Network Security Anomaly Detection via User Confirmation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face challenges in accurately detecting anomalies across a single observation point, especially with the mobility and geographic dispersal of the modern workforce and the proliferation of cloud services, making it difficult to effectively monitor and respond to suspicious network activities in real-time.

Innovation Solution

A system comprising sensors, databases, and engines that monitor network activity, detect suspicious connections, and generate user prompts for confirmation, allowing users to verify their activities, which are then used to modify alerts and notify security analysts, enabling improved anomaly detection and reporting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network security monitoring is implemented across distributed networks with mobile workforce and cloud services, then the coverage and adaptability of security monitoring is improved, but the complexity of detecting and measuring anomalies increases

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidanomaly detection difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces user confirmation as an intermediary element between automated anomaly detection and security response. When the system detects suspicious network activity, it presents the anomaly information to the user and requests confirmation or denial. This intermediary step helps verify whether detected anomalies represent actual security threats or false positives, improving detection accuracy in distributed networks where context is difficult to obtain from single observation points.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If real-time anomaly detection and user confirmation systems are deployed, then the responsiveness to security breaches is improved, but the device complexity increases

Engineering Contradiction:
Improveresponse speed to security breachesVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent segments the security monitoring system into distinct functional components: automated anomaly detection modules that continuously monitor network traffic, user notification modules that present anomalies to users, and response coordination modules that act on user confirmations. This segmentation allows each component to perform its specific function efficiently, maintaining real-time responsiveness while managing overall system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements feedback loops where user responses to anomaly notifications are fed back into the detection system. When users confirm or deny detected anomalies, this information is used to refine future detection accuracy and adjust system behavior. The feedback mechanism enables continuous improvement of anomaly detection while maintaining manageable complexity through iterative learning rather than requiring overly complex upfront design.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If user confirmation prompts are generated and transmitted to verify suspicious activities, then the accuracy of anomaly detection is improved, but the loss of time in the detection and confirmation process increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddetection and confirmation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary actions by pre-configuring anomaly detection rules, thresholds, and user notification templates before security incidents occur. The system continuously monitors and learns normal network patterns in advance, so when anomalies are detected, the confirmation process can proceed quickly using pre-established criteria and user interfaces. This preliminary preparation reduces the time penalty associated with user confirmation while maintaining high detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10129273B2System and methods for computer network security involving user confirmation of network connections
Publication Date: 2018.11.13 CISCO TECHNOLOGY INC
  • US10129273B2 patent drawing
  • US10129273B2 patent drawing
  • US10129273B2 patent drawing

AI summary

Systems and methods for detecting anomalies in network traffic and providing notification to the users of the computers that generated the network traffic for confirmation of the activities that resulted in the network traffic are described herein. According to particular embodiments, the system is configured to collect data regarding network activity (e.g., via sensors), generate inquiries to users regarding that activity, receive the user's response to those inquiries, and provide the user's response along with the network activity to a security analyst.