Network Data Monitoring With Real-Time Packet Anomaly Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network systems lack effective real-time protection against advanced persistent threats and zero-day attacks due to increased data network speeds and complexity from network disaggregation, with existing methods failing to provide preemptive security for distributed denial of service (DDoS), protocol anomalies, and software vulnerabilities.
Innovation Solution
A network system comprising a traffic collector, machine learning component, and policy component that analyzes packet metadata to generate real-time mitigation policies for anomaly detection and enforcement, using a policy agent to implement these policies across network endpoints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If standard protocols (netflow, sflow) are used for telemetry data collection, then existing system components are maintained, but real-time protection against advanced persistent threats and zero-day attacks is insufficient
Solution Approach 1:
The system performs preliminary actions by collecting packet metadata and creating time series profiles before attacks occur. Behavioral models are established in advance to enable real-time anomaly detection, allowing the system to identify and respond to zero-day attacks and advanced persistent threats before they can cause significant damage.
Solution Approach 2:
The patent introduces an intermediary analytics platform that sits between standard telemetry protocols and security response systems. This platform processes packet metadata, creates behavioral models, and generates anomaly detections, serving as a mediator that enhances security capabilities without requiring complete system replacement.
2Adaptability or versatility
If network disaggregation is implemented to improve system flexibility, then adaptability increases, but the number of subcomponents increases making the system more vulnerable
Solution Approach 1:
The analytics platform performs multiple functions including packet metadata collection, time series profile creation, behavioral model generation, anomaly detection, and mitigation policy creation. This multi-functional approach consolidates security capabilities across disaggregated network components, providing comprehensive protection without requiring separate specialized systems for each function.
3Measurement precision
If statistical analysis of packet metadata is performed to detect anomalies, then detection capability improves, but response time is delayed as new signatures must be derived after attacks are analyzed
Solution Approach 1:
The system creates time series profiles and behavioral models in advance before attacks occur. These pre-established models enable immediate real-time anomaly detection when threats are detected, eliminating the delay associated with deriving new signatures after attacks are analyzed. The system is prepared to respond instantly to zero-day attacks and advanced persistent threats.
4Productivity
If existing systems are used to monitor network traffic, then system stability is maintained, but they cannot scale to next-generation traffic densities
Solution Approach 1:
The patent introduces an intermediary analytics platform that processes packet metadata without requiring replacement of existing network infrastructure. This mediator approach enables scaling to next-generation traffic densities by adding analytical capabilities at the data collection and processing layer, maintaining system stability while dramatically increasing traffic handling capacity.
Data Source
AI summary
This disclosure describes methods, devices and systems for anomaly detection and policy enforcement. An example network server includes a network interface component configured to obtain network packets in real time from a router device. The network server also includes a data processing unit configured to extract packet metadata from the network packets. The network server further includes a policy component configured to provide a policy rule to the router device, the policy rule generated based on an analysis of the packet metadata.


