signals (authorization requests, user profiles, device information) with data plane signals (network traffic patterns, access behaviors) to create a unified anomaly detection model. This merging allows the system to cross-validate rare events against multiple dimensions of normal behavior, reducing false positives while maintaining high recall for actual attacks

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a new dimension of analysis by incorporating control plane information (authorization context, user profiles, device metadata) alongside traditional data plane traffic analysis. This additional dimension enables the system to differentiate between legitimate and malicious rare events by examining behavioral context rather than just traffic patterns alone

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of manufacture

If countermeasures are deployed reactively after identifying exploits, then implementation simplicity is improved, but security effectiveness deteriorates due to evolving attack tactics

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements proactive threat detection by continuously analyzing control plane and data plane signals to identify suspicious patterns before they result in successful attacks. The system performs preliminary actions by generating alerts and initiating investigations prior to actual security breaches, allowing security teams to prevent attacks rather than merely respond to them after exploitation occurs

Inventive Principle:
Principle #10Preliminary action

3Productivity

If false alerts are reduced to improve security team efficiency, then productivity is improved, but measurement precision must be increased which complicates the detection system

Engineering Contradiction:
Improvesecurity team efficiencyVSAvoiddetection system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates a multi-functional detection system where the control plane module serves multiple purposes: authenticating users, profiling devices, tracking authorization patterns, and providing contextual metadata for anomaly detection. This universality allows the system to reduce false alerts and improve productivity without proportionally increasing complexity, as existing control plane infrastructure is leveraged for security analysis

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11647035B2Fidelity of anomaly alerts using control plane and data plane information
Publication Date: 2023.05.09 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11647035B2 patent drawing
  • US11647035B2 patent drawing
  • US11647035B2 patent drawing

AI summary

An indication is received of a security alert. The indication is generated based on a detected anomaly in one of a data plane or a control plane of a computing environment. When the detected anomaly is in the data plane, the control plane is monitored for a subsequent anomaly in the control plane, and otherwise the data plane is monitored for a subsequent anomaly in the data plane. A correlation between the detected anomalies is determined. A notification of the security alert is sent when the correlation exceeds a predetermined threshold.