Network Threat Assessment via Exposure and Persistence Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity solutions rely heavily on manual scanning and labeled threats, which are subjective and limited, struggling to effectively prioritize and manage unlabeled anomalies detected by anomaly detection algorithms in telecommunication networks.
Innovation Solution
A method that calculates a threat level for network nodes using exposure and persistence scores, derived from network traffic data, anomaly detection, and reputation measures, allowing for automated reconfiguration of network aspects to mitigate threats without relying on manual analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If anomaly detection algorithms are used to detect threats in network traffic, then the ability to identify potential security issues is improved, but the amount of output data increases significantly requiring manual scanning
Solution Approach 1:
The patent extracts and focuses on specific critical attributes from the large volume of anomaly detection output. Instead of analyzing all detected anomalies equally, the system identifies and extracts key features such as exposure score, persistence score, and threat level metrics from the anomaly data, thereby reducing the volume of data requiring manual review while maintaining detection effectiveness
Solution Approach 2:
The patent introduces an intermediary processing layer that sits between the anomaly detection algorithm and manual analysis. This intermediary automatically calculates exposure and persistence scores, and determines threat levels for detected anomalies, serving as a mediator that transforms raw anomaly output into prioritized threat assessments that require less manual intervention
2Measurement precision
If manual scanning and analysis of anomaly detection output is performed, then detailed threat assessment is achieved, but the time and resources required increase significantly
Solution Approach 1:
The patent performs preliminary automated actions before manual analysis is required. Specifically, it pre-calculates exposure scores, persistence scores, and initial threat level assessments for all detected anomalies. This preliminary processing filters and prioritizes anomalies so that manual analysts only need to review pre-assessed high-risk items rather than scanning all anomalies from scratch
Solution Approach 2:
The system enables self-service threat assessment by automatically evaluating anomalies against established criteria for exposure and persistence. The anomaly detection output is automatically enriched with threat level calculations and prioritization metrics, allowing the system to assess itself without requiring extensive manual intervention for each anomaly
3Stability of the object's composition
If reliance on labeled threats is maintained for security assessment, then consistency in threat classification is improved, but the ability to detect and prioritize unlabeled anomalies is reduced
Solution Approach 1:
The patent changes the parameters used for threat assessment from relying solely on predefined threat labels to using calculated metrics such as exposure score, persistence score, and threat level. These parameter changes allow the system to assess both labeled and unlabeled anomalies using a consistent mathematical framework, maintaining classification consistency while expanding detection versatility
Solution Approach 2:
The patent creates a universal threat assessment mechanism that works for both labeled and unlabeled threats. The exposure and persistence scoring system serves multiple functions: it can assess known labeled threats while also evaluating previously unseen unlabeled anomalies, providing a unified approach that enhances both consistency and adaptability across different threat types
Data Source
AI summary
A processing system including at least one processor may obtain network traffic data of a network, including a first set of flow data associated with a first node, determine an anomaly factor of the first node from the network traffic data quantifying a deviation of the first set of flow data from a normal flow data associated with the first node, generate an exposure score of the first node in accordance with a measured influence of the first node in the network and the anomaly factor, generate a persistence score of the first node in accordance with a reputation measure of the first node and a measure of a recurrence of anomalous flow data associated with the first node, calculate a threat level of the first node from the exposure score and the persistence score, and reconfigure at least one aspect of the network in response to the threat level.


