Intrusion Detection Correlating Network Discovery Maps

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional intrusion detection systems (IDSs) are ineffective due to the lack of contextual information about computer network end points, leading to increased susceptibility to attacks and false positives, and existing automatic discovery methods are either manual, time-consuming, prone to errors, or destructive to the network.

Innovation Solution

A system and method that passively and automatically determine network characteristics by correlating intrusion events with stored network maps using policy configuration information, reducing false positives by evaluating events against predefined rules and generating policy violation events for unauthorized activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual auditing is used to gather contextual information, then information accuracy is improved, but time consumption and operational complexity increase

Engineering Contradiction:
Improveinformation accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables automatic self-updating of network maps through passive monitoring of network traffic. The discovery system automatically detects hosts, services, and vulnerabilities without manual intervention, and the IDS automatically updates its own contextual information database by correlating intrusion events with the network map, eliminating the need for manual auditing while maintaining high accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical auditing processes with automated electronic systems. The passive discovery system uses network traffic analysis instead of manual host-by-host auditing, and the IDS uses automatic event correlation algorithms instead of manual information gathering, dramatically reducing time consumption while maintaining or improving information accuracy

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Extent of automation

If active scanning is used to discover network information, then automation is improved, but network stability deteriorates due to destructive probing

Engineering Contradiction:
ImproveautomationVSAvoidnetwork stability
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

Instead of actively probing hosts to discover information (traditional approach), the system inverts the approach by passively monitoring network traffic to infer network characteristics. The discovery system analyzes existing network communications to identify hosts, services, and vulnerabilities without initiating disruptive scan operations, thereby maintaining network stability while achieving automation

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces a passive network map as an intermediary data structure that stores contextual information about network hosts and services. This network map serves as a mediator between the IDS and the actual network hosts, allowing the IDS to gain contextual information without directly probing or disrupting the hosts through active scanning

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If active scanning is performed periodically, then information freshness is improved, but network disruption increases

Engineering Contradiction:
Improveinformation freshnessVSAvoidnetwork disruption
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system transitions from periodic active scanning to continuous passive monitoring. The discovery system continuously analyzes network traffic to detect changes in hosts, services, and vulnerabilities in real-time, ensuring information freshness without the need for periodic disruptive scan operations. This continuous passive operation eliminates network disruption while maintaining up-to-date contextual information

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs preliminary passive discovery and maintains a current network map before intrusion detection occurs. By continuously monitoring and updating the network map in advance, the IDS has fresh contextual information readily available when intrusion events occur, eliminating the need for periodic rescanning that would cause network disruption

Inventive Principle:
Principle #10Preliminary action

4Device complexity

If IDS operates without contextual information, then system simplicity is improved, but detection accuracy deteriorates leading to false positives

Engineering Contradiction:
Improvesystem simplicityVSAvoiddetection accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent merges the intrusion detection function with the network discovery function into a unified system. The IDS and the passive discovery system are integrated, sharing common data structures (the network map) and working together to provide both contextual information and intrusion detection. This merging maintains relative system simplicity while dramatically improving detection accuracy by eliminating false positives through contextual awareness

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8046833B2Intrusion event correlation with network discovery information
Publication Date: 2011.10.25 CISCO TECHNOLOGY INC
  • US8046833B2 patent drawing
  • US8046833B2 patent drawing
  • US8046833B2 patent drawing

AI summary

A policy component includes policy configuration information. The policy configuration information contains one or more rules. Each rule and group of rules can be associated with a set of response actions. As the nodes on the monitored networks change or intrusive actions are introduced on the networks, network change events or intrusion events are generated. The policy component correlates network change events and/or intrusions events with network map information. The network map contains information on the network topology, services and network devices, amongst other things. When certain criteria is satisfied based on the correlation, a policy violation event may be issued by the system resulting in alerts or remediations.