Network Traffic Clustering for Malicious Activity Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise networks face challenges in optimizing network performance due to mixed business and non-business critical traffic using the same protocols, and in distinguishing and prioritizing malicious network traffic, such as DoS attacks and malware propagation, which is cumbersome and inefficient.
Innovation Solution
A device analyzes network traffic data using clustering and machine learning to identify behavioral clusters, calculates rankings by comparing to malicious addresses, and aggregates these rankings to prioritize investigation targets, providing data for supervisor review based on final rankings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deep assessment of each network entity is performed to identify malicious traffic, then detection precision is improved, but device complexity and loss of time increase significantly
Solution Approach 1:
The patent segments the network entities into clusters based on behavioral characteristics rather than assessing each entity individually. This clustering approach divides the large set of network entities into smaller, manageable groups that share similar traffic patterns, reducing the complexity of assessment while maintaining detection precision through group-based analysis.
Solution Approach 2:
The system performs preliminary clustering and ranking actions before detailed assessment. By pre-grouping network entities into behavioral clusters and calculating preliminary rankings based on cluster characteristics, the system reduces the scope of subsequent detailed assessments, thereby reducing device complexity and processing time while preserving detection accuracy.
2Measurement precision
If deep assessment of each network entity is performed to identify malicious traffic, then detection precision is improved, but loss of time increases significantly
Solution Approach 1:
The patent segments the network entities into clusters based on behavioral characteristics rather than assessing each entity individually. This clustering approach divides the large set of network entities into smaller, manageable groups that share similar traffic patterns, reducing the complexity of assessment while maintaining detection precision through group-based analysis.
Solution Approach 2:
The system performs preliminary clustering and ranking actions before detailed assessment. By pre-grouping network entities into behavioral clusters and calculating preliminary rankings based on cluster characteristics, the system reduces the scope of subsequent detailed assessments, thereby reducing device complexity and processing time while preserving detection accuracy.
3Measurement precision
If manual analysis of malicious traffic is performed, then detection precision is improved, but productivity decreases
Solution Approach 1:
The system performs automated clustering and ranking operations without requiring manual intervention for each network entity. The automated system groups entities by behavioral characteristics and calculates rankings based on comparisons with malicious address sets, maintaining detection precision while significantly improving productivity by eliminating manual analysis bottlenecks.
Solution Approach 2:
The patent replaces manual mechanical analysis with automated computational methods. By using algorithms to perform clustering, comparison with malicious address sets, and ranking calculations, the system maintains detection precision while dramatically improving productivity through automated processing of network entities.
4Productivity
If optimization is applied to all traffic flows using the same protocol, then productivity is improved, but measurement precision decreases
Solution Approach 1:
The patent applies different optimization treatments to different clusters of traffic flows based on their behavioral characteristics. Instead of uniform optimization for all flows using the same protocol, the system identifies distinct behavioral patterns and applies targeted optimization strategies to each cluster, thereby maintaining measurement precision while improving overall productivity through differentiated treatment.
Data Source
AI summary
In one embodiment, a device analyzes network traffic data using a clustering process, to identify a cluster of addresses associated with the network traffic data for which the associated network traffic has similar behavioral characteristics. The device calculates a set of rankings for the cluster by comparing the cluster to different sets of malicious addresses. The device aggregates the set of rankings into a final ranking by setting the rankings in the set as current rankings and iteratively calculating an average of any subset of the current rankings that comprises correlated rankings. The calculated average replaces the rankings in the subset as a current ranking. When none of the current rankings are correlated, the device performs an aggregation across all of the current rankings to form the final ranking. The device provides data indicative of the cluster for review by a supervisor, based on the final ranking.


