IP Traffic Simulator for Security Device Detection Accuracy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security devices, such as intrusion prevention systems (IPS) and data leakage prevention systems (DLPS), often incorrectly identify benign traffic as malicious, leading to unnecessary communication interruptions and false positives, highlighting a need for improved methods to measure detection accuracy.

Innovation Solution

A method and system utilizing an IP traffic simulator to send and analyze benign traffic, similar in form and content to malicious traffic, to compute detection accuracy metrics, such as the percentage of benign traffic allowed to pass through security devices, thereby identifying false positives and improving filter accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security devices use signatures or filters to detect and block malicious traffic, then security protection capability is improved, but false positive rate increases causing unnecessary blocking of benign traffic

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies preliminary action by establishing a baseline of normal benign traffic patterns before deploying security filters. The system characterizes legitimate traffic in advance, creating a reference model that allows security devices to distinguish between malicious and benign traffic more accurately, thereby reducing false positives while maintaining protection capability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs parameter changes by dynamically adjusting detection thresholds and filter sensitivity based on the established baseline. The system modifies detection parameters adaptively, comparing actual traffic against the pre-characterized benign traffic patterns, which improves detection accuracy without compromising security protection

Inventive Principle:
Principle #35Parameter changes

2Reliability

If security devices block traffic suspected to be malicious, then security effectiveness is improved, but communication interruptions increase impacting legitimate traffic flow

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidcommunication flow
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements feedback mechanisms where the system continuously monitors both blocked and allowed traffic, comparing actual outcomes against the established baseline. This feedback loop allows the system to learn from detection results and adjust its behavior, ensuring that security effectiveness is maintained while minimizing unnecessary communication interruptions to legitimate traffic

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

By pre-characterizing benign traffic patterns before deployment, the system creates a reference model that enables more accurate real-time decisions. This preliminary characterization reduces the likelihood of blocking legitimate traffic, thereby maintaining communication flow productivity while preserving security effectiveness

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2850781B1Methods, systems, and computer readable media for measuring detection accuracy of a security device using benign traffic
Publication Date: 2019.06.26 KEYSIGHT TECH SINGAPORE (SALES) PTE LTD
  • EP2850781B1 patent drawingFigure 1
  • EP2850781B1 patent drawingFigure 2
  • EP2850781B1 patent drawingFigure 3

AI summary

Methods, systems, and computer readable media for measuring detection accuracy of a security device using benign traffic are disclosed. According to one method, the method occurs at an Internet protocol (IP) traffic simulator having a first communications interface and a second communications interface. The method includes sending, by the first communications interface, a plurality of benign data packets to a security device, wherein the plurality of benign data packets is engineered to be similar to one or more malicious data packets. The method also includes receiving, by the second communications interface, zero or more of the plurality of benign data packets via the security device. The method further includes determining, using statistics associated with the plurality of benign data packets, a detection accuracy metric associated with the security device.