Host Behavior Modeling via Embedding Vectors for Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise networks face challenges in detecting anomalies and identifying potential attacks due to the complexity and dynamic nature of their behavior, which existing monitoring systems struggle to address effectively.
Innovation Solution
A method and system for modeling host behavior in a network by determining probability functions for process-level and network-level events using embedding vectors, allowing for the identification of peer hosts and anomaly scoring, which enables unsupervised anomaly detection and security action based on modeled behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional monitoring systems are used to detect anomalies in enterprise networks, then the system structure is simple and easy to implement, but the detection precision and ability to identify potential attacks deteriorate due to the complexity and dynamic nature of network behavior
Solution Approach 1:
The patent introduces embedding vectors as an intermediary representation that transforms complex network events and host states into compressed numerical representations. These embedding vectors serve as mediators between the raw network data and the anomaly detection mechanism, enabling precise detection without requiring complex processing of the original data structures.
Solution Approach 2:
The patent changes the parameter representation by using probability functions and embedding vectors instead of traditional monitoring parameters. The system models the probability of observing events given host states and uses these probabilistic parameters to detect anomalies, transforming the detection problem from complex pattern matching to statistical inference.
2Reliability
If detailed process-level and network-level events are monitored to improve anomaly detection, then the detection capability improves, but the quantity of data and processing requirements increase significantly
Solution Approach 1:
The patent extracts only the essential features from process-level and network-level events by converting them into embedding vectors. Instead of processing all raw event data, the system extracts key characteristics that are sufficient for anomaly detection, significantly reducing the data quantity while maintaining detection reliability.
Solution Approach 2:
The patent transforms high-dimensional event data into lower-dimensional embedding vectors that capture the essential behavior patterns. This dimensionality reduction allows the system to process detailed event information efficiently by representing complex events in a compressed vector space that preserves the necessary information for anomaly detection.
3Measurement precision
If behavior modeling using embedding vectors is implemented, then the ability to identify peer hosts and detect anomalies improves, but the computational complexity and processing time increase
Solution Approach 1:
The patent performs preliminary action by pre-computing and storing embedding vectors for hosts and events. These pre-computed representations are saved and reused during anomaly detection, avoiding the need to recalculate complex behavioral models in real-time. This preliminary processing significantly reduces the time required for actual anomaly detection while maintaining high precision.
Data Source
AI summary
Methods and systems for modeling host behavior in a network include determining a first probability function for observing each of a set of process-level events at a first host based on embedding vectors for the first event and the first host. A second probability function is determined for the first host issuing each of a set of network-level events connecting to a second host based on embedding vectors for the first host and the second host. The first and second probability functions are maximized to determine a set of likely process-level and network-level events for the first host. A security action is performed based on the modeled host behavior.


