Application-Aware Intrusion Detection System for Network Threat Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer networks face challenges in monitoring and managing complex web services, particularly in correlating monitoring and logging data across disparate systems, tools, and layers, which hinders the detection and mitigation of network-based threats such as DoS attacks and other security breaches, impacting service performance and user experience.

Innovation Solution

An application-aware intrusion detection system that monitors activity across multiple applications, identifies business transactions, and correlates network traffic details to initiate specific threat mitigation by associating network flows with corresponding business transactions, utilizing a combination of network agents and intrusion detection systems to flag and address security threats in real-time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If traditional monitoring and logging systems are used across disparate network systems, then data collection is possible, but correlating data across systems and connecting the chain of events becomes increasingly difficult

Engineering Contradiction:
Improvedata correlation capabilityVSAvoidsystem integration complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent introduces a correlation engine as an intermediary component that receives monitoring data from multiple disparate systems and logging infrastructure. This correlation engine processes and correlates events across different network systems, connecting the chain of events and cause-effect relationships that would otherwise be difficult to establish across independent systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The monitoring system is designed with universal data collection capabilities that can gather information from multiple disparate network systems, tools, and layers through a unified interface. The system performs multiple functions including data collection, correlation, analysis, and threat detection within a single integrated platform, reducing the complexity of managing separate monitoring systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If comprehensive monitoring of all network traffic is implemented to detect threats, then detection capability is improved, but system performance and user experience deteriorate due to increased processing overhead

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidservice performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies different levels of monitoring intensity and analysis depth to different network flows and traffic types. Rather than uniformly processing all traffic with the same level of scrutiny, the system adapts its monitoring approach based on the specific characteristics, risk profiles, and business criticality of different applications and transactions, optimizing the balance between detection capability and performance impact.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements selective monitoring that focuses computational resources on analyzing specific suspicious patterns and high-risk traffic flows rather than processing every packet with equal depth. The correlation engine applies analysis only where needed based on preliminary detection cues, avoiding excessive processing of benign traffic while maintaining comprehensive threat detection coverage.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If detailed correlation of network flows to business transactions is implemented, then threat impact assessment is improved, but data processing time and computational resources increase

Engineering Contradiction:
Improvethreat impact measurementVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary correlation and tagging of network flows with business transaction identifiers during normal operation, maintaining ready-to-use mappings between network traffic and business processes. When a threat is detected, the pre-established correlations enable immediate impact assessment without requiring time-consuming real-time analysis of which business transactions are affected.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10862921B2Application-aware intrusion detection system
Publication Date: 2020.12.08 CISCO TECHNOLOGY INC
  • US10862921B2 patent drawing
  • US10862921B2 patent drawing
  • US10862921B2 patent drawing

AI summary

In one embodiment, activity of a plurality of applications in a computer network is monitored, and a plurality of individual business transactions occurring within the plurality of applications may be identified. Additionally network traffic details associated with each particular business transaction of the plurality of individual business transactions may be determined. In response to detecting a network-based threat on a particular network flow within the computer network, the techniques herein may correlate the particular network flow to a corresponding business transaction of the plurality of individual business transactions based on the associated network traffic details of the corresponding business transaction. Accordingly, threat mitigation may be initiated specific to the corresponding business transaction in response to the detected network-based threat being correlated to the corresponding business transaction.