ML-Based Anomaly Detection for Automated Security Rule Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional solutions for generating security rules in networked environments are inefficient and resource-intensive, particularly in detecting anomalies and responding to potential threats.

Innovation Solution

A computer-implemented method and system that uses Machine Learning (ML) to identify anomaly patterns in a networked environment, parsing these patterns into behavioral rules, and generating security rules to enhance network security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional methods are used for anomaly detection and security rule generation, then security coverage is maintained, but processing time and resource consumption increase significantly

Engineering Contradiction:
Improveanomaly detection efficiencyVSAvoidsecurity rule generation time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-training machine learning models with historical network data to establish baseline behavior patterns. This preliminary training enables the models to quickly identify anomalies without requiring extensive analysis during actual security events, thereby reducing processing time while maintaining detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention replaces conventional mechanical rule-based security systems with machine learning-based automated anomaly detection. The ML models automatically learn and adapt to network behavior patterns, eliminating the need for manual rule creation and updating. This substitution significantly reduces both time and resource consumption while improving detection efficiency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If manual security rule creation is used, then rule accuracy can be ensured, but resource consumption and time requirements increase

Engineering Contradiction:
Improvesecurity rule generation speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The machine learning system performs self-service by automatically analyzing network data, identifying anomaly patterns, and generating security rules without human intervention. The models continuously learn from new data and autonomously update their detection capabilities, reducing the need for manual security operations while maintaining high rule accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The invention introduces machine learning models as an intermediary between raw network data and security rule generation. These models process and interpret complex network behaviors, translating them into actionable security rules. This intermediary layer simplifies the overall system by automating the complex analysis tasks that would otherwise require extensive manual effort.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If traditional anomaly detection methods are applied, then false positives can be reduced, but detection speed decreases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddetection speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The machine learning models employ dynamic analysis by continuously adapting to changing network conditions and behavior patterns. Rather than using static detection rules, the models learn evolving patterns in real-time, allowing them to maintain high detection accuracy while keeping pace with modern threat landscapes. This dynamic approach enables faster detection without sacrificing precision.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12238067B2Automatically generating security rules for a networked environment based on anomaly detection
Publication Date: 2025.02.25 CHECK POINT SOFTWARE TECH LTD
  • US12238067B2 patent drawing
  • US12238067B2 patent drawing
  • US12238067B2 patent drawing

AI summary

A computer implemented method of automatically generating security rules for a networked environment based on anomalies identified using Machine Learning (ML), comprising receiving one or more feature vectors each comprising a plurality of operational parameters of a plurality of objects of a networked environment, identifying one or more anomaly patterns in the networked environment by applying one or more trained ML models to the one or more feature vectors trained to identify patterns deviating from normal behavior of the plurality of objects, parsing each anomaly patterns to a set of behavioral rules by traversing the anomaly pattern through a tree-like decision model, and generating one or more security rules for the networked environment according to the set(s) of behavior rules. Wherein the one or more security rules are applied to increase security of the networked environment.