Attribute-Based Network Intrusion Detection Model
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Network Intrusion Detection Systems (NIDS) face challenges in adapting to changes in data communication networks, leading to high false positives and the need for manual updates, as they struggle to differentiate between legitimate changes and malicious activities, especially with the dynamic nature of networks and the introduction of new devices.
Innovation Solution
A method that involves parsing data traffic to extract protocol field values, deriving attribute values, selecting and updating models, and assessing compliance with attribute-based policies to generate alerts, allowing for automatic adaptation to network changes without manual intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If whitelisting systems maintain a model of normal behavior to detect both known and unknown attacks, then detection capability is improved, but false positive rate increases
Solution Approach 1:
The patent implements dynamic model updating where the normal behavior model automatically adapts to legitimate network changes over time. The system continuously learns from observed traffic patterns and updates the whitelist model without manual intervention, allowing it to distinguish between legitimate changes and actual attacks, thereby reducing false positives while maintaining detection capability.
Solution Approach 2:
The system incorporates feedback mechanisms where detection results and traffic patterns are continuously analyzed to refine the normal behavior model. By monitoring the performance and adjusting the model based on observed legitimate changes, the system reduces false positives while maintaining high detection accuracy for actual threats.
2Measurement precision
If whitelisting systems manually update the model for each legitimate change, then detection accuracy is maintained, but operational complexity increases
Solution Approach 1:
The patent implements automated model updating where the intrusion detection system performs self-updating of the normal behavior model without requiring manual operator intervention. The system automatically learns from observed traffic patterns, identifies legitimate changes, and updates the whitelist model autonomously, thereby maintaining detection accuracy while eliminating the operational complexity of manual updates.
Solution Approach 2:
The system performs preliminary learning during a baseline period to establish the normal behavior model before actual detection begins. This preliminary action allows the model to be pre-configured with accurate normal patterns, reducing the need for subsequent manual updates while maintaining high detection accuracy throughout operation.
3Object-generated harmful factors
If blacklisting systems use well-defined attack specifications, then false positives are reduced, but ability to detect unknown attacks decreases
Solution Approach 1:
The patent transitions from static blacklisting to dynamic whitelisting where the normal behavior model continuously adapts to legitimate network changes. By maintaining an updated model of what constitutes normal behavior, the system can detect deviations representing unknown attacks while avoiding false positives from legitimate activities, thus achieving both low false positive rates and high adaptability to new threats.
Data Source
AI summary
A method of detecting anomalous behaviour in data traffic includes parsing data traffic to extract protocol field values of a protocol message of data traffic, deriving attribute values of attributes of one of the first host, the second host, and the link. The method includes selecting a model relating to the one of the first host, the second host, and the link. The mode includes at least one semantic attribute expressing a semantic meaning for the first host, the second host, or the link. The method further includes updating the selected model with the derived attribute values, assessing whether the updated model complies with a set of attribute-based policies defining a security constraint of the data communication network, and generating an alert signal in case the attribute-based policies indicate that the updated model violates at least one of the attribute-based policies.


