Temporal Anomaly Detection for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems are unable to detect network attacks in a timely manner, allowing unauthorized access and malicious activities such as data exfiltration or malware uploads, due to their inability to identify unauthorized communication channels until after an attack has occurred.

Innovation Solution

A machine learning-based system that identifies clusters of user devices and communication channels within a network, using group information and user interaction data to detect anomalies and unauthorized communication channels, allowing for real-time prevention of malicious activities by modifying settings on affected devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If traditional network security systems are used, then device complexity is reduced, but detection speed and accuracy of unauthorized communication channels deteriorate

Engineering Contradiction:
Improvedetection speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent introduces a machine learning model as an intermediary component between network data and security analysis. This model processes user interaction data and communication patterns to identify unauthorized channels, enabling faster detection without requiring complex manual analysis systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical rule-based security systems with machine learning-based automated detection. The machine learning model automatically analyzes network traffic patterns and user behavior, substituting manual security monitoring mechanisms with intelligent automated systems that provide faster response times.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If machine learning-based anomaly detection is implemented, then detection accuracy of unauthorized communication channels improves, but device complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-training machine learning models with historical network data and establishing baseline communication patterns before actual security threats occur. This preparation enables the system to quickly and accurately detect anomalies without requiring complex real-time analysis of every data point.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The machine learning model performs self-service by automatically learning from network data, identifying patterns, and detecting unauthorized communication channels without requiring constant human intervention or complex configuration. The system self-optimizes its detection capabilities through continuous learning from incoming data.

Inventive Principle:
Principle #25Self-service

3Reliability

If real-time monitoring of user devices is performed, then network security improves, but network resources and throughput are consumed

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies partial action by monitoring only specific user interactions and communication patterns that are relevant to security threats, rather than analyzing all network traffic in real-time. The machine learning model focuses on key indicators such as unusual communication frequencies, unauthorized device connections, and abnormal data transfer patterns, reducing overall resource consumption while maintaining security effectiveness.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11792213B2Temporal-based anomaly detection for network security
Publication Date: 2023.10.17 BANK OF AMERICA CORP
  • US11792213B2 patent drawing
  • US11792213B2 patent drawing
  • US11792213B2 patent drawing

AI summary

A device configured to obtain a first user interaction data at a first time instance for user devices, to obtain a first set of clusters from a machine learning model based on the first user interaction data, and to determine a first cluster quantity for the first set of clusters. The device is further configured to obtain a second user interaction data at a second time instance for the user devices, to obtain a second set of clusters from the machine learning model based on the second user interaction data, and to determine a second cluster quantity for the second set of clusters. The device is further configured to determine the second cluster quantity is greater than the first cluster quantity, to identify a cluster that is not present in the first set of clusters, and to modify settings on a user device from within the cluster.