Network Behavioral Baselining for Drift Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network monitoring systems lack the ability to provide comprehensive and actionable information for identifying normal operations and deviations, especially in distributed or cloud computing environments, where components change frequently, and often rely on data from a single source, offering a limited, one-dimensional view of network activity.
Innovation Solution
The system implements behavioral baselining by storing asset and relationship attributes, connecting event streams, and detecting drifts from established baselines, allowing for the selection of operational attributes and providing actionable intelligence on network data connections, enabling contextualization of deviations with security controls.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If conventional network monitoring systems use data from a single source, then the system complexity is reduced, but the comprehensiveness of network activity information is limited
Solution Approach 1:
The patent combines multiple data sources including network flow data, authentication logs, vulnerability scan data, and asset inventory data into a unified monitoring system. This integration allows the system to maintain comprehensive information about network activities while managing complexity through centralized processing and correlation of diverse data streams.
Solution Approach 2:
The monitoring system is designed to handle multiple types of data sources and perform various analysis functions including behavioral baselining, anomaly detection, and security event correlation. This multi-functional approach enables comprehensive network monitoring without requiring separate specialized systems for each data type.
2Loss of information
If behavioral baselining with multiple data sources is implemented, then the comprehensiveness of network activity picture is improved, but the device complexity increases
Solution Approach 1:
The system segments the complex monitoring task into distinct functional modules: data collection from multiple sources, data normalization and standardization, behavioral baselining, anomaly detection, and reporting. Each module handles specific aspects of the monitoring process, making the overall complex system manageable through modular architecture.
Solution Approach 2:
The patent introduces intermediary components including data normalization layers that standardize diverse data formats, correlation engines that link events across different data sources, and baseline comparison mechanisms that contextualize anomalies. These intermediaries simplify the integration of multiple data sources by providing standardized interfaces and processing logic.
Data Source
AI summary
Systems and methods for behavioral baselining of network systems. In one embodiment, a method includes: storing, in an asset attribute database, information regarding assets, wherein each asset comprises at least one attribute; storing, in a relationship database, information regarding relationships, wherein each relationship comprises at least one attribute; selecting, from the asset attribute database, assets based on at least one attribute value; selecting, from the relationship database, one or more relationships based on at least one attribute value, the selected relationships including a first relationship; creating a baseline, wherein the baseline comprises the selected assets and the selected relationships; connecting a first event stream to the baseline, wherein the first event stream comprises a set of events, and each event comprises attributes; and detecting a drift from the baseline, wherein the drift is determined using the first event stream and is based on a failure of at least one attribute value in a first event of the first event stream to match at least one attribute value of the first relationship.


