Emergent Behavior Detection in Communications Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Advanced persistent threat (APT) attacks are difficult to detect using traditional intrusion detection methods, as they involve complex behaviors and emergent patterns that cannot be predicted through analysis at lower levels, rendering traditional anomaly detection methods ineffective.

Innovation Solution

The use of advanced analysis techniques such as particle swarm optimization (PSO) and evolutionary multiple objective (EMO) algorithms to analyze metadata and detect emergent behaviors in communications networks, identifying unusual patterns and activities indicative of APT attacks by decomposing data packets into component types and calculating weighted scores based on historical data and time periods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional intrusion detection methods are used, then the system is simple and easy to operate, but it cannot detect APT attacks with complex emergent behaviors

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments network traffic into multiple data types (e.g., HTTP traffic, FTP traffic, DNS traffic) and analyzes each type separately using specialized detectors. This segmentation allows complex APT behaviors to be detected through detailed analysis of individual traffic segments without overwhelming the entire system, resolving the contradiction between detection reliability and system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of analysis by examining metadata attributes (source IP, destination IP, port numbers, protocol types) alongside traditional packet inspection. This dimensional expansion enables detection of emergent behaviors that traditional single-dimension inspection misses, improving reliability while maintaining manageable complexity through structured multi-dimensional analysis.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If detailed analysis of all data packets is performed, then detection precision improves, but processing time increases and productivity decreases

Engineering Contradiction:
Improvedetection precisionVSAvoidprocessing speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts only the necessary metadata fields (source IP, destination IP, port numbers, protocol types) from full packet data for analysis. By taking out only the essential information needed for detection rather than processing entire packets, the system achieves high detection precision while maintaining fast processing speeds and high productivity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by analyzing only specific data types and metadata fields relevant to security detection, rather than processing all possible packet contents. This selective partial analysis provides sufficient detection precision for APT identification while significantly improving processing efficiency and productivity.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If multiple data types are analyzed simultaneously, then detection coverage improves, but false positives increase due to lack of context

Engineering Contradiction:
Improvedetection coverageVSAvoidcontext information
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent merges multiple data type analyses by integrating results from HTTP, FTP, DNS, and other traffic type detectors into a unified detection framework. This combining approach maintains comprehensive detection coverage while preserving context information through correlated analysis of multiple data types, reducing false positives through cross-validation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements feedback mechanisms where detection results from one data type inform analysis of other data types. For example, suspicious patterns detected in DNS traffic can trigger enhanced analysis of corresponding HTTP traffic, providing contextual feedback that reduces false positives while maintaining broad detection coverage.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9256735B2Detecting emergent behavior in communications networks
Publication Date: 2016.02.09 MASERGY COMMUNICATIONS INC
  • US9256735B2 patent drawing
  • US9256735B2 patent drawing
  • US9256735B2 patent drawing

AI summary

Systems and methods of detecting emergent behaviors in communications networks are disclosed. In some embodiments, a method may include decomposing a plurality of data packets into a plurality of component data types associated with a candidate alert representing a potential security threat in a network. The method may also include retrieving, from a database, a count for each of a plurality of historical data types matching at least a subset of the component data types, each of the counts quantifying an amount of data of a corresponding historical data type previously detected in the network in a given time period. The method may further include calculating a score that indicates a discrepancy between an amount of data in each of the subset of the component data types and the counts for each corresponding historical data type in the same time period, and handling the candidate alert based upon the score.