Network Event Vectors for Composite Behavioral Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network forensic approaches force a selection between directional and magnitude mapping models, leading to incomplete and suboptimal views of potential behavioral anomalies in network analysis.
Innovation Solution
A system that constructs evidence vectors from network events, compares them to directional, magnitude, and composite clusters, and identifies centroids to determine the 'best fit' for anomaly detection using self-organized maps and binocular fusion analytics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a selection between directional mapping models and magnitude mapping models is forced, then the analysis can be simplified, but the view of potential behavioral anomalies becomes incomplete and suboptimal
Solution Approach 1:
The patent merges directional mapping models and magnitude mapping models into a unified composite mapping model. This combination allows the system to simultaneously capture both directional and magnitude information from network events, resolving the contradiction by integrating multiple analytical perspectives rather than forcing a selection between them, thereby achieving both simplified analysis and complete anomaly detection.
Solution Approach 2:
The composite mapping model serves multiple functions by incorporating both directional and magnitude mapping capabilities. This multi-functional approach enables the system to analyze network behavior from various dimensions (direction, magnitude, and their interaction), providing a comprehensive view of anomalies while maintaining analytical simplicity through a single unified model structure.
2Productivity
If clustering tools are used to create clustering maps, then network behavior can be grouped and analyzed, but the selection between directional and magnitude models limits the comprehensive analysis capability
Solution Approach 1:
The patent combines directional and magnitude mapping models into a composite mapping model that creates clustering maps with enhanced versatility. This merged model can simultaneously perform directional clustering, magnitude clustering, and composite clustering, allowing comprehensive analysis of network behavior patterns while maintaining high productivity through automated clustering operations.
Solution Approach 2:
The composite mapping model adds a new dimension to traditional clustering by integrating both directional and magnitude information into a unified spatial representation. This dimensional enhancement allows the clustering maps to capture more nuanced behavioral patterns, improving both the productivity and versatility of network behavior analysis.
3Device complexity
If single-model mapping is used, then the system is simpler to implement, but the probability of identifying behavioral anomalies is reduced
Solution Approach 1:
The patent merges multiple mapping models (directional and magnitude) into a composite mapping system that improves anomaly identification reliability. By combining the strengths of both models, the system achieves higher detection accuracy while maintaining reasonable implementation complexity through a unified architectural framework that leverages existing clustering technologies.
Data Source
AI summary
Examples of the present disclosure describe systems and methods for identifying anomalous network behavior. In aspects, a network event may be observed network sensors. One or more characteristics may be extracted from the network event and used to construct an evidence vector. The evidence vector may be compared to a mapping of previously-identified events and/or event characteristics. The mapping may be represented as one or more clusters of expected behaviors and anomalous behaviors. The mapping may be modeled using analytic models for direction detection and magnitude detection. One or more centroids may be identified for each of the clusters. A “best fit” may be determined and scored for each of the analytic models. The scores may be fused into single binocular score and used to determine whether the evidence vector is likely to represent an anomaly.


