Machine-Learned Network Event Detection with Deliberate Variance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security systems struggle to detect and mitigate information concealment techniques employed by malicious entities that modify transmission characteristics to covertly extract sensitive information, leading to undetected breaches and potential disruptions.
Innovation Solution
A computing system processes network information with a machine-learned hidden information detection model to identify modulated features, then introduces deliberate variance to obfuscate the concealed information by randomizing transmission characteristics, preventing further extraction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If information retrieval techniques optimize for speed by foregoing obfuscation attempts, then extraction speed is improved, but detection probability increases and access may be revoked
Solution Approach 1:
The patent converts the harmful effect of obfuscation (which hides malicious activity) into a beneficial detection mechanism by analyzing the same obfuscation techniques as indicators of concealed information. The system detects steganographic modifications and covert channel attempts by examining anomalies in information transmission patterns, thereby turning the malicious entity's concealment efforts into evidence of their wrongdoing.
2Reliability
If information retrieval techniques use obfuscation and concealment to lower detection probability, then access continuity is improved, but detection difficulty increases
Solution Approach 1:
The patent applies parameter changes by monitoring and analyzing multiple transmission characteristics simultaneously (timing intervals, packet sizes, protocol deviations, data patterns). By examining changes in these parameters rather than relying on a single metric, the system can detect concealed information even when individual parameters appear normal. This multi-parameter analysis approach overcomes the difficulty of detecting sophisticated obfuscation techniques.
3Measurement precision
If conventional security systems monitor network traffic for breaches, then detection capability is improved, but system complexity and processing overhead increase
Solution Approach 1:
The patent implements preliminary action by establishing baseline transmission patterns and detecting deviations before significant data exfiltration occurs. The system proactively monitors for anomalies in transmission timing, packet characteristics, and protocol behavior, allowing early detection and response to potential breaches. This preventive approach reduces the need for complex reactive security measures.
Data Source
AI summary
Network information is obtained for a plurality of discrete information units transmitted by a transmitting entity. The network information is descriptive of features of network events that occurred for the discrete information units. The network information is processed with a machine-learned hidden information detection model to obtain a prediction output indicating that the features of the network events that occurred for the discrete information units are modulated to conceal hidden information. Based on the prediction output, a variance addition process is caused to be performed for a second plurality of discrete information units to be transmitted by the transmitting entity. The variance addition process causes variance to be added to features of future network events for at least some of the second plurality of discrete information units.


