Correlation Engine Network Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Application level security systems generate a high number of false alarms when detecting network attacks, reducing their accuracy and efficiency in protecting Web applications and sensitive information.
Innovation Solution
A method and system that receive attack indications, apply rules to these indications, and generate alerts only when a subset of rules indicates a potential attack, incorporating correlation engines and network sensors to differentiate between normal and abnormal behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If application level security systems generate alerts based on single irregular events, then the detection speed is fast, but the number of false alarms increases
Solution Approach 1:
The patent segments the alert generation process by dividing it into multiple evaluation stages. Instead of generating an alert based on a single irregular event, the system evaluates multiple events against predefined criteria and only generates an alert when a threshold is met. This segmentation reduces false alarms while maintaining detection speed by processing events in discrete, manageable units rather than requiring complete analysis of all possible events.
Solution Approach 2:
The patent changes the parameter of alert generation from binary (single event trigger) to multi-parameter evaluation (multiple events with weighted criteria). By introducing parameters such as event frequency, severity weights, and threshold values, the system can differentiate between genuine threats and benign irregularities, thereby reducing false alarms while maintaining fast detection response.
2Reliability
If security systems analyze multiple events to reduce false alarms, then the accuracy improves, but the processing time increases
Solution Approach 1:
The patent applies preliminary action by pre-defining evaluation criteria, event patterns, and alert thresholds before actual security monitoring begins. This allows the system to quickly compare incoming events against predetermined rules without requiring complex real-time analysis, thus improving detection accuracy while minimizing processing time delays.
Solution Approach 2:
The system performs partial analysis by evaluating only the most relevant events against alert criteria rather than analyzing every single event in detail. By focusing computational resources on high-priority events and using predefined patterns for quick matching, the system achieves high detection accuracy without the time penalty of exhaustive analysis of all events.
3Reliability
If the system processes all rules for every attack indication, then the detection thoroughness is high, but the processing efficiency decreases
Solution Approach 1:
The patent implements partial processing by applying only the necessary subset of rules to each attack indication rather than processing all rules uniformly. The system evaluates events against multiple criteria but stops processing when sufficient evidence is found or when events are clearly benign, thereby maintaining thorough detection while significantly improving processing efficiency through selective rule application.
Data Source
AI summary
A method for detecting network attacks is provided. In one implementation, the method receives a plurality of attack indications based on data transmitted on the network and applies rules to the plurality of attack indications. Also, the method generates an alert if an application of at least a subset of the rules on the plurality of attack indications indicates a potential attack. In addition, a network device that performs the method and a computer program corresponding to the method are provided.


