Outlier Detection for Dynamic Threat Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity infrastructure relies on simplistic, static rules and signatures that are backward-looking, making it ineffective in detecting new or evolving threats to enterprise or e-commerce systems, leading to increased breaches and fraud, as it cannot identify malicious usage that circumvents firewalls and rules.

Innovation Solution

A method and apparatus employing outlier score detection using statistical models to identify statistical outliers from dynamic data sources, which involves grouping log lines, extracting features, and applying multi-dimensional statistical analysis to detect scenario-specific data elements, such as threats, through a combination of outlier detection modules with varying robustness properties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static rules and signatures are used for threat detection, then the system is simple to implement and operate, but it cannot detect new or evolving threats that circumvent firewalls

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidability to detect evolving threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms static security rules into dynamic statistical models that continuously adapt to new threat patterns. The system uses multivariate statistical analysis that evolves with incoming data, allowing detection of novel threats without requiring pre-defined signatures for each threat type.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes from fixed threshold-based detection to dynamic parameter-based detection using statistical distributions. By modeling normal behavior with multivariate statistics and detecting deviations from these models, the system adapts to evolving threats through parameter adjustments rather than rule updates.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multivariate statistical analysis is applied to detect outliers, then the ability to detect scenario-specific threats improves, but the computational complexity and processing time increase

Engineering Contradiction:
Improveoutlier detection accuracyVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex multivariate analysis into manageable components: feature extraction from log lines, construction of feature tables, application of statistical models to identify outliers, and separate handling of different log line parameters. This segmentation reduces computational complexity while maintaining detection accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies statistical analysis selectively to extracted features rather than processing all raw data. By focusing computational resources on relevant features identified through extraction and grouping, the system achieves effective outlier detection without the full computational burden of analyzing every data point in detail.

Inventive Principle:
Principle #16Partial or excessive action

3Speed

If real-time processing of incoming data traffic is performed, then the speed of threat detection improves, but the loss of information increases due to potential sampling or aggregation

Engineering Contradiction:
Improvereal-time detection speedVSAvoiddata detail loss
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The patent extracts relevant features from grouped log lines while preserving the essential information needed for outlier detection. By selectively extracting meaningful features rather than processing or discarding raw data, the system maintains detection accuracy while enabling real-time processing speeds.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The feature extraction process creates a universal representation that serves multiple detection purposes simultaneously. The extracted features capture essential patterns that can be analyzed for various types of threats without requiring separate processing paths, thus preventing information loss while maintaining real-time capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10264027B2Computer-implemented process and system employing outlier score detection for identifying and detecting scenario-specific data elements from a dynamic data source
Publication Date: 2019.04.16 CORELIGHT INC
  • US10264027B2 patent drawing
  • US10264027B2 patent drawing
  • US10264027B2 patent drawing

AI summary

Methods and apparatuses employing outlier score detection method and apparatus for identifying and detecting threats to an enterprise or e-commerce system are disclosed, including grouping log lines belonging to one or more log line parameters from one or more enterprise or e-commerce system data sources and/or from incoming data traffic to the enterprise or e-commerce system; extracting one or more features from the grouped log lines into one or more features tables; using one or more statistical models on the one or more features tables to identify statistical outliers; using the one or more features tables to create one or more rules for identifying threats to the enterprise or e-commerce system; and using the one or more rules on incoming enterprise or e-commerce system data traffic to detect threats to the enterprise or e-commerce system. Other embodiments are described and claimed.