Network Device Effectiveness Identification via Event Normalization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network devices vary significantly in effectiveness for identifying attacks, making it difficult to detect ineffective devices within a computer network, especially when they are from different vendors and have disparate data formats and configurations.

Innovation Solution

A method and system that normalize event attributes across different network devices to calculate scores and similarity measures, using cosine similarity calculations to identify ineffective devices by comparing their responses to network attacks, allowing for remedial actions such as disabling or reconfiguring these devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network devices from different vendors with disparate data formats and configurations are used to provide countermeasure services, then the network can benefit from diverse facilities and services, but it becomes difficult to compare and evaluate the effectiveness of these devices in identifying attacks

Engineering Contradiction:
Improvediverse facilities and servicesVSAvoideffectiveness evaluation
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent applies homogeneity by normalizing event attributes from different network devices into a common schema. Event attributes such as severity, source address, destination address, and event type are standardized across diverse device types and vendors, enabling consistent comparison and evaluation of device effectiveness while preserving the diversity of facilities and services.

Inventive Principle:
Principle #33Homogeneity

2Productivity

If generic data analytics tools are used to analyze network events, then general data processing capability is provided, but correlation analysis of disparate data sources with different formats and semantic meanings is not effective

Engineering Contradiction:
Improvedata processing capabilityVSAvoidcorrelation analysis accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary normalization layer that sits between the diverse network device data sources and the analysis engine. This intermediary component translates and standardizes event attributes from different vendors and device types into a unified format, enabling effective correlation analysis while maintaining high data processing productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If network devices are configured to generate detailed event, log, alarm or tracking information, then comprehensive attack detection capability is improved, but the complexity of comparing and evaluating device effectiveness increases due to differing formats and configurations

Engineering Contradiction:
Improveattack detection capabilityVSAvoiddata comparison complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameters of event data by normalizing attribute values into standardized formats. Event attributes such as severity levels, address formats, and event types are transformed into consistent parameter representations, reducing data comparison complexity while preserving the comprehensive attack detection capability provided by detailed event information.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3158706B1Ineffective network equipment identification
Publication Date: 2020.06.03 BRITISH TELECOM PLC
  • EP3158706B1 patent drawingFigure 1~2
  • EP3158706B1 patent drawingFigure 3~4
  • EP3158706B1 patent drawingFigure 5

AI summary

A computer system arranged to detect an ineffective network device in a set of network devices for a computer network as a device ineffective at identifying an attack in the network, the computer system including: an input unit to receive events generated by the set of network devices for each of a plurality of time periods, each event including an attribute belonging to a class of attributes; a processing system having at least one processor and being arranged to: evaluate a normalised representative value of the attribute as a score for each network device for each of the plurality of time periods based on the received events; evaluating a measure of similarity of scores for each of a plurality of pairs of devices in the set of network devices for one or more time windows, each time window comprising two or more of the time periods; and identify a network device having evaluated similarity measures meeting a predetermined threshold as ineffective network devices.