Network Security Analytics via Entity Behavior Modeling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security measures are inadequate in detecting and addressing security threats that have already entered a computer network, as they primarily focus on preventing threats from entering rather than identifying and mitigating internal threats.

Innovation Solution

A security analytics system that receives raw data from a local network, identifies entities, determines their properties and relationships, generates an entity graph, and uses machine-learned models to detect malicious behavior by parsing relevant data fields and generating threat scores, providing users with a user interface to visualize relationships and threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security measures are deployed at the network perimeter to prevent threats from entering, then the network security against external threats is improved, but the ability to detect and address internal threats is worsened

Engineering Contradiction:
Improvenetwork securityVSAvoidthreat detection capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network into multiple monitoring zones with distributed analytics agents deployed throughout the network infrastructure. These agents independently collect and analyze data from their local segments, enabling comprehensive threat detection across the entire network while maintaining the ability to identify both external and internal threats simultaneously

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces behavioral analytics agents as intermediary components between network entities and the central security system. These agents observe and analyze the behavior of users, devices, and applications, providing detailed insights into internal network activities without interfering with normal network operations or perimeter security measures

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive data collection from all network entities is performed to improve threat detection accuracy, then the detection precision is improved, but the system complexity is worsened

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent divides the data collection and analysis function into separate modular agents deployed at different network levels. Each agent handles specific data types and analysis tasks independently, reducing the complexity burden on any single component while collectively achieving comprehensive threat detection through their coordinated efforts

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements self-service mechanisms where behavioral analytics agents automatically adapt to changing network conditions and entity behaviors without requiring manual configuration. The agents autonomously learn normal behavior patterns, adjust their monitoring focus, and generate alerts, thereby maintaining high detection accuracy while minimizing the operational complexity for system administrators

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10630706B2Modeling behavior in a network
Publication Date: 2020.04.21 VMWARE INC
  • US10630706B2 patent drawing
  • US10630706B2 patent drawing
  • US10630706B2 patent drawing

AI summary

Disclosed is a system for detecting security threats in a local network. A security analytics system collects data about entities in the local network. The raw data can be filtered to extract data fields from the raw data that are relevant to detecting security threats in the local network. The filtered data can be converted into structured data that formats the information in the filtered data. The structured data may be formatted based on a set of schema, and can be used to generate a set of features. The security analytics system can use the generated features to build machine-learned models of the behavior of entities in the local network. The security analytics system can use the machine-learned models to generate threat scores representing the likelihood a security threat is present. The security analytics system can provide an indication of the security threat to a user.