Intrusion Detection Event Risk Rating Calculation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network intrusion detection systems face challenges in accurately assessing the risk of potential attacks due to false positives and lack of precision in severity ratings, which hinders effective resource allocation and response policies.

Innovation Solution

A method that calculates an event risk rating by considering factors such as signature fidelity, attack relevance, and target value, allowing for more precise assessment and prioritization of attacks, and enabling tailored response policies based on the calculated risk rating.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network intrusion detection systems monitor all network activity in real-time to detect suspicious or malicious activity, then the system can detect attacks quickly and provide timely warnings, but the system generates false positives when known signatures are detected but have no potential impact on the computer system

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidfalse positives
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent changes the parameters for risk assessment from simple signature detection to a multi-factor evaluation model. This includes calculating risk ratings based on multiple parameters such as attack severity, system vulnerability, attack frequency, and business impact, thereby reducing false positives while maintaining detection accuracy

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring network activity, assessing risk ratings, and adjusting detection policies based on historical data and actual system behavior. This feedback loop enables the system to learn from past false positives and refine its detection accuracy over time

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If the system blocks all potential attacks based on signature detection, then attack prevention is improved, but the system cannot distinguish between actual threats and benign activity, leading to over-blocking

Engineering Contradiction:
Improveattack preventionVSAvoidresource allocation efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent introduces a risk rating calculation that evaluates multiple parameters including attack severity, system vulnerability level, attack frequency, and business impact. This multi-parameter approach enables the system to prioritize blocking actions based on actual risk rather than simply blocking all detected signatures, thereby improving resource allocation efficiency

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Instead of blocking all potential attacks uniformly, the system applies partial blocking based on calculated risk ratings. High-risk attacks are blocked automatically, while low-risk or false-positive detections are allowed to pass, avoiding excessive blocking and maintaining normal business operations

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If the system responds to all detected attacks with the same blocking policy, then the response mechanism is simple, but the system cannot prioritize resource allocation based on attack severity and impact

Engineering Contradiction:
Improveresponse mechanism simplicityVSAvoidresource allocation efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent transforms the response mechanism from a uniform blocking policy to a differentiated response strategy based on calculated risk ratings. The system evaluates multiple parameters including attack severity, system criticality, and business impact to determine appropriate response actions, enabling efficient resource allocation to high-priority threats

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements dynamic response policies that adapt based on the calculated risk rating. The response mechanism transitions from static uniform blocking to dynamic conditional responses, where the system automatically adjusts blocking, alerting, and resource allocation based on the severity and impact assessment of each detected attack

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7526806B2Method and system for addressing intrusion attacks on a computer system
Publication Date: 2009.04.28 CISCO TECHNOLOGY INC
  • US7526806B2 patent drawing
  • US7526806B2 patent drawing
  • US7526806B2 patent drawing

AI summary

According to one embodiment of the invention, a computerized method for addressing intrusion attacks directed at a computer includes receiving a data stream corresponding to a potential attack on the computer and calculating an event risk rating for the data stream. Calculating the event risk rating includes determining at least one component risk rating. In one embodiment, the component risk ratings are: a signature fidelity rating indicative of the likelihood the potential attack will affect the computer in the absence of knowledge regarding the computer, an attack relevance rating indicative of the relevance of the potential attack to the computer, and a target value rating indicative of the perceived value of the computer. The method also includes responding to the potential attack based on the calculated risk rating.