Host Behavior Modeling via Embedding Vectors for Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face challenges in detecting anomalies and identifying potential attacks due to the complexity and dynamic nature of their behavior, which existing monitoring systems struggle to address effectively.

Innovation Solution

A method and system for modeling host behavior in a network by determining probability functions for process-level and network-level events using embedding vectors, allowing for the identification of peer hosts and anomaly scoring, which enables unsupervised anomaly detection and security action based on modeled behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional monitoring systems are used to detect anomalies in enterprise networks, then the system structure is simple and easy to implement, but the detection precision and ability to identify potential attacks deteriorate due to the complexity and dynamic nature of network behavior

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces embedding vectors as an intermediary representation that transforms complex network events and host states into compressed numerical representations. These embedding vectors serve as mediators between the raw network data and the anomaly detection mechanism, enabling precise detection without requiring complex processing of the original data structures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter representation by using probability functions and embedding vectors instead of traditional monitoring parameters. The system models the probability of observing events given host states and uses these probabilistic parameters to detect anomalies, transforming the detection problem from complex pattern matching to statistical inference.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If detailed process-level and network-level events are monitored to improve anomaly detection, then the detection capability improves, but the quantity of data and processing requirements increase significantly

Engineering Contradiction:
Improveattack detection reliabilityVSAvoiddata quantity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential features from process-level and network-level events by converting them into embedding vectors. Instead of processing all raw event data, the system extracts key characteristics that are sufficient for anomaly detection, significantly reducing the data quantity while maintaining detection reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms high-dimensional event data into lower-dimensional embedding vectors that capture the essential behavior patterns. This dimensionality reduction allows the system to process detailed event information efficiently by representing complex events in a compressed vector space that preserves the necessary information for anomaly detection.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If behavior modeling using embedding vectors is implemented, then the ability to identify peer hosts and detect anomalies improves, but the computational complexity and processing time increase

Engineering Contradiction:
Improvebehavioral anomaly detection precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary action by pre-computing and storing embedding vectors for hosts and events. These pre-computed representations are saved and reused during anomaly detection, avoiding the need to recalculate complex behavioral models in real-time. This preliminary processing significantly reduces the time required for actual anomaly detection while maintaining high precision.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10476753B2Behavior-based host modeling
Publication Date: 2019.11.12 CLOUD BYTE LLC
  • US10476753B2 patent drawing
  • US10476753B2 patent drawing
  • US10476753B2 patent drawing

AI summary

Methods and systems for modeling host behavior in a network include determining a first probability function for observing each of a set of process-level events at a first host based on embedding vectors for the first event and the first host. A second probability function is determined for the first host issuing each of a set of network-level events connecting to a second host based on embedding vectors for the first host and the second host. The first and second probability functions are maximized to determine a set of likely process-level and network-level events for the first host. A security action is performed based on the modeled host behavior.