Network Behavioral Baselining for Drift Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network monitoring systems lack the ability to provide comprehensive and actionable information for identifying normal operations and deviations, especially in distributed or cloud computing environments, where components change frequently, and often rely on data from a single source, offering a limited, one-dimensional view of network activity.

Innovation Solution

The system implements behavioral baselining by storing asset and relationship attributes, connecting event streams, and detecting drifts from established baselines, allowing for the selection of operational attributes and providing actionable intelligence on network data connections, enabling contextualization of deviations with security controls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If conventional network monitoring systems use data from a single source, then the system complexity is reduced, but the comprehensiveness of network activity information is limited

Engineering Contradiction:
Improvesystem complexityVSAvoidcomprehensiveness of network activity information
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent combines multiple data sources including network flow data, authentication logs, vulnerability scan data, and asset inventory data into a unified monitoring system. This integration allows the system to maintain comprehensive information about network activities while managing complexity through centralized processing and correlation of diverse data streams.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The monitoring system is designed to handle multiple types of data sources and perform various analysis functions including behavioral baselining, anomaly detection, and security event correlation. This multi-functional approach enables comprehensive network monitoring without requiring separate specialized systems for each data type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of information

If behavioral baselining with multiple data sources is implemented, then the comprehensiveness of network activity picture is improved, but the device complexity increases

Engineering Contradiction:
Improvecomprehensiveness of network activity pictureVSAvoiddevice complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system segments the complex monitoring task into distinct functional modules: data collection from multiple sources, data normalization and standardization, behavioral baselining, anomaly detection, and reporting. Each module handles specific aspects of the monitoring process, making the overall complex system manageable through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including data normalization layers that standardize diverse data formats, correlation engines that link events across different data sources, and baseline comparison mechanisms that contextualize anomalies. These intermediaries simplify the integration of multiple data sources by providing standardized interfaces and processing logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10666673B2Behavioral baselining of network systems
Publication Date: 2020.05.26 CATBIRD NETWORKS
  • US10666673B2 patent drawing
  • US10666673B2 patent drawing
  • US10666673B2 patent drawing

AI summary

Systems and methods for behavioral baselining of network systems. In one embodiment, a method includes: storing, in an asset attribute database, information regarding assets, wherein each asset comprises at least one attribute; storing, in a relationship database, information regarding relationships, wherein each relationship comprises at least one attribute; selecting, from the asset attribute database, assets based on at least one attribute value; selecting, from the relationship database, one or more relationships based on at least one attribute value, the selected relationships including a first relationship; creating a baseline, wherein the baseline comprises the selected assets and the selected relationships; connecting a first event stream to the baseline, wherein the first event stream comprises a set of events, and each event comprises attributes; and detecting a drift from the baseline, wherein the drift is determined using the first event stream and is based on a failure of at least one attribute value in a first event of the first event stream to match at least one attribute value of the first relationship.