Network Anomaly Detection With Severity-Based Authentication Levels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current anomaly detection systems in computer networks face challenges in real-time processing of large data volumes, leading to delayed identification and resolution of network compromises, which can result in significant losses.
Innovation Solution
Anomaly detection is tied to authentication levels by using machine learning to generate anomaly thresholds, prompting administrators to authenticate at specific levels to address identified anomalies, such as unloading compromised applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If real-time anomaly detection is implemented to quickly identify network compromises, then response time is improved, but the system becomes overwhelmed by the extremely large amounts of data that need to be processed in real-time
Solution Approach 1:
The patent segments anomaly detection into multiple levels based on authentication levels. Different authentication levels (e.g., level 1, level 2, level 3) correspond to different anomaly thresholds and data processing depths. This segmentation allows the system to process data at appropriate granularities for each anomaly severity, reducing overall processing complexity while maintaining fast response times for critical anomalies.
Solution Approach 2:
The patent changes the parameter of anomaly detection by associating different anomaly thresholds with different authentication levels. When an anomaly is detected, the system determines the appropriate authentication level based on the anomaly's severity, and only processes data up to that level's threshold. This parameter-based approach allows rapid response to high-severity anomalies without processing all data at the highest level, balancing speed and complexity.
2Productivity
If automated anomaly detection solutions are used to speed up identification, then detection speed is improved, but the time to identify and resolve issues remains too long
Solution Approach 1:
The patent implements preliminary action by pre-defining multiple anomaly thresholds associated with different authentication levels before anomalies occur. When an anomaly is detected, the system immediately determines which pre-defined threshold level is exceeded and triggers the corresponding authentication level. This eliminates the need for complex real-time decision-making about response intensity, significantly reducing resolution time while maintaining high detection speed.
Solution Approach 2:
The patent makes the anomaly detection system dynamic by adjusting the processing depth and authentication requirements based on the detected anomaly's severity. Instead of a static one-size-fits-all approach, the system dynamically selects the appropriate authentication level (e.g., level 1 for minor anomalies, level 3 for critical anomalies), allowing rapid response to severe issues while avoiding unnecessary processing for minor ones, thus reducing overall resolution time.
3Reliability
If multiple anomaly thresholds with different authentication levels are implemented, then the system can prioritize responses to critical anomalies, but the complexity of the anomaly detection system increases
Solution Approach 1:
The patent applies universality by creating a multi-functional anomaly detection framework where a single detection system handles multiple authentication levels and anomaly types. Instead of building separate detection systems for different anomaly severities, one universal system processes all anomalies through a standardized multi-level threshold framework, reducing overall system complexity while maintaining reliable priority-based response capabilities.
Data Source
AI summary
An anomaly on a computer network is identified by processing data generated by the computer network. The anomaly is identified based on a first anomaly threshold of a plurality of anomaly thresholds associated with the anomaly. In response to determining that the anomaly has met the first anomaly threshold of the plurality of anomaly thresholds associated with the anomaly, a first authentication level associated with the first anomaly threshold is identified. The plurality of anomaly thresholds associated with the anomaly have a plurality of associated authentication levels. A user interface is displayed to an administrator that includes a prompt to authenticate the administrator at the first authentication level. Authenticating the administrator at the first authentication level allows the administrator to take an action associated with the anomaly. For example, the administrator may unload an application that may likely have been compromised.


