Network Traffic Analysis System for False Alarm Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to reliably differentiate between targeted and omnidirectional network traffic, leading to excessive false alarms for security analysts, as both types of traffic can exhibit similar behaviors, resulting in wasted time reviewing insignificant security alerts.

Innovation Solution

A system comprising distributed network nodes that collect mass scanning network traffic data and generate an omnidirectional network traffic database, allowing for the filtration of omnidirectional traffic and prioritization of targeted traffic, using contextual information to distinguish between the two.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current systems monitor all network traffic without differentiation, then comprehensive security monitoring is achieved, but false alarms increase significantly

Engineering Contradiction:
Improvesecurity monitoring accuracyVSAvoidtime spent reviewing false alarms
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments network traffic into two distinct categories: omnidirectional traffic (mass scanning) and targeted traffic. By creating separate processing paths and criteria for each type, the system avoids treating all traffic uniformly, thereby reducing false alarms while maintaining comprehensive monitoring coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary classification mechanism that acts as a mediator between raw network traffic and security alert generation. This intermediary layer analyzes traffic characteristics and determines whether to generate alerts, preventing direct false alarm generation from omnidirectional traffic while maintaining security monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all network scanning traffic is treated as potential threats, then security coverage is maximized, but analyst productivity decreases

Engineering Contradiction:
Improvesecurity coverageVSAvoidanalyst efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments alert processing into two streams: one for omnidirectional traffic (automatically suppressed or deprioritized) and one for targeted traffic (flagged for analyst review). This segmentation maintains comprehensive security coverage while directing analyst attention only to high-value threats, thereby improving productivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different quality levels of analysis to different types of traffic. Omnidirectional traffic receives automated classification and lower-priority handling, while targeted traffic receives full analytical scrutiny. This local differentiation optimizes resource allocation and analyst productivity without compromising overall security coverage.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If contextual information is collected from distributed network nodes, then traffic differentiation accuracy improves, but system complexity increases

Engineering Contradiction:
Improvetraffic differentiation accuracyVSAvoidsystem architecture complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal classification framework that can process traffic data from multiple distributed network nodes using the same omnidirectional/targeted criteria. This multi-functional system handles geographically distributed data collection, processing, and classification through a unified approach, managing complexity through standardization rather than increasing it.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses copying of the classification logic across multiple network nodes, where each node implements the same omnidirectional/targeted traffic differentiation algorithms. This replication of classification capability at the edge enables accurate local differentiation while centralizing the overall system architecture, managing complexity through distributed uniformity.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10659335B1Contextual analyses of network traffic
Publication Date: 2020.05.19 GREYNOISE INTELLIGENCE INC
  • US10659335B1 patent drawing
  • US10659335B1 patent drawing
  • US10659335B1 patent drawing

AI summary

Systems and methods for analyzing network traffic are provided. An exemplary system may include a plurality of network nodes distributed in multiple geographical regions. The plurality of network nodes may be configured to collect mass scanning network traffic data. The system may also include at least one processor configured to receive, from the plurality of network nodes, the collected mass scanning network traffic data. The processor may also be configured to generate an omnidirectional network traffic database based on the received mass scanning network traffic data. The processor may further be configured to receive a query against the omnidirectional network traffic database. The query may include information of a source of a network scanning activity. Moreover, the processor may be configured to determine whether the source matches any record in the omnidirectional network traffic database and generate an indication based on the determination.