Automated IDS Rule Generation via Traffic Metadata Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection systems face challenges in efficiently generating and deploying rules to identify malicious traffic, particularly in detecting zero-day attacks, as they rely on predefined signatures that may not effectively capture new or evolving malicious patterns.

Innovation Solution

A method and system that automatically formulate Intrusion Detection System (IDS) rules based on metadata parameters and traffic content analysis, allowing for interactive filtering and generation of rules that can identify malicious traffic, and includes verification and refinement processes to ensure effective rule deployment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If predefined signatures are used for intrusion detection, then the system can detect known malicious patterns, but it cannot effectively detect zero-day attacks or new malicious patterns

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect new attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary analysis of network traffic to extract metadata parameters and formulate IDS rules before actual intrusion detection occurs. By pre-processing traffic data and identifying malicious patterns in advance, the system prepares detection rules that can be quickly deployed to detect both known and emerging threats, including zero-day attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary component that bridges network investigation systems and intrusion detection systems. This intermediary automatically formulates IDS rules based on metadata parameters extracted from traffic analysis, enabling the translation of investigative findings into actionable detection rules that enhance both reliability and adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If manual configuration of IDS rules is performed, then the rules can be precisely tailored to specific threats, but the process is time-consuming and inefficient

Engineering Contradiction:
Improverule accuracyVSAvoidrule deployment speed
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The system enables self-service automation where IDS rules are automatically formulated and configured based on metadata parameters extracted from network traffic analysis. The automated formulation process maintains high rule accuracy by using precise metadata combinations while dramatically improving deployment speed, eliminating the need for manual rule configuration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes parameters by using metadata parameters (such as source IP, destination IP, ports, protocols) to dynamically formulate IDS rules. By transforming traffic characteristics into rule parameters, the system achieves both precision in rule formulation and speed in deployment, as the rules are automatically generated based on observed traffic patterns.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If comprehensive traffic analysis is performed to identify malicious patterns, then detection capability is improved, but system complexity and processing time increase

Engineering Contradiction:
Improvetraffic analysis accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts only the essential metadata parameters from comprehensive traffic analysis, such as source/destination IPs, ports, protocols, and packet characteristics. By taking out only the critical parameters needed for rule formulation rather than analyzing all traffic details, the system maintains high detection precision while reducing system complexity and processing requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9479523B2System and method for automated configuration of intrusion detection systems
Publication Date: 2016.10.25 COGNYTE TECH ISRAEL LTD
  • US9479523B2 patent drawing
  • US9479523B2 patent drawing

AI summary

Methods and systems for automated generation of malicious traffic signatures, for use in Intrusion Detection Systems (IDS). A rule generation system formulates IDS rules based on traffic analysis results obtained from a network investigation system. The rule generation system then automatically configures the IDS to apply the rules. An analysis process in the network investigation system comprises one or more metadata filters that are indicative of malicious traffic. An operator of the rule generation system is provided with a user interface that is capable of displaying the network traffic filtered in accordance with such filters.