Application-Specific Intrusion Detection for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection and prevention systems face challenges in accurately detecting and preventing network intrusions while minimizing false positives and handling encrypted traffic, often requiring frequent and potentially problematic patches for vulnerable applications, and struggling with the sheer volume of known exploits.

Innovation Solution

A system and methodology that focuses on per-application intrusion detection and prevention by defining specific intrusion descriptions for targeted applications, monitoring network traffic, and blocking malicious traffic, with a module that derives applicable intrusion descriptions and applies them to filter out exploits, thereby reducing false positives and improving detection accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional intrusion detection systems monitor all network traffic against all known exploits, then comprehensive security coverage is achieved, but false positives increase and system performance deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the intrusion detection process by application, creating separate detection streams for each application. The system divides the monolithic exploit database into application-specific subsets, monitoring traffic for each application against only its relevant exploits. This segmentation reduces false positives while maintaining comprehensive security coverage for each application.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by tailoring the detection rules and exploit subsets to each specific application's characteristics, vulnerabilities, and traffic patterns. Each application receives customized intrusion detection parameters rather than a one-size-fits-all approach, improving detection precision for each local context while maintaining overall system security.

Inventive Principle:
Principle #3Local quality

2Reliability

If intrusion detection systems use broad monitoring rules to catch all potential exploits, then security coverage is improved, but false positives increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidfalse positives
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The system segments the exploit database into application-specific subsets, so each application is monitored against only its relevant exploits rather than all known exploits. This reduces false positives generated by mismatched detection rules while maintaining comprehensive security coverage through the collective application-specific rule sets.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic adaptation by automatically adjusting the set of monitored exploits based on the detected application type and its known vulnerability profile. The system dynamically configures detection sensitivity and rule sets according to the specific application context, reducing false positives while maintaining security coverage.

Inventive Principle:
Principle #15Dynamics

3Reliability

If the system monitors network traffic for all known exploits across all applications, then comprehensive intrusion detection is achieved, but system complexity and processing overhead increase

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the intrusion detection system into application-specific modules, each handling its own traffic and exploit subset. This modular segmentation reduces overall system complexity by allowing independent configuration and management of each application's security parameters while maintaining comprehensive detection capability across the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial action by monitoring each application against only its relevant exploit subset rather than all known exploits. This reduces processing overhead and system complexity for each individual application while collectively maintaining comprehensive intrusion detection coverage across all applications through the aggregation of their specific monitored sets.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If end point security products restrict access to trusted applications, then security control is improved, but legitimate application functionality may be blocked

Engineering Contradiction:
Improvesecurity controlVSAvoidapplication functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic security control that adapts to the specific application and its legitimate traffic patterns. Rather than static blocking rules, the system dynamically adjusts monitoring sensitivity and detection thresholds based on the application's characteristics, allowing legitimate functionality to proceed while blocking actual intrusions specific to that application.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system applies local quality by customizing security controls for each specific application based on its vulnerability profile and traffic characteristics. This targeted approach ensures that security measures are tailored to the actual risks of each application, preventing over-blocking of legitimate functionality while maintaining strong security control where needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8074277B2System and methodology for intrusion detection and prevention
Publication Date: 2011.12.06 CHECK POINT SOFTWARE TECH INC
  • US8074277B2 patent drawing
  • US8074277B2 patent drawing
  • US8074277B2 patent drawing

AI summary

System and methodology for intrusion detection and prevention is described. In one embodiment, for example, a method is described for detecting and preventing network intrusion, the method comprises steps of: defining intrusion descriptions specifying exploits that may be attempted by malicious network traffic, the intrusion descriptions indicating specific applications that may be targeted by individual exploits; for a particular application participating in network communication, deriving a subset of the intrusion descriptions specifically applicable to that particular application; using the subset of the intrusion descriptions specifically applicable to that application, monitoring network traffic destined for the particular application for detecting an attempted network intrusion; and if a network intrusion is detected, blocking network traffic destined for the particular application determined to comprise an exploit.