A centralized computer network traffic monitoring and intrusion detection system for a computer network

The centralized computer network traffic monitoring and intrusion detection system addresses the limitations of traditional firewalls by integrating AI-based threat analysis and reporting, effectively enhancing network security and incident response.

WO2025116719A1PCT designated stage expired Publication Date: 2025-06-05E LOCK CORP

Patent Information

Application Number
PCT/MY2024/050009
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-28
Filing Date
2024-02-14
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

Traditional firewalls lack the capability to effectively identify and manage malicious IP addresses and fail to provide real-time analysis and incident prioritization, leading to potential security breaches and system disruptions.

Method used

A centralized computer network traffic monitoring and intrusion detection system that integrates with existing firewalls, utilizing AI-based algorithms for real-time threat analysis, contextualization, and prioritization, and generates comprehensive reports for incident mitigation.

Benefits of technology

Enhances network security by proactively detecting and managing threats, providing detailed insights for incident resolution, and automatically updating security measures to counter evolving cyber threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure MY2024050009_05062025_PF_FP_ABST
    Figure MY2024050009_05062025_PF_FP_ABST
Patent Text Reader

Abstract

A centralized network traffic monitoring and intrusion detection system (1) comprising a system log aggregation module (110) including a means for receiving (111), a means for decoding (112) the user's syslog, a means for comparing (113) the data from the means for decoding, and a means for indexing (114) the tagged data and storing the indexed data. The system (1) also comprises an analysis and alert module (120) including a means for fetching (121) the indexed data, a means for checking and correlating (122) the retrieved indexed data, a means for analysing (123) the checked and correlated data, a means for compiling (124) the analysed and prioritized data and generating a report, and a means for alerting (124). The system (1) further includes a Bad IP Feed module (130) including a means for generating (131) updated lists of bad IP addresses and hostnames and automatically updating a user's network devices.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] A CENTRALIZED COMPUTER NETWORK TRAFFIC MONITORING AND INTRUSION DETECTION SYSTEM FOR A COMPUTER NETWORK

[0002] FIELD OF THE INVENTION

[0003] This invention relates to the field of computer network security, specifically the monitoring of network traffic to aid in the detection of cyber threats in the form of intrusions and breaches to a computer network via the internet.

[0004] BACKGROUND OF THE INVENTION

[0005] The present global trend towards internet-connectivity and the digitalization of every service and the near-total reliance on digital services which continues to grow has seen an exponentially increasing volume of computer network traffic being exchanged across the internet. The sheer volume of data flowing across the internet poses a significant challenge to ensuring the security of a computer network. This coupled with the increasing and evolving complexity of cyber-attacks makes it difficult to develop efficient tools to detect them, and it is of course a continuous battle to monitor, detect and counter threats in the form of intrusions and breaches to a computer network, which are loosely called 'cyber-attacks'.

[0006] There are presently several different categories of computer network intrusion detection systems (IDS), namely IDS, which are signature-based, anomaly-based and hybrid-based techniques for detection purposes. Signature-based techniques detect intrusion by comparing known patterns or a predefined set of rules, while anomaly-based techniques focus on the current user's activities to recognize interruptions.

[0007] Signature-based intrusion detection has been the most common method used for detecting attacks and providing security. Firewalls which are primarily signature-based, serve as the cornerstone of network defense and aim to filter all connections to safeguard against unauthorized access.

[0008] However, a firewall has obvious limitations as it lacks the nuanced capability to identify and manage the wide spectrum of malicious IP addresses attempting to infiltrate networks practically non-stop. This obvious limitation means that an untold number of potentially harmful connections may pass through a firewall without detection, and this poses a significant risk to the security of a computer network.

[0009] Another shortfall of a conventional firewall is its limited capacity to analyze the severity of a threat that is encountered and its implications. In the absence of a comprehensive system to monitor, analyze, and respond to these threats in real-time, the risk of a cyber-attack resulting in a data breach, system disruption or other serious damage to network infrastructure remains high.

[0010] Compounding the situation is the sheer and escalating volume and complexity of cyber-attacks which simply overwhelms the traditional incident management processes.

[0011] With the above in mind, there is a clear need for a more advanced IDS that not only detects and thwarts threats and attacks but is also able to provide detailed insight and guidance for incident resolution.

[0012] Since present firewall solutions are unable to provide any in-depth analysis and incident prioritization, there is also a clear need for a supplementary layer of security that is intelligent so that it is able to face and counter emerging and evolving threats to a computer network.

[0013] The advent of various Artificial Intelligence (Al) -based technologies in recent times, although viewed as controversial in some quarters, is actually in a position to complement a traditional firewall due to its self-learning and self-teaching abilities.

