Entropy Approximation for Network Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network communication systems lack effective methods to distinguish between human-generated and automated communication events, particularly in detecting potential threats such as malware beaconing, password guessing, and unauthorized access, which can compromise network security.
Innovation Solution
The system employs entropy approximation and anomaly classification models trained on prior sequences of communication events to identify patterns and deviations, using Kolmogorov complexity as a proxy to differentiate between human and computing agent-generated traffic, and transmits signals to indicate potential threats based on threat prediction values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional network monitoring methods are used, then network traffic can be logged and stored, but the system cannot effectively distinguish between human-generated and automated communication events
Solution Approach 1:
The patent transforms the communication event data into entropy approximation values, changing the parameter representation from raw event sequences to compressed entropy metrics. This parameter transformation enables the system to distinguish between human-generated and automated events by measuring the regularity and predictability of communication patterns, resolving the contradiction between detection precision and method complexity.
Solution Approach 2:
The patent replaces traditional mechanical pattern-matching methods with information-theoretic entropy approximation. Instead of using complex rule-based systems to analyze communication sequences, the system uses entropy calculations to automatically differentiate between human and automated behavior, reducing analytical complexity while improving measurement precision.
2Reliability
If anomaly detection is performed on all communication events, then potential threats can be identified, but the system generates many false positives that reduce operational efficiency
Solution Approach 1:
The patent applies different analysis thresholds and entropy approximation methods to different types of communication events and network contexts. By localizing the detection sensitivity to specific event characteristics rather than applying uniform anomaly detection across all traffic, the system improves threat identification accuracy while reducing false positives that would otherwise reduce operational productivity.
3Loss of information
If comprehensive logging of communication events is implemented, then sufficient data for threat detection can be collected, but the data volume increases processing requirements and storage demands
Solution Approach 1:
The patent extracts only the essential informational content from comprehensive communication event logs by calculating entropy approximation values. Instead of storing and processing entire sequences of communication events, the system extracts entropy metrics that capture the essential patterns and regularities, maintaining information completeness for threat detection while dramatically reducing data volume and processing requirements.
Data Source
AI summary
Systems and methods for monitoring suspicious communication network traffic. The methods include obtaining data associated with a sequence of communication events transmitted via the communication network and determining an entropy approximation measure associated at least one event attribute for the sequence of communication events. The method includes generating a threat prediction value based on an anomaly classification model and the entropy approximation measure. The anomaly classification model is trained based on prior sequences of communication events to identify a non-outlier anomaly range associated with the at least one event attribute. The threat prediction value is generated based on classification of the entropy approximation measure relative to the non-outlier anomaly range associated with the at least one attribute for identifying a potential threat. The method includes transmitting a signal for communicating that the sequence is a potential threat within the communication network.


