Multidimensional Anomaly Chart for Network Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing intrusion detection systems, particularly behavior-based and host-based solutions, face challenges in managing the overflow of information and false alarms, making it difficult for administrators to interpret and respond to critical anomalies in a timely manner.

Innovation Solution

A method involving data collection from network components, anomaly detection using a multidimensional chart to visualize behavior, and computation of anomaly and criticality levels, allowing for intuitive visualization and prioritization of anomalies, with the ability to monitor nodes, users, and applications independently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If behavior-based intrusion detection systems are used to detect new and unforeseen vulnerabilities, then detection capability is improved, but false alarm rate increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidfalse alarm rate
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces a new dimension for evaluating anomalies by computing an anomaly level that combines multiple factors (deviation from normal behavior, criticality of the component, severity of the event). This multi-dimensional approach allows the system to distinguish between significant anomalies requiring attention and minor deviations that can be ignored, thereby reducing false alarms while maintaining detection capability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system dynamically changes parameters by computing anomaly levels based on multiple variables including the type of deviation, the criticality of the monitored component, and the severity of the observed event. By adjusting the weighting of these parameters, the system can adapt its sensitivity to reduce false alarms while maintaining reliable detection of genuine threats.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If host-based intrusion detection with security agents is deployed in multiple nodes, then detection coverage is improved, but information overflow increases

Engineering Contradiction:
Improvedetection coverageVSAvoidinformation volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential information from the large volume of data collected by security agents. Instead of transmitting all raw event data to the monitoring platform, the system computes anomaly levels locally at each node and only transmits the computed anomaly levels and relevant summary statistics. This extraction of essential information reduces the data volume while maintaining detection coverage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system transforms the large volume of raw event data into a condensed representation by adding the dimension of anomaly level computation. Each event is evaluated against multiple criteria (behavioral deviation, component criticality, event severity) to produce a single anomaly level value, effectively reducing information volume while preserving detection capability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If administrators manually interpret alarm logs to identify critical anomalies, then detection accuracy is improved, but response time decreases

Engineering Contradiction:
Improvedetection accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs self-service by automatically computing anomaly levels and prioritizing alerts based on the combined assessment of behavioral deviation, component criticality, and event severity. The monitoring platform automatically identifies and presents the most critical anomalies to administrators, eliminating the need for manual interpretation of all alarm logs while maintaining high detection accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where anomaly levels are continuously computed and updated based on observed behavior deviations. The monitoring platform provides feedback to administrators in the form of prioritized alerts with pre-computed anomaly levels, enabling rapid response while maintaining accurate detection through automated analysis.

Inventive Principle:
Principle #23Feedback

4Object-generated harmful factors

If knowledge-based intrusion detection systems are used to detect known malicious patterns, then false alarm rate is reduced, but detection capability deteriorates

Engineering Contradiction:
Improvefalse alarm rateVSAvoiddetection capability
Core Design Contradiction:
Object-generated harmful factorsVSReliability

Solution Approach 1:

The patent merges knowledge-based detection (pattern matching against known vulnerabilities) with behavior-based detection (monitoring deviations from normal behavior). The system combines both approaches by evaluating events against known attack patterns while simultaneously assessing behavioral deviations, component criticality, and event severity to compute a comprehensive anomaly level, thereby maintaining low false alarm rates while improving detection capability.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7930752B2Method for the detection and visualization of anomalous behaviors in a computer network
Publication Date: 2011.04.19 NEXTHINK
  • US7930752B2 patent drawing
  • US7930752B2 patent drawing
  • US7930752B2 patent drawing

AI summary

A method for the detection of anomalous behaviors in a computer network, comprising the steps of:collecting data relating to connections in a plurality of nodes in a network,sending the data from said nodes to an ADS platform,computing from said data at least one value representative of the anomaly level of the connections of each said node and/or of applications initiating said connections and/or of users,computing a multidimensional chart for visualizing the behavior of a plurality of nodes, applications and/or users in said network, wherein said value representative of the anomaly level is used as a dimension in said chart.