Network Device Effectiveness Identification via Event Normalization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network devices vary significantly in effectiveness for identifying attacks, making it difficult to detect ineffective devices within a computer network, especially when they are from different vendors and have disparate data formats and configurations.
Innovation Solution
A method and system that normalize event attributes across different network devices to calculate scores and similarity measures, using cosine similarity calculations to identify ineffective devices by comparing their responses to network attacks, allowing for remedial actions such as disabling or reconfiguring these devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network devices from different vendors with disparate data formats and configurations are used to provide countermeasure services, then the network can benefit from diverse facilities and services, but it becomes difficult to compare and evaluate the effectiveness of these devices in identifying attacks
Solution Approach 1:
The patent applies homogeneity by normalizing event attributes from different network devices into a common schema. Event attributes such as severity, source address, destination address, and event type are standardized across diverse device types and vendors, enabling consistent comparison and evaluation of device effectiveness while preserving the diversity of facilities and services.
2Productivity
If generic data analytics tools are used to analyze network events, then general data processing capability is provided, but correlation analysis of disparate data sources with different formats and semantic meanings is not effective
Solution Approach 1:
The patent introduces an intermediary normalization layer that sits between the diverse network device data sources and the analysis engine. This intermediary component translates and standardizes event attributes from different vendors and device types into a unified format, enabling effective correlation analysis while maintaining high data processing productivity.
3Reliability
If network devices are configured to generate detailed event, log, alarm or tracking information, then comprehensive attack detection capability is improved, but the complexity of comparing and evaluating device effectiveness increases due to differing formats and configurations
Solution Approach 1:
The patent changes the parameters of event data by normalizing attribute values into standardized formats. Event attributes such as severity levels, address formats, and event types are transformed into consistent parameter representations, reducing data comparison complexity while preserving the comprehensive attack detection capability provided by detailed event information.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
A computer system arranged to detect an ineffective network device in a set of network devices for a computer network as a device ineffective at identifying an attack in the network, the computer system including: an input unit to receive events generated by the set of network devices for each of a plurality of time periods, each event including an attribute belonging to a class of attributes; a processing system having at least one processor and being arranged to: evaluate a normalised representative value of the attribute as a score for each network device for each of the plurality of time periods based on the received events; evaluating a measure of similarity of scores for each of a plurality of pairs of devices in the set of network devices for one or more time windows, each time window comprising two or more of the time periods; and identify a network device having evaluated similarity measures meeting a predetermined threshold as ineffective network devices.