Automated Malicious Enumeration Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network detection and response (NDR) solutions struggle to efficiently detect malicious enumeration attacks on networks, as they require human intervention to sift through large amounts of network flow data.
Innovation Solution
A flow-based analytics approach that analyzes flow data associated with web traffic to automatically detect malicious enumeration attacks by determining if the data indicates a likelihood of such an attack and alerting administrators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network flow data is collected for threat detection, then detection capability is improved, but data volume becomes too large for human analysis
Solution Approach 1:
The patent extracts only the most relevant features from network flow data using automated feature selection techniques. Instead of analyzing all raw network data, the system identifies and extracts specific features that are most indicative of malicious enumeration attacks, reducing the data volume that requires human attention while maintaining detection effectiveness
Solution Approach 2:
The patent introduces an automated analytics engine as an intermediary between data collection and human analysis. This intermediary automatically processes the large volume of network flow data, applies machine learning models, and generates simplified alerts or findings that human analysts can easily interpret, thus bridging the gap between comprehensive data collection and manageable human review
2Loss of time
If automated detection is implemented, then analysis time is reduced, but detection precision may be compromised
Solution Approach 1:
The patent performs preliminary automated analysis to filter and prioritize suspicious activities before human review. By pre-processing the data and identifying high-probability malicious patterns using automated algorithms, the system reduces the time required for complete analysis while maintaining precision through a two-stage approach where automated systems handle routine detection and human experts focus on complex cases
Solution Approach 2:
The patent implements feedback mechanisms where detection results are continuously refined based on outcomes. The automated system learns from confirmed malicious activities and adjusts its detection parameters, improving precision over time while maintaining rapid automated processing. Human analyst feedback on false positives and negatives is incorporated to enhance the automated detection algorithms
Data Source
AI summary
A computer system implemented method includes receiving flow data associated with web traffic from one or more requesters for a website, analyzing the flow data associated with the web traffic for the website, determining whether the flow data associated with the web traffic for the website indicates a likelihood of a malicious enumeration attack, and alerting an administrator of the website of the likelihood of the malicious enumeration attack. Further disclosed is computer systems and computer program products configured to perform the disclosed methods.


