Network Detection Signatures via Configuration Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing approaches to network security using machine learning fail to account for network configuration and policy data, which provides valuable information for maintaining network security.

Innovation Solution

The method involves generating detection signatures based on attack paths in a computer network using a software representation that embodies network configuration and policy data, with the help of detection signature templates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If machine learning models are used to detect network security threats based solely on observed traffic patterns, then the system can operate autonomously without requiring detailed network configuration data, but the detection accuracy and ability to identify novel attacks are limited

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines machine learning-based anomaly detection with rule-based detection signatures derived from network configuration and policy data. This merging allows the system to leverage both the autonomous learning capabilities of ML models and the precise, context-aware detection of rule-based systems, thereby improving overall detection accuracy while maintaining manageable system complexity through modular integration

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces detection signature templates as an intermediary layer that translates network configuration and policy data into actionable detection rules. These templates serve as a mediator between the raw configuration data and the detection engine, enabling automated generation of accurate detection signatures without requiring manual rule creation, thus improving detection reliability while reducing the complexity of rule management

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If detection signatures are manually created to represent abnormal behavior, then engineers can capture specific attack patterns, but the process is time-consuming and cannot scale to cover all possible attack vectors

Engineering Contradiction:
Improvedetection coverageVSAvoidsignature development time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent enables the system to automatically generate detection signatures by analyzing network configuration and policy data itself, without requiring manual engineering for each signature. The system self-services by extracting attack paths from configuration data, matching them against templates, and generating ready-to-deploy detection signatures, thereby achieving comprehensive detection coverage while eliminating the time-consuming manual signature creation process

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary analysis of network configuration and policy data to pre-identify potential attack paths and generate detection signatures before actual attacks occur. This preliminary action allows the system to be proactively prepared with detection capabilities for all possible attack vectors defined by the network configuration, rather than reactively creating signatures after observing attacks, thus improving detection coverage while reducing response time

Inventive Principle:
Principle #10Preliminary action

3Reliability

If network configuration and policy data are utilized to generate detection signatures, then the system can detect attacks that exploit specific network relationships, but the complexity of analyzing and processing this data increases

Engineering Contradiction:
Improvecontext-aware detectionVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex task of analyzing network configuration and policy data into distinct, manageable components: parsing configuration data into structured representations, identifying attack paths through graph analysis, matching paths against detection templates, and generating signatures. This segmentation reduces processing complexity by breaking down the monolithic analysis task into modular, independently processable stages while maintaining context-aware detection capabilities

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12219070B2Method, product, and system for generating detection signatures based on attack paths in a computer network identified using a software representation that embodies network configuration and policy data for security management using detection signature templates
Publication Date: 2025.02.04 VECTRA NETWORKS
  • US12219070B2 patent drawing
  • US12219070B2 patent drawing
  • US12219070B2 patent drawing

AI summary

Disclosed is an approach for generating detection signatures based on analysis of a software representation of what is possible in a computer network based on network configuration data and network policy data. In some embodiments, the process includes maintaining a plurality of detection signature templates, generation of detection signatures (detection signature instances) using respective detection signature templates that are selected based on the analysis of the software representation. In some embodiments, detection signatures templates are of different type and may be deployed at different locations based on their respective type(s), such as at source, destination.