Intrusion Detection System Using Business Process Specification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection systems (IDS) face challenges in detecting unknown attacks and minimizing false positives, as they rely on pre-defined rules and signatures, which are inadequate for detecting deviations in business processes and can generate high false alarm rates.

Innovation Solution

A method and system that analyze events from networks or systems to identify deviations from specified business processes and rules, using a processing core and distributed sensors to validate the execution of activities and detect potential intrusions by comparing observed actions with predefined business processes and rules, even if no specific signatures are defined for the attack.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If signature detection methods are used to identify known attacks, then false positive rates are reduced, but the system cannot detect unknown attacks

Engineering Contradiction:
Improveaccuracy of intrusion detectionVSAvoidability to detect unknown attacks
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by collecting and storing business process specification data before intrusion detection occurs. The specification database is pre-populated with legitimate business process definitions, allowing the system to compare actual system behavior against these pre-established norms during detection operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system transitions from static signature-based detection to dynamic behavior analysis. Instead of relying on fixed attack signatures, the system continuously monitors and analyzes actual business process execution patterns, adapting to detect both known and unknown attacks by comparing observed behavior against the dynamic business process model.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If anomaly detection methods are used to detect new attack types, then unknown attacks can be identified, but false alarm rates increase significantly

Engineering Contradiction:
Improveability to detect new attack typesVSAvoidfalse positive rate
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The business process specification acts as an intermediary between anomaly detection and signature-based detection. Instead of directly comparing system behavior against statistical norms (which causes high false positives), the system uses the business process specification as a mediator to define what constitutes legitimate behavior, thereby reducing false alarms while maintaining the ability to detect novel attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces the mechanical statistical anomaly detection approach with a specification-based validation mechanism. Rather than relying on mathematical models and thresholds that generate false positives, the system substitutes a business logic-based approach that validates actions against predefined business process rules, significantly reducing false alarm rates.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If pre-defined rules and signatures are used for intrusion detection, then detection speed is maintained, but deviations in business processes cannot be detected

Engineering Contradiction:
Improvedetection speedVSAvoidability to detect business process deviations
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system changes the detection parameters from fixed attack signatures to flexible business process specifications. By transforming the detection framework from signature-matching to specification-validation, the system maintains efficient processing speeds while gaining the ability to detect a broader range of intrusions including business logic attacks and zero-day threats.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The business process specification serves multiple functions simultaneously: it defines legitimate behavior for detection purposes, provides a framework for both known and unknown attack detection, and enables the system to function as both a signature-based and anomaly-based detector through a unified specification-validation approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2911362B1Method and system for detecting intrusion in networks and systems based on business-process specification
Publication Date: 2018.11.21 INESC INOVACAO INSTITUTO DE NOVAS TECNOLOGIEAS
  • EP2911362B1 patent drawingFigure 1~2

AI summary

The detection of intrusions or incidents in networks and systems is carried out with the support of Intrusion Detection Systems. The present invention falls within the field of network security, control systems and information systems and refers to a method and a system of IDS based on the specification of the business processes and business rules. Through various methods, the events in each system or network are used as indication of actions on the systems involved, and analyzed to determine if they correspond to the execution of the business process specified in advance, not corresponding an alarm is produced. The present invention significantly reduces the number of typical IDS false positives and has particular application in the protection of systems that participate in business processes that are completely specifiable. Noteworthy are the industrial systems and those used in critical infrastructures.