Network Anomaly Detection Using Segmented State and Data Mining
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current anomaly detection systems in enterprise environments are limited by the short-term capabilities of state models, which restrict the amount of data and information they can process, leading to inefficiencies in detecting suspicious long-term network activities.
Innovation Solution
A method and apparatus that processes short-term event data using state-based event detection rules and generates alarm messages through predefined long-term data mining algorithms, enabling the detection of anomalous activities over extended periods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If state models are used for security event detection, then short-term event detection capability is improved, but the ability to detect long-term anomalous activities deteriorates
Solution Approach 1:
The system segments the detection process into two distinct components: a state model component that handles short-term event detection with limited memory, and a data mining component that handles long-term pattern analysis. This segmentation allows each component to specialize in its strength without being constrained by the other's limitations.
Solution Approach 2:
The patent introduces an intermediary mechanism that bridges the state model and data mining components. This intermediary processes and transfers relevant information between the two systems, allowing the state model's short-term detections to inform the data mining component's long-term analysis while maintaining the independence and strengths of each component.
2Quantity of substance
If memory capacity is increased to maintain more data keys and supporting information, then the span of time and amount of information that can be maintained is improved, but system complexity and resource requirements worsen
Solution Approach 1:
The patent extracts the long-term data storage and analysis function from the state model system and places it in a separate data mining component. This extraction allows the state model to maintain its simplicity and limited memory requirements while the data mining component handles the heavy lifting of storing and analyzing large volumes of historical data using external data sources.
3Productivity
If the number of objects and attributes in state is limited, then system resource consumption is reduced, but overall system usefulness and detection capability deteriorate
Solution Approach 1:
The patent merges the strengths of two different approaches: the state model's efficient short-term event detection with limited resources, and the data mining system's comprehensive long-term analysis capability with access to external data sources. This combination creates a hybrid system that achieves both resource efficiency and comprehensive detection capability.
Data Source
AI summary
A method and apparatus for detecting an anomalous activity in a communications network is described. In one example, short-term event data is received from a plurality of servers. An event detection rule is then executed to process the short-term event data over a predefined time period. Afterwards, at least one alarm message is generated in response to detecting the anomalous activity in accordance with at least one predefined long-term security data mining program. In response, the at least one alarm message is provided to at least one of the plurality of servers.


