Network Anomaly Detection via Port Connection Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network monitoring systems require manual analysis of internet traffic data for detecting malicious activities, which is time-consuming, prone to human error, and results in delayed identification of threats.

Innovation Solution

A computing system and method that automatically analyze network data from multiple devices to detect anomalous behavior by determining port connection activity, generating notifications for anomalies such as port volume increases or classification changes, using normalized connection counts and classification tests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual analysis of network data is used, then human judgment and flexibility are applied, but the process is time-consuming and results in delayed identification of threats

Engineering Contradiction:
Improveaccuracy of threat detectionVSAvoidtime to identify malicious activity
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary automated analysis of network data against multiple anomaly criteria before human review. By pre-processing the data and identifying potential anomalies automatically, the system prepares the information in advance for faster human decision-making, thus reducing the overall time to identify threats while maintaining reliability through subsequent human verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An automated analysis system acts as an intermediary between raw network data and human analysts. This intermediary layer performs initial filtering, normalization, and anomaly detection, presenting only relevant findings to human reviewers. This mediator approach eliminates the need for manual analysis of all raw data while ensuring human judgment is applied to suspicious cases, thereby reducing time loss without compromising detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual analysis of network data is used, then human expertise is applied, but the process is prone to human error

Engineering Contradiction:
Improveconsistency of threat detectionVSAvoidhuman error in analysis
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs self-service automated analysis using standardized algorithms and criteria to evaluate network data. By enabling the system to analyze data independently against predefined anomaly patterns, human error is eliminated from the initial detection phase. The automated process consistently applies the same criteria without fatigue or distraction, ensuring reliable and repeatable results while human experts focus on complex case evaluation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of human analysis is replaced with an automated electronic analysis system that processes network data through standardized algorithms. This substitution eliminates human error factors such as fatigue, distraction, and inconsistency. The electronic system consistently applies anomaly detection criteria across all data, providing reliable and reproducible results without the harmful effects of human error.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If automated analysis is implemented, then real-time detection is achieved, but the system complexity increases

Engineering Contradiction:
Improvespeed of threat identificationVSAvoidcomplexity of analysis system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The automated analysis system is segmented into distinct functional modules, each handling specific anomaly detection tasks. By dividing the complex analysis process into separate components that evaluate different criteria independently, the system achieves real-time detection capability while managing complexity through modular design. Each segment can be developed, maintained, and adjusted independently, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The automated analysis system is designed with universal, multi-functional components that can evaluate multiple anomaly criteria using standardized processes. By creating versatile analysis modules that can handle different types of network data and anomaly patterns through a unified framework, the system achieves high productivity across diverse scenarios without proportionally increasing complexity. The same core infrastructure supports multiple detection functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If comprehensive manual review is performed, then thorough analysis is achieved, but resource consumption increases

Engineering Contradiction:
Improvethoroughness of analysisVSAvoidhuman resources required
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system extracts and automates the routine analysis tasks from manual human review processes. By taking out the repetitive, standardized evaluation steps and automating them through computational algorithms, the system maintains thorough analysis of all data while significantly reducing human resource consumption. Human experts are freed from routine tasks and can focus on complex cases requiring human judgment, optimizing resource allocation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

An automated intermediary system performs the initial comprehensive review of all network data, filtering and prioritizing findings before human review. This intermediary layer ensures thorough analysis is applied to all data consistently while reducing the volume of work requiring human resources. The mediator prepares refined outputs that maintain analytical thoroughness while enabling human experts to concentrate on high-value assessment tasks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11374954B1Detecting anomalous network behavior
Publication Date: 2022.06.28 RAPID7 INC
  • US11374954B1 patent drawing
  • US11374954B1 patent drawing
  • US11374954B1 patent drawing

AI summary

Approaches provide for monitoring attempted network activity such as network port connections and corresponding payloads of network data obtained by a network device and, based on the attempted connections and/or payloads, identifying malicious network activity in real time. For example, network activity obtained from a plurality of network devices in a service provider environment can be monitored to attempt to detect compliance with appropriate standards and/or any of a variety of resource usage guidelines (e.g., network behavioral standards or other such rules, guidelines, or network behavior tests) based at least in part on network port connection activity with respect to at least one network device. If it is determined that network activity is not in compliance with the usage guidelines, or other such network behavior test, the system can take one or more remedial actions, which can include generating a notification identifying the malicious network activity.