Network Profiling Correlation for Security Risk Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network administrators face challenges in accurately determining the security posture of computer networks due to varying security vulnerabilities across different services and communication protocols, misconfigurations, and unwanted applications, making it difficult to detect and prevent network attacks effectively.
Innovation Solution
An intrusion detection and prevention (IDP) device with network profiling capabilities that monitors and learns network elements, uses protocol-specific decoders to analyze traffic, and builds correlations between application-layer and network elements within a relational database, allowing for the detection of policy violations and changes that may expose security risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional network monitoring methods are used, then network traffic can be observed, but security risks such as misconfigured devices, firewall holes, and unwanted services cannot be accurately detected
Solution Approach 1:
The patent segments network monitoring into multiple layers: network-layer monitoring (IP addresses, ports, protocols) and application-layer monitoring (HTTP, FTP, SMTP, DNS protocols). This segmentation allows detailed analysis of specific protocol characteristics and security parameters at each layer, improving detection accuracy while managing complexity through modular analysis approaches.
Solution Approach 2:
The patent introduces an intrusion detection and prevention (IDP) device as an intermediary between network traffic sources and destinations. This IDP device correlates network-layer and application-layer information, acts as a mediator that analyzes traffic patterns, and provides centralized security monitoring without disrupting normal network operations.
2Difficulty of detecting and measuring
If comprehensive network monitoring is implemented to detect all security risks, then detection capability improves, but system complexity and resource requirements increase
Solution Approach 1:
The monitoring system is divided into distinct functional modules: network-layer monitoring component, application-layer monitoring component, correlation database, and analysis engine. Each module handles specific aspects of traffic analysis, reducing individual component complexity while achieving comprehensive monitoring through their coordinated operation.
Solution Approach 2:
The patent adds the application-layer dimension to traditional network-layer monitoring. By incorporating application protocol analysis (HTTP, FTP, SMTP, DNS) alongside network-layer parameters (IP addresses, ports), the system creates a multi-dimensional monitoring approach that comprehensively detects security risks without overwhelming single-layer complexity.
3Measurement precision
If detailed protocol analysis is performed to identify security vulnerabilities, then detection precision improves, but processing time and computational resources increase
Solution Approach 1:
The system performs preliminary correlation of network-layer and application-layer information in advance, building a correlated dataset that combines IP addresses, ports, protocols, and application-specific parameters. This preliminary correlation prepares the data structure for rapid security analysis, reducing processing time during actual threat detection while maintaining detailed protocol analysis capabilities.
Solution Approach 2:
The patent applies protocol-specific analysis selectively based on detected traffic patterns and security requirements. Rather than analyzing every packet at maximum detail, the system performs partial analysis focused on relevant protocol characteristics and security parameters, achieving sufficient detection precision without excessive processing overhead for all traffic.
Data Source
AI summary
A correlation database stores profiling data that describes packet flows within a network. A network device presents a user interface by which a user defines a database trigger to detect database operations that change to the profiling data stored within the correlation database. The network device may maintain a log to record the detected database operations. The database trigger may specify a combination of low-level network elements associated with the packet flows and application-layer elements extracted from application-layer communications reassembled from the packet flows.


