Managed Network Anomaly Detection With High-Dimensional Event Vectors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and monitoring network environments in heterogeneous distributed networks is challenging due to the generation of numerous events that may be associated with anomalous activity or threat activity, requiring significant effort and resources to identify.

Innovation Solution

Anomaly detection in managed networks is achieved through the use of detection models trained with high-dimensional event vectors, generating reports that highlight anomalous events based on priority and confidence scores, and allowing for retraining of models based on feedback metrics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations deploy policy management tools to monitor network events, then security monitoring capability is improved, but the effort and resources required to identify anomalous events increase

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoideffort and resources to identify anomalous events
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual analysis of network events with machine learning models that automatically detect anomalies. The system uses trained models to process high-dimensional event vectors, substituting human effort with automated computational analysis that identifies anomalous patterns without requiring manual review of each event.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates simplified representations of complex network events through event vectors. By transforming raw network events into structured vector representations, the system enables efficient comparison and analysis without dealing with the full complexity of original events, reducing the cognitive and computational burden of anomaly detection.

Inventive Principle:
Principle #26Copying

2Measurement precision

If organizations monitor all network events in detail, then detection precision is improved, but the complexity of the monitoring system increases

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the most relevant features from network events to create event vectors. By selecting and extracting key attributes rather than analyzing all event details, the system achieves effective anomaly detection with reduced complexity. The extraction process focuses on features that are most indicative of anomalous behavior.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms network events into high-dimensional vector representations, changing the parameter space from raw event data to structured numerical vectors. This parameter transformation enables the application of mathematical and statistical methods for anomaly detection, improving precision while maintaining manageable system complexity through standardized vector operations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12432242B1Anomaly detection in managed networks
Publication Date: 2025.09.30 DELINEA INC
  • US12432242B1 patent drawing
  • US12432242B1 patent drawing
  • US12432242B1 patent drawing

AI summary

Embodiments detect anomalous activity in networks. Events may be generated based on an activity observed in a monitored network such that each event includes values associated with the activity. High dimensional event vectors may be generated by embedding based on the events and the values included in each event. Anomalous events may be determined based on detection models trained with a cluster of events associated with the high dimensional event vectors such that each anomalous event may correspond to a high dimensional event vector compared to conditions declared in the detection models and such that each anomalous event may be associated with a priority score or a confidence score. A user interface that displays a report that includes the anomalous events may be generated and arranged based on the priority score, the confidence score, a user selected preference, feedback metrics associated with the user interface, or the like.