Aggregating Network Sessions into Meta-Sessions for Security Ranking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems face inefficiencies in classifying and ranking network sessions, often leading to high false positives and false negatives, and require extensive manual effort, as they typically rely on simple indicators and lack access to full session data, which limits their predictive power and decision-making capabilities.

Innovation Solution

The proposed method involves aggregating network sessions with similar features into meta-sessions, using a scoring function to select and rank classifiers, and providing a subset of ranked meta-sessions for additional analysis, allowing for more effective resource allocation and enhanced security by focusing on potentially malicious sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security systems analyze all network sessions individually using simple indicators, then they can detect potential threats, but they generate high false positives and consume excessive manual effort

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidmanual analysis efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges multiple individual network sessions that share common characteristics into meta-sessions. By combining sessions with similar source IPs, destination IPs, protocols, or other features into grouped meta-sessions, the system reduces the total number of items requiring manual review while preserving threat detection capability. This directly addresses the contradiction by maintaining reliability through comprehensive analysis while improving productivity by reducing manual effort scope.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the analysis process into two distinct phases: automated meta-session creation and ranking, followed by focused manual review of only high-priority meta-sessions. This segmentation allows the system to handle large volumes of network sessions automatically through feature extraction and clustering, then concentrate human expertise only where needed, resolving the efficiency-accuracy tradeoff.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If network security systems perform comprehensive analysis of all network sessions, then they can identify malicious sessions with high accuracy, but they require extensive resources and time

Engineering Contradiction:
Improvesession classification accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary automated analysis to create meta-sessions and calculate risk scores before manual review. By pre-processing network sessions to extract features, group them into meta-sessions, and rank them by potential maliciousness, the system prepares the data in advance so that analysts can focus immediately on the most suspicious cases without wasting time on preliminary sorting or filtering.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies different levels of analysis intensity to different meta-sessions based on their risk scores. High-scoring meta-sessions receive thorough manual examination, while lower-scoring ones receive less intensive review or automated handling. This localized quality approach ensures measurement precision is applied where most needed while reducing overall analysis time.

Inventive Principle:
Principle #3Local quality

3Productivity

If network security systems use simple indicators for session classification, then they can process sessions quickly, but they produce high false positives and false negatives

Engineering Contradiction:
Improvesession processing speedVSAvoidclassification accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent uses composite feature sets that combine multiple indicators (source IP, destination IP, protocol, ports, timing patterns, data volume) to create meta-sessions. Rather than relying on single simple indicators, the system synthesizes multiple data points into a composite classification that maintains processing speed through automated feature extraction while significantly improving reliability by considering multiple dimensions of session behavior simultaneously.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS10419449B1Aggregating network sessions into meta-sessions for ranking and classification
Publication Date: 2019.09.17 EMC IP HLDG CO LLC
  • US10419449B1 patent drawing
  • US10419449B1 patent drawing
  • US10419449B1 patent drawing

AI summary

A method includes obtaining session data related to a plurality of network sessions, analyzing the session data to identify one or more features of the network sessions, and utilizing the one or more features to aggregate the plurality of network sessions into a plurality of meta-sessions. A meta-session comprises a set of network sessions having similar features. The method also includes selecting a classifier for ranking the meta-sessions based on a scoring function that characterizes performance in ranking meta-sessions having a designated characteristic, ranking the meta-sessions utilizing the selected classifier, providing a designated number of the ranked meta-sessions for additional processing to determine potential maliciousness, and modifying access by client devices to an additional network session responsive to the additional network session comprising session data with features similar to those of one of the designated number of the ranked meta-sessions determined to be potentially malicious.