Global Port-Scanning Traffic Analysis for Vulnerable Service Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The large volume of network traffic data makes manual analysis of cyberattacks infeasible, and existing methods lack concise metrics to detect suspicious port scanning activities effectively.
Innovation Solution
A method using popularity, surprisingness index (SI), and source entropy scores to analyze port scanning traffic, identifying suspicious scanning events by quantifying the likelihood and geographical pervasiveness of port usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual analysis of network traffic data is performed, then detection accuracy can be maintained, but the analysis becomes infeasible due to large data volume
Solution Approach 1:
The patent extracts and focuses on specific critical features from the overwhelming network traffic data - namely port scanning activities and their characteristics. By extracting only the relevant scanning patterns rather than analyzing all traffic manually, the system maintains detection accuracy while making the analysis feasible through automated processing of extracted features.
Solution Approach 2:
The patent transforms the analysis approach by changing parameters from manual inspection of raw traffic to automated analysis of derived metrics such as scanning rates, port popularity scores, and geographic distribution patterns. This parameter transformation enables feasible automated processing while preserving detection capability through meaningful metric selection.
2Reliability
If comprehensive port scanning analysis is performed on all traffic, then all suspicious activities can be detected, but the complexity of the analysis system increases
Solution Approach 1:
The patent segments the analysis into distinct components: port scanning detection, geographic location analysis, popularity scoring, and entropy calculation. By dividing the comprehensive analysis into separate modular segments, the system achieves reliable suspicious activity detection while managing complexity through organized, independent analysis modules that can be processed separately.
Solution Approach 2:
The patent introduces intermediary metrics such as port popularity scores and geographic distribution data that mediate between raw traffic data and final threat assessment. These intermediary representations simplify the analysis by providing structured intermediate results that bridge comprehensive data collection and actionable intelligence, reducing system complexity while maintaining detection reliability.
3Measurement precision
If detailed analysis of all scanning sources is performed, then thorough threat assessment is achieved, but the number of suspicious sources remains too large for manageable analysis
Solution Approach 1:
The patent applies local quality analysis by examining specific characteristics of scanning sources such as their geographic location, scanning patterns, and port selection preferences. Rather than treating all sources uniformly, the system identifies and focuses on sources with locally distinctive suspicious characteristics, enabling thorough threat assessment of critical sources while reducing the overall manageable quantity through selective detailed analysis.
Solution Approach 2:
The patent implements partial analysis by focusing detailed examination on a subset of high-risk scanning sources identified through initial filtering metrics. By applying excessive analysis only where needed (to the most suspicious sources) rather than uniformly to all sources, the system achieves thorough threat assessment of critical threats while keeping the total number of sources requiring detailed analysis manageable through prioritized processing.
Data Source
AI summary
A computer-implemented method includes receiving signals via a network at ports on the network, the signals corresponding to scanning activity at the ports by a plurality of sources on the network; the sources are located at a plurality of geographical bins. The method also includes determining a popularity score for each of the ports, based on a number of geographical bins sending signals to the in a first time period; calculating, for each of the geographical bins, a probability of scanning activity occurring at a port in a second time period, resulting in a plurality of probabilities for that port; and calculating, for each of the ports, a surprisingness index based on the plurality of probabilities. The method further includes estimating, in accordance with the popularity score and the surprisingness index for each of the ports, a likelihood that the port is experiencing suspicious scanning activity.


