ML Detection of Unused Open Ports

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and tracking open ports on computing devices is challenging due to their dynamic configuration and the complexity of network attacks, leading to unintentionally left open ports that can be exploited by cybercriminals.

Innovation Solution

A machine learning model is employed to detect unused open ports by analyzing execution logs from client machines to identify commonly-used executables and their associated ports, using data mining techniques to generate and train a classifier that predicts which executables are not associated with open ports, thereby identifying unused ports and notifying administrators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrators manually track and manage open ports, then security configuration can be maintained, but administrative overhead and complexity increase significantly

Engineering Contradiction:
Improvesecurity configurationVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables automatic self-monitoring and self-diagnosis of port usage status through machine learning models that continuously analyze executable processes and determine whether open ports are actively used, eliminating the need for manual administrative tracking and intervention

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual administrative processes for tracking port usage are replaced with an automated machine learning-based detection system that uses computational algorithms to analyze process data and identify unused ports, substituting human effort with intelligent automation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If all open ports are kept accessible, then service functionality is maintained, but vulnerability to cyber attacks increases

Engineering Contradiction:
Improveservice functionalityVSAvoidcyber attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system extracts and identifies specifically the unused open ports from the set of all open ports, separating them from actively used ports so they can be individually addressed for security hardening without affecting the functionality of necessary open ports

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the security parameter of identified unused ports from 'open' to 'closed' based on ML detection results, dynamically adjusting port accessibility to maintain service functionality while reducing attack surface

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If port tracking is implemented manually, then some security monitoring is achieved, but accuracy and timeliness deteriorate due to configuration changes

Engineering Contradiction:
Improveport status trackingVSAvoidport usage detection accuracy
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The machine learning model operates continuously to monitor and detect port usage status, providing ongoing real-time or near-real-time detection that maintains high accuracy despite dynamic configuration changes, unlike periodic manual checks that miss transient states

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11429724B2Machine learning detection of unused open ports
Publication Date: 2022.08.30 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11429724B2 patent drawing
  • US11429724B2 patent drawing
  • US11429724B2 patent drawing

AI summary

A security service utilizes a machine learning model to detect unused open ports. A security agent on client machines tracks the operating executables and the open ports on a machine. A machine learning model is trained for a specific port number using the more commonly-used executables that run on machines having the port opened from a large and diverse population of machines. The model is then used to determine the ports that an executable is likely to be associated with which is then used to determine if a particular machine has an unused open port.