Network Anomaly Detection via Entity Relationship Diversity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security threat detection methods, such as network behavior anomaly detection (NBAD), face challenges in accurately identifying anomalous behavior amidst normal network activities, particularly in complex network environments where malicious activities may mimic normal patterns.

Innovation Solution

A computer-implemented method and system that utilize a network behavior model to calculate abnormality scores based on diversity values representing relationships between network entities, allowing for the classification of network activities as anomalous or normal, and generating alerts for suspicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional network behavior anomaly detection methods are used to monitor network activities, then basic anomalous behavior can be detected, but malicious activities that mimic normal patterns cannot be accurately identified

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect disguised malicious activities
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent introduces a new dimension of analysis by calculating diversity values that represent the variety of relationships between network entities. Instead of only analyzing individual network activities, the system evaluates the diversity of entity relationships (e.g., number of different target machines accessed by a user, number of different source machines connecting to a service). This additional dimensional analysis enables the detection of malicious activities that mimic normal patterns, as malicious behaviors often exhibit abnormal diversity characteristics even when individual activities appear normal.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If network monitoring covers all network parameters including traffic volume, bandwidth use, and protocol use, then comprehensive behavior patterns can be learned, but the complexity of analysis increases

Engineering Contradiction:
Improvebehavior pattern learning accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and focuses on a specific, critical aspect of network behavior - the diversity of relationships between network entities. Rather than attempting to analyze all network parameters simultaneously, the system extracts diversity values that capture the essential relationships between entities (users, machines, services). This extraction approach maintains comprehensive monitoring capability while simplifying the analysis by concentrating on the most discriminative feature - entity relationship diversity - which effectively distinguishes normal from malicious behavior.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9565203B2Systems and methods for detection of anomalous network behavior
Publication Date: 2017.02.07 CYBER ARK SOFTWARE LTD
  • US9565203B2 patent drawing
  • US9565203B2 patent drawing
  • US9565203B2 patent drawing

AI summary

There is provided a computer implemented method for detecting anomalous behavior in a network, comprising: receiving data representing at least one network activity, each network activity representing a certain data access event involving certain network entities; extracting from the data the certain network entities involved in the respective network activity; retrieving at least one relevant diversity value from a network behavior model based on the extracted certain network entities, wherein the network behavior model includes at least one diversity value, wherein each respective diversity value represents a certain relationship between at least one network entity and at least one network entity type; calculating an abnormality score for the received network activity based on the retrieved relevant diversity values; and classifying the network activity as anomalous or normal based on the calculated abnormality score.