[0014] In particular, Al-based technologies which are generally categorized into machine learning, deep learning and ensemble learning have all displayed promising results in the detection of cyberattacks more efficiently.

[0015] In view of the continuously evolving threats and the availability of new Al-based technologies, it is desirable and an objective of the present invention to provide an IDS that is able to seamlessly integrate and augment a traditional firewall by providing an additional layer of security that also has the ability to not only analyse new threats which have been encountered or discovered, but to also interpret and then disseminate the new threat information to the user in the form of a comprehensive report. SUMMARY OF INVENTION

[0016] The invention is an anomaly-based IDS intended to address the critical gaps in traditional internet security measures such as firewalls, by augmenting a firewall's capabilities with the advantages of artificial intelligence (Al) and advanced analytics. The invention integrates seamlessly with existing firewall infrastructure, enhancing their ability to proactively detect, analyze, and manage connections from Internet Protocol (IP) addresses and hostnames with a malicious reputation.

[0017] A key and distinguishing feature of the invention is its ability to contextualize and prioritize threats, enabling a strategic and informed response to network security incidents. This is accomplished by utilising a local IP reputation list to tag incoming connections, and screen potential threats before they can breach the network. The system makes use of syslog data (i.e., system logging protocol messages) received from a user's network device which is transformed into a log analytics format and then indexed to enable streamlined searching and real-time security event analysis using machine learning and deep learning Al-based algorithms.

[0018] The Al-based algorithm correlates the analysis findings, compiles incidents, and assigns priorities based on the severity and impact of each threat, and then autonomously creates detailed incident reports with analysis descriptions and recommendations for threat mitigation.

[0019] In a first aspect, the invention provides a centralized network traffic monitoring and intrusion detection system for a user's computer network.

[0020] The centralized network traffic monitoring and intrusion detection system for a user's computer network comprises a system log aggregation block / module, an analysis and alert block / module and a Bad IP Feed block / module.

[0021] The system log aggregation block / module includes:

[0022] - a means for receiving / collecting from the user's network devices the syslog / system logging protocol messages that are generated by the network device,

[0023] - a means for decoding the user's syslog / system logging protocol messages received by parsing and translating the syslog / system logging protocol messages into data with a uniform and structured format to facilitate analysis of the syslog data, - a means for comparing the data from the means for decoding with a database of IP reputations such as malicious IP addresses and domain names and then tagging the data which match the contents of the database for further investigation, and

[0024] - a means for indexing the tagged data to optimize searchability and accessibility and then storing the indexed data for use as a reference for rapid threat detection and response.

[0025] The analysis and alert block / module includes:

[0026] - a means for fetching / retrieving / extracting the indexed data for subsequent analysis according to key event categories that are indicative of potential security threats or breaches, wherein the key event categories comprise a) unblocked alert-level events b) flagged indicators of concern events c) top unblocked IP's and d) top unblocked hostnames,

[0027] - a means for checking and correlating the retrieved indexed data relating to IP addresses and hostnames against a continuously updated database of known malicious activities to detect newly identified threats,

[0028] - a means for analysing the checked and correlated data to identify patterns, anomalies and potential security incidents, and prioritising the analysed data by assigning a risk score / factor according to importance / severity,

[0029] - a means for compiling the analysed and prioritized data and generating a comprehensive report that includes the details of a security incident, nature of the threat, system and data potentially affected, a severity assessment and actionable recommendations for mitigating the threat posed by the security incident, and

[0030] - a means for alerting the user of threats according to the severity of a security incident for communicating the comprehensive report generated by the means for compiling the analysed and prioritized data and generating a comprehensive report.

[0031] The Bad IP Feed block / module includes:

[0032] - a means for generating / publishing updated lists of bad IP addresses and hostnames based on the comprehensive report generated by the means for compiling the analysed and prioritized data, and

[0033] - a means for automatically updating a user's network devices with the updated lists of bad IP addresses and hostnames. The centralized network traffic monitoring and intrusion detection system for a user's computer network according to the first aspect of the invention is preferably remotely operated by a service provider.

[0034] In the centralized network traffic monitoring and intrusion detection system for a user's computer network according to the first aspect of the invention, the network devices may be a network firewall, a computer server, a computer switch or a workstation.

[0035] In the centralized network traffic monitoring and intrusion detection system for a user's computer network according to the first aspect of the invention, the system log aggregation block / module preferably uses a machine learning artificial intelligence-based algorithm to process the syslog / system logging protocol messages received from a user's network device.

