Networked Anomaly Detection for Interconnected Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information security systems for interconnected devices are ineffective in detecting and mitigating unknown threats and fail to provide comprehensive protection across a network of user devices, leading to inadequate data integrity and increased vulnerability to information security breaches.
Innovation Solution
A method and system that collect data on threats from all interconnected user devices and services to identify anomalies using a trained anomaly detection model, classify the type of anomaly, and modify information security settings on affected devices to enhance protection, reducing false positives and false negatives in threat identification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If antivirus systems are deployed on single devices, then device protection is provided, but data integrity across interconnected devices is not adequately ensured
Solution Approach 1:
The patent combines multiple antivirus systems across interconnected devices into a unified networked protection system. The system collects data from multiple devices, performs centralized anomaly detection, and coordinates responses across the network, thereby ensuring both individual device protection and overall data integrity through collaborative security monitoring.
Solution Approach 2:
The patent creates a universal protection system that serves multiple functions: it monitors individual devices, detects anomalies across the network, classifies threat types, and implements coordinated responses. This multi-functional system addresses both device-level protection and network-level data integrity requirements simultaneously.
2Measurement precision
If traditional antivirus systems are used, then known threats are detected, but new unknown threats cannot be identified
Solution Approach 1:
The patent implements a dynamic anomaly detection system that continuously learns from network data and adapts to new threat patterns. Instead of relying on static virus signatures, the system uses machine learning models that evolve with emerging threats, enabling detection of both known and unknown malicious activities through behavioral analysis.
Solution Approach 2:
The system incorporates feedback loops where detected anomalies and their outcomes are used to continuously refine the anomaly detection model. This feedback mechanism enables the system to learn from both successful detections and false positives, improving its ability to identify new threat types while maintaining accurate detection of known threats.
3Reliability
If anomaly detection is performed without classification, then anomalies are identified, but appropriate protection measures cannot be targeted
Solution Approach 1:
The patent segments the anomaly detection process into distinct classification categories (e.g., malware, ransomware, phishing, DDoS). By dividing anomalies into specific threat types, the system can apply targeted protection measures for each category, making the response process more efficient and easier to implement while maintaining reliable anomaly identification.
4Measurement precision
If comprehensive data collection from all devices is performed, then threat detection capability is improved, but system complexity increases
Solution Approach 1:
The patent introduces a centralized server as an intermediary that manages data collection from multiple devices. This mediator aggregates raw data, performs centralized anomaly detection and classification, then distributes targeted responses to individual devices. This architecture improves threat detection through comprehensive data analysis while managing system complexity by centralizing processing functions.
Data Source
AI summary
Disclosed herein are systems and methods for protecting a user's devices based on types of anomalies. In one aspect, an exemplary method comprises, determining, by a feature determiner, one or more values of features of a user's activity performed using at least one of the user's devices, detecting, by an anomaly detector, anomalies indicative of at least one threat to information security of the user's devices based on the one or more values of the features, for each detected anomaly, identifying, by the anomaly detector, a type of the anomaly and at least one device that is a source of the anomaly, wherein the type of anomaly is identified using an anomaly classifier and one or more values of features, and for each user's device, modifying, by a device protector, one or more information security settings of the user's device based on the identified type of the anomaly.


