Network Security Anomaly Detection via Behavioral Grouping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity and dispersion of networks, combined with evolving security threats and unmanaged security settings, make it difficult for network administrators to effectively detect and manage security threats across diverse devices and systems.

Innovation Solution

A network security system that captures event information from network devices, groups similar devices based on behavior, and generates graphical visualizations to identify anomalous behavior indicative of security threats, allowing for corrective actions and improved risk analytics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network administrators manually monitor and manage each network device individually, then security settings can be customized for each device, but the time and resources required to manage increasingly dispersed and complex networks become prohibitively large

Engineering Contradiction:
Improvesecurity protectionVSAvoidtime to detect and manage threats
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an intermediary system that acts as a mediator between network devices and administrators. This system automatically discovers network devices, groups them by similarity, and performs centralized monitoring and anomaly detection, eliminating the need for administrators to manually manage each device while maintaining security effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service through automated device discovery, automatic grouping based on behavior patterns, and autonomous anomaly detection. The network devices themselves generate the data needed for their own monitoring and grouping, reducing administrative overhead while improving detection speed.

Inventive Principle:
Principle #25Self-service

2Loss of time

If centralized monitoring is implemented across all network devices, then security threats can be detected more quickly, but the complexity of managing and processing data from increasingly dispersed network devices increases

Engineering Contradiction:
Improvetime to detect threatsVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent segments the network monitoring system by grouping devices into clusters based on behavioral similarities. This segmentation reduces the complexity of centralized monitoring by dividing the large-scale network into smaller, manageable groups that can be analyzed independently while still providing enterprise-wide security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameter of device identification from individual device attributes to behavioral patterns and group characteristics. By monitoring behavioral parameters rather than individual device parameters, the system reduces data complexity while maintaining detection effectiveness across dispersed networks.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If anomaly detection is performed on individual devices without grouping, then device-specific anomalies can be detected, but the ability to identify enterprise-wide security threats through correlation of security events is reduced

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidenterprise-wide threat detection
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent merges individual device anomaly detection with enterprise-wide threat detection by combining security events from grouped devices. The system correlates anomalies across devices within the same behavioral group, enabling both precise device-specific detection and comprehensive enterprise-wide threat identification through the unified grouping framework.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3131259B1Network security
Publication Date: 2019.05.22 ACCENTURE GLOBAL SERVICES LTD
  • EP3131259B1 patent drawingFigure 1
  • EP3131259B1 patent drawingFigure 2
  • EP3131259B1 patent drawingFigure 3

AI summary

A network security system detects anomalous network device behavior associated with a network device in a group of similar network devices based on baseline network device behavior determined for the group. A graphical visualization may be generated to analyze the groups.