AI Network Security Baseline Using Koopman Mode Decomposition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems face challenges in detecting real-time threats due to their inability to account for daily, weekly, monthly, and seasonal cycles, as well as normal and abnormal behavior of machines and humans, leading to overwhelming alarm systems and inadequate threat visualization and management.

Innovation Solution

The implementation of Artificial Intelligence (AI) systems that establish a baseline for network behavior, perform analysis, visualization, and security procedures, and utilize Koopman mode decomposition to classify network traffic into normal, anomalous known, and anomalous unknown categories, reducing false positives and enabling human operators to focus on unknown anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rule-based, statistics-based, or machine learning-based threat detection techniques are deployed to examine traffic on 10^8 source-destination pairs, then threat detection capability is improved, but computational complexity and processing time increase excessively

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network traffic analysis by establishing baseline profiles for normal behavior patterns and separating anomaly detection from routine monitoring. This divides the computational task into manageable components: baseline establishment, deviation detection, and alert generation, reducing the complexity of examining all 10^8 source-destination pairs in real-time.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by pre-establishing baseline profiles of normal network behavior through machine learning models before actual threat detection occurs. These baselines are created during normal operation and stored for quick comparison, enabling rapid anomaly detection without re-analyzing all historical data during threat events.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If anomaly detection systems establish baseline profiles for all network traffic, then detection accuracy is improved, but processing time and computational resources become excessive for moderate-size networks

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by focusing anomaly detection on specific subsets of network traffic that deviate from baseline patterns, rather than processing all network traffic uniformly. The system identifies and prioritizes traffic flows showing anomalies, applying detailed analysis only where needed, thus maintaining detection accuracy while reducing overall processing time.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If alarm systems detect all security threats in real-time, then threat detection completeness is improved, but false positives increase and overwhelm operators

Engineering Contradiction:
Improvethreat detection completenessVSAvoidsignal-to-noise ratio
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system implements feedback mechanisms where detected anomalies are continuously monitored and validated against evolving baseline profiles. Operators can provide feedback on false positives, which refines the machine learning models to better distinguish true threats from normal variations, progressively improving the signal-to-noise ratio while maintaining detection completeness.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10862914B1Assigning and representing security risks on a computer network
Publication Date: 2020.12.08 MIXMODE INC
  • US10862914B1 patent drawing
  • US10862914B1 patent drawing
  • US10862914B1 patent drawing

AI summary

Methods and systems for visualizing, analyzing, archiving and securing computer and internet of things (IoT) data networks are disclosed. The system includes a data collection device (sensor), preprocessing unit, analysis unit containing at least the Koopman mode analysis unit, and a postprocessing unit. The methods include Koopman mode analysis, support vector machines or deep learning used to compute the baseline, detect and rank known and unknown threats to the system, visualize and archive them. The methods also include creating and representing an Artificial Intelligence (AI) determined risk level indicators; using combined intel and notice alert severities with the AI risk level indicators to rank the alerts; using the AI indicators to create zero day risks; an AI Button to show the AI indicators and ranked alerts on a computer screen; and graphic user interfaces (GUI) to intuitively represent and interact with the AI indicators and ranked alerts.