Correlation Engine Network Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Application level security systems generate a high number of false alarms when detecting network attacks, reducing their accuracy and efficiency in protecting Web applications and sensitive information.

Innovation Solution

A method and system that receive attack indications, apply rules to these indications, and generate alerts only when a subset of rules indicates a potential attack, incorporating correlation engines and network sensors to differentiate between normal and abnormal behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If application level security systems generate alerts based on single irregular events, then the detection speed is fast, but the number of false alarms increases

Engineering Contradiction:
Improvedetection speedVSAvoidfalse alarm rate
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent segments the alert generation process by dividing it into multiple evaluation stages. Instead of generating an alert based on a single irregular event, the system evaluates multiple events against predefined criteria and only generates an alert when a threshold is met. This segmentation reduces false alarms while maintaining detection speed by processing events in discrete, manageable units rather than requiring complete analysis of all possible events.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of alert generation from binary (single event trigger) to multi-parameter evaluation (multiple events with weighted criteria). By introducing parameters such as event frequency, severity weights, and threshold values, the system can differentiate between genuine threats and benign irregularities, thereby reducing false alarms while maintaining fast detection response.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If security systems analyze multiple events to reduce false alarms, then the accuracy improves, but the processing time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-defining evaluation criteria, event patterns, and alert thresholds before actual security monitoring begins. This allows the system to quickly compare incoming events against predetermined rules without requiring complex real-time analysis, thus improving detection accuracy while minimizing processing time delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system performs partial analysis by evaluating only the most relevant events against alert criteria rather than analyzing every single event in detail. By focusing computational resources on high-priority events and using predefined patterns for quick matching, the system achieves high detection accuracy without the time penalty of exhaustive analysis of all events.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If the system processes all rules for every attack indication, then the detection thoroughness is high, but the processing efficiency decreases

Engineering Contradiction:
Improvedetection thoroughnessVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements partial processing by applying only the necessary subset of rules to each attack indication rather than processing all rules uniformly. The system evaluates events against multiple criteria but stops processing when sufficient evidence is found or when events are clearly benign, thereby maintaining thorough detection while significantly improving processing efficiency through selective rule application.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8024804B2Correlation engine for detecting network attacks and detection method
Publication Date: 2011.09.20 IMPERVA INC
  • US8024804B2 patent drawing
  • US8024804B2 patent drawing
  • US8024804B2 patent drawing

AI summary

A method for detecting network attacks is provided. In one implementation, the method receives a plurality of attack indications based on data transmitted on the network and applies rules to the plurality of attack indications. Also, the method generates an alert if an application of at least a subset of the rules on the plurality of attack indications indicates a potential attack. In addition, a network device that performs the method and a computer program corresponding to the method are provided.