Neural Network Threat Detection via Constrained Weights
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies lack automation in analyzing and understanding network/endpoint/cloud threats, requiring extensive human analytics for discovering relevant behavioral definitions and concrete threat combinations.
Innovation Solution
A neural network-based model is trained using constrained weights and pre-defined neurons to represent known behaviors, allowing for the automation of learning malicious behavior vocabulary and threat detection through behavioral matching.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If human analytics are used to discover behavioral definitions and threat combinations, then detection accuracy can be maintained, but productivity and automation level are reduced
Solution Approach 1:
The system performs self-service by automatically learning malicious behavior vocabulary and detecting threats through behavioral matching, eliminating the need for human analysts to manually define behaviors or identify threat patterns. The neural network autonomously processes network data, learns from observed behaviors, and generates threat detections without human intervention.
Solution Approach 2:
The patent replaces the mechanical human analytics process with an automated neural network-based system. Instead of human experts manually analyzing network behaviors and defining threats, the system uses machine learning algorithms to automatically discover behavioral patterns and generate threat detections, substituting human cognitive processes with computational mechanisms.
2Measurement precision
If extensive human analytics are performed for discovering behavioral definitions, then detection precision is improved, but loss of time increases
Solution Approach 1:
The system performs preliminary action by pre-defining a set of neurons to represent known behaviors before the main detection process. This allows the neural network to start with a foundation of recognized behavioral patterns and efficiently learn new malicious behaviors without requiring time-consuming manual definition of all possible behaviors from scratch.
Solution Approach 2:
The patent replaces the time-consuming manual process of human analysts defining behavioral definitions with an automated neural network that learns behaviors automatically from network data. The system processes and learns malicious behavior patterns much faster than human analysts could manually define them, significantly reducing the time loss while maintaining detection precision.
3Ease of operation
If manual analysis of network threats is performed, then explainability of behaviors is maintained, but device complexity and operational burden increase
Solution Approach 1:
The system eliminates operational burden by performing self-service threat detection automatically. The neural network autonomously processes network data, learns malicious behaviors, and generates detections without requiring human operators to manually analyze networks or interpret complex behavioral definitions, significantly easing operation while managing system complexity internally.
Data Source
AI summary
In one embodiment, a device obtains input features for a neural network-based model. The device pre-defines a set of neurons of the model to represent known behaviors associated with the input features. The device constrains weights for a plurality of outputs of the model. The device trains the neural network-based model using the constrained weights for the plurality of outputs of the model and by excluding the pre-defined set of neurons from updates during the training.


