Fuzzy Network Entity Matching for Unauthorized Connection Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems struggle to accurately identify and manage third-party entities in complex network environments due to variations in network identifiers, dynamic IP addresses, and encrypted connections, leading to cybersecurity risks such as unauthorized access and data breaches.

Innovation Solution

Employing fuzzy matching algorithms and machine learning models to correlate network identifiers with entity identifiers, integrating data from network registries and threat intelligence feeds to normalize and analyze network traffic data, detect anomalies, and update security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If direct mappings of network identifiers to registered entities are used, then entity identification is simplified, but accuracy in identifying unregistered or unknown third-party connections deteriorates

Engineering Contradiction:
Improveentity identificationVSAvoididentification accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary fuzzy matching module that sits between network traffic analysis and entity identification. This intermediary layer uses fuzzy matching algorithms to bridge the gap between network identifiers and entity identifiers, enabling accurate identification of unregistered third-party connections while maintaining operational simplicity through automated correlation processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If traditional network monitoring methods are used, then network traffic data collection is straightforward, but detection of anomalies and unauthorized connections deteriorates

Engineering Contradiction:
Improvedata collectionVSAvoidanomaly detection
Core Design Contradiction:
Ease of manufactureVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms where the fuzzy matching module continuously refines entity identification based on network traffic patterns. The system feeds back anomaly detections and unauthorized connection identifications to update the correlation between network identifiers and entity identifiers, improving anomaly detection capability over time while maintaining straightforward data collection through standardized network monitoring interfaces.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If fuzzy matching algorithms and machine learning models are integrated, then entity identification accuracy improves, but system complexity increases

Engineering Contradiction:
Improveentity identification accuracyVSAvoidsystem architecture
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex entity identification system into distinct functional modules: network traffic data collection module, fuzzy matching module, machine learning correlation module, and anomaly detection module. This segmentation allows each component to handle specific tasks independently, improving overall accuracy while managing system complexity through modular architecture where each module can be optimized and maintained separately.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250286899A1Identifying unauthorized entities from network traffic
Publication Date: 2025.09.11 HSBC GRP MANAGEMENT SERVICES LTD
  • US20250286899A1 patent drawing
  • US20250286899A1 patent drawing
  • US20250286899A1 patent drawing

AI summary

Systems, methods, and devices to detect unauthorized third-party connections within a network infrastructure, such as by analyzing network traffic data using fuzzy matching and machine learning techniques. One aspect includes receiving network traffic data comprising records of communication events involving network identifiers, determining communication relationships between network entities identified by the network identifiers, accessing entity identifiers associated with known third-party systems, and determining associations between the network identifiers and the entity identifiers using a fuzzy matching process. Other aspects include identifying communication relationships involving the third-party systems based on the associations and detecting unregistered or unknown third-party connections within the network infrastructure. Further aspects include normalizing identifiers, computing string similarity metrics, assigning confidence scores, incorporating external data sources, building network association patterns, comparing current patterns to baseline patterns to detect anomalies, and updating security policies or firewall rules in response to detected anomalies. Additional aspects are provided.