Network Behavioral Metric Extraction for Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security mechanisms lack effective mechanisms for real-time detection of abnormal network behavior and forensic analysis, especially in dynamic and complex network environments, where the selection of relevant metrics and classification of normal versus abnormal behavior are significant challenges.

Innovation Solution

A method for extracting and analyzing network behavioral metrics using a relevancy measure (η) based on normal and abnormal behavior probability distribution functions, combined with an Adaptive Exponentially Weighted Moving-Average (AEWMA) formula to track network changes and determine abnormal behavior, and a metric disintegration model to increase the significance of selected metrics to network behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing network security mechanisms are used, then basic network protection is provided, but real-time detection of abnormal network behavior and forensic analysis capabilities are insufficient

Engineering Contradiction:
Improvenetwork security detection capabilityVSAvoidabnormal behavior detection difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary actions by continuously collecting and storing network traffic data, metadata, and contextual information before attacks occur. This pre-collection of data enables rapid forensic analysis and abnormal behavior detection when security events occur, eliminating the need to wait for attacks to gather evidence.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary NBAD system that sits between network traffic and security analysis tools. This intermediary component processes raw network data, extracts behavioral metrics, and presents refined information to security systems, making abnormal behavior detection more efficient and accurate.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If comprehensive network metrics are collected for forensic analysis, then complete attack reconstruction is achieved, but data set size and processing complexity increase dramatically

Engineering Contradiction:
Improveforensic information completenessVSAvoiddata processing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system extracts only the most relevant behavioral metrics and features from the vast amount of available network data. By identifying and extracting key indicators of abnormal behavior, the system maintains complete forensic information while reducing data volume and processing complexity for analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the large forensic data set into organized categories including network traffic data, metadata, contextual information, and behavioral metrics. This segmentation allows the system to process and analyze different types of information separately, reducing overall complexity while maintaining information completeness.

Inventive Principle:
Principle #1Segmentation

3Reliability

If traditional network security systems are used, then basic protection is provided, but actionable intelligence for pursuing effective forensic analysis is lacking

Engineering Contradiction:
Improveforensic analysis effectivenessVSAvoidactionable intelligence availability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The NBAD system implements feedback mechanisms that continuously monitor network behavior, compare it against established baselines, and provide actionable intelligence when abnormalities are detected. This feedback loop enables security teams to respond effectively to threats by providing real-time insights into attack patterns and behaviors.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8028061B2Methods, systems, and computer program products extracting network behavioral metrics and tracking network behavioral changes
Publication Date: 2011.09.27 VIAVI SOLUTIONS INC(US)
  • US8028061B2 patent drawing
  • US8028061B2 patent drawing
  • US8028061B2 patent drawing

AI summary

A network behavioral metric is extracted from a communication network based on a relevancy of the metric to network behavior by identifying a network metric x that is defined as a random variable that represents a quantitative measure of a network behavior accumulated over a period of time, selecting a network feature, generating a metric disintegration model for the network metric x comprising at least one normal behavior probability distribution function for the metric x for each value of the network feature, respectively, and at least one abnormal behavior probability distribution function for the metric x for each value of the network feature, respectively, increasing a number of the values of the metric x that indicates normal network behavior and/or abnormal network behavior based on the metric disintegration model, and selecting a network metric x as a behavioral metric based on a relevancy η of the network metric x to the network behavior. Embodiments for tracking network behavioral changes are also provided.