Network Anomaly Detection Using Sequence Frequency Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing volume of network traffic in IoT and enterprise networks makes it difficult to accurately distinguish between benign and malicious activity, leading to a high rate of false alarms and inefficiencies in identifying potential threats.
Innovation Solution
A method that combines the probability of a sequence of network events, obtained using a trained statistical model like a Markov model, with a frequency characteristic to determine the likelihood of anomalous activity, allowing differentiation between benign and malicious network behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network monitoring methods are used to analyze all network traffic, then comprehensive threat detection is achieved, but false alarms increase and analysis efficiency decreases
Solution Approach 1:
The patent segments network events into sequences and analyzes them collectively rather than individually. By grouping related events into sequences and evaluating their combined probability and frequency characteristics, the system achieves better differentiation between benign and malicious activity, reducing false alarms while maintaining comprehensive threat detection.
Solution Approach 2:
The patent transforms the analysis approach by changing parameters from individual event analysis to sequence-level probability and frequency analysis. It uses probability of sequence occurrence and frequency characteristics as new parameters to evaluate network activity, enabling more accurate distinction between benign and malicious behavior.
2Measurement precision
If detailed analysis of each network event is performed, then detection accuracy improves, but computational load and time consumption increase
Solution Approach 1:
The patent performs preliminary actions by pre-calculating probability values for event sequences based on historical data and storing them for quick reference. During real-time analysis, the system retrieves pre-computed probabilities and combines them with frequency characteristics, avoiding the need for complex real-time calculations and reducing analysis time while maintaining high detection accuracy.
3Reliability
If all network events are monitored individually, then complete threat coverage is achieved, but false alarm rate increases
Solution Approach 1:
The patent merges multiple individual event analyses into a unified sequence evaluation. By combining events into sequences and assessing their joint probability and frequency characteristics together, the system maintains complete threat coverage while reducing false alarms. The merging approach allows benign events that individually appear suspicious to be correctly identified when viewed in context with their sequence counterparts.
Data Source
AI summary
A method of identifying anomalous network activity. The method includes identifying, based on network data representative of network activity within a network, at least one instance of a sequence of events that occurred within the network. A probability of the sequence of events occurring during non-anomalous network activity is obtained based on transition probabilities between events in the sequence of events. A frequency characteristic dependent on a frequency at which the sequence of events occurred within the network is determined. A likelihood of the sequence of events occurring within the network at the frequency is determined based on a combination of the probability and the frequency characteristic. It is identified, based on the likelihood, that at least a portion of the network data is anomalous.


