Privileged Analytics System for Network Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional signature-based security systems fail to accurately detect modern cyber-attacks on organizational networks due to their reliance on previously discovered vulnerabilities, resulting in low detection rates and high false alarm rates.
Innovation Solution
A computer-implemented method that identifies behavioral anomalies on a network by building and analyzing behavioral profiles using statistical and rule-based analytics, classifying anomalies as system events, and updating system status scores to determine potential network compromise, with optional user feedback for verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If signature-based security methods are used to detect cyber-attacks, then the detection process is simple and fast, but the detection accuracy is low and false alarm rate is high
Solution Approach 1:
The patent implements dynamic behavioral profiling that continuously adapts to changing network conditions and user behaviors. The system maintains evolving profiles of normal behavior patterns and dynamically compares current activities against these profiles, allowing the detection mechanism to adapt over time rather than relying on static signatures. This resolves the contradiction by making the system complex enough to achieve high accuracy through adaptive learning, while the dynamic nature allows it to remain responsive to new threats.
Solution Approach 2:
The system changes the fundamental parameter of detection from signature matching to behavioral parameter analysis. Instead of checking for known attack signatures, the system monitors multiple behavioral parameters (login times, resource access patterns, data transfer volumes) and detects anomalies through statistical deviations. This parameter transformation enables high detection accuracy for novel attacks while managing complexity through focused parameter selection and statistical methods.
2Measurement precision
If behavioral profiling and anomaly detection are implemented, then detection accuracy improves, but computational complexity and data processing requirements increase
Solution Approach 1:
The patent extracts and focuses on specific critical behavioral parameters rather than analyzing all possible network data. By selecting key indicators such as login patterns, resource access frequencies, and data transfer metrics, the system achieves high detection accuracy while reducing computational burden. This extraction approach filters out unnecessary data processing while maintaining the ability to detect sophisticated anomalies through targeted parameter monitoring.
Solution Approach 2:
The system applies partial monitoring by focusing computational resources on the most suspicious or high-risk activities rather than uniformly analyzing all network traffic. When anomalies are detected in critical areas, the system intensifies monitoring in those specific domains while maintaining baseline monitoring elsewhere. This partial action approach achieves high detection accuracy for threats while managing overall computational power requirements.
3Reliability
If real-time behavioral monitoring is performed across the entire network, then detection coverage is comprehensive, but system performance and response time are impacted
Solution Approach 1:
The patent segments the network monitoring into distributed behavioral profiling agents that operate locally at different network nodes. Each agent maintains local behavioral profiles and performs anomaly detection for its designated segment, reducing the need for centralized real-time analysis of all network traffic. This segmentation provides comprehensive detection coverage across the entire network while maintaining local processing that minimizes impact on overall network performance and response times.
Data Source
AI summary
A computer-implemented method for determining whether a computer network is compromised by unauthorized activity on the computer network. The computer-implemented method comprises identifying a behavioral anomaly of an entity on the computer network, classifying the anomaly as a system event based on an assigned score for the anomaly being at least at a predetermined score threshold, updating an incident based on at least one common parameter between the system event and other system events which comprise the incident, each system event of the incident including an assigned score from when the event was an anomaly, updating a system status based on at least the incident, and assigning a system status score to the system status, and, determining whether the system status score is at least at a predetermined threshold system status score indicating that the computer network may be compromised.


