AI Network Security Baseline Using Koopman Mode Decomposition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems face challenges in detecting real-time threats due to their inability to account for daily, weekly, monthly, and seasonal cycles, as well as normal and abnormal behavior of machines and humans, leading to overwhelming alarm systems and inadequate threat visualization and management.
Innovation Solution
The implementation of Artificial Intelligence (AI) systems that establish a baseline for network behavior, perform analysis, visualization, and security procedures, and utilize Koopman mode decomposition to classify network traffic into normal, anomalous known, and anomalous unknown categories, reducing false positives and enabling human operators to focus on unknown anomalies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If rule-based, statistics-based, or machine learning-based threat detection techniques are deployed to examine traffic on 10^8 source-destination pairs, then threat detection capability is improved, but computational complexity and processing time increase excessively
Solution Approach 1:
The patent segments the network traffic analysis by establishing baseline profiles for normal behavior patterns and separating anomaly detection from routine monitoring. This divides the computational task into manageable components: baseline establishment, deviation detection, and alert generation, reducing the complexity of examining all 10^8 source-destination pairs in real-time.
Solution Approach 2:
The system performs preliminary action by pre-establishing baseline profiles of normal network behavior through machine learning models before actual threat detection occurs. These baselines are created during normal operation and stored for quick comparison, enabling rapid anomaly detection without re-analyzing all historical data during threat events.
2Measurement precision
If anomaly detection systems establish baseline profiles for all network traffic, then detection accuracy is improved, but processing time and computational resources become excessive for moderate-size networks
Solution Approach 1:
The patent applies partial action by focusing anomaly detection on specific subsets of network traffic that deviate from baseline patterns, rather than processing all network traffic uniformly. The system identifies and prioritizes traffic flows showing anomalies, applying detailed analysis only where needed, thus maintaining detection accuracy while reducing overall processing time.
3Reliability
If alarm systems detect all security threats in real-time, then threat detection completeness is improved, but false positives increase and overwhelm operators
Solution Approach 1:
The system implements feedback mechanisms where detected anomalies are continuously monitored and validated against evolving baseline profiles. Operators can provide feedback on false positives, which refines the machine learning models to better distinguish true threats from normal variations, progressively improving the signal-to-noise ratio while maintaining detection completeness.
Data Source
AI summary
Methods and systems for visualizing, analyzing, archiving and securing computer and internet of things (IoT) data networks are disclosed. The system includes a data collection device (sensor), preprocessing unit, analysis unit containing at least the Koopman mode analysis unit, and a postprocessing unit. The methods include Koopman mode analysis, support vector machines or deep learning used to compute the baseline, detect and rank known and unknown threats to the system, visualize and archive them. The methods also include creating and representing an Artificial Intelligence (AI) determined risk level indicators; using combined intel and notice alert severities with the AI risk level indicators to rank the alerts; using the AI indicators to create zero day risks; an AI Button to show the AI indicators and ranked alerts on a computer screen; and graphic user interfaces (GUI) to intuitively represent and interact with the AI indicators and ranked alerts.


