Firewall Insider Threat Detection via Traffic Metadata Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Detecting and preventing malicious insider threats within enterprise and government networks is challenging due to the difficulty in distinguishing human-driven malicious behaviors from inside the network, as perimeter solutions are not designed to detect insider threats and existing methods are invasive, costly, and inefficient in addressing evolving threats.

Innovation Solution

A system that leverages metadata to construct predictive models of normal behavior for key assets, allowing real-time detection of unusual access and behavior deviations, without the need for individual monitoring software on each host, by monitoring internal network traffic and using machine learning to identify potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If perimeter solutions (firewalls or Intrusion Prevention Systems) are deployed to detect threats, then external threats can be detected, but insider threats cannot be detected because these systems are oriented to outsider threats and do not detect human-driven malicious behaviors from inside the network

Engineering Contradiction:
Improvethreat detection capabilityVSAvoiddetection scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies universality by transforming the firewall from a unidirectional external threat defense system into a multi-functional system that detects both external and internal threats. The firewall is enhanced to monitor bidirectional traffic flows, enabling it to detect insider threats while maintaining its original external threat detection capability. This allows a single system to serve multiple security functions without requiring separate dedicated systems for each threat type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies inversion by reversing the traditional monitoring approach. Instead of only monitoring incoming external traffic for threats, the system monitors outgoing internal traffic from authorized users to detect malicious behaviors. This inversion enables the detection of insider threats by examining traffic patterns that originate from within the network, transforming the firewall into a tool that detects threats from both directions.

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If fine-grained access controls are implemented to limit insider access to assets, then security is improved, but productivity deteriorates because access is restricted for legitimate users and maintenance costs increase

Engineering Contradiction:
Improvesecurity controlVSAvoiduser access efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies self-service by implementing dynamic access control where the system automatically adjusts user permissions based on real-time threat assessments. Instead of requiring manual administrative intervention for each access request, the system autonomously evaluates user behavior patterns, traffic metadata, and threat indicators to dynamically grant or restrict access. This enables fine-grained security control without requiring excessive manual maintenance or restricting legitimate user productivity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies dynamics by transitioning from static access control lists to dynamic, context-aware permission management. User access rights are not fixed but adapt in real-time based on assessed threat levels, user behavior anomalies, and environmental factors. This dynamic approach allows the system to maintain strict security controls for potentially malicious users while providing seamless access to legitimate users, thereby maintaining both security and productivity.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If large arrays of sensors are installed on hosts to monitor malicious behavior, then detection capability is improved, but device complexity, cost, and maintenance difficulty increase significantly

Engineering Contradiction:
Improvebehavior monitoring accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies extraction by removing the need for complex monitoring software from individual hosts and concentrating the detection functionality in the network firewall. Instead of installing sensor arrays on every host, the system extracts the essential monitoring function to the network perimeter device, which collects and analyzes traffic metadata from all hosts centrally. This significantly reduces device complexity and maintenance requirements while maintaining comprehensive monitoring capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies the intermediary principle by using the firewall as a mediating device that collects traffic metadata from all hosts without requiring direct sensor installation on each host. The firewall acts as an intermediary that passively observes and analyzes network traffic flows, extracting security-relevant information without interfering with host operations. This approach simplifies the overall system architecture by eliminating the need for complex distributed sensor networks while maintaining comprehensive monitoring capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If pre-programmed rules or heuristics are used to detect known threat scenarios, then detection of known threats is improved, but the system cannot detect evolving threats because it is impossible to know ahead of time the specific characteristics of every threat

Engineering Contradiction:
Improveknown threat detectionVSAvoidthreat evolution response
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies feedback by implementing a continuous learning mechanism where the system analyzes detected threat patterns and adjusts its detection parameters dynamically. The firewall monitors traffic metadata, identifies anomalous patterns, and uses this feedback to refine its threat detection models in real-time. This allows the system to adapt to evolving threats by learning from actual observed behaviors rather than relying solely on pre-programmed rules, while maintaining reliable detection of known threat types.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies parameter changes by dynamically adjusting detection thresholds, analysis parameters, and evaluation criteria based on observed traffic patterns and emerging threat indicators. Instead of using fixed pre-programmed rules, the system modifies its detection parameters in real-time to match the characteristics of current threats. This enables the system to effectively detect both known threats using established parameters and evolving threats by adapting parameters to match new threat patterns.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3215943B1A system for implementing threat detection using threat and risk assessment of asset-actor interactions
Publication Date: 2021.04.21 VECTRA NETWORKS
  • EP3215943B1 patent drawingFigure 1
  • EP3215943B1 patent drawingFigure 2
  • EP3215943B1 patent drawingFigure 3

AI summary

Disclosed is an approach to detect insider threats, by tracking unusual access activity for a specific user or computer with regard to accessing key assets over time. In this way, malicious activity and the different preparation phases of attacks can be identified.