Network Intelligence Database for Unknown Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems, such as IDS, rely on recognizing known attack patterns and are overwhelmed by the exponential increase in attacks, unable to detect or stop unknown signatures, and lack information about the identity and reputation of connected networks, leading to false positives and inadequate security measures.
Innovation Solution
A Network Intelligence Database that gathers and stores information about networks, including hostility level, security measures, and reputation, allowing networks to determine communication based on these factors, using a master database and customer network intelligence systems to provide real-time security updates and policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If IDS systems use known attack patterns and signatures for detection, then detection accuracy for known attacks is improved, but the system cannot detect unknown attacks and must be constantly upgraded
Solution Approach 1:
The system performs preliminary actions by continuously gathering network information, building reputation profiles, and establishing baseline behavior patterns before attacks occur. This allows the system to detect unknown attacks by comparing them against established network reputations and behavioral baselines, rather than waiting for signature updates
Solution Approach 2:
The patent introduces network reputation scores and information agents as intermediaries between the IDS and attack detection. These agents gather information about network behavior and reputation, mediating the detection process by providing contextual information that helps identify both known and unknown attacks without relying solely on signatures
2Productivity
If IDS systems monitor all network traffic in real-time, then detection capability is improved, but the systems become overwhelmed by the exponential increase in attacks
Solution Approach 1:
The system applies local quality by distributing detection resources and using localized reputation assessments for different network segments and sources. Instead of uniformly analyzing all traffic with equal depth, the system adjusts monitoring intensity and analysis depth based on network reputation and traffic characteristics, reducing overall system complexity while maintaining detection effectiveness
Solution Approach 2:
The patent implements partial action by using reputation scores to selectively apply deeper analysis only to suspicious or low-reputation traffic sources. High-reputation traffic receives minimal scrutiny while low-reputation traffic undergoes comprehensive analysis, allowing the system to handle exponential attack increases without becoming overwhelmed
3Device complexity
If network security devices lack information about network identity and reputation, then device simplicity is maintained, but false positives increase and security measures become inadequate
Solution Approach 1:
The system implements self-service through autonomous information agents that automatically gather network information, build reputation profiles, and update security policies without human intervention. This automation provides reliable reputation-based security decisions while keeping the core security devices relatively simple, as the intelligence-gathering function is performed independently by specialized agents
Data Source
AI summary
A network security system takes an active approach to network security. This is accomplished by providing intelligence about other networks. A master network intelligence database is established that uses a plurality of network information agents for gathering information about networks and providing the information to the master network intelligence database. A customer network security system is then able to secure the customer network in dependence upon information received from the master network intelligence. Security information includes at least one of hostility level on the Internet, collected from numerous sites; security event history; spam levels; hosted services; public wireless; organization type; organization associations; peer ISPs; bandwidth connection to the Internet; active security measures; number of users on the network; age of the network; inappropriate content served; industry; geographic placement; open proxy servers; and contact information.


