Privileged Analytics System for Network Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional signature-based security systems fail to accurately detect modern cyber-attacks on organizational networks due to their reliance on previously discovered vulnerabilities, resulting in low detection rates and high false alarm rates.

Innovation Solution

A computer-implemented method that identifies behavioral anomalies on a network by building and analyzing behavioral profiles using statistical and rule-based analytics, classifying anomalies as system events, and updating system status scores to determine potential network compromise, with optional user feedback for verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If signature-based security methods are used to detect cyber-attacks, then the detection process is simple and fast, but the detection accuracy is low and false alarm rate is high

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements dynamic behavioral profiling that continuously adapts to changing network conditions and user behaviors. The system maintains evolving profiles of normal behavior patterns and dynamically compares current activities against these profiles, allowing the detection mechanism to adapt over time rather than relying on static signatures. This resolves the contradiction by making the system complex enough to achieve high accuracy through adaptive learning, while the dynamic nature allows it to remain responsive to new threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the fundamental parameter of detection from signature matching to behavioral parameter analysis. Instead of checking for known attack signatures, the system monitors multiple behavioral parameters (login times, resource access patterns, data transfer volumes) and detects anomalies through statistical deviations. This parameter transformation enables high detection accuracy for novel attacks while managing complexity through focused parameter selection and statistical methods.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If behavioral profiling and anomaly detection are implemented, then detection accuracy improves, but computational complexity and data processing requirements increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidcomputational power
Core Design Contradiction:
Measurement precisionVSPower

Solution Approach 1:

The patent extracts and focuses on specific critical behavioral parameters rather than analyzing all possible network data. By selecting key indicators such as login patterns, resource access frequencies, and data transfer metrics, the system achieves high detection accuracy while reducing computational burden. This extraction approach filters out unnecessary data processing while maintaining the ability to detect sophisticated anomalies through targeted parameter monitoring.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies partial monitoring by focusing computational resources on the most suspicious or high-risk activities rather than uniformly analyzing all network traffic. When anomalies are detected in critical areas, the system intensifies monitoring in those specific domains while maintaining baseline monitoring elsewhere. This partial action approach achieves high detection accuracy for threats while managing overall computational power requirements.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If real-time behavioral monitoring is performed across the entire network, then detection coverage is comprehensive, but system performance and response time are impacted

Engineering Contradiction:
Improvedetection coverageVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the network monitoring into distributed behavioral profiling agents that operate locally at different network nodes. Each agent maintains local behavioral profiles and performs anomaly detection for its designated segment, reducing the need for centralized real-time analysis of all network traffic. This segmentation provides comprehensive detection coverage across the entire network while maintaining local processing that minimizes impact on overall network performance and response times.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9712548B2Privileged analytics system
Publication Date: 2017.07.18 CYBER ARK SOFTWARE LTD
  • US9712548B2 patent drawing
  • US9712548B2 patent drawing
  • US9712548B2 patent drawing

AI summary

A computer-implemented method for determining whether a computer network is compromised by unauthorized activity on the computer network. The computer-implemented method comprises identifying a behavioral anomaly of an entity on the computer network, classifying the anomaly as a system event based on an assigned score for the anomaly being at least at a predetermined score threshold, updating an incident based on at least one common parameter between the system event and other system events which comprise the incident, each system event of the incident including an assigned score from when the event was an anomaly, updating a system status based on at least the incident, and assigning a system status score to the system status, and, determining whether the system status score is at least at a predetermined threshold system status score indicating that the computer network may be compromised.