Session-Based Anomaly Detection via Network Profile Risk Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise computer networks face challenges in providing adequate security due to the continuous growth in size and diversity of user devices, which strains existing network security systems, and conventional credential-based authentication techniques often fail to detect and remediate advanced persistent threats (APTs) effectively.
Innovation Solution
The implementation of automated detection of session-based access anomalies through processing data characterizing VPN sessions to generate network session profiles, which supplements conventional authentication techniques by extracting features and generating risk scores for real-time anomaly detection and alert generation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional credential-based authentication techniques are used, then network security systems can operate with limited resources, but they fail to detect and remediate advanced persistent threats (APTs) effectively
Solution Approach 1:
The system performs preliminary actions by continuously collecting session data and pre-processing it into session profiles that capture user behavior patterns. This preparation work is done in advance so that when anomalies need to be detected, the system can quickly compare current sessions against pre-analyzed historical patterns, improving detection effectiveness without adding complex real-time processing requirements
Solution Approach 2:
The security system is segmented into distinct functional components: session data collection, profile generation, anomaly detection, and alert generation. This segmentation allows each component to operate independently with optimized resource requirements, making the overall system more manageable and effective at detecting APTs without requiring a monolithic complex architecture
2Reliability
If network security systems process security alerts and deploy attack remediation measures in large enterprise networks, then protection coverage is improved, but available functionality is strained by the demands of large enterprise networks
Solution Approach 1:
The system extracts only the essential features from session data that are relevant for anomaly detection, rather than processing complete session records. By extracting key behavioral patterns and characteristics, the system reduces the processing burden while maintaining effective protection coverage across large enterprise networks
Solution Approach 2:
The system changes parameters by transforming raw session data into aggregated session profiles that summarize user behavior over time. This parameter transformation reduces data volume and complexity, allowing the security system to maintain high protection coverage without being overwhelmed by the processing demands of large networks
3Reliability
If automated detection of session-based access anomalies is implemented, then detection performance against APTs is improved, but system complexity increases
Solution Approach 1:
The system implements self-service by automatically generating session profiles from collected data without requiring manual configuration or intervention. The automated profile generation and anomaly detection processes enable the system to improve detection performance while managing complexity through self-configuration and adaptive learning from historical patterns
Data Source
AI summary
A processing device in one embodiment comprises a processor coupled to a memory and is configured to obtain data characterizing a plurality of network sessions for each of a plurality of user identifiers. The network sessions are initiated from a plurality of user devices over at least one network and may comprise respective virtual private network (VPN) sessions. The processing device is further configured to process the data characterizing the network sessions for a given one of the plurality of user identifiers to generate a network session profile for the given user identifier, the network session profile comprising a plurality of histograms for respective ones of a plurality of features extracted from the data characterizing the plurality of network sessions for the given user identifier. A risk score is generated for a current network session utilizing features extracted from the data characterizing that session and the network session profile.


