Network Anomaly Detection via Entity Relationship Diversity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security threat detection methods, such as network behavior anomaly detection (NBAD), face challenges in accurately identifying anomalous behavior amidst normal network activities, particularly in complex network environments where malicious activities may mimic normal patterns.
Innovation Solution
A computer-implemented method and system that utilize a network behavior model to calculate abnormality scores based on diversity values representing relationships between network entities, allowing for the classification of network activities as anomalous or normal, and generating alerts for suspicious activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional network behavior anomaly detection methods are used to monitor network activities, then basic anomalous behavior can be detected, but malicious activities that mimic normal patterns cannot be accurately identified
Solution Approach 1:
The patent introduces a new dimension of analysis by calculating diversity values that represent the variety of relationships between network entities. Instead of only analyzing individual network activities, the system evaluates the diversity of entity relationships (e.g., number of different target machines accessed by a user, number of different source machines connecting to a service). This additional dimensional analysis enables the detection of malicious activities that mimic normal patterns, as malicious behaviors often exhibit abnormal diversity characteristics even when individual activities appear normal.
2Reliability
If network monitoring covers all network parameters including traffic volume, bandwidth use, and protocol use, then comprehensive behavior patterns can be learned, but the complexity of analysis increases
Solution Approach 1:
The patent extracts and focuses on a specific, critical aspect of network behavior - the diversity of relationships between network entities. Rather than attempting to analyze all network parameters simultaneously, the system extracts diversity values that capture the essential relationships between entities (users, machines, services). This extraction approach maintains comprehensive monitoring capability while simplifying the analysis by concentrating on the most discriminative feature - entity relationship diversity - which effectively distinguishes normal from malicious behavior.
Data Source
AI summary
There is provided a computer implemented method for detecting anomalous behavior in a network, comprising: receiving data representing at least one network activity, each network activity representing a certain data access event involving certain network entities; extracting from the data the certain network entities involved in the respective network activity; retrieving at least one relevant diversity value from a network behavior model based on the extracted certain network entities, wherein the network behavior model includes at least one diversity value, wherein each respective diversity value represents a certain relationship between at least one network entity and at least one network entity type; calculating an abnormality score for the received network activity based on the retrieved relevant diversity values; and classifying the network activity as anomalous or normal based on the calculated abnormality score.


