Enterprise Server Behavior Profiling for Anomalous Contact Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems lack effective methods to detect and respond to anomalous behavior in enterprise server devices, which can indicate potential security breaches, due to data processing challenges and the rarity of new connections outside their usual communication domains.

Innovation Solution

A system and method for generating behavior profiling reports and associating severity scores for enterprise server devices, using historical security event data and owner data to identify anomalous connections and create connected graphs, leveraging Big Data processing technologies to analyze network sensor logs and react to security incidents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security monitoring methods are used, then system complexity is kept low, but the ability to detect anomalous server behavior is insufficient

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network monitoring system into multiple specialized components: behavior profilers that analyze individual server patterns, anomaly detectors that identify deviations, and graph generators that visualize relationships. This segmentation enables sophisticated detection capabilities while managing system complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by continuously building behavior profiles of servers based on their historical communication patterns before anomalies occur. This baseline behavior data is prepared in advance, enabling rapid detection when deviations happen, thus improving reliability without proportionally increasing complexity.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If comprehensive network traffic analysis is performed, then detection precision is improved, but data processing time increases

Engineering Contradiction:
Improveanomaly detection precisionVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by focusing analysis only on relevant behavior dimensions - specifically communication patterns and connections - rather than analyzing all possible server attributes. This selective approach maintains high detection precision for security-relevant anomalies while reducing overall data processing time.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system creates simplified copies of complex network behavior through behavior profiles that capture essential communication patterns. These profiles serve as representative models that can be quickly compared against actual traffic, enabling precise anomaly detection without processing the full complexity of raw network data in real-time.

Inventive Principle:
Principle #26Copying

3Productivity

If behavior profiling reports with severity scores are generated, then forensic investigation efficiency is improved, but information processing complexity increases

Engineering Contradiction:
Improveforensic investigation efficiencyVSAvoidinformation processing complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent uses a visual metaphor similar to color changes by implementing severity scores that categorize anomalies into distinct levels (e.g., low, medium, high severity). This classification system allows forensic investigators to quickly prioritize cases based on visual cues from the scores, improving investigation efficiency without requiring complex analysis of the underlying data.

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The behavior profiling report acts as an intermediary between raw network data and forensic investigation. It processes and summarizes complex communication patterns into structured, interpretable findings with severity assessments, reducing the information processing complexity required by investigators while maintaining high productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10797974B2Enterprise server behavior profiling
Publication Date: 2020.10.06 AT&T INTELLECTUAL PROPERTY I L P
  • US10797974B2 patent drawing
  • US10797974B2 patent drawing
  • US10797974B2 patent drawing

AI summary

Generation of behavior profiling reports is provided for enterprise server devices in a network of enterprise server devices, as well as generation and association of severity scores for behavior profiling reports generated for enterprise server devices included in the network of enterprise server devices. A method can comprise receiving historical security event data representing historical security events of a first device and owner data representing an owner of the first device, and, as a function of the historical security event data and the owner data, an anomalous contact established between the first device and the second device can be identified. Further, in response to identifying the existence of the anomalous contact, the second device can be depicted on a connected graph of anomalous contacts established by the first device.