[0036] In the centralized network traffic monitoring and intrusion detection system for a user's computer network according to the first aspect of the invention, the analysis and alert block / module preferably uses:

[0037] - a machine-learning artificial intelligence-based algorithm to analyse the checked and correlated data to identify patterns, anomalies and potential security incidents including the identification of spikes in network traffic from certain IP addresses, hostnames or regions, and abnormal patterns of access, and to interpret the analysed and prioritized data in the context of the conditions and environment of a network in order to understand its significance, to structure the contents for the comprehensive report, and

[0038] - a deep-learning artificial intelligence-based algorithm to interpret the structured contents of the comprehensive report and to generate human-like text in the comprehensive report. Here, 'human-like text' means text that is clear, understandable by the reader and relevant to the subject or matter at hand, as if it were prepared by a human author.

[0039] The centralized network traffic monitoring and intrusion detection system for a user's computer network according to the first aspect of the invention, the means for alerting the user of threats according to the severity of a security incident, transmits the comprehensive report preferably by email or other communication protocols.

[0040] In a second aspect, the invention provides a method of centrally monitoring network traffic and detecting intrusions to a user's computer network. The method of centrally monitoring network traffic and detecting intrusions to a user's computer network comprises the steps of: receiving / collecting from the user's network devices the syslog / system logging protocol messages generated by the network device,

[0041] - decoding the user's syslog / system logging protocol messages received by parsing, and translating the syslog / system logging protocol messages into data with a uniform and structured format to facilitate analysis of the syslog data,

[0042] - comparing the decoded data with a database of IP reputations such as malicious IP addresses and domain names, and then tagging the data which match the contents of the database for further investigation,

[0043] - indexing the tagged data to optimize searchability and accessibility and then storing the indexed data for use as a reference for rapid threat detection and response,

[0044] - fetching / retrieving / extracting the indexed data for subsequent analysis according to key event categories that are indicative of potential security threats or breaches, wherein the key event categories comprise a) unblocked alert-level events b) flagged indicators of concern events c) top unblocked IP's and d) top unblocked hostnames,

[0045] - checking and correlating the retrieved indexed data relating to IP addresses and hostnames against a continuously updated database of known malicious activities to detect newly identified threats,

[0046] - analysing the checked and correlated data by an artificial intelligence-based algorithm to identify patterns, anomalies and potential security incidents, and prioritising the analysed data by assigning a risk score / factor according to importance / severity,

[0047] - compiling the analysed and prioritized data, and generating a comprehensive report that includes the details of a security incident, nature of the threat, system and data potentially affected, a severity assessment and actionable recommendations for mitigating the threat posed by the security incident,

[0048] - alerting the user of threats according to the severity of a security incident,

[0049] - generating / publishing updated lists of bad IP addresses and hostnames based on the comprehensive report generated, and

[0050] - automatically updating a user's network devices with the updated lists of bad IP addresses and hostnames.

[0051] In the method of centrally monitoring network traffic and detecting intrusions to a user's computer network according to the second aspect of the invention, the steps are preferably carried out remotely by a service provider. In the method of centrally monitoring network traffic and detecting intrusions to a user's computer network according to the second aspect of the invention, the step of receiving / collecting from the user's network devices the syslog / system logging protocol messages generated by the network device is preferably carried out by a machine learning artificial intelligence-based algorithm.

[0052] In the method of centrally monitoring network traffic and detecting intrusions to a user's computer network according to the second aspect of the invention, the step of analysing the checked and correlated data by an artificial intelligence-based algorithm to identify patterns, anomalies and potential security incidents, and prioritising the analysed data by assigning a risk score / factor according to importance / severity is preferably carried out by a machine-learning artificial intelligence-based algorithm.

[0053] In the method of centrally monitoring network traffic and detecting intrusions to a user's computer network according to the second aspect of the invention, the step of compiling the analysed and prioritized data and generating a comprehensive report that includes the details of a security incident, nature of the threat, system and data potentially affected, a severity assessment and actionable recommendations for mitigating the threat posed by the security incident is preferably carried out by a deep-learning artificial intelligence-based algorithm.

[0054] In the method of centrally monitoring network traffic and detecting intrusions to a user's computer network according to the second aspect of the invention, the step of alerting the user of threats according to the severity of a security incident includes transmitting the comprehensive report generated preferably by email or other communication protocols.

