Network Monitoring System for Early Scanning Activity Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer networks, particularly those using Internet Protocol, face challenges in detecting security violations such as reconnaissance, exploits, and denial of service attacks in a timely manner, often resulting in damage before detection.
Innovation Solution
A method and system for monitoring network activity using NetFlow data and IP Graph visualization to detect scanning activity by comparing data sets over time intervals, employing statistical tests like the Kolmogorov-Smirnov test and entropy analysis to identify significant changes indicative of scanning, and providing alerts when thresholds are exceeded.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security monitoring methods are used, then security violations can be detected, but detection occurs only after damage has already occurred
Solution Approach 1:
The system performs preliminary detection of reconnaissance activities (scanning, probing) before actual security violations occur. By monitoring for preliminary attack indicators such as port scanning and service probing, the system enables early warning and preventive action before exploits or denial of service attacks can cause damage.
Solution Approach 2:
The system establishes baseline network behavior patterns and creates a cushion of early detection capability. By continuously monitoring network traffic against established baselines and detecting deviations that indicate reconnaissance activities, the system provides a protective buffer that allows administrators to take preventive measures before actual security breaches occur.
2Reliability
If network monitoring is implemented to detect security violations early, then detection capability is improved, but false alarms and inaccurate detection may increase
Solution Approach 1:
The system incorporates feedback mechanisms where detected patterns are continuously analyzed and refined. Statistical tests evaluate whether observed network behaviors represent true security threats or normal variations, and the system adjusts its detection thresholds and parameters based on accumulated data, reducing false alarms while maintaining detection reliability.
Solution Approach 2:
The system dynamically adjusts detection parameters such as thresholds and time windows based on network conditions and observed patterns. By changing parameters adaptively rather than using fixed values, the system improves detection accuracy while reducing false positives, allowing it to distinguish between legitimate network activity and actual scanning attacks more effectively.
Data Source
AI summary
Described is a system and method for receiving first data corresponding to usage of a network, receiving second data corresponding to usage of the network, comparing the first data to the second data and providing an indication of a network event when the second data varies from the second data greater than a predetermined threshold.


