Layered Host Scoring for Dynamic Network Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network security detection systems lack the ability to dynamically assess the synergistic effect of security events and provide contextual information, leading to inadequate severity level determination and increased reliance on human judgment for evaluating network threats.
Innovation Solution
Implementing a layered scoring system that generates dynamic certainty and threat scores for network hosts based on session data analysis, integrating past historical detection data to provide enhanced alarm data for network administrators, using modules like detection scoring and host scoring processes to combine detection scores across time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If static severity metrics are used for security events, then the system implementation is simple, but the ability to dynamically assess the synergistic effect of security events is lost
Solution Approach 1:
The patent transforms static severity metrics into dynamic layered scores that evolve over time. The system implements detection scores, host scores, and alarm scores that are continuously updated based on new security events and historical data, allowing the severity assessment to adapt dynamically rather than remaining fixed
Solution Approach 2:
The patent introduces a temporal dimension to severity assessment by incorporating historical detection data and calculating layered scores across multiple time points. This transforms the assessment from a single static value to a multi-dimensional evaluation that considers evolution over time, adding depth to the severity measurement
2Device complexity
If contextual information about security events is not provided, then the alert data remains simple and easy to process, but human operators must make judgment calls in an informational vacuum
Solution Approach 1:
The system performs preliminary analysis by automatically calculating detection scores, host scores, and contextual information before presenting alerts to operators. This pre-processing of security events into scored, contextualized data reduces the cognitive burden on operators who receive pre-analyzed information rather than raw event data
3Speed
If real-time detection only is implemented, then the system responds quickly to current threats, but it cannot assess threats that accumulated over time
Solution Approach 1:
The patent adds a temporal dimension to threat detection by incorporating historical data into the scoring mechanism. The system evaluates security events not just in isolation at detection time, but in context of their evolution over time, allowing accumulation of threat evidence across multiple time points while maintaining real-time detection capability
Data Source
AI summary
Approaches for detecting network intrusions, such as malware infection, Trojans, worms, or bot net mining activities includes: identifying one or more threat detections in session datasets, the session datasets corresponding to network traffic from a plurality of hosts; determining a layered detection score, the layered detection score corresponding to a certainty score and threat score; determining a layered host score, the layered host score corresponding to a certainty score and threat score; and generating alarm data comprising the layered detection score and the layered host score. In some embodiments, the network traffic may be received passively through a network switch; for example, by “tapping” the switch. Other additional objects, features, and advantages of the invention are described in the detailed description, figures and claims.


