Network Monitoring System for Early Scanning Activity Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer networks, particularly those using Internet Protocol, face challenges in detecting security violations such as reconnaissance, exploits, and denial of service attacks in a timely manner, often resulting in damage before detection.

Innovation Solution

A method and system for monitoring network activity using NetFlow data and IP Graph visualization to detect scanning activity by comparing data sets over time intervals, employing statistical tests like the Kolmogorov-Smirnov test and entropy analysis to identify significant changes indicative of scanning, and providing alerts when thresholds are exceeded.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security monitoring methods are used, then security violations can be detected, but detection occurs only after damage has already occurred

Engineering Contradiction:
Improvesecurity violation detection reliabilityVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary detection of reconnaissance activities (scanning, probing) before actual security violations occur. By monitoring for preliminary attack indicators such as port scanning and service probing, the system enables early warning and preventive action before exploits or denial of service attacks can cause damage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes baseline network behavior patterns and creates a cushion of early detection capability. By continuously monitoring network traffic against established baselines and detecting deviations that indicate reconnaissance activities, the system provides a protective buffer that allows administrators to take preventive measures before actual security breaches occur.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Reliability

If network monitoring is implemented to detect security violations early, then detection capability is improved, but false alarms and inaccurate detection may increase

Engineering Contradiction:
Improvescanning attack detection reliabilityVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system incorporates feedback mechanisms where detected patterns are continuously analyzed and refined. Statistical tests evaluate whether observed network behaviors represent true security threats or normal variations, and the system adjusts its detection thresholds and parameters based on accumulated data, reducing false alarms while maintaining detection reliability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system dynamically adjusts detection parameters such as thresholds and time windows based on network conditions and observed patterns. By changing parameters adaptively rather than using fixed values, the system improves detection accuracy while reducing false positives, allowing it to distinguish between legitimate network activity and actual scanning attacks more effectively.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8713141B1System and method for monitoring network activity
Publication Date: 2014.04.29 AT&T INTELLECTUAL PROPERTY II LP
  • US8713141B1 patent drawing
  • US8713141B1 patent drawing
  • US8713141B1 patent drawing

AI summary

Described is a system and method for receiving first data corresponding to usage of a network, receiving second data corresponding to usage of the network, comparing the first data to the second data and providing an indication of a network event when the second data varies from the second data greater than a predetermined threshold.