Network Behavioral Metric Extraction for Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security mechanisms lack effective mechanisms for real-time detection of abnormal network behavior and forensic analysis, especially in dynamic and complex network environments, where the selection of relevant metrics and classification of normal versus abnormal behavior are significant challenges.
Innovation Solution
A method for extracting and analyzing network behavioral metrics using a relevancy measure (η) based on normal and abnormal behavior probability distribution functions, combined with an Adaptive Exponentially Weighted Moving-Average (AEWMA) formula to track network changes and determine abnormal behavior, and a metric disintegration model to increase the significance of selected metrics to network behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing network security mechanisms are used, then basic network protection is provided, but real-time detection of abnormal network behavior and forensic analysis capabilities are insufficient
Solution Approach 1:
The system performs preliminary actions by continuously collecting and storing network traffic data, metadata, and contextual information before attacks occur. This pre-collection of data enables rapid forensic analysis and abnormal behavior detection when security events occur, eliminating the need to wait for attacks to gather evidence.
Solution Approach 2:
The patent introduces an intermediary NBAD system that sits between network traffic and security analysis tools. This intermediary component processes raw network data, extracts behavioral metrics, and presents refined information to security systems, making abnormal behavior detection more efficient and accurate.
2Loss of information
If comprehensive network metrics are collected for forensic analysis, then complete attack reconstruction is achieved, but data set size and processing complexity increase dramatically
Solution Approach 1:
The system extracts only the most relevant behavioral metrics and features from the vast amount of available network data. By identifying and extracting key indicators of abnormal behavior, the system maintains complete forensic information while reducing data volume and processing complexity for analysis.
Solution Approach 2:
The patent segments the large forensic data set into organized categories including network traffic data, metadata, contextual information, and behavioral metrics. This segmentation allows the system to process and analyze different types of information separately, reducing overall complexity while maintaining information completeness.
3Reliability
If traditional network security systems are used, then basic protection is provided, but actionable intelligence for pursuing effective forensic analysis is lacking
Solution Approach 1:
The NBAD system implements feedback mechanisms that continuously monitor network behavior, compare it against established baselines, and provide actionable intelligence when abnormalities are detected. This feedback loop enables security teams to respond effectively to threats by providing real-time insights into attack patterns and behaviors.
Data Source
AI summary
A network behavioral metric is extracted from a communication network based on a relevancy of the metric to network behavior by identifying a network metric x that is defined as a random variable that represents a quantitative measure of a network behavior accumulated over a period of time, selecting a network feature, generating a metric disintegration model for the network metric x comprising at least one normal behavior probability distribution function for the metric x for each value of the network feature, respectively, and at least one abnormal behavior probability distribution function for the metric x for each value of the network feature, respectively, increasing a number of the values of the metric x that indicates normal network behavior and/or abnormal network behavior based on the metric disintegration model, and selecting a network metric x as a behavioral metric based on a relevancy η of the network metric x to the network behavior. Embodiments for tracking network behavioral changes are also provided.


