Multi-method Gateway Network Security System for Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security technologies are inadequate in detecting and preventing sophisticated network security breaches, as they often result in high false alarm rates, fail to examine packets effectively, and cannot prevent attacks in real-time, especially when integrated with firewalls and intrusion detection systems.

Innovation Solution

A multi-method network security system (MMIDP) that integrates stateful signature detection, traffic signature detection, and protocol anomaly detection, equipped with software modules like IP defragmentation, flow management, and protocol anomaly detection, to accurately identify and drop suspicious packets before they reach network hosts or the outside network, while being centrally managed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If multiple detection methods are integrated to improve detection accuracy, then the system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system divides intrusion detection into three independent modules: stateful signature detection module, traffic signature detection module, and protocol anomaly detection module. Each module handles specific detection tasks separately, allowing the system to achieve comprehensive detection accuracy while maintaining manageable complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent combines three different detection methodologies (stateful inspection, signature matching, and anomaly detection) into a unified intrusion detection system. The modules work together synergistically, with each contributing unique detection capabilities that complement the others, achieving higher overall detection accuracy than any single method could provide alone.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If real-time packet examination is performed to prevent attacks, then the processing time and system resource consumption increase

Engineering Contradiction:
Improveattack prevention capabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary classification of packets using efficient filtering mechanisms before applying more intensive detection methods. Routine packets are processed quickly through simple filters, while only suspicious packets undergo deeper examination, reducing overall processing time while maintaining reliable attack prevention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies full-depth inspection only to packets that trigger suspicion thresholds, rather than examining every packet with maximum scrutiny. This partial action approach maintains high reliability for detecting actual attacks while significantly reducing average processing time for normal traffic.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If comprehensive packet inspection is performed to reduce false alarms, then the false alarm rate decreases but the system complexity increases

Engineering Contradiction:
Improvefalse alarm rateVSAvoidinspection complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Different detection modules apply specialized inspection techniques tailored to specific packet characteristics and threat types. The stateful signature detection module examines connection states, the traffic signature module patterns data flows, and the protocol anomaly module validates protocol compliance. This localized specialization reduces false alarms while keeping each module's complexity manageable.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses a composite detection approach combining multiple detection methodologies (stateful inspection, signature matching, anomaly detection) that work together to provide comprehensive verification. This composite strategy cross-validates findings across different detection methods, significantly reducing false alarms through multi-faceted verification.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS8370936B2Multi-method gateway-based network security systems and methods
Publication Date: 2013.02.05 JUNIPER NETWORKS INC
  • US8370936B2 patent drawing
  • US8370936B2 patent drawing
  • US8370936B2 patent drawing

AI summary

Systems and methods for detecting and preventing network security breaches are described. The systems and methods present a gateway-based packet-forwarding network security solution to not only detect security breaches but also prevent them by directly dropping suspicious packets and connections. The systems and methods employ multiple techniques to detect and prevent network security breaches, including stateful signature detection, traffic signature detection, and protocol anomaly detection.