Network Threat Assessment via Exposure and Persistence Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity solutions rely heavily on manual scanning and labeled threats, which are subjective and limited, struggling to effectively prioritize and manage unlabeled anomalies detected by anomaly detection algorithms in telecommunication networks.

Innovation Solution

A method that calculates a threat level for network nodes using exposure and persistence scores, derived from network traffic data, anomaly detection, and reputation measures, allowing for automated reconfiguration of network aspects to mitigate threats without relying on manual analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If anomaly detection algorithms are used to detect threats in network traffic, then the ability to identify potential security issues is improved, but the amount of output data increases significantly requiring manual scanning

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidoutput data volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts and focuses on specific critical attributes from the large volume of anomaly detection output. Instead of analyzing all detected anomalies equally, the system identifies and extracts key features such as exposure score, persistence score, and threat level metrics from the anomaly data, thereby reducing the volume of data requiring manual review while maintaining detection effectiveness

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary processing layer that sits between the anomaly detection algorithm and manual analysis. This intermediary automatically calculates exposure and persistence scores, and determines threat levels for detected anomalies, serving as a mediator that transforms raw anomaly output into prioritized threat assessments that require less manual intervention

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If manual scanning and analysis of anomaly detection output is performed, then detailed threat assessment is achieved, but the time and resources required increase significantly

Engineering Contradiction:
Improvethreat assessment qualityVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary automated actions before manual analysis is required. Specifically, it pre-calculates exposure scores, persistence scores, and initial threat level assessments for all detected anomalies. This preliminary processing filters and prioritizes anomalies so that manual analysts only need to review pre-assessed high-risk items rather than scanning all anomalies from scratch

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service threat assessment by automatically evaluating anomalies against established criteria for exposure and persistence. The anomaly detection output is automatically enriched with threat level calculations and prioritization metrics, allowing the system to assess itself without requiring extensive manual intervention for each anomaly

Inventive Principle:
Principle #25Self-service

3Stability of the object's composition

If reliance on labeled threats is maintained for security assessment, then consistency in threat classification is improved, but the ability to detect and prioritize unlabeled anomalies is reduced

Engineering Contradiction:
Improvethreat classification consistencyVSAvoidunlabeled threat detection capability
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The patent changes the parameters used for threat assessment from relying solely on predefined threat labels to using calculated metrics such as exposure score, persistence score, and threat level. These parameter changes allow the system to assess both labeled and unlabeled anomalies using a consistent mathematical framework, maintaining classification consistency while expanding detection versatility

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates a universal threat assessment mechanism that works for both labeled and unlabeled threats. The exposure and persistence scoring system serves multiple functions: it can assess known labeled threats while also evaluating previously unseen unlabeled anomalies, providing a unified approach that enhances both consistency and adaptability across different threat types

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10958677B2Risk identification for unlabeled threats in network traffic
Publication Date: 2021.03.23 AT&T INTELLECTUAL PROPERTY I L P
  • US10958677B2 patent drawing
  • US10958677B2 patent drawing
  • US10958677B2 patent drawing

AI summary

A processing system including at least one processor may obtain network traffic data of a network, including a first set of flow data associated with a first node, determine an anomaly factor of the first node from the network traffic data quantifying a deviation of the first set of flow data from a normal flow data associated with the first node, generate an exposure score of the first node in accordance with a measured influence of the first node in the network and the anomaly factor, generate a persistence score of the first node in accordance with a reputation measure of the first node and a measure of a recurrence of anomalous flow data associated with the first node, calculate a threat level of the first node from the exposure score and the persistence score, and reconfigure at least one aspect of the network in response to the threat level.