Network Access Gateway Aberrant Traffic Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems, particularly those using network access gateways, face challenges in detecting aberrant behavior behind the gateway due to limitations in observing and attributing traffic to specific clients, leading to difficulties in identifying and addressing malware and DoS attacks, which often result in network congestion and increased costs for ISPs and LAN clients.
Innovation Solution
A system and method that employs a processor, network interfaces, and computer instructions to continuously monitor and analyze network communications, log or notify aberrant activity, and apply access controls without human intervention, allowing for real-time detection and response to malicious traffic without disrupting innocent clients or requiring manual analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual traffic analysis is performed by taking remote control of the gateway, then the sources of network offenses can be identified, but the process requires human intervention, proper network observation tools, sufficient skill level, and consumes remaining network capacity and processing power
Solution Approach 1:
The gateway automatically detects aberrant traffic patterns and identifies malware-infected clients without requiring human intervention. The suspicion accumulator component continuously monitors traffic, accumulates suspicion levels, and autonomously generates notifications when thresholds are exceeded, making the system self-sufficient in detecting network offenses.
Solution Approach 2:
The patent introduces an intermediary suspicion accumulator component that sits between the traffic observation mechanism and the notification system. This intermediary automatically processes raw traffic data, applies detection rules, accumulates suspicion metrics, and triggers notifications only when predefined thresholds are met, eliminating the need for manual analysis while maintaining detection accuracy.
2Productivity
If continuous monitoring of all LAN traffic is implemented, then aberrant behavior can be detected in real-time, but network capacity and processing power are consumed
Solution Approach 1:
The detection system applies different monitoring intensities to different traffic characteristics. Rather than uniformly analyzing all traffic at maximum depth, the system selectively applies observation rules based on traffic patterns, focusing computational resources on suspicious activities while using minimal resources for normal traffic, thereby maintaining high detection speed without exhausting network capacity.
Solution Approach 2:
The system implements partial monitoring by applying observation rules selectively rather than analyzing every packet in detail. The suspicion accumulator only intensifies monitoring when specific thresholds are approached, applying full analytical power only when necessary, thus achieving effective real-time detection while conserving network capacity and processing power.
3Measurement precision
If the ISP attempts to observe and attribute LAN traffic to specific clients, then responsibility can be assigned and corrective action taken, but the routing nature and IP masquerading of the gateway prevent sufficient observation
Solution Approach 1:
Instead of attempting to observe traffic from the ISP side upstream of the gateway where IP masquerading obscures client identities, the patent inverts the observation point to the gateway's downstream side where traffic originates. This allows direct observation of client traffic patterns and automatic attribution to specific clients based on their unique traffic characteristics, bypassing the IP masquerading obstacle entirely.
4Reliability
If remote control and manual examination of gateway traffic is performed, then network offenses can be identified, but the process disrupts connectivity of innocent clients and requires human skill
Solution Approach 1:
The gateway autonomously performs detection and notification functions without requiring human operators to take remote control or manually examine traffic. The system self-manages the entire detection process, from observing traffic patterns to generating notifications, eliminating operational complexity and disruption while maintaining reliable detection through automated rule-based analysis.
Data Source
AI summary
A system and method for detecting aberrant network behavior. One embodiment provides a system of detecting aberrant network behavior behind a network access gateway comprising a processor, a first network interface coupled to the processor, a second network interface coupled to the processor, a storage media accessible by the processor and a set of computer instructions executable by the processor. The computer instructions can be executable to observe network communications arriving at the first network interface from multiple clients and determine when the traffic of a particular client is indicative of malware infection or other hostile network activity. If the suspicious network communication is determined to be of a sufficient volume, type, or duration the computer instructions can be executable to log such activity to storage media, or to notify an administrative entity via either the first network interface or second network interface, or to make the computer instructions be executable to perform other configured actions related to the functioning of the network access gateway.


