Network Access Gateway Aberrant Traffic Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems, particularly those using network access gateways, face challenges in detecting aberrant behavior behind the gateway due to limitations in observing and attributing traffic to specific clients, leading to difficulties in identifying and addressing malware and DoS attacks, which often result in network congestion and increased costs for ISPs and LAN clients.

Innovation Solution

A system and method that employs a processor, network interfaces, and computer instructions to continuously monitor and analyze network communications, log or notify aberrant activity, and apply access controls without human intervention, allowing for real-time detection and response to malicious traffic without disrupting innocent clients or requiring manual analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual traffic analysis is performed by taking remote control of the gateway, then the sources of network offenses can be identified, but the process requires human intervention, proper network observation tools, sufficient skill level, and consumes remaining network capacity and processing power

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The gateway automatically detects aberrant traffic patterns and identifies malware-infected clients without requiring human intervention. The suspicion accumulator component continuously monitors traffic, accumulates suspicion levels, and autonomously generates notifications when thresholds are exceeded, making the system self-sufficient in detecting network offenses.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary suspicion accumulator component that sits between the traffic observation mechanism and the notification system. This intermediary automatically processes raw traffic data, applies detection rules, accumulates suspicion metrics, and triggers notifications only when predefined thresholds are met, eliminating the need for manual analysis while maintaining detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If continuous monitoring of all LAN traffic is implemented, then aberrant behavior can be detected in real-time, but network capacity and processing power are consumed

Engineering Contradiction:
Improvedetection speedVSAvoidnetwork capacity
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The detection system applies different monitoring intensities to different traffic characteristics. Rather than uniformly analyzing all traffic at maximum depth, the system selectively applies observation rules based on traffic patterns, focusing computational resources on suspicious activities while using minimal resources for normal traffic, thereby maintaining high detection speed without exhausting network capacity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements partial monitoring by applying observation rules selectively rather than analyzing every packet in detail. The suspicion accumulator only intensifies monitoring when specific thresholds are approached, applying full analytical power only when necessary, thus achieving effective real-time detection while conserving network capacity and processing power.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If the ISP attempts to observe and attribute LAN traffic to specific clients, then responsibility can be assigned and corrective action taken, but the routing nature and IP masquerading of the gateway prevent sufficient observation

Engineering Contradiction:
Improvetraffic attribution accuracyVSAvoidtraffic observation difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

Instead of attempting to observe traffic from the ISP side upstream of the gateway where IP masquerading obscures client identities, the patent inverts the observation point to the gateway's downstream side where traffic originates. This allows direct observation of client traffic patterns and automatic attribution to specific clients based on their unique traffic characteristics, bypassing the IP masquerading obstacle entirely.

Inventive Principle:
Principle #13The other way round (Inversion)

4Reliability

If remote control and manual examination of gateway traffic is performed, then network offenses can be identified, but the process disrupts connectivity of innocent clients and requires human skill

Engineering Contradiction:
Improvedetection reliabilityVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The gateway autonomously performs detection and notification functions without requiring human operators to take remote control or manually examine traffic. The system self-manages the entire detection process, from observing traffic patterns to generating notifications, eliminating operational complexity and disruption while maintaining reliable detection through automated rule-based analysis.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7590728B2System and method for detection of aberrant network behavior by clients of a network access gateway
Publication Date: 2009.09.15 OPEN TV INC
  • US7590728B2 patent drawing
  • US7590728B2 patent drawing
  • US7590728B2 patent drawing

AI summary

A system and method for detecting aberrant network behavior. One embodiment provides a system of detecting aberrant network behavior behind a network access gateway comprising a processor, a first network interface coupled to the processor, a second network interface coupled to the processor, a storage media accessible by the processor and a set of computer instructions executable by the processor. The computer instructions can be executable to observe network communications arriving at the first network interface from multiple clients and determine when the traffic of a particular client is indicative of malware infection or other hostile network activity. If the suspicious network communication is determined to be of a sufficient volume, type, or duration the computer instructions can be executable to log such activity to storage media, or to notify an administrative entity via either the first network interface or second network interface, or to make the computer instructions be executable to perform other configured actions related to the functioning of the network access gateway.