Private Network Threat Detection Using Host Behavior Baselines

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security devices generate a large number of network threat events, making it difficult for administrators to identify those that require immediate attention due to the increasing complexity and sophistication of network threats.

Innovation Solution

Identify common hosts within a private computer network by their IP and hostname, generate a baseline of their network behavior using a sliding time window, and issue alerts for anomalous events that exceed a risk threshold, thereby prioritizing critical threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security devices inspect all network traffic to detect threats, then threat detection capability is improved, but the number of false positive threat events increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsignal-to-noise ratio
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the large set of threat events into two categories: common events (matching baseline behavior) and anomalous events (deviating from baseline). This segmentation allows administrators to focus only on the small subset of truly suspicious events, effectively separating signal from noise while maintaining comprehensive detection coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by establishing baseline behavior profiles for each host before evaluating new threat events. This pre-computed baseline serves as a reference framework that automatically filters out routine threats, allowing the system to proactively identify only those events that warrant administrator attention.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If network security devices declare all detected threat events, then comprehensive threat monitoring is improved, but administrator workload increases

Engineering Contradiction:
Improvethreat monitoring coverageVSAvoidadministrator analysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an intermediary automated analysis layer between threat detection and administrator review. This intermediary system compares each threat event against established baselines and automatically filters out common events, presenting only anomalous events to administrators. This intermediary processing dramatically reduces administrator workload while maintaining comprehensive monitoring coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback by continuously comparing new threat events against historical baseline data and adjusting its classification accordingly. This feedback mechanism enables the system to learn from patterns over time, automatically adapting to distinguish between routine and suspicious activities, thereby reducing false alarms and administrator burden.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If network security devices use sophisticated detection rules, then detection accuracy is improved, but device complexity increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by transforming the detection approach from static rule-based classification to dynamic baseline comparison. Instead of relying on complex predefined rules, the system changes the parameter of evaluation to include historical behavior patterns, frequency metrics, and anomaly scoring. This parameter transformation maintains high detection accuracy while simplifying the operational complexity of the detection system.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12432238B1System and method for identifying anomalous network threat events that occur in a private computer network
Publication Date: 2025.09.30 TREND MICRO INC
  • US12432238B1 patent drawing
  • US12432238B1 patent drawing
  • US12432238B1 patent drawing

AI summary

Network threat events are declared in response to detecting network traffic data indicative of network threats in network traffic involving hosts of a private computer network. Common hosts of the private computer network are identified in network threat events that have occurred within a sampling period. For each identified common host, a baseline of network behavior of the common host in network threat events that have occurred within a sliding time window is generated. A new threat event that has occurred after the sliding time window is identified as anomalous by comparing a network behavior of a common host in the new network threat event against the baseline of network behavior of the common host. An alert is issued in response to detecting an anomalous network threat event that has a risk rating that exceeds a threshold risk level.