Intrusion Detection System Using Business Process Specification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current intrusion detection systems (IDS) face challenges in detecting unknown attacks and minimizing false positives, as they rely on pre-defined rules and signatures, which are inadequate for detecting deviations in business processes and can generate high false alarm rates.
Innovation Solution
A method and system that analyze events from networks or systems to identify deviations from specified business processes and rules, using a processing core and distributed sensors to validate the execution of activities and detect potential intrusions by comparing observed actions with predefined business processes and rules, even if no specific signatures are defined for the attack.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If signature detection methods are used to identify known attacks, then false positive rates are reduced, but the system cannot detect unknown attacks
Solution Approach 1:
The system performs preliminary actions by collecting and storing business process specification data before intrusion detection occurs. The specification database is pre-populated with legitimate business process definitions, allowing the system to compare actual system behavior against these pre-established norms during detection operations.
Solution Approach 2:
The system transitions from static signature-based detection to dynamic behavior analysis. Instead of relying on fixed attack signatures, the system continuously monitors and analyzes actual business process execution patterns, adapting to detect both known and unknown attacks by comparing observed behavior against the dynamic business process model.
2Adaptability or versatility
If anomaly detection methods are used to detect new attack types, then unknown attacks can be identified, but false alarm rates increase significantly
Solution Approach 1:
The business process specification acts as an intermediary between anomaly detection and signature-based detection. Instead of directly comparing system behavior against statistical norms (which causes high false positives), the system uses the business process specification as a mediator to define what constitutes legitimate behavior, thereby reducing false alarms while maintaining the ability to detect novel attacks.
Solution Approach 2:
The system replaces the mechanical statistical anomaly detection approach with a specification-based validation mechanism. Rather than relying on mathematical models and thresholds that generate false positives, the system substitutes a business logic-based approach that validates actions against predefined business process rules, significantly reducing false alarm rates.
3Productivity
If pre-defined rules and signatures are used for intrusion detection, then detection speed is maintained, but deviations in business processes cannot be detected
Solution Approach 1:
The system changes the detection parameters from fixed attack signatures to flexible business process specifications. By transforming the detection framework from signature-matching to specification-validation, the system maintains efficient processing speeds while gaining the ability to detect a broader range of intrusions including business logic attacks and zero-day threats.
Solution Approach 2:
The business process specification serves multiple functions simultaneously: it defines legitimate behavior for detection purposes, provides a framework for both known and unknown attack detection, and enables the system to function as both a signature-based and anomaly-based detector through a unified specification-validation approach.
Data Source
Figure 1~2
AI summary
The detection of intrusions or incidents in networks and systems is carried out with the support of Intrusion Detection Systems. The present invention falls within the field of network security, control systems and information systems and refers to a method and a system of IDS based on the specification of the business processes and business rules. Through various methods, the events in each system or network are used as indication of actions on the systems involved, and analyzed to determine if they correspond to the execution of the business process specified in advance, not corresponding an alarm is produced. The present invention significantly reduces the number of typical IDS false positives and has particular application in the protection of systems that participate in business processes that are completely specifiable. Noteworthy are the industrial systems and those used in critical infrastructures.