Network Profiling Correlation for Security Risk Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network administrators face challenges in accurately determining the security posture of computer networks due to varying security vulnerabilities across different services and communication protocols, misconfigurations, and unwanted applications, making it difficult to detect and prevent network attacks effectively.

Innovation Solution

An intrusion detection and prevention (IDP) device with network profiling capabilities that monitors and learns network elements, uses protocol-specific decoders to analyze traffic, and builds correlations between application-layer and network elements within a relational database, allowing for the detection of policy violations and changes that may expose security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional network monitoring methods are used, then network traffic can be observed, but security risks such as misconfigured devices, firewall holes, and unwanted services cannot be accurately detected

Engineering Contradiction:
Improvesecurity posture detection accuracyVSAvoiddifficulty in detecting security risks
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments network monitoring into multiple layers: network-layer monitoring (IP addresses, ports, protocols) and application-layer monitoring (HTTP, FTP, SMTP, DNS protocols). This segmentation allows detailed analysis of specific protocol characteristics and security parameters at each layer, improving detection accuracy while managing complexity through modular analysis approaches.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intrusion detection and prevention (IDP) device as an intermediary between network traffic sources and destinations. This IDP device correlates network-layer and application-layer information, acts as a mediator that analyzes traffic patterns, and provides centralized security monitoring without disrupting normal network operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If comprehensive network monitoring is implemented to detect all security risks, then detection capability improves, but system complexity and resource requirements increase

Engineering Contradiction:
Improvecomprehensive security detection capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The monitoring system is divided into distinct functional modules: network-layer monitoring component, application-layer monitoring component, correlation database, and analysis engine. Each module handles specific aspects of traffic analysis, reducing individual component complexity while achieving comprehensive monitoring through their coordinated operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds the application-layer dimension to traditional network-layer monitoring. By incorporating application protocol analysis (HTTP, FTP, SMTP, DNS) alongside network-layer parameters (IP addresses, ports), the system creates a multi-dimensional monitoring approach that comprehensively detects security risks without overwhelming single-layer complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If detailed protocol analysis is performed to identify security vulnerabilities, then detection precision improves, but processing time and computational resources increase

Engineering Contradiction:
Improveprotocol-specific security detection precisionVSAvoidtraffic analysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary correlation of network-layer and application-layer information in advance, building a correlated dataset that combines IP addresses, ports, protocols, and application-specific parameters. This preliminary correlation prepares the data structure for rapid security analysis, reducing processing time during actual threat detection while maintaining detailed protocol analysis capabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies protocol-specific analysis selectively based on detected traffic patterns and security requirements. Rather than analyzing every packet at maximum detail, the system performs partial analysis focused on relevant protocol characteristics and security parameters, achieving sufficient detection precision without excessive processing overhead for all traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7810151B1Automated change detection within a network environment
Publication Date: 2010.10.05 JUNIPER NETWORKS INC
  • US7810151B1 patent drawing
  • US7810151B1 patent drawing
  • US7810151B1 patent drawing

AI summary

A correlation database stores profiling data that describes packet flows within a network. A network device presents a user interface by which a user defines a database trigger to detect database operations that change to the profiling data stored within the correlation database. The network device may maintain a log to record the detected database operations. The database trigger may specify a combination of low-level network elements associated with the packet flows and application-layer elements extracted from application-layer communications reassembled from the packet flows.