Network Asset Behavior Analysis for Security Risk Prediction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity methods lack the ability to effectively predict and detect security risks from assets connected to a computer network without manual labeling or definition of asset types, especially for unmanaged devices and new asset types, leading to potential security threats going undetected.
Innovation Solution
A method that discovers assets connected to a network, associates their behaviors with asset types, calculates similarity scores over time, and generates security alerts based on deviations from expected behaviors, allowing for real-time identification of potential security threats without manual intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual labeling and definition of asset types are used for security risk detection, then detection accuracy is improved, but device complexity and time consumption increase
Solution Approach 1:
The system automatically discovers assets, calculates similarity scores, and generates security alerts without manual intervention. The asset discovery module autonomously identifies assets on the network, the similarity calculation module automatically compares asset behaviors against known patterns, and the alert generation module proactively notifies security personnel of potential threats, eliminating the need for manual asset labeling and monitoring
Solution Approach 2:
The system pre-calculates similarity scores for assets by comparing their behaviors against known asset type patterns before security incidents occur. By continuously monitoring and scoring asset similarities in advance, the system prepares security risk assessments proactively, enabling rapid response when deviations are detected without requiring manual analysis at the time of incident
2Measurement precision
If manual labeling and definition of asset types are used for security risk detection, then detection accuracy is improved, but loss of time increases
Solution Approach 1:
The system continuously monitors asset behaviors and recalculates similarity scores in real-time without interruption. The asset discovery module operates continuously to identify new assets, the similarity calculation module constantly updates scores as asset behaviors change, and the alert generation module continuously checks for deviations, ensuring uninterrupted security monitoring that eliminates manual checking cycles
Solution Approach 2:
The system implements a feedback loop where generated security alerts trigger investigations, and investigation results are fed back to refine the similarity scoring model. This continuous feedback improves detection accuracy over time while maintaining automated operation, reducing the need for repeated manual analysis and decreasing overall monitoring time
3Productivity
If automated similarity scoring is used for security risk detection, then productivity is improved, but measurement precision may worsen
Solution Approach 1:
The system transforms complex asset behavior data into simplified similarity score parameters that quantify security risk. By converting multidimensional behavior observations into single-dimensional similarity scores comparing asset behaviors against known patterns, the system maintains measurement precision while enabling efficient automated processing and comparison across numerous assets
Data Source
AI summary
One variation of a method for predicting security risks of assets on a computer network includes: over a first period of time, detecting an asset connected to the computer network and a first set of behaviors exhibited by the asset; associating the asset with a first set of assets based on similarity of the first set of behaviors to behaviors characteristic of the first set of assets; over a second period of time succeeding the first period of time, detecting the asset connected to the computer network and a second set of behaviors exhibited by the asset; detecting deviation of the asset from the first set of assets based on differences between the second set of behaviors and behaviors characteristic of the first set of assets; and generating a security alert for the asset in response to deviation of the asset from the first set of assets.