[0055] In a third aspect, the invention provides a computer-readable storage medium and one or more computer programs stored which contain instructions that, when executed, causes the computer- readable storage medium to: receive / collect from the user's network devices the syslog / system logging protocol messages generated by the network device,

[0056] - decode the user's syslog / system logging protocol messages received by parsing, and translate the syslog / system logging protocol messages into data with a uniform and structured format to facilitate analysis of the syslog data, - compare the decoded data with a database of IP reputations such as malicious IP addresses and domain names, and then tag the data which match the contents of the database for further investigation,

[0057] - index the tagged data to optimize searchability and accessibility and then store the indexed data for use as a reference for rapid threat detection and response,

[0058] - fetch / retrieve / extract the indexed data for subsequent analysis according to key event categories that are indicative of potential security threats or breaches, namely a) unblocked alert-level events b) flagged indicators of concern events c) top unblocked IP's and d) top unblocked hostnames,

[0059] - check and correlate the retrieved indexed data relating to IP addresses and hostnames against a continuously updated database of known malicious activities to detect newly identified threats,

[0060] - analyse the checked and correlated data by an artificial intelligence-based algorithm to identify patterns, anomalies and potential security incidents, and prioritise the analysed data by assigning a risk score / factor according to importance / severity,

[0061] - compile the analysed and prioritized data, and generate a comprehensive report that includes the details of a security incident, nature of the threat, system and data potentially affected, a severity assessment and actionable recommendations for mitigating the threat posed by the security incident,

[0062] - alert the user of threats according to the severity of a security incident,

[0063] - generate / publish updated lists of bad IP addresses and hostnames based on the comprehensive report generated, and

[0064] - automatically update a user's network devices with the updated lists of bad IP addresses and hostnames.

[0065] DESCRIPTION OF THE DRAWINGS

[0066] The invention is illustrated, though not limited by the following description of the embodiments that is being given by way of example only, with reference to the accompanying drawings in which:

[0067] Figure 1 illustrates a block diagram of the centralized network traffic monitoring and intrusion detection system for a user's computer network according to the first aspect of the invention. Figure 2 illustrates a flow chart of the method of centrally monitoring network traffic and detecting intrusions to a user's computer network according to the second aspect of the invention.

[0068] DETAILED DESCRIPTION OF THE INVENTION

[0069] Figure 1 illustrates in the form of a block diagram, the individual blocks / modules which make up the centralized network traffic monitoring and intrusion detection system 1 for a user's computer network according to the first aspect of the invention.

[0070] For the purpose of explaining the invention, the centralized network traffic monitoring and intrusion detection system 1 for a user's computer network according to the first aspect of the invention may be visualized as essentially comprising the following blocks / modules:

[0071] 1. a system log aggregation block / module 110,

[0072] 2. an analysis and alert block / module 120, and

[0073] 3. a Bad IP Feed block / module 130.

[0074] The system log aggregation block / module 110 in turn comprises: la) a Syslog Collector 111, lb) a Data Decoder 112, lc) an loC Marker 113, ld) an Event Indexer 114, and

[0075] The analysis and alert block / module 120 in turn comprises:

[0076] 2a) an Event Fetcher 121

[0077] 2b) a Malicious IP / Host Checker 122,

[0078] 2c) an Al Analyzer 123, and

[0079] 2d) an Incident Reporter and Alerter 124.

[0080] The Bad IP Feed block / module 130 in turn comprises:

[0081] 3a) a Bad IP Feeder 131. The syslog collector 111 serves as a means for receiving from the user's network devices the syslog / system logging protocol messages that are generated by the network device.

[0082] The syslog collector 111 utilises a machine learning artificial intelligence-based algorithm to aid in processing the syslog / system logging protocol messages that are received from a user's network device.

[0083] The syslog collection process is initiated by a user's network device following configurations made within their firewall log forwarding settings. This setup ensures that logs are automatically transmitted to the system, providing a real-time stream of data regarding network activity. The collection mechanism is designed to be compatible with a wide range of device types and firewall models, allowing for a seamless integration into the customer's existing security infrastructure.

[0084] As logs are generated by the customer's devices, they encapsulate detailed records of network events, security alerts, and other relevant operational data. These logs are forwarded based on predefined rules set within the firewall, ensuring that all pertinent information is captured without overwhelming the system with extraneous data.

[0085] The syslog collector 111 essentially acts as a centralized repository for the syslog / system logging protocol messages received from a user's network device, and prepares it for the subsequent stages of decoding, analysis, and threat management. It is robust enough to handle high volumes of data and is designed to operate efficiently, ensuring minimal latency in the collection and processing of logs.

[0086] The data decoder 112 serves as a means for decoding the syslog / system logging protocol messages received by the syslog collector 111 by parsing and translating the syslog / system logging protocol messages into data with a uniform and structured format to facilitate the subsequent analysis of the syslog data. This includes breaking down each message into its constituent parts, such as source IP, destination IP, timestamp, log level, and the specific event message.

[0087] The decoding of the syslog / system logging protocol messages received by the syslog collector 111 is a critical step as it facilitates the conversion of numerous and varied log entries from different devices into a uniform format, enabling efficient and effective analysis. The structured data which is processed by the data decoder 112 provides the foundation for the system's AI- based analysis and threat identification processes. The loC marker 113 serves as a means for comparing the data from the data decoder 112 with a database of IP reputations and then tagging the data which match the contents of the database for further investigation.

