Anomaly Alert Fidelity via Control and Data Plane Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current threat detection systems face challenges in accurately differentiating between rare legitimate events and malicious events, leading to false positives and reduced credibility due to the reactive nature of countermeasures against evolving exploits in computer networks.
Innovation Solution
The integration of data plane and control plane signals to enhance anomaly detection, using a probabilistic model that correlates {resource, entity, time-window} tuples to differentiate between legitimate and malicious access anomalies, thereby improving precision and recall of security alerts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If anomaly detection is used to identify attacks by alerting on rare events, then recall is improved, but precision deteriorates due to false positives from legitimate rare events
Solution Approach 1:
The patent combines control plane signals (authorization requests, user profiles, device information) with data plane signals (network traffic patterns, access behaviors) to create a unified anomaly detection model. This merging allows the system to cross-validate rare events against multiple dimensions of normal behavior, reducing false positives while maintaining high recall for actual attacks
Solution Approach 2:
The patent introduces a new dimension of analysis by incorporating control plane information (authorization context, user profiles, device metadata) alongside traditional data plane traffic analysis. This additional dimension enables the system to differentiate between legitimate and malicious rare events by examining behavioral context rather than just traffic patterns alone
2Ease of manufacture
If countermeasures are deployed reactively after identifying exploits, then implementation simplicity is improved, but security effectiveness deteriorates due to evolving attack tactics
Solution Approach 1:
The patent implements proactive threat detection by continuously analyzing control plane and data plane signals to identify suspicious patterns before they result in successful attacks. The system performs preliminary actions by generating alerts and initiating investigations prior to actual security breaches, allowing security teams to prevent attacks rather than merely respond to them after exploitation occurs
3Productivity
If false alerts are reduced to improve security team efficiency, then productivity is improved, but measurement precision must be increased which complicates the detection system
Solution Approach 1:
The patent creates a multi-functional detection system where the control plane module serves multiple purposes: authenticating users, profiling devices, tracking authorization patterns, and providing contextual metadata for anomaly detection. This universality allows the system to reduce false alerts and improve productivity without proportionally increasing complexity, as existing control plane infrastructure is leveraged for security analysis
Data Source
AI summary
An indication is received of a security alert. The indication is generated based on a detected anomaly in one of a data plane or a control plane of a computing environment. When the detected anomaly is in the data plane, the control plane is monitored for a subsequent anomaly in the control plane, and otherwise the data plane is monitored for a subsequent anomaly in the data plane. A correlation between the detected anomalies is determined. A notification of the security alert is sent when the correlation exceeds a predetermined threshold.


