Automated Risk Score Weighting for Network Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise computer networks face challenges in detecting and remediating access anomalies due to the strain on network security systems caused by continuous growth and sophisticated attacks like advanced persistent threats (APTs), which conventional credential-based authentication techniques often fail to address effectively.
Innovation Solution
Implementing automated detection of access anomalies using risk score aggregation, where feature risk scores are weighted based on automatically-set weights determined by deviations from a predetermined probability distribution, allowing for enhanced security without manual intervention and dynamic adaptation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional credential-based authentication techniques are used, then the security system is simple to operate, but it fails to detect sophisticated attacks like APTs effectively
Solution Approach 1:
The patent segments the authentication process into multiple independent risk score components (geographic risk, device risk, behavioral risk, etc.), each evaluated separately and then aggregated. This allows complex attack detection through multiple simple, manageable risk assessments rather than a single complex authentication mechanism.
Solution Approach 2:
The system dynamically changes authentication parameters by assigning different weights to various risk factors based on their deviation from normal patterns. Instead of fixed authentication rules, the system adapts weights according to observed deviations, enabling detection of sophisticated attacks while maintaining operational simplicity.
2Reliability
If manual weight setting for risk scores is performed, then the detection accuracy can be optimized, but it requires significant manual intervention and cannot adapt dynamically
Solution Approach 1:
The system performs self-service by automatically calculating optimal weights for each risk factor based on observed data patterns. The weight assignment mechanism autonomously adjusts to new attack patterns without human intervention, maintaining high detection accuracy while achieving full automation. Each risk factor's weight is determined by its deviation from normal behavior patterns.
Solution Approach 2:
The system implements feedback loops where detection results and observed patterns continuously inform weight adjustments. The automatic weight setting mechanism uses feedback from actual attack detection performance and pattern deviations to dynamically optimize detection accuracy, eliminating the need for manual reconfiguration.
3Reliability
If the network security system processes all security alerts in large enterprise networks, then comprehensive security monitoring is achieved, but the limited resources of the system become strained
Solution Approach 1:
The patent applies local quality by focusing security processing resources on high-risk areas identified through the risk scoring mechanism. Instead of uniform processing of all alerts, the system dynamically allocates attention to specific users, devices, or access patterns with higher composite risk scores, achieving comprehensive security coverage with limited resources.
Solution Approach 2:
The system changes processing parameters by adjusting the threshold for alert generation and resource allocation based on composite risk scores. High-risk patterns trigger more intensive processing and lower thresholds, while low-risk patterns use higher thresholds and less resource-intensive processing, optimizing the balance between security coverage and processing capacity.
Data Source
AI summary
A processing device in one embodiment comprises a processor coupled to a memory and is configured to generate access profiles for respective user identifiers, to obtain data characterizing a current access for a given one of the user identifiers, to extract a plurality of features from the data characterizing the current access for the given user identifier, and to generate feature risk scores based on the extracted features and the access profile for the given user identifier. The processing device is further configured to aggregate the feature risk scores into a composite risk score. The aggregation illustratively comprises weighting the feature risk scores utilizing automatically-set feature risk score weights. The composite risk score is compared to a threshold, and an alert is generated relating to the current access based on a result of comparing the composite risk score to the threshold.


