Security Log Mining via Data Fusion and Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems struggle to effectively detect anomalous behavior in both physical and computing access events by isolating structured and non-structured data, leading to inefficiencies in identifying unauthorized access and resource-intensive computations.

Innovation Solution

Combining structured and non-structured data using a data fusion unit to generate a behavior model through anomaly detection engines, which compares real-time behavior to a logistic regression-based model for accurate and efficient detection of anomalous access patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If structured and non-structured data are isolated and analyzed separately, then the system maintains simplicity in data processing, but the detection accuracy of anomalous behavior deteriorates

Engineering Contradiction:
Improvedata processing structureVSAvoidanomaly detection accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent combines structured data (from access control systems, video management systems, intrusion detection systems) and non-structured data (video feeds, images, audio) into a unified data structure with common identifiers. This merging enables comprehensive anomaly detection by analyzing both data types together rather than separately, improving detection accuracy while maintaining systematic processing through unified data structures and common identifier systems.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If comprehensive data from multiple security systems is integrated, then the detection capability of anomalous behavior is improved, but the computing resources required deteriorate

Engineering Contradiction:
Improvedetection capabilityVSAvoidcomputing resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary actions by pre-processing data from multiple security systems, extracting key features and organizing them into unified data structures with common identifiers before anomaly detection. Behavior models are generated in advance based on historical data, enabling the system to compare real-time events against pre-established patterns. This preliminary organization and model generation reduces the computational burden during real-time anomaly detection while maintaining comprehensive detection capability.

Inventive Principle:
Principle #10Preliminary action

3Speed

If real-time behavior is continuously compared to behavior models, then the detection speed of anomalous behavior is improved, but the computing resources required deteriorate

Engineering Contradiction:
Improvedetection speedVSAvoidcomputing resources
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The patent changes parameters by implementing efficient comparison mechanisms that leverage the unified data structure and common identifiers. The system compares real-time event parameters against pre-generated behavior models using optimized algorithms that exploit the structured organization of data. This parameter-based comparison approach enables fast real-time detection while reducing computational resources by avoiding redundant processing and leveraging the pre-organized data structure.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9661010B2Security log mining devices, methods, and systems
Publication Date: 2017.05.23 HONEYWELL INTERNATIONAL INC
  • US9661010B2 patent drawing
  • US9661010B2 patent drawing
  • US9661010B2 patent drawing

AI summary

Devices, methods, and systems for security log mining are described herein. One method includes combining, using a data fusion unit of an access control system, features of structured and non-structured data associated with system access events for a number of users into a combined data set, generating, using an anomaly detection engine of the access control system, a model of behavior for the number of users based on the combined data set, and comparing, using the anomaly detection engine of the access control system, real time behavior for the number of users to the model for the number of users to determine whether the real time behavior for the number of users is anomalous behavior for the number of users.