Network Asset Behavior Analysis for Security Risk Prediction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity methods lack the ability to effectively predict and detect security risks from assets connected to a computer network without manual labeling or definition of asset types, especially for unmanaged devices and new asset types, leading to potential security threats going undetected.

Innovation Solution

A method that discovers assets connected to a network, associates their behaviors with asset types, calculates similarity scores over time, and generates security alerts based on deviations from expected behaviors, allowing for real-time identification of potential security threats without manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual labeling and definition of asset types are used for security risk detection, then detection accuracy is improved, but device complexity and time consumption increase

Engineering Contradiction:
Improvesecurity risk detection accuracyVSAvoidmanual intervention requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system automatically discovers assets, calculates similarity scores, and generates security alerts without manual intervention. The asset discovery module autonomously identifies assets on the network, the similarity calculation module automatically compares asset behaviors against known patterns, and the alert generation module proactively notifies security personnel of potential threats, eliminating the need for manual asset labeling and monitoring

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-calculates similarity scores for assets by comparing their behaviors against known asset type patterns before security incidents occur. By continuously monitoring and scoring asset similarities in advance, the system prepares security risk assessments proactively, enabling rapid response when deviations are detected without requiring manual analysis at the time of incident

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If manual labeling and definition of asset types are used for security risk detection, then detection accuracy is improved, but loss of time increases

Engineering Contradiction:
Improvesecurity risk detection accuracyVSAvoidtime for security monitoring
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system continuously monitors asset behaviors and recalculates similarity scores in real-time without interruption. The asset discovery module operates continuously to identify new assets, the similarity calculation module constantly updates scores as asset behaviors change, and the alert generation module continuously checks for deviations, ensuring uninterrupted security monitoring that eliminates manual checking cycles

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system implements a feedback loop where generated security alerts trigger investigations, and investigation results are fed back to refine the similarity scoring model. This continuous feedback improves detection accuracy over time while maintaining automated operation, reducing the need for repeated manual analysis and decreasing overall monitoring time

Inventive Principle:
Principle #23Feedback

3Productivity

If automated similarity scoring is used for security risk detection, then productivity is improved, but measurement precision may worsen

Engineering Contradiction:
Improvesecurity monitoring efficiencyVSAvoidsecurity risk detection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system transforms complex asset behavior data into simplified similarity score parameters that quantify security risk. By converting multidimensional behavior observations into single-dimensional similarity scores comparing asset behaviors against known patterns, the system maintains measurement precision while enabling efficient automated processing and comparison across numerous assets

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10855715B2Method for predicting security risks of assets on a computer network
Publication Date: 2020.12.01 SUMO LOGIC INC
  • US10855715B2 patent drawing
  • US10855715B2 patent drawing
  • US10855715B2 patent drawing

AI summary

One variation of a method for predicting security risks of assets on a computer network includes: over a first period of time, detecting an asset connected to the computer network and a first set of behaviors exhibited by the asset; associating the asset with a first set of assets based on similarity of the first set of behaviors to behaviors characteristic of the first set of assets; over a second period of time succeeding the first period of time, detecting the asset connected to the computer network and a second set of behaviors exhibited by the asset; detecting deviation of the asset from the first set of assets based on differences between the second set of behaviors and behaviors characteristic of the first set of assets; and generating a security alert for the asset in response to deviation of the asset from the first set of assets.