Graph-Matching Intrusion Detection for Coordinated Network Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network intrusion detection systems are ineffective in detecting modern security threats due to high false alarm rates, inability to detect insider and coordinated attacks, and lack of adaptability to evolving attack methods, as they rely on static rules and do not consider the context of network activity.

Innovation Solution

The enhanced graph matching intrusion detection system (eGMIDS) uses distributed sensors to collect and fuse data, generating a graphical representation of network activity and employing graph matching algorithms to identify threat patterns, including inexact matching and secondary evidence mechanisms to detect emerging threats and reduce false alarms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional rule-based or event-based intrusion detection systems are used, then they can detect specific known threats, but they produce high false positive rates and cannot detect emerging or coordinated attacks

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidability to detect emerging threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts to emerging threats by continuously learning from network traffic patterns and updating its detection models. Instead of relying on static rules, the system evolves its detection capabilities to identify new attack types and coordinated attacks as they emerge, resolving the contradiction between reliable detection of known threats and adaptability to emerging threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes its detection parameters and thresholds dynamically based on learned patterns from network traffic. By adjusting sensitivity parameters and detection criteria based on accumulated data, the system maintains high accuracy for known threats while becoming increasingly effective at detecting emerging attack patterns that differ from traditional signatures.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If analysts manually review extensive network traffic records, then they can identify potential threats, but the process is time-consuming and ineffective for large networks

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidtime for security analysis
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system replaces manual mechanical analysis of network traffic with automated intelligent detection algorithms. These algorithms rapidly process extensive network records, identifying threats with high precision without the time constraints of human analysts, thereby resolving the contradiction between accurate threat identification and analysis time.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs self-service by automatically analyzing network traffic, identifying threats, and generating alerts without requiring continuous manual intervention. The automated detection mechanisms continuously monitor and analyze network records, freeing analysts from time-consuming routine review while maintaining high detection accuracy.

Inventive Principle:
Principle #25Self-service

3Stability of the object's composition

If static intrusion detection rules are maintained, then they provide consistent detection for documented threats, but they require manual updates and leave networks vulnerable during update intervals

Engineering Contradiction:
Improvedetection rule consistencyVSAvoidresponse to new attack types
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The system transitions from static detection rules to dynamic adaptive detection mechanisms. The detection models continuously evolve based on learned patterns from network traffic, maintaining stability in their core detection logic while adapting to new attack types, thereby resolving the contradiction between rule consistency and adaptability to new threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback loops where detection results and network traffic patterns continuously inform rule updates. This feedback mechanism allows the system to maintain consistent detection performance for known threats while automatically adapting to new attack types, eliminating the vulnerability gaps associated with manual rule updates.

Inventive Principle:
Principle #23Feedback

4Ease of operation

If conventional systems analyze events in isolation, then they can detect individual security incidents, but they fail to detect coordinated attacks involving multiple users or devices

Engineering Contradiction:
Improveindividual event detectionVSAvoidcoordinated attack detection capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system merges individual event analysis with contextual relationship analysis. By combining isolated event detection with graph-based relationship mapping that connects events across multiple users and devices, the system maintains ease of individual event detection while enabling reliable identification of coordinated attack patterns through the relationships between events.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system adds a new dimension to event analysis by incorporating relational context and network topology information. Instead of analyzing events in one dimension (isolation), the system analyzes events in multiple dimensions including user relationships, device connections, and temporal patterns, enabling detection of coordinated attacks while preserving individual event detection capabilities.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS7624448B2Intelligent intrusion detection system utilizing enhanced graph-matching of network activity with context data
Publication Date: 2009.11.24 NORTHROP GRUMMAN SYSTEMS CORP
  • US7624448B2 patent drawing
  • US7624448B2 patent drawing
  • US7624448B2 patent drawing

AI summary

A method, system, and computer program product for utilizing a mapping of activity occurring at and between devices on a computer network to detect and prevent network intrusions. An enhanced graph matching intrusion detection system (eGMIDS) is provided that provides data collection functions, data fusion techniques, graph matching algorithms, and secondary and other search mechanisms. Threats are modeled as a set of entities and interrelations between the entities and sample threat patterns are stored within a database. The eGMIDS utility initiates a graph matching algorithm by which the threat patterns are compared within the generated activity graph via subgraph isomorphism. A multi-layered approach including a targeted secondary layer search following a match during a primary layer search is provided. Searches are tempered by attributes and constraints and the eGMIDS reduces the number of threat patterns searched by utilizing ontological generalization.