Private Network Threat Detection Using Host Behavior Baselines
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security devices generate a large number of network threat events, making it difficult for administrators to identify those that require immediate attention due to the increasing complexity and sophistication of network threats.
Innovation Solution
Identify common hosts within a private computer network by their IP and hostname, generate a baseline of their network behavior using a sliding time window, and issue alerts for anomalous events that exceed a risk threshold, thereby prioritizing critical threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network security devices inspect all network traffic to detect threats, then threat detection capability is improved, but the number of false positive threat events increases
Solution Approach 1:
The patent segments the large set of threat events into two categories: common events (matching baseline behavior) and anomalous events (deviating from baseline). This segmentation allows administrators to focus only on the small subset of truly suspicious events, effectively separating signal from noise while maintaining comprehensive detection coverage.
Solution Approach 2:
The system performs preliminary action by establishing baseline behavior profiles for each host before evaluating new threat events. This pre-computed baseline serves as a reference framework that automatically filters out routine threats, allowing the system to proactively identify only those events that warrant administrator attention.
2Reliability
If network security devices declare all detected threat events, then comprehensive threat monitoring is improved, but administrator workload increases
Solution Approach 1:
The patent introduces an intermediary automated analysis layer between threat detection and administrator review. This intermediary system compares each threat event against established baselines and automatically filters out common events, presenting only anomalous events to administrators. This intermediary processing dramatically reduces administrator workload while maintaining comprehensive monitoring coverage.
Solution Approach 2:
The system implements feedback by continuously comparing new threat events against historical baseline data and adjusting its classification accordingly. This feedback mechanism enables the system to learn from patterns over time, automatically adapting to distinguish between routine and suspicious activities, thereby reducing false alarms and administrator burden.
3Measurement precision
If network security devices use sophisticated detection rules, then detection accuracy is improved, but device complexity increases
Solution Approach 1:
The patent applies parameter changes by transforming the detection approach from static rule-based classification to dynamic baseline comparison. Instead of relying on complex predefined rules, the system changes the parameter of evaluation to include historical behavior patterns, frequency metrics, and anomaly scoring. This parameter transformation maintains high detection accuracy while simplifying the operational complexity of the detection system.
Data Source
AI summary
Network threat events are declared in response to detecting network traffic data indicative of network threats in network traffic involving hosts of a private computer network. Common hosts of the private computer network are identified in network threat events that have occurred within a sampling period. For each identified common host, a baseline of network behavior of the common host in network threat events that have occurred within a sliding time window is generated. A new threat event that has occurred after the sliding time window is identified as anomalous by comparing a network behavior of a common host in the new network threat event against the baseline of network behavior of the common host. An alert is issued in response to detecting an anomalous network threat event that has a risk rating that exceeds a threshold risk level.


