Anomaly Detection via Z-Score and Directionality Magnitude
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing techniques for detecting anomalous network activity often result in false positives, distracting security personnel and diverting resources from actual malicious activity.
Innovation Solution
A method and system that utilize network metadata to generate z-scores and directionality magnitudes, comparing current activity against baselines to detect anomalies, and issue alerts only when thresholds are exceeded, while suppressing alerts for minor deviations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing techniques are used to detect anomalous network activity, then security personnel can identify potential threats, but false positives increase causing distraction and resource diversion
Solution Approach 1:
The patent transforms network metadata parameters through logarithmic transformation to normalize distributions and stabilize variance. This parameter transformation enables more accurate statistical analysis (z-scores) by converting skewed network traffic data into a more uniform distribution, thereby improving anomaly detection accuracy while reducing false positives caused by natural traffic variability
Solution Approach 2:
The system continuously compares current network activity against baseline patterns and feeds back anomaly scores (z-scores) to security personnel. This feedback mechanism allows security teams to adjust thresholds and parameters based on actual performance, progressively reducing false positives while maintaining detection of genuine threats through iterative refinement
2Measurement precision
If alert thresholds are lowered to catch more anomalies, then detection sensitivity increases, but false positives increase distracting security personnel
Solution Approach 1:
The patent applies a multi-threshold approach where alerts are generated only when z-scores exceed specific thresholds (e.g., |z| > 2 or |z| > 3). This partial action principle allows the system to process all network data with high sensitivity but selectively alert only on statistically significant anomalies, preventing alert fatigue from minor deviations while maintaining detection of genuine threats
Solution Approach 2:
The z-score calculation acts as an intermediary between raw network metadata and security alerts. By introducing this statistical mediator that quantifies deviation from baseline in standard deviations, the system transforms raw traffic variations into meaningful anomaly scores, allowing precise control over detection sensitivity and false positive rates through threshold adjustment on the z-score rather than raw traffic values
Data Source
AI summary
Methods and systems for detecting anomalous network activity. The system may receive network metadata regarding activity on a network and generate at least one of a z-score and a directionality magnitude related to the network activity. The system may then issue an alert upon detecting an anomaly exists on the network based upon at least one of the generated z-score exceeding a z-score threshold and the generated directionality magnitude deviating from a baseline directionality magnitude.


