Cloud ML Device Reputation Profiles for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current electronic security systems lack effective methods to monitor and protect networked devices from unauthorized access and malicious activities, as they struggle to differentiate between typical and atypical device behavior in real-time, leading to potential compromises.

Innovation Solution

A cloud-based machine learning system that collects and analyzes data from networked devices to establish baseline behavior, identifies anomalies, and assigns reputation scores, using machine learning to adapt and provide remediation recommendations, thereby enhancing security by detecting and mitigating threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If cloud-based machine learning systems collect and analyze device data to establish baseline behavior and identify anomalies, then detection precision of atypical behavior is improved, but device complexity and data processing requirements increase

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments device monitoring into multiple independent components: data collection agents running locally on devices, centralized cloud-based machine learning processors, and separate reputation scoring modules. This segmentation allows each component to be optimized independently and reduces overall system complexity while maintaining high detection precision through specialized processing at each stage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cloud-based machine learning engine as an intermediary between device data collection and security decision-making. This intermediary processes raw device data, establishes baselines, identifies anomalies, and generates recommendations, thereby improving detection precision without requiring complex processing at the device level itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time monitoring and analysis of device behavior is implemented, then security protection is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously collecting device data and establishing baseline behavior patterns in advance. The machine learning models pre-process and analyze historical data to create reference profiles, enabling rapid comparison against current device behavior without requiring complex real-time analysis, thus improving security while reducing processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements periodic data collection and analysis cycles rather than continuous intensive processing. Devices report status at defined intervals, and the system performs batch processing of this data through machine learning algorithms, achieving effective security monitoring with reduced computational overhead and faster processing compared to continuous real-time analysis.

Inventive Principle:
Principle #19Periodic action

3Measurement precision

If machine learning algorithms process large volumes of device data, then accuracy of behavior classification is improved, but energy consumption increases

Engineering Contradiction:
Improvebehavior classification accuracyVSAvoidenergy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts and processes only the most relevant device data characteristics through machine learning algorithms rather than analyzing all available data. By identifying and focusing on key behavioral indicators and critical device attributes, the system achieves high classification accuracy while significantly reducing the volume of data requiring processing and the associated energy consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system dynamically adjusts processing parameters based on device context and threat level. The machine learning models modify their analysis depth, data collection frequency, and processing intensity according to the specific device profile and current operational conditions, enabling accurate behavior classification while optimizing energy consumption by reducing processing power for low-risk devices.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11049039B2Static and dynamic device profile reputation using cloud-based machine learning
Publication Date: 2021.06.29 MCAFEE LLC
  • US11049039B2 patent drawing
  • US11049039B2 patent drawing
  • US11049039B2 patent drawing

AI summary

Disclosed herein are cloud-based machine learning systems and methods for monitoring networked devices to identify and classify characteristics, to infer typical or atypical behavior and assign reputation profiles across various networked devices, and to make remediation recommendations. In some embodiments, a cloud-based machine learning system may learn the typical operation and interfacing of a plurality of reputable devices that are known to be free from malicious software and other threats. In some embodiments, a cloud-based machine learning system may learn the typical operation and interfacing of a device, and may identify atypical operations or interfaces associated with that device by comparing the operations and interfaces to those of a plurality of networked devices or to those of a defined standard reference device.