Network Intrusion Detection via Protocol Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network intrusion detection systems rely on predefined associations between TCP/UDP port numbers and application layer protocols, which can lead to false negatives when server applications are deployed on non-standard ports, making it difficult to detect misbehavior and policy violations accurately.

Innovation Solution

A method that uses passive observation of network traffic to identify application layer protocols independently of predefined port associations, allowing for real-time detection of misuse by selecting appropriate analysis tasks and misuse signatures based on the detected protocol, and integrating protocol identification and intrusion detection in a single device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional IDS uses predefined port-protocol associations for protocol identification, then the detection process is simple and fast, but false negatives occur when servers are deployed on non-standard ports

Engineering Contradiction:
Improvedetection speedVSAvoiddetection accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent replaces the mechanical lookup system (port number to protocol mapping tables) with an intelligent analysis system that examines actual data flow characteristics. The detection engine analyzes payload content, protocol-specific patterns, and communication behaviors to identify protocols dynamically, eliminating reliance on static port associations and enabling accurate detection regardless of port numbers.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the identification parameter from static port numbers to dynamic data flow characteristics. By analyzing payload content, protocol-specific patterns, and communication behaviors, the system adapts its protocol identification to the actual observed traffic rather than predetermined port assignments, resolving the contradiction between speed and accuracy.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If manual configuration is used to associate protocols with ports, then customization is possible, but the configuration requires constant updates due to network dynamics

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidconfiguration maintenance time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements self-service by enabling the detection engine to automatically discover and adapt to protocol-port associations through passive observation of data flows. The system continuously learns the actual protocol deployments in the network by analyzing traffic patterns, eliminating the need for manual configuration updates and reducing maintenance overhead while maintaining high adaptability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the detection engine continuously observes network traffic and uses this information to dynamically adjust its protocol identification. The system learns from observed data flows and updates its understanding of protocol deployments automatically, providing both adaptability and reducing manual intervention requirements.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If passive observation is used for protocol identification, then network disruption is avoided, but protocol identification accuracy decreases when servers use non-standard ports

Engineering Contradiction:
Improvenetwork operation continuityVSAvoidprotocol identification accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent replaces passive port-based identification with active content-based analysis. By examining payload content, protocol-specific patterns, and communication behaviors in the observed traffic, the system achieves accurate protocol identification without disrupting network operations. The intelligent analysis compensates for the lack of active probing while maintaining high precision.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8042182B2Method and system for network intrusion detection, related network and computer program product
Publication Date: 2011.10.18 III HOLDINGS 1 LLC
  • US8042182B2 patent drawing
  • US8042182B2 patent drawing
  • US8042182B2 patent drawing

AI summary

A system for providing intrusion detection in a network wherein data flows are exchanged using associated network ports and application layer protocols. The system includes a monitoring module configured for monitoring data flows in the network, a protocol identification engine configured for detecting information on the application layer protocols involved in the monitored data flows, and an intrusion detection module configured for operating based on the information on application layer protocols detected. Intrusion detection is thus provided independently of any predefined association between the network ports and the application layer protocols.