Aggregating Network Sessions into Meta-Sessions for Security Ranking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems face inefficiencies in classifying and ranking network sessions, often leading to high false positives and false negatives, and require extensive manual effort, as they typically rely on simple indicators and lack access to full session data, which limits their predictive power and decision-making capabilities.
Innovation Solution
The proposed method involves aggregating network sessions with similar features into meta-sessions, using a scoring function to select and rank classifiers, and providing a subset of ranked meta-sessions for additional analysis, allowing for more effective resource allocation and enhanced security by focusing on potentially malicious sessions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network security systems analyze all network sessions individually using simple indicators, then they can detect potential threats, but they generate high false positives and consume excessive manual effort
Solution Approach 1:
The patent merges multiple individual network sessions that share common characteristics into meta-sessions. By combining sessions with similar source IPs, destination IPs, protocols, or other features into grouped meta-sessions, the system reduces the total number of items requiring manual review while preserving threat detection capability. This directly addresses the contradiction by maintaining reliability through comprehensive analysis while improving productivity by reducing manual effort scope.
Solution Approach 2:
The patent segments the analysis process into two distinct phases: automated meta-session creation and ranking, followed by focused manual review of only high-priority meta-sessions. This segmentation allows the system to handle large volumes of network sessions automatically through feature extraction and clustering, then concentrate human expertise only where needed, resolving the efficiency-accuracy tradeoff.
2Measurement precision
If network security systems perform comprehensive analysis of all network sessions, then they can identify malicious sessions with high accuracy, but they require extensive resources and time
Solution Approach 1:
The patent performs preliminary automated analysis to create meta-sessions and calculate risk scores before manual review. By pre-processing network sessions to extract features, group them into meta-sessions, and rank them by potential maliciousness, the system prepares the data in advance so that analysts can focus immediately on the most suspicious cases without wasting time on preliminary sorting or filtering.
Solution Approach 2:
The patent applies different levels of analysis intensity to different meta-sessions based on their risk scores. High-scoring meta-sessions receive thorough manual examination, while lower-scoring ones receive less intensive review or automated handling. This localized quality approach ensures measurement precision is applied where most needed while reducing overall analysis time.
3Productivity
If network security systems use simple indicators for session classification, then they can process sessions quickly, but they produce high false positives and false negatives
Solution Approach 1:
The patent uses composite feature sets that combine multiple indicators (source IP, destination IP, protocol, ports, timing patterns, data volume) to create meta-sessions. Rather than relying on single simple indicators, the system synthesizes multiple data points into a composite classification that maintains processing speed through automated feature extraction while significantly improving reliability by considering multiple dimensions of session behavior simultaneously.
Data Source
AI summary
A method includes obtaining session data related to a plurality of network sessions, analyzing the session data to identify one or more features of the network sessions, and utilizing the one or more features to aggregate the plurality of network sessions into a plurality of meta-sessions. A meta-session comprises a set of network sessions having similar features. The method also includes selecting a classifier for ranking the meta-sessions based on a scoring function that characterizes performance in ranking meta-sessions having a designated characteristic, ranking the meta-sessions utilizing the selected classifier, providing a designated number of the ranked meta-sessions for additional processing to determine potential maliciousness, and modifying access by client devices to an additional network session responsive to the additional network session comprising session data with features similar to those of one of the designated number of the ranked meta-sessions determined to be potentially malicious.


