Correlating Network and Intrusion Data to Identify Attack Entry Points

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection systems lack coordination with network equipment, making it difficult to quickly identify the entry point of attacks, leading to delayed response and potential misidentification of legitimate traffic as malicious, which can result in unintended filtering of important messages and overwhelming of firewalls during denial-of-service attacks.

Innovation Solution

A correlation engine is used to combine intrusion detection information with network information from routers to identify the logical and physical entry point of attacks, allowing for targeted blocking of malicious traffic and aiding in forensic investigations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If intrusion detection systems and network equipment operate separately without coordination, then device complexity is reduced, but the ability to quickly identify attack entry points deteriorates

Engineering Contradiction:
Improvesystem coordinationVSAvoidtime to identify entry point
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The patent merges intrusion detection information with network equipment information through a correlation engine that integrates data from multiple separate devices. This combination enables unified analysis of attack patterns across the network, allowing rapid identification of entry points without requiring complex manual coordination between separate systems.

Inventive Principle:
Principle #5Merging (Combining)

2Object-affected harmful factors

If source-address filtering is used to block denial of service attacks, then attack damage is limited, but legitimate customer messages are inadvertently filtered out

Engineering Contradiction:
Improveattack damageVSAvoidlegitimate message delivery
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent segments the network into multiple monitoring points and correlates attack data across these segments. By analyzing the spatial distribution and patterns of malicious traffic across different network segments, the system can distinguish between genuine customer messages and spoofed attack traffic, enabling selective blocking that protects against attacks while maintaining reliable delivery of legitimate messages.

Inventive Principle:
Principle #1Segmentation

3Loss of information

If technicians perform unstructured analysis of intrusion detection data, then comprehensive investigation is possible, but the entry point may not be found for several hours

Engineering Contradiction:
Improvecomprehensive investigationVSAvoidentry point identification speed
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent implements preliminary automated correlation and analysis of network data before human technicians need to intervene. The correlation engine pre-processes intrusion detection information and network data, establishing baseline patterns and relationships that enable rapid entry point identification. This preliminary action reduces the time required for comprehensive investigation from hours to minutes while maintaining thoroughness.

Inventive Principle:
Principle #10Preliminary action

4Object-affected harmful factors

If firewalls are configured to block DoS traffic, then attack traffic is filtered, but the firewall is quickly overwhelmed

Engineering Contradiction:
ImproveDoS traffic blockingVSAvoidfirewall capacity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies partial filtering by identifying and blocking only the specific portion of traffic that constitutes the attack, rather than attempting to block all potentially malicious traffic. The correlation engine analyzes attack patterns and directs blocking actions only at identified entry points and specific malicious traffic flows, preventing firewall overload while effectively stopping DoS attacks.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7845004B2Correlating network information and intrusion information to find the entry point of an attack upon a protected computer
Publication Date: 2010.11.30 A10 NETWORKS INC
  • US7845004B2 patent drawing
  • US7845004B2 patent drawing
  • US7845004B2 patent drawing

AI summary

A method for determining the entry point of an attack by a vandal such as a hacker upon a device such as a computer or a server such as a web server that operates under the protection of an intrusion detection system. Intrusion detection information regarding the attack and network information regarding the attack are correlated, and the entry point of the attack thereby deduced. In one embodiment, a source address of a message representative of the attack is found in a router table of a router that provides a connection supporting the attack. Logical ports of the connection are determined, and the corresponding physical ports found, thereby identifying the attack's entry point into the protected device.