Community Anomaly Detection Policy Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current anomaly detection systems in organizations lack effective techniques for generating and sharing policies, relying on expert knowledge and best practices that may not be comprehensive or up-to-date, leading to inefficiencies in detecting anomalies.
Innovation Solution
A community-based policy sharing method that clusters organizations based on predefined parameters, selects and shares policies within clusters, simulates policy performance, normalizes and abstracts policies for sharing, and weights them by source organization influence, allowing for the dissemination of effective anomaly detection policies across similar organizations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If organizations develop their own anomaly detection policies based on expert knowledge, then policies can be customized to organizational needs, but policies may not be comprehensive or up-to-date and development time increases
Solution Approach 1:
The system performs preliminary actions by pre-processing and storing policies from multiple organizations in a policy repository before they are needed. Policies are normalized, abstracted, and made available for quick retrieval and sharing, eliminating the need for each organization to develop policies from scratch and reducing development time while maintaining reliability through community-contributed expertise
Solution Approach 2:
The system creates and shares copies of anomaly detection policies across multiple organizations through the policy repository. Instead of each organization developing unique policies, they can copy and adapt proven policies from the repository, significantly reducing development time while maintaining detection effectiveness through shared organizational knowledge
2Adaptability or versatility
If organizations share policies across all organizations, then best practices can be disseminated widely, but policies may not be relevant to all organizations and complexity increases
Solution Approach 1:
The system applies local quality by normalizing and abstracting policies to extract organization-specific attributes while retaining core detection logic. This allows policies to be shared across organizations with different characteristics, as each organization can receive customized versions of policies that are relevant to their specific context, increasing adaptability without proportionally increasing management complexity
Solution Approach 2:
The system changes parameters by transforming concrete organizational policies into abstracted representations with configurable parameters. Policies are converted from organization-specific implementations to parameterized templates that can be adapted to different organizations by adjusting parameters, enabling widespread sharing while managing complexity through standardization
3Productivity
If policies are normalized and abstracted for sharing, then policies can be shared more effectively across organizations, but processing complexity increases
Solution Approach 1:
The system performs normalization and abstraction as preliminary actions when policies are first contributed to the repository. By pre-processing policies into standardized formats with extracted attributes and abstracted logic, the system enables efficient sharing and retrieval without requiring complex processing at the time of policy deployment, improving productivity while managing processing complexity through upfront preparation
Data Source
AI summary
Techniques are provided for community-based anomaly detection policy sharing among organizations. One method comprises obtaining a cluster of organizations derived from clustering multiple organizations based on predefined clustering parameters; obtaining multiple policies from the organizations in the cluster; selecting one of the obtained plurality of policies based on a predefined policy sharing criteria; and sharing the selected policy with one or more of the organizations in the cluster. A use of the selected policy by one or more of the organizations may be simulated to evaluate a performance of the selected policy. The selected policy may be normalized and/or abstracted prior to being shared with organizations in the cluster. A given policy obtained from the organizations in the cluster may be weighted based on an influence rating of one or more source organizations that provided the given policy.


