Automated Malicious Enumeration Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network detection and response (NDR) solutions struggle to efficiently detect malicious enumeration attacks on networks, as they require human intervention to sift through large amounts of network flow data.

Innovation Solution

A flow-based analytics approach that analyzes flow data associated with web traffic to automatically detect malicious enumeration attacks by determining if the data indicates a likelihood of such an attack and alerting administrators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network flow data is collected for threat detection, then detection capability is improved, but data volume becomes too large for human analysis

Engineering Contradiction:
Improvethreat detection capabilityVSAvoiddata volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the most relevant features from network flow data using automated feature selection techniques. Instead of analyzing all raw network data, the system identifies and extracts specific features that are most indicative of malicious enumeration attacks, reducing the data volume that requires human attention while maintaining detection effectiveness

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an automated analytics engine as an intermediary between data collection and human analysis. This intermediary automatically processes the large volume of network flow data, applies machine learning models, and generates simplified alerts or findings that human analysts can easily interpret, thus bridging the gap between comprehensive data collection and manageable human review

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If automated detection is implemented, then analysis time is reduced, but detection precision may be compromised

Engineering Contradiction:
Improveanalysis timeVSAvoiddetection precision
Core Design Contradiction:
Loss of timeVSMeasurement precision

Solution Approach 1:

The patent performs preliminary automated analysis to filter and prioritize suspicious activities before human review. By pre-processing the data and identifying high-probability malicious patterns using automated algorithms, the system reduces the time required for complete analysis while maintaining precision through a two-stage approach where automated systems handle routine detection and human experts focus on complex cases

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where detection results are continuously refined based on outcomes. The automated system learns from confirmed malicious activities and adjusts its detection parameters, improving precision over time while maintaining rapid automated processing. Human analyst feedback on false positives and negatives is incorporated to enhance the automated detection algorithms

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250126140A1Malicious enumeration attack detection
Publication Date: 2025.04.17 SOPHOS LTD
  • US20250126140A1 patent drawing
  • US20250126140A1 patent drawing
  • US20250126140A1 patent drawing

AI summary

A computer system implemented method includes receiving flow data associated with web traffic from one or more requesters for a website, analyzing the flow data associated with the web traffic for the website, determining whether the flow data associated with the web traffic for the website indicates a likelihood of a malicious enumeration attack, and alerting an administrator of the website of the likelihood of the malicious enumeration attack. Further disclosed is computer systems and computer program products configured to perform the disclosed methods.