[0088] An loC (Indicator of Compromise) is an artifact that has been observed on a network or in an operating system, that indicates with high confidence, the occurrence of an intrusion.

[0089] The database of IP reputations includes dynamic lists of known malicious IP addresses and domain names gathered from multiple trusted sources. As soon as newly received data is decoded, it is immediately checked against these lists. If a match is found, the system tags the data accordingly, flagging it for further investigation and action.

[0090] The event indexer 114 serves as a means for indexing the tagged data from the loC marker 113 to optimize searchability and accessibility and then storing the indexed data for use as a reference for rapid threat detection and response.

[0091] The indexing of events is akin to creating a detailed map of the data, allowing the system to quickly locate and retrieve specific entries based on various search criteria. This could include sorting by severity, time frame, source IP, or any other relevant identifier. A well-indexed database is crucial for rapid threat detection and response, ensuring that the system can keep pace with the high rate and volume of data being received and processed.

[0092] The event fetcher 121 serves as a means for fetching / retrieving / extracting the indexed data from the event indexer 114 for subsequent analysis according to key event categories that are indicative of potential security threats or breaches.

[0093] The key event categories are a) unblocked alert-level events, b) flagged indicators of concern events, c) top unblocked IP's and d) top unblocked hostnames, and each of these key event categories are defined as follows. a) Unblocked alert-level events relate to unblocked events that are marked as alerts and have a severity rating of medium or higher, which indicates a potential threat that has not been automatically blocked. b) Flagged loC events relate to unblocked events where the IP or hostname has been flagged as an loC by the IP reputation list. c) Top unblocked IPs relates to the top 10 unblocked IP addresses, which could indicate a concentrated attack or a persistent threat. d) Top unblocked hostnames relate to the top 10 unblocked hostnames to watch for recurring patterns that might signify a security risk.

[0094] The malicious IP / host checker 122 serves as a means for checking and correlating the indexed data relating to IP addresses and hostnames retrieved by the event fetcher 121 against a database of known malicious activities to detect newly identified threats.

[0095] This database of known malicious activities is continually updated with the latest global threat intelligence, ensuring that the system's knowledge base is up-to-date and current. This step is critical for capturing any newly identified threats that may not be included in the local reputation list at a given point in time.

[0096] The Al analyser 123 serves as a means for analysing the checked and correlated data from the malicious IP / host checker 122 to identify patterns, anomalies and potential security incidents, and prioritising the analysed data by assigning a risk score / factor according to importance / severity.

[0097] The incident reporter and alerter 124 serves as a means for compiling the analysed and prioritized data from the Al analyser 123 and generating a comprehensive report that includes the details of a security incident, nature of the threat, system and data potentially affected, a severity assessment and actionable recommendations for mitigating the threat posed by the security incident.

[0098] These reports are generated in a clear and concise format, suitable for both technical and nontechnical stakeholders, ensuring that the insights are accessible and actionable.

[0099] In addition, the incident reporter and alerter 124 also serves as a means for alerting the user of threats according to the severity of a security incident for communicating the comprehensive report generated by the means for compiling the analysed and prioritized data and generating a comprehensive report. The threat alerts are designed to grab the attention of the user, ensuring that they are aware of the threats and understand the recommended actions. The alerting process is configured to prioritize high-severity incidents, ensuring that the most urgent threats are addressed first.

[0100] To accomplish the above, the Al analyser 123 and incident reporter 124 both utilize a combination of machine-learning and deep-learning Al-based algorithms.

[0101] A machine-learning artificial intelligence-based algorithm is utilized to analyse the checked and correlated data to identify patterns, anomalies and potential security incidents including the identification of spikes in network traffic from certain IP addresses, hostnames or regions, and abnormal patterns of access, and then to interpret the analysed and prioritized data in the context of the conditions and environment of a network in order to understand its significance, to structure the contents for the comprehensive report.

[0102] Thereafter, a deep-learning artificial intelligence-based algorithm is utilized to interpret the structured contents of the comprehensive report for the purpose of generating human-like text (i.e., text that is clear, understandable by the reader and relevant to the subject or matter at hand, which has the appearance of being authored by a human) in the contents of the comprehensive report that is generated.

[0103] The Bad IP Feeder 131 serves as a means for generating and publishing updated lists of bad IP addresses and hostnames based on the comprehensive report generated by the Al analyser 123.

[0104] In addition to the above, the Bad IP Feeder 301 also serves as a means for automatically updating a user's network devices with the updated lists of bad IP addresses and hostnames.

