Anomaly Detection via Z-Score and Directionality Magnitude

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing techniques for detecting anomalous network activity often result in false positives, distracting security personnel and diverting resources from actual malicious activity.

Innovation Solution

A method and system that utilize network metadata to generate z-scores and directionality magnitudes, comparing current activity against baselines to detect anomalies, and issue alerts only when thresholds are exceeded, while suppressing alerts for minor deviations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing techniques are used to detect anomalous network activity, then security personnel can identify potential threats, but false positives increase causing distraction and resource diversion

Engineering Contradiction:
Improveaccuracy of anomaly detectionVSAvoidfalse positives
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent transforms network metadata parameters through logarithmic transformation to normalize distributions and stabilize variance. This parameter transformation enables more accurate statistical analysis (z-scores) by converting skewed network traffic data into a more uniform distribution, thereby improving anomaly detection accuracy while reducing false positives caused by natural traffic variability

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system continuously compares current network activity against baseline patterns and feeds back anomaly scores (z-scores) to security personnel. This feedback mechanism allows security teams to adjust thresholds and parameters based on actual performance, progressively reducing false positives while maintaining detection of genuine threats through iterative refinement

Inventive Principle:
Principle #23Feedback

2Measurement precision

If alert thresholds are lowered to catch more anomalies, then detection sensitivity increases, but false positives increase distracting security personnel

Engineering Contradiction:
Improvedetection sensitivityVSAvoidtime spent on false alarms
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies a multi-threshold approach where alerts are generated only when z-scores exceed specific thresholds (e.g., |z| > 2 or |z| > 3). This partial action principle allows the system to process all network data with high sensitivity but selectively alert only on statistically significant anomalies, preventing alert fatigue from minor deviations while maintaining detection of genuine threats

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The z-score calculation acts as an intermediary between raw network metadata and security alerts. By introducing this statistical mediator that quantifies deviation from baseline in standard deviations, the system transforms raw traffic variations into meaningful anomaly scores, allowing precise control over detection sensitivity and false positive rates through threshold adjustment on the z-score rather than raw traffic values

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11509670B2Detecting anomalous network activity
Publication Date: 2022.11.22 RAPID7 INC
  • US11509670B2 patent drawing
  • US11509670B2 patent drawing
  • US11509670B2 patent drawing

AI summary

Methods and systems for detecting anomalous network activity. The system may receive network metadata regarding activity on a network and generate at least one of a z-score and a directionality magnitude related to the network activity. The system may then issue an alert upon detecting an anomaly exists on the network based upon at least one of the generated z-score exceeding a z-score threshold and the generated directionality magnitude deviating from a baseline directionality magnitude.