Layered Host Scoring for Dynamic Network Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security detection systems lack the ability to dynamically assess the synergistic effect of security events and provide contextual information, leading to inadequate severity level determination and increased reliance on human judgment for evaluating network threats.

Innovation Solution

Implementing a layered scoring system that generates dynamic certainty and threat scores for network hosts based on session data analysis, integrating past historical detection data to provide enhanced alarm data for network administrators, using modules like detection scoring and host scoring processes to combine detection scores across time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If static severity metrics are used for security events, then the system implementation is simple, but the ability to dynamically assess the synergistic effect of security events is lost

Engineering Contradiction:
Improvesystem implementation complexityVSAvoidseverity assessment accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent transforms static severity metrics into dynamic layered scores that evolve over time. The system implements detection scores, host scores, and alarm scores that are continuously updated based on new security events and historical data, allowing the severity assessment to adapt dynamically rather than remaining fixed

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a temporal dimension to severity assessment by incorporating historical detection data and calculating layered scores across multiple time points. This transforms the assessment from a single static value to a multi-dimensional evaluation that considers evolution over time, adding depth to the severity measurement

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If contextual information about security events is not provided, then the alert data remains simple and easy to process, but human operators must make judgment calls in an informational vacuum

Engineering Contradiction:
Improvealert data structureVSAvoidoperator decision-making ease
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The system performs preliminary analysis by automatically calculating detection scores, host scores, and contextual information before presenting alerts to operators. This pre-processing of security events into scored, contextualized data reduces the cognitive burden on operators who receive pre-analyzed information rather than raw event data

Inventive Principle:
Principle #10Preliminary action

3Speed

If real-time detection only is implemented, then the system responds quickly to current threats, but it cannot assess threats that accumulated over time

Engineering Contradiction:
Improvethreat detection speedVSAvoidhistorical threat context
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The patent adds a temporal dimension to threat detection by incorporating historical data into the scoring mechanism. The system evaluates security events not just in isolation at detection time, but in context of their evolution over time, allowing accumulation of threat evidence across multiple time points while maintaining real-time detection capability

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9565208B2System and method for detecting network intrusions using layered host scoring
Publication Date: 2017.02.07 VECTRA NETWORKS
  • US9565208B2 patent drawing
  • US9565208B2 patent drawing
  • US9565208B2 patent drawing

AI summary

Approaches for detecting network intrusions, such as malware infection, Trojans, worms, or bot net mining activities includes: identifying one or more threat detections in session datasets, the session datasets corresponding to network traffic from a plurality of hosts; determining a layered detection score, the layered detection score corresponding to a certainty score and threat score; determining a layered host score, the layered host score corresponding to a certainty score and threat score; and generating alarm data comprising the layered detection score and the layered host score. In some embodiments, the network traffic may be received passively through a network switch; for example, by “tapping” the switch. Other additional objects, features, and advantages of the invention are described in the detailed description, figures and claims.