Network Security Device Monitoring Time Sync Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In networked directory services environments, existing technologies fail to effectively monitor the life cycle of network client devices and detect anomalies and malicious patterns, which can lead to security breaches and unauthorized access.

Innovation Solution

An automated system and method that monitors time synchronization traffic between network client devices and a time server, identifying true identities, connections, disconnections, and detecting anomalies by using a security device comprising a network traffic listener, data extractor, connection type identifier, network client device identification engine, anomaly detection engine, and report generator.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If time synchronization traffic monitoring is implemented to detect anomalies and malicious patterns, then network security detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork security detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security device as an intermediary component that sits between network clients and the time server. This device passively monitors time synchronization traffic without interfering with the core time synchronization function, thereby improving security detection capability while maintaining system simplicity through a dedicated monitoring component rather than complicating the existing time synchronization protocol

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security device is segmented into distinct functional modules: a time synchronization message parser that extracts information from NTP/PTP packets, a connection life cycle monitor that tracks client connections, and an anomaly detection engine that identifies malicious patterns. This segmentation allows each module to perform its specific function efficiently while keeping the overall system architecture clear and maintainable

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If comprehensive connection monitoring is performed to identify client identities and connections, then security monitoring accuracy is improved, but processing time increases

Engineering Contradiction:
Improvesecurity monitoring accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The security device performs preliminary actions by maintaining connection state information and client identity mappings in advance. When time synchronization packets arrive, the device already has pre-established data structures to quickly match packets to clients, eliminating the need for complex real-time analysis and reducing processing time while maintaining high monitoring accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device creates simplified copies of connection state information and client identity data in easily queryable formats. Instead of analyzing raw network packets in real-time, the security device maintains replicated connection state data that can be quickly searched and compared, significantly reducing processing time while preserving monitoring accuracy

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3342119B1Monitoring the life cycle of a computer network connection
Publication Date: 2022.08.24 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3342119B1 patent drawingFigure 1
  • EP3342119B1 patent drawingFigure 2
  • EP3342119B1 patent drawingFigure 3

AI summary

Monitoring of a life cycle of a connection of a network client device to a network via monitoring time synchronization traffic flowing between one or more network client devices and a time server in a network is provided. A system for monitoring a life cycle of a connection of a network client device to a network includes a security device operable to identify a true identity of the one or more network client devices, identify a network client device's connections to and disconnections from the network, determine which network client devices have been associated with a particular internet protocol (IP) address, and generate an output of connection and disconnection information associated with a network client device. In some examples, the security device is operable to detect anomalies and malicious patterns in the network.