Hybrid Data Surveillance System for Contextual Security Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information security technologies fail to effectively address data exfiltration and Data Loss Prevention (DLP) by not applying signature-based or anomaly-based intrusion detection techniques, and lack a holistic approach using supervised and unsupervised machine learning for analyzing user behavior and data packets in a conceptualized hypercube.

Innovation Solution

A hybrid data surveillance system employing supervised and unsupervised machine learning techniques for analyzing user behavior and packet content, using Deep Packet Inspection (DPI) to establish a baseline for normal behavior and detect anomalies by clustering packets in an n-dimensional hypercube, with fuzzy hashing for identifying security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional signature-based or anomaly-based intrusion detection techniques are used, then detection capability is provided, but they fail to effectively address data exfiltration and DLP

Engineering Contradiction:
Improvedetection capabilityVSAvoideffectiveness against data exfiltration
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent combines multiple detection approaches (signature-based, anomaly-based, supervised machine learning, and unsupervised machine learning) into a unified data surveillance system. This merging allows the system to leverage the strengths of each approach while compensating for their individual weaknesses, particularly in detecting data exfiltration and preventing data loss that traditional single-method systems cannot effectively address.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The surveillance system is designed to perform multiple functions: detecting security threats, analyzing user behavior, identifying data exfiltration attempts, and providing DLP capabilities. By making the system universal and multi-functional, it can effectively address various types of security incidents including data exfiltration, which traditional specialized intrusion detection systems fail to handle properly.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If Deep Packet Inspection and machine learning analysis are implemented, then real-time security detection is achieved, but system complexity increases

Engineering Contradiction:
Improvereal-time detection speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the data surveillance system into distinct functional modules: Deep Packet Inspection components, supervised machine learning analysis components, unsupervised machine learning analysis components, and contextual information processing components. This segmentation allows each module to be optimized independently and managed separately, reducing overall system complexity while maintaining real-time detection capabilities through coordinated operation of the segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces contextual information as an intermediary layer that enhances detection accuracy without requiring increased computational complexity in the core inspection and analysis engines. This intermediary contextual data helps the system make more informed decisions with the same computational resources, achieving real-time detection without proportionally increasing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If contextual information is attached to server logs, then proactive remedial actions are enabled, but data processing overhead increases

Engineering Contradiction:
Improvesecurity response effectivenessVSAvoiddata processing overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system performs preliminary analysis and attaches contextual information to server logs in advance, before security incidents occur. This preliminary action enables proactive remedial measures to be taken when anomalies are detected, improving security response effectiveness. By preparing contextual information beforehand rather than generating it during incident response, the system avoids excessive data processing overhead during critical security events.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10542026B2Data surveillance system with contextual information
Publication Date: 2020.01.21 FLYING CLOUD TECH INC
  • US10542026B2 patent drawing
  • US10542026B2 patent drawing
  • US10542026B2 patent drawing

AI summary

Data surveillance techniques are presented for the detection of security issues, especially of the kind where privileged data may be stolen by steganographic, data manipulation or any form of exfiltration attempts. Such attempts may be made by rogue users or admins from the inside of a network, or from outside hackers who are able to intrude into the network and impersonate themselves as legitimate users. The system and methods use a triangulation process whereby analytical results pertaining to data protocol, user-behavior and packet content are combined to establish a baseline for the data. Subsequent incoming data is then scored and compared against the baseline to detect any security anomalies. A centroid representing the normal population of the data packets is identified. The design allows establishing the context of various events of interest in the organization, thus enabling dynamic management of security policies.