Hybrid Data Surveillance System for Contextual Security Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information security technologies fail to effectively address data exfiltration and Data Loss Prevention (DLP) by not applying signature-based or anomaly-based intrusion detection techniques, and lack a holistic approach using supervised and unsupervised machine learning for analyzing user behavior and data packets in a conceptualized hypercube.
Innovation Solution
A hybrid data surveillance system employing supervised and unsupervised machine learning techniques for analyzing user behavior and packet content, using Deep Packet Inspection (DPI) to establish a baseline for normal behavior and detect anomalies by clustering packets in an n-dimensional hypercube, with fuzzy hashing for identifying security threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional signature-based or anomaly-based intrusion detection techniques are used, then detection capability is provided, but they fail to effectively address data exfiltration and DLP
Solution Approach 1:
The patent combines multiple detection approaches (signature-based, anomaly-based, supervised machine learning, and unsupervised machine learning) into a unified data surveillance system. This merging allows the system to leverage the strengths of each approach while compensating for their individual weaknesses, particularly in detecting data exfiltration and preventing data loss that traditional single-method systems cannot effectively address.
Solution Approach 2:
The surveillance system is designed to perform multiple functions: detecting security threats, analyzing user behavior, identifying data exfiltration attempts, and providing DLP capabilities. By making the system universal and multi-functional, it can effectively address various types of security incidents including data exfiltration, which traditional specialized intrusion detection systems fail to handle properly.
2Productivity
If Deep Packet Inspection and machine learning analysis are implemented, then real-time security detection is achieved, but system complexity increases
Solution Approach 1:
The patent segments the data surveillance system into distinct functional modules: Deep Packet Inspection components, supervised machine learning analysis components, unsupervised machine learning analysis components, and contextual information processing components. This segmentation allows each module to be optimized independently and managed separately, reducing overall system complexity while maintaining real-time detection capabilities through coordinated operation of the segments.
Solution Approach 2:
The system introduces contextual information as an intermediary layer that enhances detection accuracy without requiring increased computational complexity in the core inspection and analysis engines. This intermediary contextual data helps the system make more informed decisions with the same computational resources, achieving real-time detection without proportionally increasing system complexity.
3Reliability
If contextual information is attached to server logs, then proactive remedial actions are enabled, but data processing overhead increases
Solution Approach 1:
The system performs preliminary analysis and attaches contextual information to server logs in advance, before security incidents occur. This preliminary action enables proactive remedial measures to be taken when anomalies are detected, improving security response effectiveness. By preparing contextual information beforehand rather than generating it during incident response, the system avoids excessive data processing overhead during critical security events.
Data Source
AI summary
Data surveillance techniques are presented for the detection of security issues, especially of the kind where privileged data may be stolen by steganographic, data manipulation or any form of exfiltration attempts. Such attempts may be made by rogue users or admins from the inside of a network, or from outside hackers who are able to intrude into the network and impersonate themselves as legitimate users. The system and methods use a triangulation process whereby analytical results pertaining to data protocol, user-behavior and packet content are combined to establish a baseline for the data. Subsequent incoming data is then scored and compared against the baseline to detect any security anomalies. A centroid representing the normal population of the data packets is identified. The design allows establishing the context of various events of interest in the organization, thus enabling dynamic management of security policies.


