Automated Risk Score Weighting for Network Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise computer networks face challenges in detecting and remediating access anomalies due to the strain on network security systems caused by continuous growth and sophisticated attacks like advanced persistent threats (APTs), which conventional credential-based authentication techniques often fail to address effectively.

Innovation Solution

Implementing automated detection of access anomalies using risk score aggregation, where feature risk scores are weighted based on automatically-set weights determined by deviations from a predetermined probability distribution, allowing for enhanced security without manual intervention and dynamic adaptation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional credential-based authentication techniques are used, then the security system is simple to operate, but it fails to detect sophisticated attacks like APTs effectively

Engineering Contradiction:
Improvedetection effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into multiple independent risk score components (geographic risk, device risk, behavioral risk, etc.), each evaluated separately and then aggregated. This allows complex attack detection through multiple simple, manageable risk assessments rather than a single complex authentication mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically changes authentication parameters by assigning different weights to various risk factors based on their deviation from normal patterns. Instead of fixed authentication rules, the system adapts weights according to observed deviations, enabling detection of sophisticated attacks while maintaining operational simplicity.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If manual weight setting for risk scores is performed, then the detection accuracy can be optimized, but it requires significant manual intervention and cannot adapt dynamically

Engineering Contradiction:
Improvedetection accuracyVSAvoidautomation level
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system performs self-service by automatically calculating optimal weights for each risk factor based on observed data patterns. The weight assignment mechanism autonomously adjusts to new attack patterns without human intervention, maintaining high detection accuracy while achieving full automation. Each risk factor's weight is determined by its deviation from normal behavior patterns.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback loops where detection results and observed patterns continuously inform weight adjustments. The automatic weight setting mechanism uses feedback from actual attack detection performance and pattern deviations to dynamically optimize detection accuracy, eliminating the need for manual reconfiguration.

Inventive Principle:
Principle #23Feedback

3Reliability

If the network security system processes all security alerts in large enterprise networks, then comprehensive security monitoring is achieved, but the limited resources of the system become strained

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by focusing security processing resources on high-risk areas identified through the risk scoring mechanism. Instead of uniform processing of all alerts, the system dynamically allocates attention to specific users, devices, or access patterns with higher composite risk scores, achieving comprehensive security coverage with limited resources.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes processing parameters by adjusting the threshold for alert generation and resource allocation based on composite risk scores. High-risk patterns trigger more intensive processing and lower thresholds, while low-risk patterns use higher thresholds and less resource-intensive processing, optimizing the balance between security coverage and processing capacity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11082442B1Automated setting of risk score aggregation weights for detection of access anomalies in a computer network
Publication Date: 2021.08.03 EMC IP HLDG CO LLC
  • US11082442B1 patent drawing
  • US11082442B1 patent drawing
  • US11082442B1 patent drawing

AI summary

A processing device in one embodiment comprises a processor coupled to a memory and is configured to generate access profiles for respective user identifiers, to obtain data characterizing a current access for a given one of the user identifiers, to extract a plurality of features from the data characterizing the current access for the given user identifier, and to generate feature risk scores based on the extracted features and the access profile for the given user identifier. The processing device is further configured to aggregate the feature risk scores into a composite risk score. The aggregation illustratively comprises weighting the feature risk scores utilizing automatically-set feature risk score weights. The composite risk score is compared to a threshold, and an alert is generated relating to the current access based on a result of comparing the composite risk score to the threshold.