Application-Aware Intrusion Detection System for Network Threat Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer networks face challenges in monitoring and managing complex web services, particularly in correlating monitoring and logging data across disparate systems, tools, and layers, which hinders the detection and mitigation of network-based threats such as DoS attacks and other security breaches, impacting service performance and user experience.
Innovation Solution
An application-aware intrusion detection system that monitors activity across multiple applications, identifies business transactions, and correlates network traffic details to initiate specific threat mitigation by associating network flows with corresponding business transactions, utilizing a combination of network agents and intrusion detection systems to flag and address security threats in real-time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If traditional monitoring and logging systems are used across disparate network systems, then data collection is possible, but correlating data across systems and connecting the chain of events becomes increasingly difficult
Solution Approach 1:
The patent introduces a correlation engine as an intermediary component that receives monitoring data from multiple disparate systems and logging infrastructure. This correlation engine processes and correlates events across different network systems, connecting the chain of events and cause-effect relationships that would otherwise be difficult to establish across independent systems.
Solution Approach 2:
The monitoring system is designed with universal data collection capabilities that can gather information from multiple disparate network systems, tools, and layers through a unified interface. The system performs multiple functions including data collection, correlation, analysis, and threat detection within a single integrated platform, reducing the complexity of managing separate monitoring systems.
2Reliability
If comprehensive monitoring of all network traffic is implemented to detect threats, then detection capability is improved, but system performance and user experience deteriorate due to increased processing overhead
Solution Approach 1:
The system applies different levels of monitoring intensity and analysis depth to different network flows and traffic types. Rather than uniformly processing all traffic with the same level of scrutiny, the system adapts its monitoring approach based on the specific characteristics, risk profiles, and business criticality of different applications and transactions, optimizing the balance between detection capability and performance impact.
Solution Approach 2:
The system implements selective monitoring that focuses computational resources on analyzing specific suspicious patterns and high-risk traffic flows rather than processing every packet with equal depth. The correlation engine applies analysis only where needed based on preliminary detection cues, avoiding excessive processing of benign traffic while maintaining comprehensive threat detection coverage.
3Measurement precision
If detailed correlation of network flows to business transactions is implemented, then threat impact assessment is improved, but data processing time and computational resources increase
Solution Approach 1:
The system performs preliminary correlation and tagging of network flows with business transaction identifiers during normal operation, maintaining ready-to-use mappings between network traffic and business processes. When a threat is detected, the pre-established correlations enable immediate impact assessment without requiring time-consuming real-time analysis of which business transactions are affected.
Data Source
AI summary
In one embodiment, activity of a plurality of applications in a computer network is monitored, and a plurality of individual business transactions occurring within the plurality of applications may be identified. Additionally network traffic details associated with each particular business transaction of the plurality of individual business transactions may be determined. In response to detecting a network-based threat on a particular network flow within the computer network, the techniques herein may correlate the particular network flow to a corresponding business transaction of the plurality of individual business transactions based on the associated network traffic details of the corresponding business transaction. Accordingly, threat mitigation may be initiated specific to the corresponding business transaction in response to the detected network-based threat being correlated to the corresponding business transaction.


