Network Threat Detection Using Machine Learning Anomaly Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cybersecurity solutions fail to effectively detect and prioritize network threats, particularly from insider actors, as they do not utilize machine learning models to differentiate normal from abnormal entity metric behavior, leading to incomplete threat assessment and missed security issues.
Innovation Solution
A system employing machine learning models to calculate anomaly scores for observed metric values, aggregating these scores to determine threat scores for entities, and generating a security threat presentation that identifies high-scoring entities, providing detailed information on their threat levels and behaviors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional cybersecurity solutions are used to monitor network threats, then basic threat detection is maintained, but the ability to differentiate normal from abnormal entity metric behavior is insufficient, leading to incomplete threat assessment
Solution Approach 1:
The patent replaces conventional rule-based cybersecurity detection mechanisms with machine learning models that automatically learn and adapt to normal entity metric behavior patterns. These ML models analyze multiple metrics simultaneously to generate anomaly scores, enabling precise differentiation between normal and abnormal behavior without manual rule configuration, thereby improving detection accuracy and preventing information loss in threat assessment
Solution Approach 2:
The system transforms static threshold-based threat detection into dynamic anomaly scoring by continuously analyzing entity metric behavior across multiple parameters. Machine learning models evaluate changes in various metrics (network traffic patterns, access behaviors, resource utilization) to generate composite anomaly scores, allowing the system to adapt to evolving threat patterns and provide comprehensive threat assessment without losing critical information
2Measurement precision
If machine learning models are implemented to calculate anomaly scores for each metric, then threat detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent divides the complex threat detection system into modular components: individual machine learning models are trained and deployed for each specific metric (network traffic, access patterns, resource usage). Each model independently calculates anomaly scores for its designated metric, and these scores are then aggregated to form overall threat assessments. This segmentation reduces system complexity by making each component manageable and independently deployable while maintaining high detection accuracy
Solution Approach 2:
The system employs a universal machine learning framework that can be applied across multiple different metrics and entity types. The same anomaly detection methodology and scoring mechanism work consistently for various metrics (network traffic, file access, authentication patterns), eliminating the need for completely separate systems for each metric and reducing overall system complexity while maintaining accuracy
3Reliability
If multiple metrics are monitored and aggregated into threat scores for each entity, then comprehensive threat prioritization is achieved, but processing time and computational resources increase
Solution Approach 1:
The system performs preliminary actions by pre-training machine learning models offline using historical entity metric data before deployment. During runtime, the pre-trained models can quickly calculate anomaly scores for new metrics without requiring extensive real-time computation. This preliminary training phase separates the computationally intensive learning process from the time-critical detection process, enabling reliable threat prioritization across multiple metrics while minimizing processing time delays
Solution Approach 2:
The patent merges multiple individual anomaly scores from different metrics into a single aggregated threat score for each entity. By combining the outputs of multiple ML models into one comprehensive threat score, the system achieves reliable threat prioritization that considers all monitored metrics simultaneously, while avoiding the need to process and analyze each metric separately in real-time, thus reducing overall processing time
Data Source
AI summary
System and methods for determining network threats are disclosed. For each entity operating in a network being monitored for network security, an example method obtains an observed metric value for each metric that characterizes actions performed by the entity. Each observed metric value may be input into a machine learning model that is specific to the metric in order to determine an anomaly score for the observed metric value that represents how anomalous the observed metric value is relative to an expected metric value for the metric. A threat score may then be determined for each entity from the anomaly scores for each metric. A security threat presentation that identifies one or more high-scoring entities according to the threat scores may be generated and provided for display on a user device.


