Network Detection Signatures via Configuration Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing approaches to network security using machine learning fail to account for network configuration and policy data, which provides valuable information for maintaining network security.
Innovation Solution
The method involves generating detection signatures based on attack paths in a computer network using a software representation that embodies network configuration and policy data, with the help of detection signature templates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If machine learning models are used to detect network security threats based solely on observed traffic patterns, then the system can operate autonomously without requiring detailed network configuration data, but the detection accuracy and ability to identify novel attacks are limited
Solution Approach 1:
The patent combines machine learning-based anomaly detection with rule-based detection signatures derived from network configuration and policy data. This merging allows the system to leverage both the autonomous learning capabilities of ML models and the precise, context-aware detection of rule-based systems, thereby improving overall detection accuracy while maintaining manageable system complexity through modular integration
Solution Approach 2:
The patent introduces detection signature templates as an intermediary layer that translates network configuration and policy data into actionable detection rules. These templates serve as a mediator between the raw configuration data and the detection engine, enabling automated generation of accurate detection signatures without requiring manual rule creation, thus improving detection reliability while reducing the complexity of rule management
2Reliability
If detection signatures are manually created to represent abnormal behavior, then engineers can capture specific attack patterns, but the process is time-consuming and cannot scale to cover all possible attack vectors
Solution Approach 1:
The patent enables the system to automatically generate detection signatures by analyzing network configuration and policy data itself, without requiring manual engineering for each signature. The system self-services by extracting attack paths from configuration data, matching them against templates, and generating ready-to-deploy detection signatures, thereby achieving comprehensive detection coverage while eliminating the time-consuming manual signature creation process
Solution Approach 2:
The patent performs preliminary analysis of network configuration and policy data to pre-identify potential attack paths and generate detection signatures before actual attacks occur. This preliminary action allows the system to be proactively prepared with detection capabilities for all possible attack vectors defined by the network configuration, rather than reactively creating signatures after observing attacks, thus improving detection coverage while reducing response time
3Reliability
If network configuration and policy data are utilized to generate detection signatures, then the system can detect attacks that exploit specific network relationships, but the complexity of analyzing and processing this data increases
Solution Approach 1:
The patent segments the complex task of analyzing network configuration and policy data into distinct, manageable components: parsing configuration data into structured representations, identifying attack paths through graph analysis, matching paths against detection templates, and generating signatures. This segmentation reduces processing complexity by breaking down the monolithic analysis task into modular, independently processable stages while maintaining context-aware detection capabilities
Data Source
AI summary
Disclosed is an approach for generating detection signatures based on analysis of a software representation of what is possible in a computer network based on network configuration data and network policy data. In some embodiments, the process includes maintaining a plurality of detection signature templates, generation of detection signatures (detection signature instances) using respective detection signature templates that are selected based on the analysis of the software representation. In some embodiments, detection signatures templates are of different type and may be deployed at different locations based on their respective type(s), such as at source, destination.


