Network Intelligence Database for Unknown Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems, such as IDS, rely on recognizing known attack patterns and are overwhelmed by the exponential increase in attacks, unable to detect or stop unknown signatures, and lack information about the identity and reputation of connected networks, leading to false positives and inadequate security measures.

Innovation Solution

A Network Intelligence Database that gathers and stores information about networks, including hostility level, security measures, and reputation, allowing networks to determine communication based on these factors, using a master database and customer network intelligence systems to provide real-time security updates and policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If IDS systems use known attack patterns and signatures for detection, then detection accuracy for known attacks is improved, but the system cannot detect unknown attacks and must be constantly upgraded

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect unknown attacks
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by continuously gathering network information, building reputation profiles, and establishing baseline behavior patterns before attacks occur. This allows the system to detect unknown attacks by comparing them against established network reputations and behavioral baselines, rather than waiting for signature updates

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces network reputation scores and information agents as intermediaries between the IDS and attack detection. These agents gather information about network behavior and reputation, mediating the detection process by providing contextual information that helps identify both known and unknown attacks without relying solely on signatures

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If IDS systems monitor all network traffic in real-time, then detection capability is improved, but the systems become overwhelmed by the exponential increase in attacks

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem overload
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system applies local quality by distributing detection resources and using localized reputation assessments for different network segments and sources. Instead of uniformly analyzing all traffic with equal depth, the system adjusts monitoring intensity and analysis depth based on network reputation and traffic characteristics, reducing overall system complexity while maintaining detection effectiveness

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by using reputation scores to selectively apply deeper analysis only to suspicious or low-reputation traffic sources. High-reputation traffic receives minimal scrutiny while low-reputation traffic undergoes comprehensive analysis, allowing the system to handle exponential attack increases without becoming overwhelmed

Inventive Principle:
Principle #16Partial or excessive action

3Device complexity

If network security devices lack information about network identity and reputation, then device simplicity is maintained, but false positives increase and security measures become inadequate

Engineering Contradiction:
Improvedevice simplicityVSAvoidsecurity effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system implements self-service through autonomous information agents that automatically gather network information, build reputation profiles, and update security policies without human intervention. This automation provides reliable reputation-based security decisions while keeping the core security devices relatively simple, as the intelligence-gathering function is performed independently by specialized agents

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8024795B2Network intelligence system
Publication Date: 2011.09.20 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8024795B2 patent drawing
  • US8024795B2 patent drawing
  • US8024795B2 patent drawing

AI summary

A network security system takes an active approach to network security. This is accomplished by providing intelligence about other networks. A master network intelligence database is established that uses a plurality of network information agents for gathering information about networks and providing the information to the master network intelligence database. A customer network security system is then able to secure the customer network in dependence upon information received from the master network intelligence. Security information includes at least one of hostility level on the Internet, collected from numerous sites; security event history; spam levels; hosted services; public wireless; organization type; organization associations; peer ISPs; bandwidth connection to the Internet; active security measures; number of users on the network; age of the network; inappropriate content served; industry; geographic placement; open proxy servers; and contact information.