Network Identifier Reputation Scoring for False Positive Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security measures often incorrectly identify legitimate traffic as malicious, leading to false positives and unintended impact on legitimate activity, as they rely solely on detection methods like port scanning and brute-force attacks without considering the reputation of network resources.

Innovation Solution

A reputation and confidence scoring system that analyzes network telemetry information, including authentication, outbound traffic, web activity, and historical data, to determine the likelihood of malicious activity and potential impact on legitimate traffic, employing rule-based and machine learning techniques to provide accurate scoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If remediation actions are taken to block suspected malicious traffic, then network security is improved, but legitimate traffic may be incorrectly blocked causing false positives

Engineering Contradiction:
Improvenetwork securityVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent introduces reputation scores and confidence scores as intermediary evaluation mechanisms between traffic detection and remediation actions. These scores act as mediators that assess the legitimacy of traffic patterns before blocking, allowing the system to differentiate between malicious and legitimate enumeration attempts. The reputation score evaluates the network identifier's historical behavior while the confidence score measures the certainty of malicious activity detection, together providing a nuanced decision-making framework that reduces false positives.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameters used for traffic evaluation from simple binary detection (malicious/legitimate) to multi-dimensional scoring (reputation score, confidence score, risk level). This parameter transformation allows for more granular assessment of traffic legitimacy, enabling the system to adjust remediation actions based on the calculated scores rather than applying uniform blocking rules that cause false positives.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If detection methods like port scanning and brute-force attacks are used, then malicious activity identification is improved, but false positive rates increase impacting legitimate activity

Engineering Contradiction:
Improvemalicious activity detectionVSAvoidimpact on legitimate traffic
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary evaluation of network identifiers by calculating reputation scores based on historical telemetry data before taking remediation actions. This preliminary assessment examines past behavior patterns, authentication activities, and network interactions to establish a baseline reputation. When suspicious activity is detected, the pre-calculated reputation score and confidence score are used to determine whether the activity is likely malicious or legitimate, preventing unnecessary blocking of legitimate traffic.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where telemetry data from network identifiers is continuously collected and used to update reputation scores and confidence scores. This feedback loop allows the system to learn from past detections and adjust its evaluation criteria over time. The feedback from remediation outcomes further refines the scoring models, improving the distinction between malicious and legitimate traffic patterns and reducing false positives in subsequent detections.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12149559B1Reputation and confidence scoring for network identifiers based on network telemetry
Publication Date: 2024.11.19 AMAZON TECH INC
  • US12149559B1 patent drawing
  • US12149559B1 patent drawing
  • US12149559B1 patent drawing

AI summary

Described are systems and methods for determining a reputation score and/or a confidence score for a network identifier that represents, respectively, a likelihood that the network identifier presents a threat and/or a likelihood that the network activity associated with the network identifier corresponds to a port scanning, enumeration, or other malicious event. Embodiments of the present disclosure can utilize various network telemetry information, such as authentication activity, outbound traffic activity, web activity, honeypot connection activity, or network classification information to determine the reputation and/or confidence scores in response to a query/request and/or in connection with potentially malicious activity that can represent a likelihood that the detected potentially malicious activity is malicious/legitimate and the potential impact that remediation measures taken against the network identifier may have in the event that the detected network activity was legitimate.