Risk Score Assignment for Network Entity Subsets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern data centers face challenges in processing and indexing large volumes of machine-generated data due to its unstructured nature, making it difficult to apply semantic meaning and perform efficient searching operations.

Innovation Solution

A data aggregation and analysis system that evaluates triggering conditions applied to search results to assign risk scores to entities, optimizing processing by focusing on a subset of entities and creating a baseline behavior for peer groups, and using a graphical user interface to visually present risk scores for real-time monitoring and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If monitoring and analyzing activity of all entities in a data center, then security coverage and detection capability are improved, but processing complexity and computational resources increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides entities into peer groups based on similar activity patterns and characteristics. Instead of treating all entities uniformly, the system segments them into manageable groups that can be analyzed collectively, reducing processing complexity while maintaining comprehensive security coverage across all entities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates baseline behavior profiles that represent typical activity patterns for each peer group. These baselines serve as templates that can be applied to multiple entities within the group, allowing the system to evaluate numerous entities against a single standardized model rather than analyzing each entity individually from scratch.

Inventive Principle:
Principle #26Copying

2Loss of information

If processing large volumes of unstructured machine-generated data, then data analysis completeness is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvedata analysis completenessVSAvoidprocessing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system transforms unstructured machine-generated data into structured activity metrics by defining specific parameters and measurement criteria. This parameterization allows the system to process data efficiently by focusing on predetermined metrics rather than analyzing all raw data elements, reducing processing time while maintaining analysis completeness for critical security indicators.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system pre-establishes baseline behavior profiles and evaluation criteria before actual security analysis begins. By preparing these reference models in advance, the system can quickly compare current entity activity against known patterns without performing complex analysis in real-time, significantly reducing processing time while maintaining thorough evaluation.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If applying comprehensive search operations to all data, then detection accuracy is improved, but processing efficiency decreases

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies different analysis depths and evaluation strictness levels to different peer groups based on their risk profiles and characteristics. High-risk groups receive more rigorous analysis with stricter thresholds, while low-risk groups undergo lighter evaluation. This localized approach maintains high detection accuracy for critical threats while improving overall processing efficiency by not applying maximum scrutiny uniformly to all entities.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10496816B2Supplementary activity monitoring of a selected subset of network entities
Publication Date: 2019.12.03 CISCO TECHNOLOGY INC
  • US10496816B2 patent drawing
  • US10496816B2 patent drawing
  • US10496816B2 patent drawing

AI summary

Systems and methods are disclosed for associating an entity with a risk score that may indicate a security threat associated with the entity's activity. An exemplary method may involve monitoring the activity of a subset of the set of entities (e.g., entities included in a watch list) by executing a search query against events indicating the activity of the subset of entities. The events may be associated with timestamps and may include machine data. Executing the search query may produce search results that pertain to activity of a particular entity from the subset. The search results may be evaluated based on a triggering condition corresponding to the statistical baseline. When the triggering condition is met, a risk score for the particular entity may be updated. The updated risk score may be displayed to a user via a graphical user interface (GUI).