Network Anomaly Detection With Ensemble Machine Learning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security appliances and software products in computer networks face scalability and network visibility limitations, struggling to detect malicious activities effectively due to localized monitoring and inability to utilize context information from other network segments.
Innovation Solution
A distributed data processing system employing machine learning techniques for real-time and batch processing of network events, enabling scalable and comprehensive anomaly detection across the network, using machine learning models to analyze user and entity behaviors without relying on pre-existing signatures or rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security appliances are deployed to monitor network traffic, then malware detection capability is improved, but scalability is worsened due to appliance swap requirements when traffic increases
Solution Approach 1:
The patent segments the network into multiple monitored segments with appliances deployed at strategic locations. Each appliance monitors its local segment while a central server aggregates data from all segments, enabling scalable deployment without requiring appliance swaps when traffic increases.
Solution Approach 2:
The patent combines localized appliance monitoring with centralized server analysis. The central server merges data from multiple appliances across different network segments, providing comprehensive malware detection while maintaining scalability through distributed architecture.
2Reliability
If security appliances are deployed to monitor network traffic, then intrusion detection capability is improved, but network visibility is worsened due to limited view of other network segments
Solution Approach 1:
The patent merges localized appliance data with centralized server data to create a comprehensive network-wide view. The central server aggregates information from multiple appliances monitoring different segments, eliminating blind spots and providing complete network visibility for intrusion detection.
Solution Approach 2:
The central server acts as an intermediary that collects, correlates, and analyzes data from multiple appliances. This intermediary role enables appliances with limited local visibility to benefit from comprehensive network-wide context for detecting sophisticated malware.
3Reliability
If installed software products are deployed on terminal devices to monitor data, then malware detection is improved, but scalability is worsened due to hardware upgrade limitations
Solution Approach 1:
The patent segments detection functions between lightweight terminal software and a powerful centralized server. Terminal devices perform local monitoring while the central server handles complex analysis, allowing scalability without upgrading terminal hardware.
Solution Approach 2:
The central server acts as an intermediary that receives data from terminal devices and performs sophisticated malware analysis. This architecture enables scalable deployment where terminal hardware remains simple while detection capability scales with server resources.
Data Source
AI summary
A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.


