Correlating Network and Intrusion Data to Identify Attack Entry Points
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current intrusion detection systems lack coordination with network equipment, making it difficult to quickly identify the entry point of attacks, leading to delayed response and potential misidentification of legitimate traffic as malicious, which can result in unintended filtering of important messages and overwhelming of firewalls during denial-of-service attacks.
Innovation Solution
A correlation engine is used to combine intrusion detection information with network information from routers to identify the logical and physical entry point of attacks, allowing for targeted blocking of malicious traffic and aiding in forensic investigations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If intrusion detection systems and network equipment operate separately without coordination, then device complexity is reduced, but the ability to quickly identify attack entry points deteriorates
Solution Approach 1:
The patent merges intrusion detection information with network equipment information through a correlation engine that integrates data from multiple separate devices. This combination enables unified analysis of attack patterns across the network, allowing rapid identification of entry points without requiring complex manual coordination between separate systems.
2Object-affected harmful factors
If source-address filtering is used to block denial of service attacks, then attack damage is limited, but legitimate customer messages are inadvertently filtered out
Solution Approach 1:
The patent segments the network into multiple monitoring points and correlates attack data across these segments. By analyzing the spatial distribution and patterns of malicious traffic across different network segments, the system can distinguish between genuine customer messages and spoofed attack traffic, enabling selective blocking that protects against attacks while maintaining reliable delivery of legitimate messages.
3Loss of information
If technicians perform unstructured analysis of intrusion detection data, then comprehensive investigation is possible, but the entry point may not be found for several hours
Solution Approach 1:
The patent implements preliminary automated correlation and analysis of network data before human technicians need to intervene. The correlation engine pre-processes intrusion detection information and network data, establishing baseline patterns and relationships that enable rapid entry point identification. This preliminary action reduces the time required for comprehensive investigation from hours to minutes while maintaining thoroughness.
4Object-affected harmful factors
If firewalls are configured to block DoS traffic, then attack traffic is filtered, but the firewall is quickly overwhelmed
Solution Approach 1:
The patent applies partial filtering by identifying and blocking only the specific portion of traffic that constitutes the attack, rather than attempting to block all potentially malicious traffic. The correlation engine analyzes attack patterns and directs blocking actions only at identified entry points and specific malicious traffic flows, preventing firewall overload while effectively stopping DoS attacks.
Data Source
AI summary
A method for determining the entry point of an attack by a vandal such as a hacker upon a device such as a computer or a server such as a web server that operates under the protection of an intrusion detection system. Intrusion detection information regarding the attack and network information regarding the attack are correlated, and the entry point of the attack thereby deduced. In one embodiment, a source address of a message representative of the attack is found in a router table of a router that provides a connection supporting the attack. Logical ports of the connection are determined, and the corresponding physical ports found, thereby identifying the attack's entry point into the protected device.


