3D Network Anomaly Dashboards for Rapid Pattern Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional user behavior analysis (UBA) struggles to identify critical behavior anomalies across large enterprise networks with hundreds to thousands of users, as generalized organizational rules fail to detect deviations in typical yet potentially malicious patterns, making it difficult for security analysts to rapidly discover and react to threats.

Innovation Solution

A digital fingerprinting (DFP) workflow using artificial intelligence and machine learning to generate fine-grained, unsupervised behavior models for each account, analyzing day-to-day activities to identify user-specific anti-patterns, with tunable parameters for customizable threat detection and explainability, and deploying models at various granularities to reduce false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional generalized organizational rules are used for user behavior analysis, then the system is simple to implement, but it fails to detect deviations in typical yet potentially malicious patterns across large enterprise networks

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the enterprise network into multiple organizational units (OUs) and creates separate behavior models for each OU. This allows the system to analyze user behavior at a granular level while maintaining manageability. Each OU gets its own baseline model trained on historical data, enabling precise detection of anomalies specific to that unit without requiring a single complex model for the entire enterprise.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical dimension to the analysis by implementing models at multiple levels: individual user level, organizational unit level, and enterprise level. This multi-dimensional approach allows the system to detect anomalies that might be invisible at any single level, improving detection accuracy while distributing computational complexity across multiple manageable models.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If fine-grained behavior models are generated for each account using AI/ML, then anomaly detection accuracy improves, but the computational complexity and resource requirements increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidmodel management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Instead of creating one complex enterprise-wide model, the system segments modeling into multiple smaller OU-level models and user-level models. Each model is trained on relevant historical data for its specific scope, making them computationally manageable while collectively providing comprehensive coverage. This segmentation reduces the complexity of individual models while maintaining high detection accuracy through aggregated insights.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by pre-training baseline behavior models for each organizational unit using historical data before actual threat detection begins. These pre-trained models establish normal behavior patterns in advance, so when real-time analysis is needed, the system only needs to compare current behavior against established baselines rather than performing full analysis from scratch, reducing computational complexity during operation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive analysis of every account login and application activity is performed, then detection capability improves, but the ability to rapidly identify critical behavior anomalies for security analysts deteriorates due to information overload

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidanalyst response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system extracts and focuses on the most critical anomalies by comparing user behavior against OU-level baseline models. Instead of presenting all detected deviations to analysts, the system identifies and extracts only those anomalies that represent significant deviations from established patterns, filtering out noise and presenting a prioritized list of critical threats that require immediate attention.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements local quality by creating behavior models tailored to each specific organizational unit's characteristics rather than applying a uniform enterprise-wide model. Each OU model learns the specific normal behavior patterns of its users, allowing the system to detect anomalies with high precision relevant to that local context. This reduces false positives and ensures analysts receive high-quality, context-relevant alerts.

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If generalized organizational rules are used, then false positives are reduced through simple rule-based detection, but the system cannot detect novel threats that deviate from established patterns

Engineering Contradiction:
Improvethreat detection versatilityVSAvoiddetection reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements dynamics by using machine learning models that continuously adapt to changing user behavior patterns. Unlike static rule-based systems, these models learn from historical data and evolve their understanding of normal behavior over time. This allows the system to detect novel threats that deviate from established patterns while maintaining reliability through continuous adaptation to legitimate behavior changes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies parameter changes by training models on historical behavior data to establish dynamic baselines for each organizational unit. These baselines capture the normal range of behavior parameters for each OU, allowing the system to detect anomalies when behavior falls outside these dynamically determined parameters. This approach provides both versatility in detecting various threat types and reliability through statistically grounded detection thresholds.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12401672B2Finding anomalous patterns
Publication Date: 2025.08.26 NVIDIA CORP
  • US12401672B2 patent drawing
  • US12401672B2 patent drawing
  • US12401672B2 patent drawing

AI summary

Technologies for generating a graphical user interface (GUI) dashboard with a three-dimensional (3D) grid of unit cells are described. An anomaly statistic can be determined for a set of records. A subset of network address identifiers can be identified and sorted according to the anomaly statistic. The subset can have higher anomaly statistics than other network address identifiers. There can be a maximum number in the subset. The GUI dashboard is generated with unit cells organized by the subset of network address identifiers as rows, time intervals as columns, colors as a configurable anomaly score indicator, and a number of network access events as column heights. Each unit cell is a colored, 3D visual object representing a composite score of anomaly scores associated with zero or more network access events corresponding to the respective network address identifier at the respective time interval. The GUI dashboard is rendered on a display.