Graph-Based Network Intrusion Detection via Distributed Sensor Fusion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network intrusion detection systems are ineffective in detecting modern security threats due to their static nature, high false positive rates, and inability to handle coordinated or insider attacks, as they analyze events in isolation without considering context and communication structures.

Innovation Solution

The enhanced graph matching intrusion detection system (eGMIDS) utilizes data collection, fusion techniques, and graph matching algorithms to create a graphical representation of network activity, allowing for early detection of threats by comparing pre-established threat patterns within the activity graph, and employing inexact matching to adapt to changing attack strategies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional IDS analyze events in isolation using rule-based or event-based systems, then the system structure remains simple and easy to implement, but the detection accuracy deteriorates due to high false positive rates and inability to detect coordinated attacks

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transitions from analyzing events in isolation (1D) to representing network activity as graphs with nodes and edges (2D/3D structure), adding dimensional context about relationships between events, hosts, and users. This graphical representation enables detection of coordinated attacks by visualizing connections that would be invisible in traditional event-by-event analysis.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system combines multiple data sources and analysis methods into a unified graph-based framework. It integrates event data, network flow data, and contextual information into composite graphical models that represent complex attack patterns, similar to how composite materials combine different substances to achieve superior properties.

Inventive Principle:
Principle #40Composite materials

2Adaptability or versatility

If rule-based IDS are used to filter harmful traffic, then the system remains static and easy to maintain, but the adaptability deteriorates when facing new or evolving attack methods

Engineering Contradiction:
Improveadaptability to new attacksVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements dynamic graph pattern matching that can adapt to new attack patterns by updating graphical models and relationship definitions. Rather than static rules, the system dynamically analyzes evolving network relationships and adjusts its detection patterns based on observed behavior, enabling response to novel threats without complete reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system pre-establishes graphical models of normal network behavior and known attack patterns, allowing it to quickly detect deviations. By preparing graphical representations of expected relationships and patterns in advance, the system can rapidly adapt to new threats by comparing against these pre-built models without requiring complex real-time rule generation.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If conventional IDS present alarms for every detected event, then the system ensures thorough monitoring, but the ease of operation deteriorates as analysts are overwhelmed by false positives

Engineering Contradiction:
Improveanalyst workloadVSAvoiddetection reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system merges multiple individual event alarms into unified graphical representations that show relationships between events. By combining related events into single graph visualizations, the system reduces the number of separate alarms analysts must evaluate while maintaining comprehensive detection coverage, as the graph structure reveals connections that would require multiple separate alerts in traditional systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system extracts and highlights only the most significant relationships and patterns from the vast amount of network data, presenting distilled graphical insights rather than raw event lists. This extraction of essential information from complex data sets reduces analyst workload by focusing attention on high-value detections while maintaining reliable threat identification.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8266697B2Enabling network intrusion detection by representing network activity in graphical form utilizing distributed data sensors to detect and transmit activity data
Publication Date: 2012.09.11 NORTHROP GRUMMAN SYSTEMS CORP
  • US8266697B2 patent drawing
  • US8266697B2 patent drawing
  • US8266697B2 patent drawing

AI summary

A method, system, and computer program product for detecting and mapping activity occurring at and between devices on a computer network for utilization within an intrusion detection mechanism. An enhanced graph matching intrusion detection system (eGMIDS) utility executing on a control server provides data collection functions and data fusion techniques. The eGMIDS comprises multiple sensors and associated unique adaptors that are located at different remote devices of the network and utilized to detect specific types of activity occurring at the respective devices relevant to eGMIDS processing. The sensors convert the data into eGMIDS format and encapsulate the data in a special transmission packet that is transmitted to the control server. The eGMIDS utility converts the activity data within these packets into eGMIDS-usable format and then processes the converted data via a data fusion technique to generate a graphical representation of the network (devices) and the activity occurring at/amongst the various devices.