Network Anomaly Detection Using Segmented State and Data Mining

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anomaly detection systems in enterprise environments are limited by the short-term capabilities of state models, which restrict the amount of data and information they can process, leading to inefficiencies in detecting suspicious long-term network activities.

Innovation Solution

A method and apparatus that processes short-term event data using state-based event detection rules and generates alarm messages through predefined long-term data mining algorithms, enabling the detection of anomalous activities over extended periods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If state models are used for security event detection, then short-term event detection capability is improved, but the ability to detect long-term anomalous activities deteriorates

Engineering Contradiction:
Improveshort-term event detection capabilityVSAvoiddetection time span
Core Design Contradiction:
Measurement precisionVSDuration of action of moving object

Solution Approach 1:

The system segments the detection process into two distinct components: a state model component that handles short-term event detection with limited memory, and a data mining component that handles long-term pattern analysis. This segmentation allows each component to specialize in its strength without being constrained by the other's limitations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism that bridges the state model and data mining components. This intermediary processes and transfers relevant information between the two systems, allowing the state model's short-term detections to inform the data mining component's long-term analysis while maintaining the independence and strengths of each component.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If memory capacity is increased to maintain more data keys and supporting information, then the span of time and amount of information that can be maintained is improved, but system complexity and resource requirements worsen

Engineering Contradiction:
Improveamount of data and information maintainedVSAvoidsystem complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent extracts the long-term data storage and analysis function from the state model system and places it in a separate data mining component. This extraction allows the state model to maintain its simplicity and limited memory requirements while the data mining component handles the heavy lifting of storing and analyzing large volumes of historical data using external data sources.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If the number of objects and attributes in state is limited, then system resource consumption is reduced, but overall system usefulness and detection capability deteriorate

Engineering Contradiction:
Improvesystem resource efficiencyVSAvoidsystem usefulness
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent merges the strengths of two different approaches: the state model's efficient short-term event detection with limited resources, and the data mining system's comprehensive long-term analysis capability with access to external data sources. This combination creates a hybrid system that achieves both resource efficiency and comprehensive detection capability.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7930746B1Method and apparatus for detecting anomalous network activities
Publication Date: 2011.04.19 SERVICENOW INC
  • US7930746B1 patent drawing
  • US7930746B1 patent drawing
  • US7930746B1 patent drawing

AI summary

A method and apparatus for detecting an anomalous activity in a communications network is described. In one example, short-term event data is received from a plurality of servers. An event detection rule is then executed to process the short-term event data over a predefined time period. Afterwards, at least one alarm message is generated in response to detecting the anomalous activity in accordance with at least one predefined long-term security data mining program. In response, the at least one alarm message is provided to at least one of the plurality of servers.