[0105] The Bad IP Feeder 131 alerts a user of threats according to the severity of a security incident by transmitting the comprehensive report direct to the user. This may be accomplished by email or any other suitable communication protocols.

[0106] Integration of the Bad IP Feed into the customer's security infrastructure enhances the overall protective capabilities of the network, ensuring that the most up-to-date defences are always in place.

[0107] The Bad IP Feed feature is structured to be automatically ingested by customer firewalls or other security devices, allowing them to pre-emptively block potentially harmful traffic. The Bad IP Feed is updated on a continuous update cycle, ensuring that the latest threat intelligence is rapidly disseminated. As the Al component of the system identifies and confirms new threat sources, these IPs are added to the feed in near real-time. Conversely, IPs can also be removed from the feed if they are deemed no longer a threat, preventing unnecessary blocking that could interfere with legitimate network operations.

[0108] This proactive blocking mechanism serves as a critical first line of defense, reducing the window of opportunity for attackers to exploit vulnerabilities. By automating the blocking process, the system minimizes the need for human intervention, allowing security teams to allocate their resources to more complex tasks that require expert analysis and decision-making.

[0109] The centralized network traffic monitoring and intrusion detection system for a user's computer network according to the first aspect of the invention is embodied as a computer program that is stored in a remote computer readable storage medium such as a computer server (i.e., a physical server), or perhaps a cloud-based server (i.e., a virtual server) operated by a service provider that may be accessed by a user's network devices, which may be a network firewall, a computer server, a computer switch or a workstation, or even a combination of these devices.

[0110] A user's network device will access the centralized network traffic monitoring and intrusion detection system for a user's computer network according to the first aspect of the invention by transmitting the syslog / system logging protocol messages that are generated by the device via a secure link that has been prepared and provided by the service provider using TCP / IP or UDP (User Datagram Protocol).

[0111] The transmission of the syslog / system logging protocol messages via the secure link is automatic, requiring no additional intervention from the user and the continuous transmission provides a real-time stream of data regarding network activity to the centralized network traffic monitoring and intrusion detection system. This ensures a consistent and comprehensive collection of data, which is critical for maintaining an up-to-date and accurate overview of the network's security posture.

[0112] Figure 2 illustrates in the form of a flow chart, the method of centrally monitoring network traffic and detecting intrusions to a user's computer network according to the second aspect of the invention. The method of centrally monitoring network traffic and detecting intrusions to a user's computer network commences with the step of the system receiving S201 from the user's network devices the syslog / system logging protocol messages generated by the network device.

[0113] This is followed by the step of decoding S202 the user's syslog / system logging protocol messages received by parsing and translating the syslog / system logging protocol messages into data with a uniform and structured format to facilitate analysis of the syslog data.

[0114] Next, follows the step of comparing S203 the decoded data with a database of IP reputations such as malicious IP addresses and domain names, and then tagging the data which match the contents of the database for further investigation.

[0115] Thereafter, comes the step of indexing S204 the tagged data to optimize searchability and accessibility and then storing the indexed data for use as a reference for rapid threat detection and response.

[0116] Next, comes the step of fetching / retrieving / extracting S205 the indexed data for subsequent analysis according to key event categories that are indicative of potential security threats or breaches. The step of fetching S205 is carried out according to the key event categories which comprise a) unblocked alert-level events, b) flagged indicators of concern events, c) top unblocked IP's and d) top unblocked hostnames.

[0117] This is followed by the step of checking and correlating S206 the retrieved indexed data relating to IP addresses and hostnames against a continuously updated database of known malicious activities to detect newly identified threats.

[0118] This is followed by the step of analysing S207 the checked and correlated data by an artificial intelligence-based algorithm to identify patterns, anomalies and potential security incidents, and prioritising the analysed data by assigning a risk score / factor according to importance / severity.

[0119] Thereafter, comes the step of compiling S208 the analysed and prioritized data, and generating a comprehensive report that includes the details of a security incident, nature of the threat, system and data potentially affected, a severity assessment and actionable recommendations for mitigating the threat posed by the security incident. The preceding step is immediately followed by the step of alerting S209 the user of threats according to the severity of a security incident.

[0120] Finally, comes the step of generating / publishing S210 the updated lists of bad IP addresses and hostnames based on the comprehensive report generated, and automatically updating a user's network devices with the updated lists of bad IP addresses and hostnames.

[0121] Since the centralized network traffic monitoring and intrusion detection system for a user's computer network according to the first aspect of the invention may also be embodied as a computer program that is stored in a remote computer readable storage medium, a third aspect of the invention relates to a computer-readable storage medium and one or more computer programs which are stored in the computer-readable storage medium, that when executed, causes the computer-readable storage medium to carry out the method according to the second aspect of the invention.

