Network Embeddings for Anomaly Detection in Security Analytics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security systems face challenges in accurately distinguishing between outliers and valid anomalies in network data, and existing NLP techniques struggle with high-dimensional data, limiting their effectiveness in network monitoring and security analytics.

Innovation Solution

The use of semantic learning approaches, specifically network embeddings, represents network interactions as vectors in a dimensional space, allowing for contextual analysis of transaction records and visualization of network activity to identify anomalies and trends, thereby improving accuracy and efficiency in network security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional network monitoring methods are used to detect anomalies, then the system can identify potential security threats, but the accuracy is low and false positives increase due to inability to differentiate outliers from valid anomalies

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent transforms network transaction data into vector representations in an embedding space, changing the parameter representation from discrete network protocols to continuous vector dimensions. This allows semantic similarity computation and contextual analysis, enabling the system to distinguish between random outliers and genuine anomalies based on their positional relationships in the embedding space rather than simple threshold comparisons

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces NLP embedding models as an intermediary layer between raw network data and anomaly detection algorithms. These embeddings serve as a mediator that captures semantic relationships and contextual information, allowing the detection system to analyze network interactions with the same effectiveness as natural language processing, thereby improving distinction between outliers and anomalies

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If NLP techniques are applied to network data analysis, then contextual understanding improves, but the high-dimensional nature of network data limits the effectiveness of traditional NLP approaches

Engineering Contradiction:
Improvecontextual information retentionVSAvoiddata dimensionality
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies dimensionality reduction techniques to transform high-dimensional network data into lower-dimensional embedding vectors that preserve semantic relationships. By projecting network transactions into a compressed embedding space, the system maintains contextual information while reducing computational complexity, making NLP techniques applicable to network security analytics

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11258814B2Methods and systems for using embedding from Natural Language Processing (NLP) for enhanced network analytics
Publication Date: 2022.02.22 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11258814B2 patent drawing
  • US11258814B2 patent drawing
  • US11258814B2 patent drawing

AI summary

Systems and methods are provided for utilizing natural language process (NLP), namely semantic learning approaches, in the realm of network security. Techniques include analyzing network transaction records to form a crafted corpus related to a semantics of network activity. The crafted corpus can be adapted to include sequences of network entities that are deemed most appropriate for analyzing a particular category related to network activity. For example, crafted corpuses can include sequences of servers accessed by each user, in order to identify activity trends in a user's normal activity. A network embeddings model can be trained on the crafted corpus. The network embeddings model includes an embedding space of text that represents interactions between network entities and captures contextual similarities of text, which further measures similarities between the network entities in the embedding space. Using network embeddings model, network activity is monitored and modeled over time, and anomalies efficiently detected.