Non-rule Security Detection via Baseline Anomaly Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security systems rely on rules-based correlation methods for detecting intrusions, which are limited in their ability to quickly and accurately identify threats, and fail to provide full context for incident resolution.

Innovation Solution

A non-rule based security detection system that generates baselines for data sources, detects anomalies, and correlates them with geolocation to identify security events, enabling rapid incident resolution and threat context without relying on predefined rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If rules-based correlation methods are used for detecting intrusions, then the system can identify known threat patterns, but the system fails to provide full context for incident resolution and cannot quickly identify new threats

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidcontext information for incident resolution
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent combines multiple data sources including network traffic data, host-based security data, endpoint data, and threat intelligence into a unified security analytics platform. This merging of diverse data sources provides comprehensive context for incident resolution while maintaining accurate threat detection capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security analytics platform performs multiple functions including anomaly detection, threat detection, incident correlation, and context provision through a single integrated system. This multi-functional approach eliminates the need for separate rules-based systems while providing both accurate detection and comprehensive context.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional security systems use predefined rules to correlate events, then the system can detect known intrusion patterns, but the system cannot adapt to new threats and requires manual rule updates

Engineering Contradiction:
Improvedetection of known threatsVSAvoidresponse to new threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system uses dynamic anomaly detection that continuously learns normal behavior patterns and adapts to new threats without requiring manual rule updates. The machine learning models are trained on historical data and automatically adjust to detect both known and emerging threat patterns, providing both reliability for known threats and adaptability for new threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security analytics platform performs self-learning through automated anomaly detection and threat identification without requiring manual intervention for rule creation or updates. The system automatically correlates events, identifies patterns, and adapts to new threat landscapes, eliminating the need for manual rule maintenance while maintaining reliable detection.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If multiple data sources are analyzed continuously for anomaly detection, then the system can provide comprehensive security monitoring, but the system complexity increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidsystem architecture complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the security analytics system into distinct functional modules including data collection components, baseline generation components, anomaly detection components, and correlation components. Each module processes specific data types and performs dedicated functions, making the complex system manageable while maintaining comprehensive multi-source analysis capabilities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10601844B2Non-rule based security risk detection
Publication Date: 2020.03.24 GUAVUS INC
  • US10601844B2 patent drawing
  • US10601844B2 patent drawing
  • US10601844B2 patent drawing

AI summary

A non-rule based security detection system and method is described. The method includes identifying a plurality of data sources. The method then proceeds to generate a baseline for each data source. The baseline includes a plurality of data source outputs that are evaluated over a time period. A plurality of data source anomalies are detected, in which each data source anomaly is associated with at least one data source output exceeding a threshold for the data source baseline. A geolocation for each data source anomaly is then identified. A plurality of correlations between the plurality of data source anomalies and the geolocation for each data source anomaly are generated. At least one correlation is associated with a security event.