Intrusion Detection System Adaptive Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems, including intrusion detection systems (IDS), face challenges such as high false positives, false negatives, data overload, and resource-intensive personnel requirements, which make it difficult to effectively detect and respond to cyber attacks, especially distinguishing between general and specific targeted attacks.

Innovation Solution

A computer network intrusion detection system that includes an intrusion alert generator, an analyzer to determine attack characteristics, and an adaptive filter to reduce false alerts and automatically differentiate between general and specific attacks, coupled with a managed security service that employs an edge manager to perform vulnerability tests and preemptive measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional intrusion detection systems use multiple security layers and comprehensive monitoring, then detection capability is improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and focuses monitoring on specific attack characteristics and patterns rather than attempting to monitor all network traffic comprehensively. The system identifies and prioritizes key indicators of intrusion (such as specific packet patterns, protocol anomalies, and known attack signatures) to reduce monitoring scope while maintaining effective detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies different monitoring and detection strategies to different network segments and traffic types based on their specific risk profiles. Rather than uniform monitoring, the patent implements localized detection mechanisms tailored to critical network areas, allowing intensive monitoring where needed while reducing monitoring overhead in less critical zones.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If intrusion detection systems generate detailed alerts for all detected attacks, then detection precision is improved, but false positives increase and personnel resources are consumed

Engineering Contradiction:
Improvedetection precisionVSAvoidfalse positives
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent combines multiple detection signals and attack indicators into unified alert categories. Instead of generating separate detailed alerts for each detected anomaly, the system merges related indicators into consolidated alert types that represent broader attack patterns, reducing the total number of alerts while maintaining precision through contextual aggregation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system dynamically adjusts alert generation based on contextual information and threat intelligence. The patent implements adaptive alerting that modifies detection sensitivity and alert detail levels in real-time based on current network conditions, known threat patterns, and historical data, thereby reducing false positives while maintaining precision when needed.

Inventive Principle:
Principle #15Dynamics

3Reliability

If the system monitors all network traffic comprehensively, then detection coverage is improved, but data overload occurs

Engineering Contradiction:
Improvedetection coverageVSAvoiddata volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts and focuses monitoring on specific attack characteristics and patterns rather than attempting to monitor all network traffic comprehensively. The system identifies and prioritizes key indicators of intrusion (such as specific packet patterns, protocol anomalies, and known attack signatures) to reduce monitoring scope while maintaining effective detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies partial monitoring to critical network segments and traffic types while using lighter monitoring for less critical areas. The patent implements selective detection that concentrates resources on high-value targets such as critical servers, authentication traffic, and known vulnerability vectors, achieving sufficient detection coverage without the overhead of comprehensive monitoring.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7603711B2Intrusion detection system
Publication Date: 2009.10.13 SECNAP NETWORK SECURITY
  • US7603711B2 patent drawing
  • US7603711B2 patent drawing
  • US7603711B2 patent drawing

AI summary

An intrusion detection system monitors the rate and characteristics of Internet attacks on a computer network and filters attack alerts based upon various rates and frequencies of the attacks. The intrusion detection system monitors attacks on other hosts and determines if the attacks are random or general attacks or attacks directed towards a specific computer network and generates a corresponding signal. The intrusion detections system also tests a computer network's vulnerability to attacks detected on the other monitored hosts.