Firewall Insider Threat Detection via Traffic Metadata Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Detecting and preventing malicious insider threats within enterprise and government networks is challenging due to the difficulty in distinguishing human-driven malicious behaviors from inside the network, as perimeter solutions are not designed to detect insider threats and existing methods are invasive, costly, and inefficient in addressing evolving threats.
Innovation Solution
A system that leverages metadata to construct predictive models of normal behavior for key assets, allowing real-time detection of unusual access and behavior deviations, without the need for individual monitoring software on each host, by monitoring internal network traffic and using machine learning to identify potential threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If perimeter solutions (firewalls or Intrusion Prevention Systems) are deployed to detect threats, then external threats can be detected, but insider threats cannot be detected because these systems are oriented to outsider threats and do not detect human-driven malicious behaviors from inside the network
Solution Approach 1:
The patent applies universality by transforming the firewall from a unidirectional external threat defense system into a multi-functional system that detects both external and internal threats. The firewall is enhanced to monitor bidirectional traffic flows, enabling it to detect insider threats while maintaining its original external threat detection capability. This allows a single system to serve multiple security functions without requiring separate dedicated systems for each threat type.
Solution Approach 2:
The patent applies inversion by reversing the traditional monitoring approach. Instead of only monitoring incoming external traffic for threats, the system monitors outgoing internal traffic from authorized users to detect malicious behaviors. This inversion enables the detection of insider threats by examining traffic patterns that originate from within the network, transforming the firewall into a tool that detects threats from both directions.
2Reliability
If fine-grained access controls are implemented to limit insider access to assets, then security is improved, but productivity deteriorates because access is restricted for legitimate users and maintenance costs increase
Solution Approach 1:
The patent applies self-service by implementing dynamic access control where the system automatically adjusts user permissions based on real-time threat assessments. Instead of requiring manual administrative intervention for each access request, the system autonomously evaluates user behavior patterns, traffic metadata, and threat indicators to dynamically grant or restrict access. This enables fine-grained security control without requiring excessive manual maintenance or restricting legitimate user productivity.
Solution Approach 2:
The patent applies dynamics by transitioning from static access control lists to dynamic, context-aware permission management. User access rights are not fixed but adapt in real-time based on assessed threat levels, user behavior anomalies, and environmental factors. This dynamic approach allows the system to maintain strict security controls for potentially malicious users while providing seamless access to legitimate users, thereby maintaining both security and productivity.
3Measurement precision
If large arrays of sensors are installed on hosts to monitor malicious behavior, then detection capability is improved, but device complexity, cost, and maintenance difficulty increase significantly
Solution Approach 1:
The patent applies extraction by removing the need for complex monitoring software from individual hosts and concentrating the detection functionality in the network firewall. Instead of installing sensor arrays on every host, the system extracts the essential monitoring function to the network perimeter device, which collects and analyzes traffic metadata from all hosts centrally. This significantly reduces device complexity and maintenance requirements while maintaining comprehensive monitoring capability.
Solution Approach 2:
The patent applies the intermediary principle by using the firewall as a mediating device that collects traffic metadata from all hosts without requiring direct sensor installation on each host. The firewall acts as an intermediary that passively observes and analyzes network traffic flows, extracting security-relevant information without interfering with host operations. This approach simplifies the overall system architecture by eliminating the need for complex distributed sensor networks while maintaining comprehensive monitoring capability.
4Reliability
If pre-programmed rules or heuristics are used to detect known threat scenarios, then detection of known threats is improved, but the system cannot detect evolving threats because it is impossible to know ahead of time the specific characteristics of every threat
Solution Approach 1:
The patent applies feedback by implementing a continuous learning mechanism where the system analyzes detected threat patterns and adjusts its detection parameters dynamically. The firewall monitors traffic metadata, identifies anomalous patterns, and uses this feedback to refine its threat detection models in real-time. This allows the system to adapt to evolving threats by learning from actual observed behaviors rather than relying solely on pre-programmed rules, while maintaining reliable detection of known threat types.
Solution Approach 2:
The patent applies parameter changes by dynamically adjusting detection thresholds, analysis parameters, and evaluation criteria based on observed traffic patterns and emerging threat indicators. Instead of using fixed pre-programmed rules, the system modifies its detection parameters in real-time to match the characteristics of current threats. This enables the system to effectively detect both known threats using established parameters and evolving threats by adapting parameters to match new threat patterns.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed is an approach to detect insider threats, by tracking unusual access activity for a specific user or computer with regard to accessing key assets over time. In this way, malicious activity and the different preparation phases of attacks can be identified.