Network Traffic Clustering for Malicious Activity Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face challenges in optimizing network performance due to mixed business and non-business critical traffic using the same protocols, and in distinguishing and prioritizing malicious network traffic, such as DoS attacks and malware propagation, which is cumbersome and inefficient.

Innovation Solution

A device analyzes network traffic data using clustering and machine learning to identify behavioral clusters, calculates rankings by comparing to malicious addresses, and aggregates these rankings to prioritize investigation targets, providing data for supervisor review based on final rankings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep assessment of each network entity is performed to identify malicious traffic, then detection precision is improved, but device complexity and loss of time increase significantly

Engineering Contradiction:
Improvedetection precisionVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the network entities into clusters based on behavioral characteristics rather than assessing each entity individually. This clustering approach divides the large set of network entities into smaller, manageable groups that share similar traffic patterns, reducing the complexity of assessment while maintaining detection precision through group-based analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary clustering and ranking actions before detailed assessment. By pre-grouping network entities into behavioral clusters and calculating preliminary rankings based on cluster characteristics, the system reduces the scope of subsequent detailed assessments, thereby reducing device complexity and processing time while preserving detection accuracy.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If deep assessment of each network entity is performed to identify malicious traffic, then detection precision is improved, but loss of time increases significantly

Engineering Contradiction:
Improvedetection precisionVSAvoidloss of time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the network entities into clusters based on behavioral characteristics rather than assessing each entity individually. This clustering approach divides the large set of network entities into smaller, manageable groups that share similar traffic patterns, reducing the complexity of assessment while maintaining detection precision through group-based analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary clustering and ranking actions before detailed assessment. By pre-grouping network entities into behavioral clusters and calculating preliminary rankings based on cluster characteristics, the system reduces the scope of subsequent detailed assessments, thereby reducing device complexity and processing time while preserving detection accuracy.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If manual analysis of malicious traffic is performed, then detection precision is improved, but productivity decreases

Engineering Contradiction:
Improvedetection precisionVSAvoidproductivity
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system performs automated clustering and ranking operations without requiring manual intervention for each network entity. The automated system groups entities by behavioral characteristics and calculates rankings based on comparisons with malicious address sets, maintaining detection precision while significantly improving productivity by eliminating manual analysis bottlenecks.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical analysis with automated computational methods. By using algorithms to perform clustering, comparison with malicious address sets, and ranking calculations, the system maintains detection precision while dramatically improving productivity through automated processing of network entities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Productivity

If optimization is applied to all traffic flows using the same protocol, then productivity is improved, but measurement precision decreases

Engineering Contradiction:
ImproveproductivityVSAvoidmeasurement precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent applies different optimization treatments to different clusters of traffic flows based on their behavioral characteristics. Instead of uniform optimization for all flows using the same protocol, the system identifies distinct behavioral patterns and applies targeted optimization strategies to each cluster, thereby maintaining measurement precision while improving overall productivity through differentiated treatment.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10904271B2Active prioritization of investigation targets in network security
Publication Date: 2021.01.26 CISCO TECHNOLOGY INC
  • US10904271B2 patent drawing
  • US10904271B2 patent drawing
  • US10904271B2 patent drawing

AI summary

In one embodiment, a device analyzes network traffic data using a clustering process, to identify a cluster of addresses associated with the network traffic data for which the associated network traffic has similar behavioral characteristics. The device calculates a set of rankings for the cluster by comparing the cluster to different sets of malicious addresses. The device aggregates the set of rankings into a final ranking by setting the rankings in the set as current rankings and iteratively calculating an average of any subset of the current rankings that comprises correlated rankings. The calculated average replaces the rankings in the subset as a current ranking. When none of the current rankings are correlated, the device performs an aggregation across all of the current rankings to form the final ranking. The device provides data indicative of the cluster for review by a supervisor, based on the final ranking.