[0122] As can be seen from the foregoing, the present invention provides an effective solution to the problem of dealing with ever-increasing volumes of threats to a computer network which also evolve rapidly and unceasingly.

[0123] The present invention is not limited to what has been disclosed here, as the description serves only to exemplify the invention and further modifications are readily apparent without departing from the scope of the invention.

Claims

CLAIMS1. A centralized network traffic monitoring and intrusion detection system (1) for a user's computer network, said system comprising: a system log aggregation block / module (110) including: a means for receiving / collecting (111) from the user's network devices the syslog / system logging protocol messages that are generated by the network device; a means for decoding (112) the user's syslog / system logging protocol messages received by parsing and translating the syslog / system logging protocol messages into data with a uniform and structured format to facilitate analysis of the syslog data; a means for comparing (113) the data from the means for decoding with a database of IP reputations such as malicious IP addresses and domain names and then tagging the data which match the contents of the database for further investigation; and a means for indexing (114) the tagged data to optimize searchability and accessibility and then storing the indexed data for use as a reference for rapid threat detection and response; an analysis and alert block / module including (120): a means for fetching / retrieving / extracting (121) the indexed data for subsequent analysis according to key event categories that are indicative of potential security threats or breaches, wherein the key event categories comprise a) unblocked alert-level events b) flagged indicators of concern events c) top unblocked IP's and d) top unblocked hostnames; a means for checking and correlating (122) the retrieved indexed data relating to IP addresses and hostnames against a continuously updated database of known malicious activities to detect newly identified threats; a means for analysing (123) the checked and correlated data to identify patterns, anomalies and potential security incidents, and prioritising the analysed data by assigning a risk score / factor according to importance / severity; a means for compiling (124) the analysed and prioritized data and generating a comprehensive report that includes the details of a security incident, nature of the threat, system and data potentially affected, a severity assessment and actionable recommendations for mitigating the threat posed by the security incident; and a means for alerting (124) the user of threats according to the severity of a security incident for communicating the comprehensive report generated by the means for compiling the analysed and prioritized data and generating a comprehensive report; anda Bad IP Feed block / module (130) including: a means for generating / publishing (131) updated lists of bad IP addresses and hostnames based on the comprehensive report generated by the means for compiling the analysed and prioritized data; and a means for automatically updating (131) a user's network devices with the updated lists of bad IP addresses and hostnames.

2. The centralized network traffic monitoring and intrusion detection system (1) for a user's computer network according to claim 1, wherein the system is remotely operated by a service provider.

3. The centralized network traffic monitoring and intrusion detection system (1) for a user's computer network according to claim 1 or claim 2, wherein the network devices may be a network firewall, a computer server, a computer switch or a workstation.

4. The centralized network traffic monitoring and intrusion detection system (1) for a user's computer network according to any of the preceding claims, wherein the system log aggregation block / module (110) uses a machine learning artificial intelligence-based algorithm to process the syslog / system logging protocol messages received from a user's network device.

5. The centralized network traffic monitoring and intrusion detection system (1) for a user's computer network according to any of the preceding claims, wherein the analysis and alert block / module (120) uses: a machine-learning artificial intelligence-based algorithm to analyse the checked and correlated data to identify patterns, anomalies and potential security incidents including the identification of spikes in network traffic from certain IP addresses, hostnames or regions, and abnormal patterns of access, and to interpret the analysed and prioritized data in the context of the conditions and environment of a network in order to understand its significance, to structure the contents for the comprehensive report; and a deep-learning artificial intelligence-based algorithm to interpret the structured contents of the comprehensive report and to generate human-like text in the comprehensive report that is generated.

6. The centralized network traffic monitoring and intrusion detection system (1) for a user's computer network according to any of the preceding claims, wherein the means for alerting theuser of threats according to the severity of a security incident transmits the comprehensive report by email or other communication protocols.

