Network Anomaly Detection via Device Profile Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing anomaly detection methods in networks, particularly in dynamic and large-scale infrastructures, face challenges in scalability and accuracy, including the inability to differentiate between malicious and benign activities, and the risk of false positives due to incomplete learning phases.
Innovation Solution
A method and apparatus for detecting anomalies in network infrastructures that utilize a network analyzer to identify data packets, extract device identification fields, match devices with predefined standards, and compare allowed protocols and function codes with actual traffic, signaling anomalies when deviations are detected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a learning phase is used to memorize protocols and function codes before protecting phase, then detection accuracy is improved, but the system complexity and time consumption increase
Solution Approach 1:
The patent applies preliminary action by pre-populating a knowledge database with standard device profiles, protocols, and function codes before the system begins operation. This eliminates the need for a learning phase where the system would otherwise need to memorize network traffic patterns, thereby maintaining detection accuracy while reducing system complexity and deployment time.
Solution Approach 2:
The patent applies preliminary action by conducting validation of the knowledge database during the setup phase rather than during operation. This ensures the database contains only legitimate device profiles before anomaly detection begins, improving accuracy without requiring a separate learning phase that would increase system complexity.
2Measurement precision
If a long learning phase is used to secure more data, then detection accuracy is improved, but the time to deploy and the risk of false positives increase
Solution Approach 1:
The patent performs the equivalent of a long learning phase in advance by pre-populating the knowledge database with comprehensive device profiles, protocols, and function codes during system setup. This eliminates deployment time delays while maintaining high detection accuracy, as the system begins operation with complete knowledge of legitimate network behavior.
Solution Approach 2:
The patent uses a static, pre-defined knowledge database that can be quickly deployed and updated without requiring lengthy learning phases. This approach trades the continuous adaptation of learning systems for the efficiency of pre-configured knowledge, reducing deployment time while maintaining accuracy through comprehensive initial data collection.
3Adaptability or versatility
If the learning phase is used in a dynamic and big network, then more protocols are learned, but the scalability and validation difficulty increase
Solution Approach 1:
The patent applies preliminary action by pre-defining device profiles with supported protocols and function codes in a structured knowledge database. This allows the system to scale to large dynamic networks without learning phases, as the database can be efficiently queried to determine if observed traffic matches known legitimate patterns, maintaining both protocol coverage and scalability.
Solution Approach 2:
The patent segments the knowledge representation into discrete device profiles, each with defined protocols and function codes. This structured segmentation enables efficient storage, retrieval, and validation of device behavior patterns in large networks, allowing the system to handle diverse protocols while maintaining scalability through organized data structures rather than monolithic learning models.
4Measurement precision
If signature-based IDS is used to compare packets with pre-configured patterns, then detection accuracy is improved, but the adaptability to new threats decreases
Solution Approach 1:
The patent applies preliminary action by pre-configuring device profiles with legitimate protocols and function codes, enabling the system to detect anomalies including new threats by identifying deviations from established baselines. This approach maintains the precision of signature-based detection while improving adaptability, as the system can flag unknown function codes or protocol variations as anomalies without requiring pre-existing signatures for every potential threat.
Data Source
Figure 1
Figure 2
AI summary
The present invention relates to a method and to an apparatus for detecting anomalies of an infrastructure in a network comprising analysing a data packet (PD) exchanged in a network and identifying the network protocol and all the fields, through a network analyser (101), defining an identified protocol and identified fields of said data packet (PD), and, by means of computerized data processing means (102), extracting identification fields, to identify a device of the infrastructure in the network, matching the identified device with a plurality of predefined standard devices in a predefined devices knowledge database, to recognise a matching device, retrieving one or more allowed fields and one or more allowed protocols of the matching device from the predefined devices knowledge database, comparing the allowed fields and the allowed protocols respectively with the identified fields and the identified protocol, defining at least one critical state of the infrastructure when the identified fields differ from the allowed fields or when the identified protocol differ from the allowed protocols and signalling an anomaly of the infrastructure when at least one of the critical states is identified.