Distributed Data Surveillance for Network Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information security technologies fail to effectively address data exfiltration and Data Loss Prevention (DLP) by not employing holistic approaches with supervised and unsupervised machine learning, lacking effective clustering schemes for data packets, and not performing Deep Packet Inspection (DPI) across the entire data set, especially in distributed environments.

Innovation Solution

A system that performs data surveillance by establishing a baseline through protocol, user-behavior, and packet analysis, using unsupervised machine learning for clustering and Deep Packet Inspection, and deploying in a distributed manner to detect anomalies and security issues across the entire network, with a 'community capture' approach to identify security and performance issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional intrusion detection systems are used, then security monitoring is provided, but they fail to effectively detect data exfiltration and produce high false positive rates

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse positives
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent transforms security monitoring from signature-based detection to behavioral baseline-based detection. By continuously learning normal traffic patterns through unsupervised machine learning and changing the detection parameters from static signatures to dynamic behavioral baselines, the system achieves more accurate detection of data exfiltration while reducing false positives.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces traditional mechanical intrusion detection methods (signature matching, rule-based systems) with machine learning-based behavioral analysis. The system uses unsupervised learning to automatically establish baselines and supervised learning to detect anomalies, substituting manual rule creation with automated intelligent detection that adapts to changing traffic patterns.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If Deep Packet Inspection is performed on entire data set, then detection precision is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvedetection precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the detection process into multiple stages: first analyzing packet metadata and flow characteristics, then selectively applying Deep Packet Inspection only to suspicious packets identified in earlier stages. This hierarchical segmentation allows the system to maintain high detection precision while minimizing the computational overhead of DPI by applying it only where necessary.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements partial DPI by analyzing only the portions of packets necessary for detection. Instead of inspecting every byte of every packet, the system performs selective inspection based on behavioral indicators, analyzing just enough data to detect anomalies while avoiding unnecessary processing of normal traffic.

Inventive Principle:
Principle #16Partial or excessive action

3Area of stationary object

If distributed surveillance system is deployed, then coverage area is expanded, but system complexity increases

Engineering Contradiction:
Improvenetwork coverageVSAvoidsystem architecture
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

The patent merges the surveillance functionality into existing network infrastructure components such as routers, switches, and firewalls. By integrating the machine learning models and detection logic into already-deployed network devices, the system expands coverage without adding separate complex infrastructure, thereby reducing overall system complexity while maintaining wide network coverage.

Inventive Principle:
Principle #5Merging (Combining)

4Loss of information

If rolling baseline continuously adapts to normal traffic, then false positives are reduced, but system adaptability requirements increase

Engineering Contradiction:
Improvefalse positive reductionVSAvoidsystem adaptability
Core Design Contradiction:
Loss of informationVSAdaptability or versatility

Solution Approach 1:

The patent implements a feedback mechanism where the system continuously monitors detection performance and uses this feedback to adjust the rolling baseline. The supervised learning component learns from labeled anomalies and feedback from security analysts, automatically refining the baseline to reduce false positives while adapting to legitimate changes in network behavior patterns.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10516689B2Distributed data surveillance in a community capture environment
Publication Date: 2019.12.24 FLYING CLOUD TECH INC
  • US10516689B2 patent drawing
  • US10516689B2 patent drawing
  • US10516689B2 patent drawing

AI summary

Data surveillance techniques are presented for the detection of security issues, especially of the kind where privileged data may be stolen by steganographic, data manipulation or any form of exfiltration attempts. Such attempts may be made by rogue users or admins from the inside of a network, or from outside hackers who are able to intrude into the network and impersonate themselves as legitimate users. The system and methods use a triangulation process whereby analytical results pertaining to data protocol, user-behavior and packet content are combined to establish a baseline for the data. Subsequent incoming data is then scored and compared against the baseline to detect any security anomalies. The design incorporates deployment in a distributed network so that the devices of the network participate in the detection of anomalies as a community.