Intrusion Detection Correlating Network Discovery Maps
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional intrusion detection systems (IDSs) are ineffective due to the lack of contextual information about computer network end points, leading to increased susceptibility to attacks and false positives, and existing automatic discovery methods are either manual, time-consuming, prone to errors, or destructive to the network.
Innovation Solution
A system and method that passively and automatically determine network characteristics by correlating intrusion events with stored network maps using policy configuration information, reducing false positives by evaluating events against predefined rules and generating policy violation events for unauthorized activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual auditing is used to gather contextual information, then information accuracy is improved, but time consumption and operational complexity increase
Solution Approach 1:
The system enables automatic self-updating of network maps through passive monitoring of network traffic. The discovery system automatically detects hosts, services, and vulnerabilities without manual intervention, and the IDS automatically updates its own contextual information database by correlating intrusion events with the network map, eliminating the need for manual auditing while maintaining high accuracy
Solution Approach 2:
The patent replaces manual mechanical auditing processes with automated electronic systems. The passive discovery system uses network traffic analysis instead of manual host-by-host auditing, and the IDS uses automatic event correlation algorithms instead of manual information gathering, dramatically reducing time consumption while maintaining or improving information accuracy
2Extent of automation
If active scanning is used to discover network information, then automation is improved, but network stability deteriorates due to destructive probing
Solution Approach 1:
Instead of actively probing hosts to discover information (traditional approach), the system inverts the approach by passively monitoring network traffic to infer network characteristics. The discovery system analyzes existing network communications to identify hosts, services, and vulnerabilities without initiating disruptive scan operations, thereby maintaining network stability while achieving automation
Solution Approach 2:
The patent introduces a passive network map as an intermediary data structure that stores contextual information about network hosts and services. This network map serves as a mediator between the IDS and the actual network hosts, allowing the IDS to gain contextual information without directly probing or disrupting the hosts through active scanning
3Loss of information
If active scanning is performed periodically, then information freshness is improved, but network disruption increases
Solution Approach 1:
The system transitions from periodic active scanning to continuous passive monitoring. The discovery system continuously analyzes network traffic to detect changes in hosts, services, and vulnerabilities in real-time, ensuring information freshness without the need for periodic disruptive scan operations. This continuous passive operation eliminates network disruption while maintaining up-to-date contextual information
Solution Approach 2:
The system performs preliminary passive discovery and maintains a current network map before intrusion detection occurs. By continuously monitoring and updating the network map in advance, the IDS has fresh contextual information readily available when intrusion events occur, eliminating the need for periodic rescanning that would cause network disruption
4Device complexity
If IDS operates without contextual information, then system simplicity is improved, but detection accuracy deteriorates leading to false positives
Solution Approach 1:
The patent merges the intrusion detection function with the network discovery function into a unified system. The IDS and the passive discovery system are integrated, sharing common data structures (the network map) and working together to provide both contextual information and intrusion detection. This merging maintains relative system simplicity while dramatically improving detection accuracy by eliminating false positives through contextual awareness
Data Source
AI summary
A policy component includes policy configuration information. The policy configuration information contains one or more rules. Each rule and group of rules can be associated with a set of response actions. As the nodes on the monitored networks change or intrusive actions are introduced on the networks, network change events or intrusion events are generated. The policy component correlates network change events and/or intrusions events with network map information. The network map contains information on the network topology, services and network devices, amongst other things. When certain criteria is satisfied based on the correlation, a policy violation event may be issued by the system resulting in alerts or remediations.


