Cloned Network Environment for Malicious Traffic Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network traffic monitoring methods face challenges in developing and validating efficient and accurate network security detection, as they often rely on replaying copies of malicious traffic, which can risk live networks and are less effective with the shift towards machine learning that requires realistic data for training classifiers.

Innovation Solution

A computer-implemented system and method that creates a test network environment by cloning nodes from a host network, generating records of communication metadata, and overlaying test traffic onto live network traffic to train detection models, allowing for accurate malicious traffic detection without risking the live network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional methods replay copies of malicious traffic for testing, then detection capabilities can be validated, but the live network is placed at actual risk and the testing is less effective for machine learning

Engineering Contradiction:
Improvedetection accuracyVSAvoidrisk to live network
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates a cloned network environment that replicates the structure, topology, and behavior of the live network. This clone serves as a safe test bed where malicious traffic can be injected and detected without risking the actual live network. The cloning process preserves network characteristics while isolating the testing environment, allowing realistic detection validation without harmful effects to production systems.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If conventional methods use replayed malicious traffic, then testing can proceed, but the data is not realistic enough for effective machine learning training

Engineering Contradiction:
Improveeffectiveness for machine learningVSAvoidrealism of training data
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The cloned network environment generates authentic network traffic patterns, metadata, and communication flows that mirror the live network's real behavior. This provides machine learning models with realistic training data that captures actual network dynamics, protocols, and traffic characteristics, rather than synthetic or replayed data that lacks the nuance and variability of real-world networks.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The cloned network acts as an intermediary between theoretical detection algorithms and the live production network. It provides a intermediate testing layer that generates realistic data for training and validation, bridging the gap between controlled experiments and real-world deployment without exposing the actual network to risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If live production nodes are used for testing detection models, then realistic detection scenarios can be tested, but the network security is compromised

Engineering Contradiction:
Improvedetection validation accuracyVSAvoidnetwork security
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

Instead of using live production nodes, the patent creates a cloned network that replicates their structure and behavior. This clone allows detection models to be tested against realistic network scenarios including actual traffic patterns, device configurations, and communication protocols, while maintaining network security by isolating all testing activities to the cloned environment.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11588841B2Generating malicious network traffic detection models using cloned network environments
Publication Date: 2023.02.21 CISCO TECHNOLOGY INC
  • US11588841B2 patent drawing
  • US11588841B2 patent drawing

AI summary

Techniques and mechanisms are disclosed for creating an environment for detecting malicious network traffic. A test computer network including a plurality of cloned nodes is created. The plurality of cloned nodes in the test computer network corresponds to at least some of a plurality of target nodes of a host computer network, and the test computer network has no network connectivity to the host computer network. Sensors in both the host computer network and the test computer network generate network flow records that are sent to a detection processing pipeline. The detection processing pipeline merges the records received from the sensors and uses the merged records to train at least one model used to identify instances of malicious network traffic.