Network Security Data Collection Module for Active Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional intrusion detection systems are reactive and fail to consider additional data that may be useful in detecting malicious activity, limiting their ability to detect and resolve attacks effectively.

Innovation Solution

A network security system with a data collection module that actively requests and correlates additional data from external and internal sources, enhancing the detection of potential attacks by considering data not received by sensors in the normal course of operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional passive data collection is used, then the system structure remains simple, but the detection capability is limited because additional useful data is not considered

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by proactively requesting and collecting additional data from multiple sources before analysis is needed. The data collection module anticipates what information might be useful for detection and gathers it in advance, rather than waiting for passive data to arrive. This preliminary data gathering enhances detection capability while maintaining a relatively simple system structure through automated request generation.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If active data collection from multiple sources is implemented, then enhanced correlations and detection accuracy are achieved, but the data processing complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoiddata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The data collection module serves multiple functions: it generates requests for additional data, collects data from diverse sources, performs correlations, and feeds results back to the detection system. This multi-functional approach consolidates what would otherwise require separate specialized components, achieving enhanced detection accuracy while managing data processing complexity through a unified modular design.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If the data collection module is integrated into the normal event flow, then data processing is streamlined, but the active data collection activities impair normal processing

Engineering Contradiction:
Improvedata processing efficiencyVSAvoidnormal processing performance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the data collection function into a separate, isolated module that operates independently from the normal event flow. This segmentation allows active data collection activities to proceed without interfering with or being interfered by normal processing operations. The module can request and process additional data in parallel, maintaining overall data processing efficiency while protecting normal processing performance.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8572733B1System and method for active data collection in a network security system
Publication Date: 2013.10.29 EVERFOX HOLDINGS LLC
  • US8572733B1 patent drawing
  • US8572733B1 patent drawing
  • US8572733B1 patent drawing

AI summary

A network security system comprises a plurality of sensors, a management server, and a data collection module. The plurality of sensors receive first data associated with potential attacks on the system. The manager server is coupled to at least one sensor and correlates at least a portion of the first data to detect potential attacks on the system. The data collection module is coupled to the manager server and generates at least one request for second data based upon at least one of the first data and the correlated data. The data collection module communicates the request to at least one source different from the plurality of sensors.