Network Security Analysis System Using Dynamic Baseline Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems for computer networks face challenges in efficiently detecting and categorizing anomalous activity due to the dynamic and evolving nature of normal network behavior, which complicates the identification of network anomalies.

Innovation Solution

A network security analysis system that implements a high-speed analytical framework using natural language processing and machine learning techniques to establish and maintain a baseline network model, dynamically adapting to changes in normal behavior by analyzing a sliding window of network activity, and utilizing Elasticsearch, Logstash, and Kibana software stacks for data ingestion, processing, and visualization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional security systems use static baseline models for network analysis, then system complexity is reduced, but the ability to detect evolving anomalies deteriorates

Engineering Contradiction:
Improveadaptability to evolving network behaviorVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic baseline models that automatically adapt to changing network behavior through continuous learning from historical data. The system uses machine learning algorithms to update baseline expectations of normal network activity, allowing it to detect anomalies in evolving network environments without manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs self-updating baseline models that automatically learn from network data without requiring manual intervention. The baseline model continuously refines its understanding of normal behavior by processing incoming network traffic, enabling the system to adapt to new patterns autonomously.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If security systems analyze comprehensive network data to improve anomaly detection accuracy, then detection precision improves, but processing time increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments network data into distinct categories and processes different types of data through specialized analysis pipelines. By dividing the comprehensive network data into manageable segments (e.g., traffic flow, packet contents, metadata), the system maintains high detection accuracy while reducing overall processing time through parallel processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial analysis to most network traffic by comparing against baseline models, and reserves comprehensive deep analysis for suspicious packets that deviate from normal behavior. This selective approach maintains high detection accuracy for anomalies while minimizing processing time for the majority of normal traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10305924B2Network security analysis system
Publication Date: 2019.05.28 ACCENTURE GLOBAL SOLUTIONS LTD
  • US10305924B2 patent drawing
  • US10305924B2 patent drawing
  • US10305924B2 patent drawing

AI summary

A network security analysis system performs anomaly detection with low false positives by implementing a multiple perspective analysis of network data. The analysis system implements natural language processing techniques to examine the content of network and time series data to identify anomalies within new activity.