Multidimensional Anomaly Chart for Network Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing intrusion detection systems, particularly behavior-based and host-based solutions, face challenges in managing the overflow of information and false alarms, making it difficult for administrators to interpret and respond to critical anomalies in a timely manner.
Innovation Solution
A method involving data collection from network components, anomaly detection using a multidimensional chart to visualize behavior, and computation of anomaly and criticality levels, allowing for intuitive visualization and prioritization of anomalies, with the ability to monitor nodes, users, and applications independently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If behavior-based intrusion detection systems are used to detect new and unforeseen vulnerabilities, then detection capability is improved, but false alarm rate increases
Solution Approach 1:
The patent introduces a new dimension for evaluating anomalies by computing an anomaly level that combines multiple factors (deviation from normal behavior, criticality of the component, severity of the event). This multi-dimensional approach allows the system to distinguish between significant anomalies requiring attention and minor deviations that can be ignored, thereby reducing false alarms while maintaining detection capability.
Solution Approach 2:
The system dynamically changes parameters by computing anomaly levels based on multiple variables including the type of deviation, the criticality of the monitored component, and the severity of the observed event. By adjusting the weighting of these parameters, the system can adapt its sensitivity to reduce false alarms while maintaining reliable detection of genuine threats.
2Reliability
If host-based intrusion detection with security agents is deployed in multiple nodes, then detection coverage is improved, but information overflow increases
Solution Approach 1:
The patent extracts only the essential information from the large volume of data collected by security agents. Instead of transmitting all raw event data to the monitoring platform, the system computes anomaly levels locally at each node and only transmits the computed anomaly levels and relevant summary statistics. This extraction of essential information reduces the data volume while maintaining detection coverage.
Solution Approach 2:
The system transforms the large volume of raw event data into a condensed representation by adding the dimension of anomaly level computation. Each event is evaluated against multiple criteria (behavioral deviation, component criticality, event severity) to produce a single anomaly level value, effectively reducing information volume while preserving detection capability.
3Measurement precision
If administrators manually interpret alarm logs to identify critical anomalies, then detection accuracy is improved, but response time decreases
Solution Approach 1:
The system performs self-service by automatically computing anomaly levels and prioritizing alerts based on the combined assessment of behavioral deviation, component criticality, and event severity. The monitoring platform automatically identifies and presents the most critical anomalies to administrators, eliminating the need for manual interpretation of all alarm logs while maintaining high detection accuracy.
Solution Approach 2:
The system implements feedback mechanisms where anomaly levels are continuously computed and updated based on observed behavior deviations. The monitoring platform provides feedback to administrators in the form of prioritized alerts with pre-computed anomaly levels, enabling rapid response while maintaining accurate detection through automated analysis.
4Object-generated harmful factors
If knowledge-based intrusion detection systems are used to detect known malicious patterns, then false alarm rate is reduced, but detection capability deteriorates
Solution Approach 1:
The patent merges knowledge-based detection (pattern matching against known vulnerabilities) with behavior-based detection (monitoring deviations from normal behavior). The system combines both approaches by evaluating events against known attack patterns while simultaneously assessing behavioral deviations, component criticality, and event severity to compute a comprehensive anomaly level, thereby maintaining low false alarm rates while improving detection capability.
Data Source
AI summary
A method for the detection of anomalous behaviors in a computer network, comprising the steps of:collecting data relating to connections in a plurality of nodes in a network,sending the data from said nodes to an ADS platform,computing from said data at least one value representative of the anomaly level of the connections of each said node and/or of applications initiating said connections and/or of users,computing a multidimensional chart for visualizing the behavior of a plurality of nodes, applications and/or users in said network, wherein said value representative of the anomaly level is used as a dimension in said chart.


