Entropy Approximation for Network Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network communication systems lack effective methods to distinguish between human-generated and automated communication events, particularly in detecting potential threats such as malware beaconing, password guessing, and unauthorized access, which can compromise network security.

Innovation Solution

The system employs entropy approximation and anomaly classification models trained on prior sequences of communication events to identify patterns and deviations, using Kolmogorov complexity as a proxy to differentiate between human and computing agent-generated traffic, and transmits signals to indicate potential threats based on threat prediction values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional network monitoring methods are used, then network traffic can be logged and stored, but the system cannot effectively distinguish between human-generated and automated communication events

Engineering Contradiction:
Improveability to distinguish human-generated from automated communication eventsVSAvoidcomplexity of analysis methods
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transforms the communication event data into entropy approximation values, changing the parameter representation from raw event sequences to compressed entropy metrics. This parameter transformation enables the system to distinguish between human-generated and automated events by measuring the regularity and predictability of communication patterns, resolving the contradiction between detection precision and method complexity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces traditional mechanical pattern-matching methods with information-theoretic entropy approximation. Instead of using complex rule-based systems to analyze communication sequences, the system uses entropy calculations to automatically differentiate between human and automated behavior, reducing analytical complexity while improving measurement precision.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If anomaly detection is performed on all communication events, then potential threats can be identified, but the system generates many false positives that reduce operational efficiency

Engineering Contradiction:
Improveaccuracy of threat identificationVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different analysis thresholds and entropy approximation methods to different types of communication events and network contexts. By localizing the detection sensitivity to specific event characteristics rather than applying uniform anomaly detection across all traffic, the system improves threat identification accuracy while reducing false positives that would otherwise reduce operational productivity.

Inventive Principle:
Principle #3Local quality

3Loss of information

If comprehensive logging of communication events is implemented, then sufficient data for threat detection can be collected, but the data volume increases processing requirements and storage demands

Engineering Contradiction:
Improvecompleteness of communication event dataVSAvoiddata volume
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential informational content from comprehensive communication event logs by calculating entropy approximation values. Instead of storing and processing entire sequences of communication events, the system extracts entropy metrics that capture the essential patterns and regularities, maintaining information completeness for threat detection while dramatically reducing data volume and processing requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12010134B2Systems and methods of adaptively securing network communication channels
Publication Date: 2024.06.11 ROYAL BANK OF CANADA
  • US12010134B2 patent drawing
  • US12010134B2 patent drawing
  • US12010134B2 patent drawing

AI summary

Systems and methods for monitoring suspicious communication network traffic. The methods include obtaining data associated with a sequence of communication events transmitted via the communication network and determining an entropy approximation measure associated at least one event attribute for the sequence of communication events. The method includes generating a threat prediction value based on an anomaly classification model and the entropy approximation measure. The anomaly classification model is trained based on prior sequences of communication events to identify a non-outlier anomaly range associated with the at least one event attribute. The threat prediction value is generated based on classification of the entropy approximation measure relative to the non-outlier anomaly range associated with the at least one attribute for identifying a potential threat. The method includes transmitting a signal for communicating that the sequence is a potential threat within the communication network.