Network Anomaly Detection via Statistical Digital Dossier
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods in telecommunications networks fail to detect malicious behavior, as they do not account for compromised devices or applications, and cannot identify anomalies in network usage patterns that may indicate malicious activity.
Innovation Solution
A method that creates a statistical digital dossier of network participant behavior based on observable usage values, such as data transferred, IP address destinations, and encryption key length, and compares real-time usage values against this model to detect deviations and issue alerts to administrators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If human-oriented authentication methods are used to verify network participants, then authentication reliability is improved, but the ability to detect malicious behavior is worsened
Solution Approach 1:
The patent introduces an intermediary behavioral analysis system that operates between authentication and network access. This system creates a digital dossier of normal behavioral patterns and uses it as a mediator to detect anomalies, allowing the system to maintain authentication reliability while adding malicious behavior detection capability through pattern comparison rather than direct authentication challenges.
Solution Approach 2:
The patent replaces mechanical authentication methods (passwords, biometrics) with a computational behavioral analysis system. Instead of relying on mechanical verification of user identity, the system substitutes a digital modeling approach that continuously monitors and compares network usage patterns against established baselines, enabling detection of malicious behavior that mechanical authentication cannot detect.
2Measurement precision
If statistical digital dossier and real-time monitoring are implemented to detect anomalies, then malicious behavior detection precision is improved, but device complexity is worsened
Solution Approach 1:
The patent creates a digital copy or model (digital dossier) of normal network participant behavior patterns. This copy serves as a reference template that can be repeatedly compared against real-time traffic without requiring complex analysis of each individual data packet. The copying approach simplifies the detection process by replacing complex real-time analysis with pattern matching against the pre-established digital model.
3Measurement precision
If continuous monitoring of network usage patterns is performed, then detection capability is improved, but loss of time for data processing is worsened
Solution Approach 1:
The patent performs preliminary action by establishing the digital dossier of normal behavioral patterns before actual anomaly detection begins. This pre-processing step creates a ready-reference model that eliminates the need for complex real-time analysis during monitoring. By preparing the behavioral baseline in advance, the system reduces processing time during actual detection operations while maintaining high detection precision.
Data Source
AI summary
The invention is a method of detecting malicious behavior of a network participant. Specific usage values observable at a network connectivity layer are defined. These usage values can be size of data transferred, quantity of data bursts, a quantity of IP address destinations, a network protocol being used, and/or a length of an encryption key. The invention measures the usage values for the network participant across multiple networks over a predetermined period of time and creates a statistical digital dossier representative of patterns of the measured usage values for the network participant. The invention monitors the behavior of the network participant by measuring current usage values. The current usage values are compared against the statistical digital dossier and, if a deviation beyond a predefined tolerance is detected, an alert signal is issued.


