Session-Based Anomaly Detection via Network Profile Risk Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise computer networks face challenges in providing adequate security due to the continuous growth in size and diversity of user devices, which strains existing network security systems, and conventional credential-based authentication techniques often fail to detect and remediate advanced persistent threats (APTs) effectively.

Innovation Solution

The implementation of automated detection of session-based access anomalies through processing data characterizing VPN sessions to generate network session profiles, which supplements conventional authentication techniques by extracting features and generating risk scores for real-time anomaly detection and alert generation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional credential-based authentication techniques are used, then network security systems can operate with limited resources, but they fail to detect and remediate advanced persistent threats (APTs) effectively

Engineering Contradiction:
Improvedetection effectiveness against APTsVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by continuously collecting session data and pre-processing it into session profiles that capture user behavior patterns. This preparation work is done in advance so that when anomalies need to be detected, the system can quickly compare current sessions against pre-analyzed historical patterns, improving detection effectiveness without adding complex real-time processing requirements

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security system is segmented into distinct functional components: session data collection, profile generation, anomaly detection, and alert generation. This segmentation allows each component to operate independently with optimized resource requirements, making the overall system more manageable and effective at detecting APTs without requiring a monolithic complex architecture

Inventive Principle:
Principle #1Segmentation

2Reliability

If network security systems process security alerts and deploy attack remediation measures in large enterprise networks, then protection coverage is improved, but available functionality is strained by the demands of large enterprise networks

Engineering Contradiction:
Improveprotection coverageVSAvoidsecurity system processing capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system extracts only the essential features from session data that are relevant for anomaly detection, rather than processing complete session records. By extracting key behavioral patterns and characteristics, the system reduces the processing burden while maintaining effective protection coverage across large enterprise networks

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes parameters by transforming raw session data into aggregated session profiles that summarize user behavior over time. This parameter transformation reduces data volume and complexity, allowing the security system to maintain high protection coverage without being overwhelmed by the processing demands of large networks

Inventive Principle:
Principle #35Parameter changes

3Reliability

If automated detection of session-based access anomalies is implemented, then detection performance against APTs is improved, but system complexity increases

Engineering Contradiction:
Improveanomaly detection performanceVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service by automatically generating session profiles from collected data without requiring manual configuration or intervention. The automated profile generation and anomaly detection processes enable the system to improve detection performance while managing complexity through self-configuration and adaptive learning from historical patterns

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10003607B1Automated detection of session-based access anomalies in a computer network through processing of session data
Publication Date: 2018.06.19 EMC IP HLDG CO LLC
  • US10003607B1 patent drawing
  • US10003607B1 patent drawing
  • US10003607B1 patent drawing

AI summary

A processing device in one embodiment comprises a processor coupled to a memory and is configured to obtain data characterizing a plurality of network sessions for each of a plurality of user identifiers. The network sessions are initiated from a plurality of user devices over at least one network and may comprise respective virtual private network (VPN) sessions. The processing device is further configured to process the data characterizing the network sessions for a given one of the plurality of user identifiers to generate a network session profile for the given user identifier, the network session profile comprising a plurality of histograms for respective ones of a plurality of features extracted from the data characterizing the plurality of network sessions for the given user identifier. A risk score is generated for a current network session utilizing features extracted from the data characterizing that session and the network session profile.