Distributed Anomaly Detector for Network Terminal Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack a comprehensive solution for detecting and predicting anomalies in network terminals within distributed networks, particularly in preventing malicious attacks that exploit vulnerabilities, leading to suboptimal system behavior and performance.

Innovation Solution

A computer-implemented method and system utilizing a distributed architecture with an anomaly detector that collects behavioral data, compares it to pre-stored behavior profiles, and employs intelligent agents to optimize and update network terminal behavior, integrated with a distributed knowledge database and hardware platform modules for anomaly detection and prediction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anomaly detection methods are used in distributed networks, then system security is compromised, but implementing comprehensive anomaly detection increases system complexity

Engineering Contradiction:
Improvesystem securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the anomaly detection function into separate intelligent agents deployed on individual network terminals rather than a centralized system. Each agent independently monitors its local terminal's behavioral data, segmenting the overall detection task across multiple distributed nodes. This reduces the complexity burden on any single component while maintaining comprehensive security coverage across the entire distributed network.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If behavioral data collection is implemented across all network terminals, then anomaly detection accuracy is improved, but data collection and processing time increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddata collection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system pre-collects and stores behavioral data from network terminals in a distributed knowledge database before anomalies occur. By continuously gathering baseline behavioral patterns during normal operation, the system prepares detection data in advance, enabling rapid anomaly identification when deviations occur without requiring time-consuming data collection at the moment of detection.

Inventive Principle:
Principle #10Preliminary action

3Speed

If intelligent agents are deployed on each network terminal, then real-time anomaly detection is achieved, but resource consumption on individual terminals increases

Engineering Contradiction:
Improvedetection speedVSAvoidterminal resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The intelligent agents on network terminals perform partial anomaly detection by analyzing only local behavioral data and comparing it against stored profiles, rather than processing all possible system parameters. This selective, partial monitoring enables real-time detection capability while consuming fewer terminal resources, with the understanding that comprehensive analysis can be performed by the distributed system as a whole.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11775403B2Method and system for developing an anomaly detector for detecting an anomaly parameter on network terminals in a distributed network
Publication Date: 2023.10.03 SORBOTICS LLC
  • US11775403B2 patent drawing
  • US11775403B2 patent drawing
  • US11775403B2 patent drawing

AI summary

The present invention discloses a computer implemented method for developing an anomaly detector which is adapted to detect/predict anomaly in one or more network terminals and optimize the behavior of the network terminals. The said method is adapted to collect and monitor the behavior of the network terminals and compare it with the behavior profile of the network terminals in order to detect the anomaly parameter. The behavior profile is the normal interaction of the software and hardware components of the network terminals. A system for implementation and execution of such anomaly detector is also disclosed.