Network Connection Control via Adaptive Communication Degradation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network intrusion detection systems face challenges in accurately distinguishing between genuine and false alarms, leading to either missed intrusions or excessive operator alerts, which can result in poor system performance and delayed responses due to their binary response nature.

Innovation Solution

Implementing a method and apparatus that degrades communication between a data processor and a network by delaying or reducing communication requests, allowing the system to respond in a benign manner, such as reducing bandwidth or delaying connection initiation, while monitoring abnormal behavior and notifying operators only when thresholds are exceeded.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If the sensitivity of the intrusion detection system is increased to reduce false negatives, then the detection of real intrusions is improved, but the rate of false positives increases correspondingly

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidfalse alarm rate
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The system applies partial action by implementing a two-stage response mechanism. Instead of immediately responding to all detected intrusions with full countermeasures, the system first applies a mild degradation action (bandwidth reduction) to suspected intrusions. This allows the system to maintain high sensitivity for detecting intrusions while minimizing the harmful impact of false positives, as the degraded communication can be further analyzed before definitive action is taken.

Inventive Principle:
Principle #16Partial or excessive action

2Loss of time

If automatic systems are used to reduce operator involvement, then response time is improved, but false alarms result in poor system performance due to drastic responses

Engineering Contradiction:
Improveresponse timeVSAvoidsystem performance
Core Design Contradiction:
Loss of timeVSProductivity

Solution Approach 1:

The system implements dynamics by making the response mechanism adaptive rather than static. The communication degradation level is dynamically adjusted based on the confidence level of intrusion detection. For low-confidence detections, milder degradation is applied, while high-confidence intrusions receive stronger countermeasures. This dynamic approach allows automatic systems to respond quickly without consistently applying drastic measures that would harm system performance.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system uses cheap short-living objects by implementing temporary communication degradation rather than permanent connection termination. When an intrusion is detected, the system applies temporary bandwidth reduction or delay that can be quickly reversed if proven to be a false alarm. This disposable approach to countermeasures allows rapid automatic response while minimizing long-term impact on system performance if the detection was incorrect.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Speed

If communication requests are immediately processed, then system responsiveness is improved, but unauthorized access can occur before detection

Engineering Contradiction:
Improvecommunication processing speedVSAvoidnetwork security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system applies preliminary action by performing intrusion detection and assessment before fully processing communication requests. When a communication request is detected, the system immediately evaluates it for suspicious patterns and applies preliminary degradation measures if intrusion is suspected. This allows the system to maintain high responsiveness for legitimate traffic while preventing unauthorized access through pre-emptive countermeasures.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7558216B2Network connection control
Publication Date: 2009.07.07 HEWLETT PACKARD ENTERPRISE DEV LP
  • US7558216B2 patent drawing
  • US7558216B2 patent drawing
  • US7558216B2 patent drawing

AI summary

A method and apparatus for controlling communications in a data network comprises detecting a request to initiate communication between a data processor and the network and determining if the communication request is abnormal and if so, controlling the data processor to degrade the resulting communication.