Network Anomaly Detection via Geometric Distance Clustering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems in computer networks are inadequate in detecting nefarious activity, particularly evasive malware, and isolating targeted computing devices or groups within a network is a complex challenge.
Innovation Solution
The system calculates statistical parameters for groups of networked computing devices, analyzes communication data, and computes an operating point geometric distance to detect anomalies, using methods such as weighted averages and standard deviations to flag anomalous behavior, with the ability to categorize and assign severity levels to detected anomalies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security systems are used to detect network threats, then the system structure is simple, but the detection capability is insufficient and cannot identify evasive malware effectively
Solution Approach 1:
The patent replaces traditional rule-based security detection mechanisms with a machine learning-based anomaly detection system. The system uses statistical parameter calculation, geometric distance computation, and clustering algorithms to automatically identify malicious behavior patterns, substituting mechanical detection rules with intelligent computational models that can adapt to evasive malware.
Solution Approach 2:
The patent transforms security detection from binary rule-matching to continuous parameter-based anomaly scoring. By calculating statistical parameters (mean, standard deviation) and geometric distances of network device behaviors, the system converts discrete security rules into continuous parameter spaces where anomalies can be detected through mathematical distance measurements and clustering techniques.
2Adaptability or versatility
If more computing devices are added to the network, then network functionality increases, but network vulnerability increases due to more potential attack points
Solution Approach 1:
The patent implements a self-service security monitoring system where each computing device's behavior is automatically analyzed against learned normal patterns. The system autonomously calculates statistical parameters for each device, computes anomaly scores through geometric distance measurements, and identifies potential threats without requiring manual security configuration for each device, enabling scalable security across large networks.
Solution Approach 2:
The patent establishes a feedback mechanism where the anomaly detection system continuously monitors network device behaviors, compares them against learned statistical norms, and provides real-time security assessments. The system uses feedback from geometric distance calculations and clustering results to dynamically identify and respond to emerging threats, creating a closed-loop security system that adapts to changing network conditions.
3Reliability
If sophisticated network attack techniques are used, then attack effectiveness increases, but detection difficulty increases making attacks go undetected
Solution Approach 1:
The patent replaces traditional signature-based detection with machine learning-based behavioral analysis. Instead of relying on known attack signatures that sophisticated malware can evade, the system uses statistical parameter calculation and geometric distance computation to identify anomalies based on deviations from normal behavior patterns, enabling detection of previously unseen and evasive malware variants.
Solution Approach 2:
The patent transforms security detection from rule-based binary decisions to continuous parameter-based anomaly identification. By computing statistical parameters (mean, standard deviation) and geometric distances in multi-dimensional behavior spaces, the system converts discrete security rules into continuous parameter spaces where sophisticated attacks stand out as statistical anomalies regardless of their specific techniques.
Data Source
AI summary
Computer network anomaly detection systems and methods are disclosed. One embodiment includes retrieving one or more learned profiles for a group of networked computing devices included in a computer network from a database. For each pair of computing devices in the group, a pairwise distance matrix may be computed. Each pairwise distance in the pairwise distance matrix is computed based on a statistical data profile associated with each computing device in each pair of computing devices from the group. The statistical data profiles may be included in the learned profiles. Any pairwise distances that are greater than a threshold may be removed from the pairwise distance matrix to generate a reduced pairwise distance matrix. One or more computing devices associated with the remaining pairwise distances in the reduced pairwise distance matrix may be sorted into a cluster of computing devices. An anomaly score may be computed for the cluster.


