Network Identifier Reputation Scoring for False Positive Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security measures often incorrectly identify legitimate traffic as malicious, leading to false positives and unintended impact on legitimate activity, as they rely solely on detection methods like port scanning and brute-force attacks without considering the reputation of network resources.
Innovation Solution
A reputation and confidence scoring system that analyzes network telemetry information, including authentication, outbound traffic, web activity, and historical data, to determine the likelihood of malicious activity and potential impact on legitimate traffic, employing rule-based and machine learning techniques to provide accurate scoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If remediation actions are taken to block suspected malicious traffic, then network security is improved, but legitimate traffic may be incorrectly blocked causing false positives
Solution Approach 1:
The patent introduces reputation scores and confidence scores as intermediary evaluation mechanisms between traffic detection and remediation actions. These scores act as mediators that assess the legitimacy of traffic patterns before blocking, allowing the system to differentiate between malicious and legitimate enumeration attempts. The reputation score evaluates the network identifier's historical behavior while the confidence score measures the certainty of malicious activity detection, together providing a nuanced decision-making framework that reduces false positives.
Solution Approach 2:
The patent changes the parameters used for traffic evaluation from simple binary detection (malicious/legitimate) to multi-dimensional scoring (reputation score, confidence score, risk level). This parameter transformation allows for more granular assessment of traffic legitimacy, enabling the system to adjust remediation actions based on the calculated scores rather than applying uniform blocking rules that cause false positives.
2Measurement precision
If detection methods like port scanning and brute-force attacks are used, then malicious activity identification is improved, but false positive rates increase impacting legitimate activity
Solution Approach 1:
The patent performs preliminary evaluation of network identifiers by calculating reputation scores based on historical telemetry data before taking remediation actions. This preliminary assessment examines past behavior patterns, authentication activities, and network interactions to establish a baseline reputation. When suspicious activity is detected, the pre-calculated reputation score and confidence score are used to determine whether the activity is likely malicious or legitimate, preventing unnecessary blocking of legitimate traffic.
Solution Approach 2:
The patent implements a feedback mechanism where telemetry data from network identifiers is continuously collected and used to update reputation scores and confidence scores. This feedback loop allows the system to learn from past detections and adjust its evaluation criteria over time. The feedback from remediation outcomes further refines the scoring models, improving the distinction between malicious and legitimate traffic patterns and reducing false positives in subsequent detections.
Data Source
AI summary
Described are systems and methods for determining a reputation score and/or a confidence score for a network identifier that represents, respectively, a likelihood that the network identifier presents a threat and/or a likelihood that the network activity associated with the network identifier corresponds to a port scanning, enumeration, or other malicious event. Embodiments of the present disclosure can utilize various network telemetry information, such as authentication activity, outbound traffic activity, web activity, honeypot connection activity, or network classification information to determine the reputation and/or confidence scores in response to a query/request and/or in connection with potentially malicious activity that can represent a likelihood that the detected potentially malicious activity is malicious/legitimate and the potential impact that remediation measures taken against the network identifier may have in the event that the detected network activity was legitimate.


