Network Metadata Analysis for Suspicious Administrative Activity Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security systems face difficulties in effectively and efficiently detecting malicious administrative activity within networks, particularly in dynamic environments where fine-grain logging is not supported, and centralized authentication is risky or impossible to implement.

Innovation Solution

A system that analyzes network traffic to identify administrative hosts and their realms by learning behavior patterns, using metadata analysis and graph theoretic measures to detect suspicious activity, and generates alerts for anomalies in administrative protocol usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional network security systems use access logs to detect unauthorized access, then detection capability is improved, but the system becomes ineffective when fine-grain logging is not supported or when superuser accounts are used maliciously

Engineering Contradiction:
Improvedetection capabilityVSAvoideffectiveness in dynamic environments
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary detection system that sits between network traffic and the analysis engine. This intermediary layer captures and analyzes metadata from administrative protocols (SSH, SNMP, SIP, SIP, SCCP, H.323, RDP, Telnet, FTP) without requiring access to the target device's internal logging mechanisms. By mediating the detection process at the network layer, the system overcomes the limitation of unavailable fine-grain logs while maintaining high detection precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical approach of relying on target device logging capabilities with a network-based metadata analysis system. Instead of mechanically accessing logs from switches, routers, or VMs (which may not support fine-grain logging), the system substitutes this with electronic analysis of protocol metadata captured from network traffic, enabling detection in environments where traditional logging is unavailable or risky.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If centralized authentication is implemented to detect malicious activity, then security monitoring is improved, but the system becomes risky or impossible to implement in architecture devices such as switches, routers, or baseboard management controllers

Engineering Contradiction:
Improvesecurity monitoringVSAvoidimplementability in network devices
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent positions the detection system as an intermediary that monitors administrative protocol traffic without requiring centralized authentication implementation in network devices. The system captures metadata from protocols like SSH, SNMP, and Telnet as they traverse the network, providing reliable security monitoring without modifying or centralizing authentication mechanisms in switches, routers, or BMCs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the authentication and detection functionality from the network devices themselves (switches, routers, BMCs) and places it in a separate network-based analysis system. By taking out the need for centralized authentication implementation from the target devices, the system eliminates the risks and implementation difficulties associated with modifying network infrastructure devices while maintaining security monitoring capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If logging is performed in virtual machine based datacenters to detect suspicious activity, then detection accuracy is improved, but the system becomes ineffective due to the transient nature of the target host

Engineering Contradiction:
Improvedetection accuracyVSAvoidhost persistence
Core Design Contradiction:
Measurement precisionVSDuration of action of stationary object

Solution Approach 1:

The patent ensures continuous detection capability in virtualized environments by continuously monitoring network traffic metadata rather than relying on transient host-based logging. The network-based system maintains continuous observation of administrative protocol traffic, ensuring that detection accuracy is preserved even when VM hosts are transient, migrated, or ephemeral. This continuous network-layer monitoring bypasses the persistence issues of individual VM hosts.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent introduces a network-based intermediary detection system that operates at the network layer rather than the host level. This intermediary captures metadata from administrative protocols as they traverse the network infrastructure, providing persistent detection capability that is independent of the transient nature of VM hosts. The intermediary maintains continuous observation regardless of host lifecycle events.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3293938B1Method and system for detecting suspicious administrative activity
Publication Date: 2021.06.30 VECTRA NETWORKS
  • EP3293938B1 patent drawingFigure 1A
  • EP3293938B1 patent drawingFigure 1B
  • EP3293938B1 patent drawingFigure 2

AI summary

Disclosed is an improved approach for identifying suspicious administrative host activity within a network. Network traffic is examined to learn the behavior of hosts within a network. This provides an effective way of determining whether or not a host is performing suspicious activity over an administrative protocol.