Network Device Security via Communication Behavior Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication networks face challenges in protecting devices from suspicious behavior, such as malware or security breaches, which can lead to abnormal communication patterns that threaten network security.

Innovation Solution

A security system that monitors communication behavior and generates a profile of expected behavior for devices on the network, allowing for the identification and isolation of abnormal or malicious activity, thereby preventing potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security measures are used, then basic protection is provided, but suspicious communication patterns cannot be detected

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by establishing baseline communication profiles for each device before suspicious activity occurs. These profiles capture normal communication patterns including frequency, data volume, and interaction partners, enabling the system to detect deviations that indicate malware or security breaches

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where communication data is constantly monitored, compared against established profiles, and used to dynamically update security decisions. When abnormal patterns are detected, the system provides feedback by isolating the affected device and updating its profile to reflect the new baseline after verification

Inventive Principle:
Principle #23Feedback

2Measurement precision

If communication monitoring is increased to detect suspicious behavior, then security detection capability is improved, but network performance is degraded

Engineering Contradiction:
Improvesuspicious activity detectionVSAvoidnetwork communication efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system applies partial monitoring by focusing computational resources only on analyzing communication patterns that deviate from established baselines. Instead of examining every packet in detail, the system uses profile-based filtering to identify and deeply analyze only the suspicious portion of traffic, reducing overall processing overhead while maintaining detection precision

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If devices are isolated upon detecting abnormal communication, then network security is protected, but legitimate communication may be interrupted

Engineering Contradiction:
Improvenetwork security protectionVSAvoidcommunication continuity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies preliminary anti-action by implementing a staged isolation approach. Before fully isolating a device, the system first monitors and confirms abnormal patterns persist, then applies graduated restrictions starting with limited isolation measures. This prevents premature isolation of legitimate devices while still providing rapid response capability for confirmed threats

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system enables self-service by allowing devices to be automatically re-integrated into the network once their communication patterns return to normal or are verified as safe. The isolation and re-integration processes are automated based on continuous profile monitoring, reducing manual intervention while maintaining security

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11539729B2Protecting network devices from suspicious communications
Publication Date: 2022.12.27 COMCAST CABLE COMM LLC
  • US11539729B2 patent drawing
  • US11539729B2 patent drawing
  • US11539729B2 patent drawing

AI summary

According to some aspects, disclosed methods and systems may comprise generating a profile that is based on monitoring a communication pattern associated with a device. Subsequent communications associated with the device may be monitored. Based on the profile and the subsequent communication, a security status may be associated with the device.