Global Port-Scanning Traffic Analysis for Vulnerable Service Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The large volume of network traffic data makes manual analysis of cyberattacks infeasible, and existing methods lack concise metrics to detect suspicious port scanning activities effectively.

Innovation Solution

A method using popularity, surprisingness index (SI), and source entropy scores to analyze port scanning traffic, identifying suspicious scanning events by quantifying the likelihood and geographical pervasiveness of port usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual analysis of network traffic data is performed, then detection accuracy can be maintained, but the analysis becomes infeasible due to large data volume

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis feasibility
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts and focuses on specific critical features from the overwhelming network traffic data - namely port scanning activities and their characteristics. By extracting only the relevant scanning patterns rather than analyzing all traffic manually, the system maintains detection accuracy while making the analysis feasible through automated processing of extracted features.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms the analysis approach by changing parameters from manual inspection of raw traffic to automated analysis of derived metrics such as scanning rates, port popularity scores, and geographic distribution patterns. This parameter transformation enables feasible automated processing while preserving detection capability through meaningful metric selection.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive port scanning analysis is performed on all traffic, then all suspicious activities can be detected, but the complexity of the analysis system increases

Engineering Contradiction:
Improvesuspicious activity detectionVSAvoidanalysis system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the analysis into distinct components: port scanning detection, geographic location analysis, popularity scoring, and entropy calculation. By dividing the comprehensive analysis into separate modular segments, the system achieves reliable suspicious activity detection while managing complexity through organized, independent analysis modules that can be processed separately.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary metrics such as port popularity scores and geographic distribution data that mediate between raw traffic data and final threat assessment. These intermediary representations simplify the analysis by providing structured intermediate results that bridge comprehensive data collection and actionable intelligence, reducing system complexity while maintaining detection reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If detailed analysis of all scanning sources is performed, then thorough threat assessment is achieved, but the number of suspicious sources remains too large for manageable analysis

Engineering Contradiction:
Improvethreat assessment thoroughnessVSAvoidnumber of suspicious sources
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent applies local quality analysis by examining specific characteristics of scanning sources such as their geographic location, scanning patterns, and port selection preferences. Rather than treating all sources uniformly, the system identifies and focuses on sources with locally distinctive suspicious characteristics, enabling thorough threat assessment of critical sources while reducing the overall manageable quantity through selective detailed analysis.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial analysis by focusing detailed examination on a subset of high-risk scanning sources identified through initial filtering metrics. By applying excessive analysis only where needed (to the most suspicious sources) rather than uniformly to all sources, the system achieves thorough threat assessment of critical threats while keeping the total number of sources requiring detailed analysis manageable through prioritized processing.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250301002A1Method to detect vulnerable internet services via changes to global port-scanning traffic
Publication Date: 2025.09.25 ORACLE INT CORP
  • US20250301002A1 patent drawing
  • US20250301002A1 patent drawing
  • US20250301002A1 patent drawing

AI summary

A computer-implemented method includes receiving signals via a network at ports on the network, the signals corresponding to scanning activity at the ports by a plurality of sources on the network; the sources are located at a plurality of geographical bins. The method also includes determining a popularity score for each of the ports, based on a number of geographical bins sending signals to the in a first time period; calculating, for each of the geographical bins, a probability of scanning activity occurring at a port in a second time period, resulting in a plurality of probabilities for that port; and calculating, for each of the ports, a surprisingness index based on the plurality of probabilities. The method further includes estimating, in accordance with the popularity score and the surprisingness index for each of the ports, a likelihood that the port is experiencing suspicious scanning activity.