Neural Network Threat Detection via Constrained Weights

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies lack automation in analyzing and understanding network/endpoint/cloud threats, requiring extensive human analytics for discovering relevant behavioral definitions and concrete threat combinations.

Innovation Solution

A neural network-based model is trained using constrained weights and pre-defined neurons to represent known behaviors, allowing for the automation of learning malicious behavior vocabulary and threat detection through behavioral matching.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If human analytics are used to discover behavioral definitions and threat combinations, then detection accuracy can be maintained, but productivity and automation level are reduced

Engineering Contradiction:
Improveautomation of threat detectionVSAvoidspeed of threat analysis
Core Design Contradiction:
Extent of automationVSProductivity

Solution Approach 1:

The system performs self-service by automatically learning malicious behavior vocabulary and detecting threats through behavioral matching, eliminating the need for human analysts to manually define behaviors or identify threat patterns. The neural network autonomously processes network data, learns from observed behaviors, and generates threat detections without human intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical human analytics process with an automated neural network-based system. Instead of human experts manually analyzing network behaviors and defining threats, the system uses machine learning algorithms to automatically discover behavioral patterns and generate threat detections, substituting human cognitive processes with computational mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If extensive human analytics are performed for discovering behavioral definitions, then detection precision is improved, but loss of time increases

Engineering Contradiction:
Improvedetection precisionVSAvoidtime for behavior discovery
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-defining a set of neurons to represent known behaviors before the main detection process. This allows the neural network to start with a foundation of recognized behavioral patterns and efficiently learn new malicious behaviors without requiring time-consuming manual definition of all possible behaviors from scratch.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the time-consuming manual process of human analysts defining behavioral definitions with an automated neural network that learns behaviors automatically from network data. The system processes and learns malicious behavior patterns much faster than human analysts could manually define them, significantly reducing the time loss while maintaining detection precision.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If manual analysis of network threats is performed, then explainability of behaviors is maintained, but device complexity and operational burden increase

Engineering Contradiction:
Improveease of threat detectionVSAvoidcomplexity of analysis system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system eliminates operational burden by performing self-service threat detection automatically. The neural network autonomously processes network data, learns malicious behaviors, and generates detections without requiring human operators to manually analyze networks or interpret complex behavioral definitions, significantly easing operation while managing system complexity internally.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250030703A1Learning of malicious behavior vocabulary and threat detection through behavior matching
Publication Date: 2025.01.23 CISCO TECHNOLOGY INC
  • US20250030703A1 patent drawing
  • US20250030703A1 patent drawing
  • US20250030703A1 patent drawing

AI summary

In one embodiment, a device obtains input features for a neural network-based model. The device pre-defines a set of neurons of the model to represent known behaviors associated with the input features. The device constrains weights for a plurality of outputs of the model. The device trains the neural network-based model using the constrained weights for the plurality of outputs of the model and by excluding the pre-defined set of neurons from updates during the training.