Distributed Network Intrusion Detection via Graph-Based Data Mining

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The sheer volume of data in large electronic networks makes manual intrusion detection infeasible, and existing automated solutions are inefficient or ineffective, particularly due to reliance on centralized administration and attack signatures.

Innovation Solution

A distributed network intrusion detection system using machine learning and graph-based data mining across network nodes, eliminating the need for central components and enabling detection of both internal and external attacks without attack signatures, by distributing storage and execution of system components and employing open-source tools like TcpDump and Wireshark for data analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual analysis of network data is performed, then detection accuracy can be maintained, but the approach becomes infeasible due to the sheer volume of work required

Engineering Contradiction:
Improvedetection accuracyVSAvoidwork capacity
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent segments the centralized intrusion detection function into distributed detection agents deployed across multiple network nodes. Each agent independently analyzes local network traffic, dividing the overwhelming data analysis task into manageable portions that can be processed in parallel, thus maintaining detection accuracy while overcoming the productivity limitation of manual analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces manual mechanical analysis with automated machine learning algorithms and graph-based data mining techniques. These automated systems process network data without human intervention, substituting the infeasible manual analysis approach with scalable computational methods that maintain high detection accuracy across large volumes of network traffic.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If centralized administration and detection systems are used, then system management is simplified, but the system becomes vulnerable to disablement and attacks

Engineering Contradiction:
Improvesystem managementVSAvoidsystem resilience
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the centralized detection system into multiple independent distributed agents deployed across network nodes. This segmentation eliminates the single point of failure vulnerability inherent in centralized systems, as each agent operates autonomously and the failure of individual agents does not compromise the overall detection capability, thereby improving system resilience while maintaining manageable operation through standardized agent deployment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of centralizing detection functions in a single vulnerable point, the patent inverts the architecture by distributing detection capabilities across numerous network nodes. This inversion transforms the system from centrally-controlled and vulnerable to decentralized and resilient, where the collective intelligence of distributed agents provides both security against disablement and manageable operation through uniform agent behavior.

Inventive Principle:
Principle #13The other way round (Inversion)

3Measurement precision

If attack signatures are used for intrusion detection, then detection effectiveness against known attacks is improved, but the system cannot detect variants of previously identified infrequent behavior

Engineering Contradiction:
Improvedetection effectivenessVSAvoiddetection coverage
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent employs dynamic machine learning algorithms that continuously adapt to new attack patterns rather than relying on static attack signatures. The system learns from observed network behavior and automatically updates its detection models, enabling it to detect both known attacks and variants of previously unidentified threats, thus achieving both detection effectiveness and broad adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the detection parameter from fixed attack signatures to dynamic behavioral patterns identified through graph-based data mining. By analyzing relationships and patterns in network traffic rather than matching against predetermined signatures, the system achieves versatility in detecting both known and variant attacks while maintaining high detection effectiveness through sophisticated pattern recognition.

Inventive Principle:
Principle #35Parameter changes

4Productivity

If distributed storage and execution of system components is implemented, then scalability to larger networks is enabled, but system complexity increases

Engineering Contradiction:
Improvenetwork scalabilityVSAvoidsystem architecture
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the intrusion detection system into standardized, independent agents that can be distributed across network nodes. This segmentation enables scalability as new nodes can be added with identical agent deployments, and the modular architecture manages complexity by breaking down the overall system into uniform, easily deployable components that scale linearly with network size.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8161550B2Network intrusion detection
Publication Date: 2012.04.17 KNOWLEDGE BASED SYST
  • US8161550B2 patent drawing
  • US8161550B2 patent drawing
  • US8161550B2 patent drawing

AI summary

Apparatus and systems, as well as methods and articles, may operate to monitor communications between network nodes coupled to each other via at least one network, and map the communications to one or more communications graphs which are physically distributed over a plurality of network hosts. Network intrusion is detected using distributed graph-based data mining with respect to a selected subgraph and the communications graphs. Other embodiments are described and claimed.