Network Breach Detection via Traffic Topology Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems lack effective methods to detect and remediate computing system breaches within network environments, failing to predict and prevent the lateral movement of security threats efficiently.

Innovation Solution

A system utilizing network traffic monitoring to identify computing systems, generate network topology, predict breach pathways, and implement remediation steps based on likelihood scores, incorporating machine learning for dynamic adjustment and validation checks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network traffic monitoring and predictive analytics are implemented to detect and predict breach pathways, then security detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the security monitoring task into distinct functional modules: network traffic data collection, topology detection, predictive analytics engine, and automated remediation. Each module handles a specific aspect of the security monitoring process, making the overall complex system manageable and maintainable while improving detection capabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary predictive analytics engine that acts as a mediator between raw network traffic data and security remediation actions. This intermediary layer processes and analyzes traffic patterns to predict breach pathways, thereby improving detection capability without requiring direct complex interactions between data collection and remediation systems

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If automated remediation steps are implemented based on predictive analytics, then response time is improved, but risk of false positives increases

Engineering Contradiction:
Improveresponse timeVSAvoidaccuracy of breach detection
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-configuring remediation steps and policies before breaches occur. When predictive analytics identify potential breach pathways, the system executes pre-planned remediation actions, significantly reducing response time while maintaining accuracy through预先 established detection criteria and validation mechanisms

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the system continuously monitors the effectiveness of remediation actions and adjusts its predictive analytics accordingly. This feedback loop validates whether predicted breaches were accurate and refines the analytics engine to reduce false positives while maintaining rapid response capabilities

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11792211B2System for detecting and remediating computing system breaches using computing network traffic monitoring
Publication Date: 2023.10.17 BANK OF AMERICA CORP
  • US11792211B2 patent drawing
  • US11792211B2 patent drawing

AI summary

A system is provided for detecting and remediating computing system breaches using computing network traffic monitoring. In particular, the system may identify one or more computing systems within a network as well as relationships between such computing systems to determine a network topology. Based on the network topology, the system may use historical network traffic data associated with the computing systems in the network to generate predicted entry points and lateral pathways of a security breach that may take place within particular computing systems. Then, based on the computing systems affected as well as entry points and path traversals of the breach, the system may generate and/or implement one or more remediation steps to address existing and/or future breaches. In this way, the system may provide an intelligent method of augmenting the security of a computing network.