Parameter Identification for Cybersecurity Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Monitoring systems face challenges in identifying anomalous data due to the difficulty in determining which monitoring parameters are necessary for anomaly detection, leading to excessive resource usage from storing large amounts of data, where some data may not be useful for identifying cybersecurity events or other issues.
Innovation Solution
A system that uses a parameter identification system to determine auxiliary features within datasets, which segregates data based on computer name and folder name, allowing for anomaly detection and alert condition identification by inputting the target feature and auxiliary features into a machine learning model to segment and aggregate data into timeseries datasets for anomaly detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If enterprises store as much data as possible for later review, then the ability to identify cybersecurity events is improved, but excessive computing resources are consumed for storage
Solution Approach 1:
The patent extracts and stores only the essential features and auxiliary features needed for anomaly detection, rather than storing all raw monitoring data. The parameter identification system identifies and retains only the critical parameters required for detecting cybersecurity events, discarding redundant data while maintaining detection capability.
Solution Approach 2:
The patent segments the monitoring data into essential features and auxiliary features that are necessary for anomaly detection. By dividing the data into these specific components and storing only them, the system reduces overall storage requirements while preserving the ability to identify cybersecurity events through anomaly detection algorithms.
2Loss of information
If enterprises store all collected data to avoid losing vital information, then data completeness is improved, but resource usage increases excessively
Solution Approach 1:
The parameter identification system extracts only the critical parameters and auxiliary features necessary for anomaly detection, storing them in a compressed format. This extraction process eliminates redundant data while ensuring that all information needed for detecting cybersecurity events is preserved, thus reducing storage requirements without compromising detection completeness.
Solution Approach 2:
The patent transforms raw monitoring data into a reduced set of parameters and auxiliary features that capture the essential characteristics needed for anomaly detection. By changing the data representation from raw comprehensive data to processed parameter sets, the system maintains information completeness for security event identification while significantly reducing storage resource consumption.
3Measurement precision
If monitoring systems collect all monitoring parameters, then the ability to detect anomalies is improved, but device complexity increases
Solution Approach 1:
The parameter identification system extracts only the essential features and auxiliary features required for accurate anomaly detection, eliminating unnecessary monitoring parameters. This extraction reduces the complexity of the monitoring system by focusing on a minimal sufficient set of parameters while maintaining the precision needed to detect cybersecurity events effectively.
Solution Approach 2:
The patent segments the monitoring parameters into essential features and auxiliary features, organizing them into a structured format that simplifies processing. This segmentation reduces system complexity by clearly defining which parameters are necessary for anomaly detection and how they should be processed, while preserving the measurement precision required for accurate security event identification.
Data Source
AI summary
Methods and systems are described herein for determining auxiliary parameters within datasets, the auxiliary parameters being used to segregate the datasets such that anomaly detection may be performed on the segregated datasets. Based on anomaly detection, alert conditions may then be identified. In particular, a system may, using a machine learning model, determine for a particular target feature (e.g., a parameter being monitored) one or more auxiliary features (other parameters) that effect the values of that parameter and transmit the target feature and the auxiliary features in a message to a monitoring system indicating which features to monitor. The collected data may then be received by the system and transformed into a timeseries dataset, which may then be used to detect anomalies within the data and thereby identify any anomalous points.