7. A method (2) of centrally monitoring network traffic and detecting intrusions to a user's computer network, said method comprising the steps of: receiving / collecting (S201) from the user's network devices the syslog / system logging protocol messages generated by the network device; decoding (S202) the user's syslog / system logging protocol messages received by parsing, and translating the syslog / system logging protocol messages into data with a uniform and structured format to facilitate analysis of the syslog data; comparing (S203) the decoded data with a database of IP reputations such as malicious IP addresses and domain names, and then tagging the data which match the contents of the database for further investigation; indexing (S204) the tagged data to optimize searchability and accessibility and then storing the indexed data for use as a reference for rapid threat detection and response; fetching / retrieving / extracting (S205) the indexed data for subsequent analysis according to key event categories that are indicative of potential security threats or breaches, wherein the key event categories comprise a) unblocked alert-level events b) flagged indicators of concern events c) top unblocked IP's and d) top unblocked hostnames; checking and correlating (S206) the retrieved indexed data relating to IP addresses and hostnames against a continuously updated database of known malicious activities to detect newly identified threats; analysing (S207) the checked and correlated data by an artificial intelligence-based algorithm to identify patterns, anomalies and potential security incidents, and prioritising the analysed data by assigning a risk score / factor according to importance / severity; compiling (S208) the analysed and prioritized data, and generating a comprehensive report that includes the details of a security incident, nature of the threat, system and data potentially affected, a severity assessment and actionable recommendations for mitigating the threat posed by the security incident; alerting (S209) the user of threats according to the severity of a security incident; and generating / publishing (S210) updated lists of bad IP addresses and hostnames based on the comprehensive report generated; and automatically updating (S210) a user's network devices with the updated lists of bad IP addresses and hostnames.

8. The method (2) of centrally monitoring network traffic and detecting intrusions to a user's computer network according to claim 7, wherein the steps are carried out remotely by a service provider.

9. The method (2) of centrally monitoring network traffic and detecting intrusions to a user's computer network according to claim 7 or 8, wherein the step of receiving / collecting (S201) from the user's network devices the syslog / system logging protocol messages generated by the network device is carried out by a machine learning artificial intelligence-based algorithm.

10. The method (2) of centrally monitoring network traffic and detecting intrusions to a user's computer network according to any of claims 7 to 9, wherein the step of analysing (S207) the checked and correlated data by an artificial intelligence-based algorithm to identify patterns, anomalies and potential security incidents, and prioritising the analysed data by assigning a risk score / factor according to importance / severity is carried out by a machine-learning artificial intelligence-based algorithm.

11. The method (2) of centrally monitoring network traffic and detecting intrusions to a user's computer network according to any of claims 7 to 10, wherein the step of compiling (S208) the analysed and prioritized data, and generating a comprehensive report that includes the details of a security incident, nature of the threat, system and data potentially affected, a severity assessment and actionable recommendations for mitigating the threat posed by the security incident is carried out by a deep-learning artificial intelligence-based algorithm.

12. The method (2) of centrally monitoring network traffic and detecting intrusions to a user's computer network according to any of claims 7 to 11, wherein the step of alerting (S209) the user of threats according to the severity of a security incident includes communicating transmitting the comprehensive report generated by email or other communication protocols.

13. A computer-readable storage medium and one or more computer programs stored therein, the computer programs containing instructions, which when executed, causes the computer-readable storage medium to: receive / collect from the user's network devices the syslog / system logging protocol messages generated by the network device; decode the user's syslog / system logging protocol messages received by parsing, and translate the syslog / system logging protocol messages into data with a uniform and structured format to facilitate analysis of the syslog data;compare the decoded data with a database of IP reputations such as malicious IP addresses and domain names, and then tag the data which match the contents of the database for further investigation; and index the tagged data to optimize searchability and accessibility and then store the indexed data for use as a reference for rapid threat detection and response; fetch / retrieve / extract the indexed data for subsequent analysis according to key event categories that are indicative of potential security threats or breaches, wherein the key event categories comprise a) unblocked alert-level events b) flagged indicators of concern events c) top unblocked IP's and d) top unblocked hostnames, check and correlate the retrieved indexed data relating to IP addresses and hostnames against a continuously updated database of known malicious activities to detect newly identified threats; analyse the checked and correlated data by an artificial intelligence-based algorithm to identify patterns, anomalies and potential security incidents, and prioritise the analysed data by assigning a risk score / factor according to importance / severity; compile the analysed and prioritized data, and generate a comprehensive report that includes the details of a security incident, nature of the threat, system and data potentially affected, a severity assessment and actionable recommendations for mitigating the threat posed by the security incident; alert the user of threats according to the severity of a security incident; generate / publish updated lists of bad IP addresses and hostnames based on the comprehensive report generated; and automatically update a user's network devices with the updated lists of bad IP addresses and hostnames.

Citation Information

Patent Citations

  • Artificial intelligence with cyber security

    US10158653B1

  • System, method and computer-accessible medium for network intrusion detection

    US10735438B2

  • Anomaly detection based on communication between entities over a network

    US11258807B2

  • Identifying malicious network devices

    US11425148B2

Cited By

  • Automatic log abnormity analysis system

    CN120415903A

  • Network security situation awareness system and method based on multiple dimensions

    CN120750680A

  • Network security supervision system based on artificial intelligence technology

    CN121333783A

  • Data security protection method and system of data center

    CN121547186A

  • Intelligent aggregation noise reduction and risk assessment method and system for network security alarm

    CN121966928A