Network Security Device Baseline Profile Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of physical and cyber security systems in networks is challenging due to the use of unsecure communication networks, which exposes sites to combined cyber and physical attacks, creating a conflict between security and connectivity in various organizations.

Innovation Solution

A network security system with security devices equipped with hardware processors that create a baseline profile of network activity and detect irregular events by monitoring traffic deviations, allowing for immediate actions such as generating alerts, blocking communications, or performing counter-attacks to protect the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If unsecure communication networks are used to connect physical security elements and network appliances, then connectivity and service availability are improved, but the network becomes exposed to combined cyber and physical attacks

Engineering Contradiction:
ImproveconnectivityVSAvoidcyber and physical attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces security devices as intermediary components between network appliances and the unsecure communication network. These security devices monitor network traffic, detect irregular events, and block malicious communications, thereby mediating between the need for network connectivity and the risk of cyber attacks. The security device acts as a buffer that allows connectivity while filtering out harmful factors.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary security measures by establishing baseline profiles of normal network activity before attacks occur. The system proactively monitors network traffic, detects deviations from established baselines, and prepares to block malicious communications before they can compromise the network. This preliminary detection and response mechanism prevents attacks rather than merely reacting to them.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security devices monitor and block all potential threats to protect the network, then network security is improved, but legitimate network traffic may be disrupted

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork traffic flow
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the monitoring parameters dynamically by establishing baseline profiles of normal network activity and comparing current traffic against these baselines. Rather than using fixed blocking rules, the system adjusts its detection sensitivity based on learned normal patterns, allowing legitimate traffic to pass while identifying anomalies that deviate from established parameters. This dynamic parameter adjustment reduces false positives and maintains smooth traffic flow.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements a feedback mechanism where the security device continuously monitors network traffic, learns from observed patterns, and adjusts its blocking decisions based on this feedback. The system provides feedback to network administrators about detected irregular events and allows for tuning of detection sensitivity. This feedback loop enables the system to distinguish between legitimate traffic variations and actual threats, maintaining security while minimizing disruption to normal operations.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10015176B2Network protection
Publication Date: 2018.07.03 CYBERSEAL
  • US10015176B2 patent drawing
  • US10015176B2 patent drawing
  • US10015176B2 patent drawing

AI summary

A network security system for a network, the network comprising a plurality of networked appliances, the security system comprising one or more security devices, wherein each security device of the one or more security devices is associated with one or more networked security appliances of the plurality of networked security appliances, and wherein each security device comprises: a network interface comprising one or more ports, wherein each networked security appliance of the one or more networked security appliances associated with the security device is operatively coupled with the security device via a different port of the ports; at least one processor configured to: upon initial setup of said security device, create a baseline profile of an activity of the network, and following an activation of a protection mode, identify an irregular event by detecting a deviation of network traffic passing through a port of the ports from said baseline profile.