Peer-Based Host Anomaly Detection in Enterprise Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face challenges in detecting anomalous behavior effectively due to their large size and dynamic nature, which existing monitoring systems struggle to address, especially in identifying anomalies in host behavior that deviate from historical profiles.

Innovation Solution

A system that models host behavior based on historical events, identifies peer hosts with similar behavior profiles, and calculates an anomaly score using a processor to determine the risk level of a host, enabling unsupervised anomaly detection and triggering security management actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional monitoring systems are used to detect anomalous behavior in enterprise networks, then system coverage is achieved, but detection precision deteriorates due to the large size and dynamic nature of enterprise networks

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidnetwork monitoring complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the enterprise network into multiple monitoring zones or domains, each with its own anomaly detection subsystem. Instead of monitoring the entire network as a single complex system, the network is divided into smaller manageable segments that can be analyzed independently, improving detection precision while reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local anomaly detection capabilities at distributed monitoring points throughout the network, allowing each segment to analyze behavior patterns specific to its local context. This local quality approach enables precise detection of anomalies relevant to each network segment without being overwhelmed by global network complexity.

Inventive Principle:
Principle #3Local quality

2Reliability

If comprehensive host behavior monitoring is implemented, then anomaly detection capability is improved, but system resource consumption increases

Engineering Contradiction:
Improvesecurity detection reliabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent establishes baseline behavior profiles for hosts in advance by analyzing historical data and normal operation patterns. These pre-computed baselines are stored and reused for anomaly detection, avoiding the need to re-analyze entire historical datasets for each detection event, thus reducing computational resource consumption while maintaining reliable anomaly detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements monitoring that focuses on critical behavior parameters and high-risk activities rather than attempting to capture and analyze every single host event. By selectively monitoring only the most significant behavior aspects, the system achieves reliable security detection with reduced computational overhead.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of time

If real-time anomaly detection is implemented in large networks, then security response time is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity response timeVSAvoiddetection system complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent extracts and isolates the anomaly detection logic from the overall network management system, creating a dedicated, specialized detection module. This extraction allows real-time anomaly detection to be implemented with focused computational resources on detection algorithms, reducing the complexity burden on the broader network management infrastructure while maintaining fast security response times.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10367842B2Peer-based abnormal host detection for enterprise security systems
Publication Date: 2019.07.30 CLOUD BYTE LLC
  • US10367842B2 patent drawing
  • US10367842B2 patent drawing
  • US10367842B2 patent drawing

AI summary

Systems and methods for determining a risk level of a host in a network include modeling a target host's behavior based on historical events recorded at the target host. One or more original peer hosts having behavior similar to the target host's behavior are determined. An anomaly score for the target host is determined based on how the target host's behavior changes relative to behavior of the one or more original peer hosts over time. A security management action is performed based on the anomaly score.