Unsupervised Attack Ring Detection for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network attack detection systems are reactive, unable to effectively analyze links across accounts, and fail to leverage new digital information, making them less effective against evolving and coordinated modern attacks.

Innovation Solution

An unsupervised machine learning engine that combines clustering techniques and graph analysis to detect fraudulent or suspicious patterns from unlabeled data, processing all account activities in real-time to identify correlated abuse, fraud, and money laundering activities, without requiring labeled data or frequent re-tuning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional Knowledge Based Authentication (KBA) is used, then user verification can be performed, but it can be easily bypassed by attackers obtaining information from social media, public records, and the dark web

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidattack effectiveness
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces conventional Knowledge Based Authentication (KBA) with an unsupervised machine learning system that analyzes behavioral patterns and correlations across multiple accounts. Instead of relying on static knowledge questions that can be researched, the system uses clustering algorithms and graph analysis to detect coordinated attack patterns, substituting a dynamic analytical approach for static verification methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent combines multiple detection techniques including unsupervised learning, clustering algorithms, graph analysis, and correlation detection into a composite detection system. This multi-layered approach integrates various analytical methods to create a robust authentication security system that can detect coordinated attacks through pattern recognition across diverse data sources.

Inventive Principle:
Principle #40Composite materials

2Object-generated harmful factors

If attackers perform attacks from a larger number of individual accounts, then the overall aggregated impact becomes significantly larger, but detecting these distributed attacks becomes more difficult

Engineering Contradiction:
Improveaggregated attack impactVSAvoidattack detection difficulty
Core Design Contradiction:
Object-generated harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent merges multiple individual account analyses into a unified detection framework by building graphs that connect accounts through shared characteristics, behaviors, and correlations. The system combines clustering results from multiple accounts to identify coordinated attack rings, merging isolated detection signals into a comprehensive view of distributed attack patterns.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent transitions from analyzing individual accounts in isolation to examining accounts across multiple dimensions simultaneously - temporal patterns, behavioral correlations, network relationships, and attribute similarities. By adding these dimensional layers of analysis, the system can detect coordinated attacks that span multiple accounts across different time periods and activity types.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If supervised learning models are used for attack detection, then detection accuracy can be achieved, but the system requires frequent re-tuning as attack patterns evolve

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem adaptability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements an unsupervised learning system that automatically adapts to new attack patterns without requiring manual re-tuning or labeled training data. The clustering algorithms and correlation analysis self-adjust by identifying emerging patterns in the data stream, allowing the system to service its own adaptation needs through continuous unsupervised learning from incoming account activity data.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent employs dynamic clustering algorithms that continuously adapt to changing data distributions and emerging attack patterns. The system uses dynamic threshold adjustment and adaptive feature weighting that automatically respond to new patterns in the data, making the detection system flexible and responsive to evolving attack methodologies without requiring manual intervention.

Inventive Principle:
Principle #15Dynamics

4Ease of operation

If existing detection systems analyze accounts in isolation, then individual account assessment is simple, but they are unable to effectively analyze links across accounts

Engineering Contradiction:
Improveanalysis simplicityVSAvoidinter-account relationship information
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent segments the analysis process into distinct components: individual account feature extraction, pairwise correlation calculation, cluster formation, and graph construction. This segmentation allows the system to maintain computational efficiency while building comprehensive inter-account relationship models, breaking down the complex multi-account analysis into manageable processing stages.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11522873B2Detecting network attacks
Publication Date: 2022.12.06 DATAVISOR INC
  • US11522873B2 patent drawing
  • US11522873B2 patent drawing
  • US11522873B2 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for detecting network attacks. One of the methods includes obtaining input data associated with a plurality of accounts associated with a particular entity; extracting features from the input data; performing unsupervised attack ring detection using the extracted features, wherein the unsupervised attack ring detection identifies suspicious clusters of accounts that have strong similarity or correlations in the high dimensional feature space; and generating an output for the detected attack rings.