Compound Attack Detection in Network Intrusion Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques for detecting network attacks rely solely on pattern matching, which is inadequate for identifying sophisticated attack behaviors, especially those involving protocol anomalies that cannot be easily detected through text-based methods.

Innovation Solution

An intrusion detection and prevention (IDP) device integrates textual and non-textual pattern matching with protocol-specific anomaly detection, allowing administrators to define compound attack signatures that combine patterns and protocol anomalies to identify complex attack behaviors, and selectively discards malicious packet flows.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional pattern matching techniques are used for attack detection, then the detection method is simple and easy to implement, but the detection accuracy is insufficient for sophisticated attacks

Engineering Contradiction:
Improveattack detection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent combines multiple detection techniques (pattern matching, protocol anomaly detection, and compound attack definition) into a unified intrusion detection system. The IDP device integrates these different approaches to work together, allowing the system to detect both simple pattern-based attacks and complex protocol anomalies simultaneously, thereby improving detection accuracy without requiring completely separate systems

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The intrusion detection and prevention device is designed to perform multiple functions: it can detect known attacks using pattern matching, identify unknown attacks through protocol anomaly detection, and prevent attacks by blocking malicious packet flows. This multi-functional approach allows a single system to address diverse attack types while maintaining manageable complexity through integrated design

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If multiple patterns are used to improve attack detection accuracy, then the detection coverage increases, but the difficulty of detecting certain attacks remains

Engineering Contradiction:
Improveattack detection accuracyVSAvoidattack detection difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces protocol anomaly detection as an intermediary mechanism that bridges the gap between pattern matching and sophisticated attack detection. Instead of relying solely on complex pattern combinations, the system uses protocol knowledge and anomaly detection to identify attacks that deviate from expected behavior, making detection easier while maintaining high accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the detection parameters by moving from purely text-based pattern matching to include protocol-specific parameters and anomaly thresholds. By defining compound attack definitions that incorporate both patterns and protocol anomalies, the system adapts its detection parameters to match the specific characteristics of different attack types, reducing detection difficulty while improving accuracy

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If the IDP device applies compound attack definitions to analyze packet flows, then the detection capability improves, but the processing time and system resources increase

Engineering Contradiction:
Improveattack detection accuracyVSAvoidpacket flow processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-defining compound attack definitions and protocol anomaly rules before actual packet flow analysis. This allows the IDP device to have detection criteria ready in advance, enabling faster matching and evaluation during real-time packet inspection, thereby reducing processing time while maintaining high detection accuracy

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8209756B1Compound attack detection in a computer network
Publication Date: 2012.06.26 JUNIPER NETWORKS INC
  • US8209756B1 patent drawing
  • US8209756B1 patent drawing
  • US8209756B1 patent drawing

AI summary

An intrusion detection and prevention (IDP) device includes an attack detection module and a forwarding component. The attack detection module applies a compound attack definition to a packet flow of a computer network to determine whether the packet flow includes at least one pattern and at least one protocol anomaly. The forwarding component selectively discards the packet flow based on the determination. The IDP device may further include a reassembly module to form application-layer communications from the packet flows, and a plurality of protocol-specific decoders to process the application-layer communications to extract application-layer elements and detect protocol anomalies.