Distributed Network Intrusion Detection Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional intrusion detection systems are inadequate in monitoring complex network environments, failing to detect security breaches effectively due to limitations in host-based and network-based systems, particularly in large networks with unmanaged hosts and encrypted traffic, and lack comprehensive monitoring capabilities.

Innovation Solution

A network intrusion detection system utilizing distributed correlation across multiple host agents, where each host monitors and analyzes local traffic and shares summarized data with other hosts to correlate suspicious activities, reducing the need for physical devices and enhancing detection accuracy by combining data from multiple sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If host-based sensors are installed at each machine to monitor traffic, then detection capability for individual host intrusions is improved, but system complexity and cost increase significantly in large networks

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the network into managed and unmanaged host categories, applying different monitoring strategies to each segment. Managed hosts receive full host-based sensor monitoring, while unmanaged hosts are monitored through network traffic analysis, reducing overall system complexity while maintaining detection coverage

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network-based intrusion detection system serves multiple functions: it monitors both managed and unmanaged hosts, detects intrusions at network level and individual host level, and provides centralized management. This multi-functionality reduces the need for separate dedicated systems for each function

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If network-based sensors monitor all network traffic, then comprehensive network monitoring is achieved, but blind spots remain for unmanaged hosts and encrypted traffic

Engineering Contradiction:
Improvemonitoring comprehensivenessVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system merges network-based monitoring and host-based monitoring into a unified approach. Network sensors monitor traffic to/from unmanaged hosts and encrypted traffic, while host-based sensors monitor managed hosts, and the results are correlated to provide comprehensive intrusion detection coverage without blind spots

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system introduces an intermediary correlation layer that processes and correlates data from both network-based and host-based sensors. This intermediary layer fills detection gaps by contextualizing network traffic with host-level information, enabling accurate detection of intrusions involving unmanaged hosts and encrypted traffic

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If centralized intrusion detection system processes all security data, then comprehensive analysis is achieved, but processing time and network bandwidth consumption increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system segments the data processing function across multiple levels: local hosts perform initial processing and correlation of their own security data, regional managers aggregate data from multiple hosts, and the central system performs high-level analysis. This segmentation reduces the processing burden on the centralized system and decreases overall processing time

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs partial correlation locally at each host, processing only the security-relevant data and correlations needed for local intrusion detection. This partial action reduces the volume of data that needs to be transmitted and processed centrally, decreasing network bandwidth consumption and processing time while maintaining detection accuracy

Inventive Principle:
Principle #16Partial or excessive action

4Ease of manufacture

If existing host security technologies are leveraged for intrusion detection, then cost is reduced, but detection accuracy may be compromised

Engineering Contradiction:
Improvesystem costVSAvoiddetection accuracy
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system makes existing host security technologies serve multiple functions: they continue to provide local host protection while simultaneously generating security data for network-wide intrusion detection. This multi-functionality justifies the investment in existing technologies while achieving comprehensive detection coverage at reduced cost

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback mechanisms where security data collected from host-based sensors is correlated with network traffic patterns and fed back to improve local detection algorithms. This feedback loop enhances detection accuracy by continuously learning from network-wide patterns while leveraging existing host security infrastructure

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9560068B2Network intrusion detection with distributed correlation
Publication Date: 2017.01.31 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9560068B2 patent drawing
  • US9560068B2 patent drawing
  • US9560068B2 patent drawing

AI summary

A network security system employing multiple levels of processing to identify security threats. Multiple host machines may each contain an agent that detects possibilities of security threats based on raw data sensed locally at that host. The hosts may share information obtained from local analysis and each host may use information generated at one or more other hosts, in combination with information generated locally, to identify a security concern, indicating with greater certainty that a security threat exists. Based on security concerns generated by multiple hosts, a security threat may be to indicated and protective action may be taken.