Enterprise Server Behavior Profiling for Anomalous Contact Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems lack effective methods to detect and respond to anomalous behavior in enterprise server devices, which can indicate potential security breaches, due to data processing challenges and the rarity of new connections outside their usual communication domains.
Innovation Solution
A system and method for generating behavior profiling reports and associating severity scores for enterprise server devices, using historical security event data and owner data to identify anomalous connections and create connected graphs, leveraging Big Data processing technologies to analyze network sensor logs and react to security incidents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network security monitoring methods are used, then system complexity is kept low, but the ability to detect anomalous server behavior is insufficient
Solution Approach 1:
The patent segments the network monitoring system into multiple specialized components: behavior profilers that analyze individual server patterns, anomaly detectors that identify deviations, and graph generators that visualize relationships. This segmentation enables sophisticated detection capabilities while managing system complexity through modular design.
Solution Approach 2:
The system performs preliminary actions by continuously building behavior profiles of servers based on their historical communication patterns before anomalies occur. This baseline behavior data is prepared in advance, enabling rapid detection when deviations happen, thus improving reliability without proportionally increasing complexity.
2Measurement precision
If comprehensive network traffic analysis is performed, then detection precision is improved, but data processing time increases
Solution Approach 1:
The patent applies partial action by focusing analysis only on relevant behavior dimensions - specifically communication patterns and connections - rather than analyzing all possible server attributes. This selective approach maintains high detection precision for security-relevant anomalies while reducing overall data processing time.
Solution Approach 2:
The system creates simplified copies of complex network behavior through behavior profiles that capture essential communication patterns. These profiles serve as representative models that can be quickly compared against actual traffic, enabling precise anomaly detection without processing the full complexity of raw network data in real-time.
3Productivity
If behavior profiling reports with severity scores are generated, then forensic investigation efficiency is improved, but information processing complexity increases
Solution Approach 1:
The patent uses a visual metaphor similar to color changes by implementing severity scores that categorize anomalies into distinct levels (e.g., low, medium, high severity). This classification system allows forensic investigators to quickly prioritize cases based on visual cues from the scores, improving investigation efficiency without requiring complex analysis of the underlying data.
Solution Approach 2:
The behavior profiling report acts as an intermediary between raw network data and forensic investigation. It processes and summarizes complex communication patterns into structured, interpretable findings with severity assessments, reducing the information processing complexity required by investigators while maintaining high productivity.
Data Source
AI summary
Generation of behavior profiling reports is provided for enterprise server devices in a network of enterprise server devices, as well as generation and association of severity scores for behavior profiling reports generated for enterprise server devices included in the network of enterprise server devices. A method can comprise receiving historical security event data representing historical security events of a first device and owner data representing an owner of the first device, and, as a function of the historical security event data and the owner data, an anomalous contact established between the first device and the second device can be identified. Further, in response to identifying the existence of the anomalous contact, the second device can be depicted on a connected graph of anomalous contacts established by the first device.


