Network Anomaly Detection via Device Profile Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anomaly detection methods in networks, particularly in dynamic and large-scale infrastructures, face challenges in scalability and accuracy, including the inability to differentiate between malicious and benign activities, and the risk of false positives due to incomplete learning phases.

Innovation Solution

A method and apparatus for detecting anomalies in network infrastructures that utilize a network analyzer to identify data packets, extract device identification fields, match devices with predefined standards, and compare allowed protocols and function codes with actual traffic, signaling anomalies when deviations are detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a learning phase is used to memorize protocols and function codes before protecting phase, then detection accuracy is improved, but the system complexity and time consumption increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-populating a knowledge database with standard device profiles, protocols, and function codes before the system begins operation. This eliminates the need for a learning phase where the system would otherwise need to memorize network traffic patterns, thereby maintaining detection accuracy while reducing system complexity and deployment time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies preliminary action by conducting validation of the knowledge database during the setup phase rather than during operation. This ensures the database contains only legitimate device profiles before anomaly detection begins, improving accuracy without requiring a separate learning phase that would increase system complexity.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If a long learning phase is used to secure more data, then detection accuracy is improved, but the time to deploy and the risk of false positives increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddeployment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs the equivalent of a long learning phase in advance by pre-populating the knowledge database with comprehensive device profiles, protocols, and function codes during system setup. This eliminates deployment time delays while maintaining high detection accuracy, as the system begins operation with complete knowledge of legitimate network behavior.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses a static, pre-defined knowledge database that can be quickly deployed and updated without requiring lengthy learning phases. This approach trades the continuous adaptation of learning systems for the efficiency of pre-configured knowledge, reducing deployment time while maintaining accuracy through comprehensive initial data collection.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Adaptability or versatility

If the learning phase is used in a dynamic and big network, then more protocols are learned, but the scalability and validation difficulty increase

Engineering Contradiction:
Improveprotocol coverageVSAvoidscalability
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-defining device profiles with supported protocols and function codes in a structured knowledge database. This allows the system to scale to large dynamic networks without learning phases, as the database can be efficiently queried to determine if observed traffic matches known legitimate patterns, maintaining both protocol coverage and scalability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the knowledge representation into discrete device profiles, each with defined protocols and function codes. This structured segmentation enables efficient storage, retrieval, and validation of device behavior patterns in large networks, allowing the system to handle diverse protocols while maintaining scalability through organized data structures rather than monolithic learning models.

Inventive Principle:
Principle #1Segmentation

4Measurement precision

If signature-based IDS is used to compare packets with pre-configured patterns, then detection accuracy is improved, but the adaptability to new threats decreases

Engineering Contradiction:
Improvemalicious attack detectionVSAvoidnew threat detection
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by pre-configuring device profiles with legitimate protocols and function codes, enabling the system to detect anomalies including new threats by identifying deviations from established baselines. This approach maintains the precision of signature-based detection while improving adaptability, as the system can flag unknown function codes or protocol variations as anomalies without requiring pre-existing signatures for every potential threat.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4236202B1Method and apparatus for detecting anomalies of an infrastructure in a network
Publication Date: 2025.05.07 NOZOMI NETWORKS SAGL
  • EP4236202B1 patent drawingFigure 1
  • EP4236202B1 patent drawingFigure 2

AI summary

The present invention relates to a method and to an apparatus for detecting anomalies of an infrastructure in a network comprising analysing a data packet (PD) exchanged in a network and identifying the network protocol and all the fields, through a network analyser (101), defining an identified protocol and identified fields of said data packet (PD), and, by means of computerized data processing means (102), extracting identification fields, to identify a device of the infrastructure in the network, matching the identified device with a plurality of predefined standard devices in a predefined devices knowledge database, to recognise a matching device, retrieving one or more allowed fields and one or more allowed protocols of the matching device from the predefined devices knowledge database, comparing the allowed fields and the allowed protocols respectively with the identified fields and the identified protocol, defining at least one critical state of the infrastructure when the identified fields differ from the allowed fields or when the identified protocol differ from the allowed protocols and signalling an anomaly of the infrastructure when at least one of the critical states is identified.