Endpoint Criticality-Based Anomaly Detection Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network anomaly detection systems treat all endpoints equally, leading to overshadowing of critical alerts from sensitive endpoints, as the importance of endpoints in a network is not considered, resulting in varying consequences based on location and connectivity.

Innovation Solution

A device determines the criticality of each endpoint in a network using telemetry data and selects appropriate anomaly detection models for deployment based on endpoint criticality, optimizing resource allocation and alert prioritization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all endpoints are monitored with equal anomaly detection resources, then comprehensive network security coverage is achieved, but critical alerts from sensitive endpoints are overshadowed by alerts from less critical endpoints

Engineering Contradiction:
Improvealert detection reliabilityVSAvoidcritical alert visibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent assigns different monitoring priorities and resource allocations to different endpoints based on their criticality levels. Critical endpoints receive enhanced monitoring resources and higher priority alert processing, while less critical endpoints receive standard monitoring. This resolves the contradiction by ensuring critical alerts are not overshadowed while maintaining comprehensive coverage across all endpoints.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments endpoints into different criticality tiers (e.g., critical, standard, low-priority) and applies differentiated anomaly detection strategies to each segment. This segmentation allows the system to prioritize processing of alerts from critical endpoints without completely neglecting other endpoints, thus preventing critical alert overshadowing while maintaining overall network security coverage.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If anomaly detection models are deployed to all endpoints uniformly, then consistent monitoring quality is maintained across the network, but resource consumption increases unnecessarily for less critical areas

Engineering Contradiction:
Improvemonitoring quality consistencyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent deploys anomaly detection models with varying degrees of complexity and resource intensity based on endpoint criticality. Critical endpoints receive full-featured, high-precision monitoring models, while less critical endpoints receive simplified models or reduced monitoring frequency. This approach maintains adequate monitoring quality across all endpoints while significantly reducing unnecessary resource consumption in non-critical areas.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies partial monitoring action to less critical endpoints by reducing the frequency or depth of anomaly detection in those areas, while applying full monitoring action to critical endpoints. This partial action approach ensures that sufficient monitoring quality is maintained for security-critical areas without wasting computational resources on less important endpoints.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If monitoring resources are concentrated on critical endpoints only, then alert prioritization and response efficiency improve, but coverage and detection capability in non-critical areas are reduced

Engineering Contradiction:
Improvealert response efficiencyVSAvoidnetwork-wide detection coverage
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments monitoring resources and endpoint populations into critical and non-critical groups, allocating premium resources to critical endpoints while maintaining baseline monitoring for all endpoints. This segmentation enables the system to concentrate advanced detection capabilities where they provide maximum value while preserving fundamental security coverage across the entire network, thus maintaining both response efficiency and detection coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a multi-tiered monitoring architecture where a universal baseline monitoring system covers all endpoints, and additional specialized monitoring resources are layered on top for critical endpoints. This universal base layer ensures network-wide detection coverage, while the specialized layer enhances response efficiency for critical alerts without leaving non-critical areas completely unprotected.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12155526B1Deploying network anomaly detection systems based on endpoint criticality
Publication Date: 2024.11.26 CISCO TECHNOLOGY INC
  • US12155526B1 patent drawing
  • US12155526B1 patent drawing
  • US12155526B1 patent drawing

AI summary

In one embodiment, a device determines a criticality of each of a plurality of endpoints in a network, based on network telemetry data regarding the network. The device translates a plurality of anomaly detection models available for deployment to the network and their metadata into a set of adjustable resources. The device generates an anomaly detection deployment strategy for the network by selecting a set of one or more of the plurality of anomaly detection models for deployment to one or more execution points in the network, based on the criticality of each of the plurality of endpoints and on the set of adjustable resources. The device causes the set to be deployed to the one or more execution points in the network, in accordance with the anomaly detection deployment strategy.