Network Service Detection via Protocol Baseline Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing complex enterprise networks is costly and challenging due to performance issues and security threats, with existing solutions failing to effectively detect and mitigate network anomalies and new service deployments in a timely manner.

Innovation Solution

A graphical user interface for an intrusion detection system that allows users to configure new service detection processes, including specifying entities to track, the scope of tracking, and alert severity, along with a method to retrieve baseline and current port protocols to identify new services, and a computer program product for detecting new services by comparing protocol lists.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network segmentation is implemented using firewalls, routers, VLANs and other technologies to provide fault isolation and mitigate worm spread, then network security and reliability are improved, but network complexity and management cost increase

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically detects new services by comparing baseline protocol lists with current ones, eliminating the need for manual configuration and monitoring of each service. The intrusion detection system self-configures by retrieving and comparing protocol lists without requiring continuous human intervention to update security rules.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors network traffic and compares current protocol usage against stored baseline data, providing feedback when new services are detected. This closed-loop approach automatically triggers alerts when deviations from baseline behavior occur, enabling dynamic adaptation to changing network conditions.

Inventive Principle:
Principle #23Feedback

2Reliability

If manual monitoring and detection of network anomalies is performed, then security awareness is improved, but response time and productivity deteriorate

Engineering Contradiction:
Improvesecurity awarenessVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The intrusion detection system automatically performs anomaly detection by retrieving baseline protocol lists, comparing them with current traffic patterns, and generating alerts without requiring manual analysis. This automation eliminates the bottleneck of human review while maintaining high security awareness through continuous automated monitoring.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-retrieves and stores baseline protocol lists before anomalies occur, enabling immediate comparison with current traffic patterns. This preliminary preparation of reference data allows for rapid detection and response to new services, eliminating delays associated with manual baseline establishment.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive service detection is implemented to detect all new services in the network, then security coverage is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity coverageVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only the essential protocol information needed for detection by retrieving and comparing specific protocol lists rather than analyzing all network traffic in detail. This selective extraction of baseline protocol data enables comprehensive security coverage while reducing processing complexity and resource consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system uses partial action by comparing only the differences between baseline and current protocol lists rather than analyzing every network interaction in full detail. This approach provides sufficient security coverage to detect new services while minimizing the computational resources required for comprehensive monitoring.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7698730B2Service detection
Publication Date: 2010.04.13 RIVERBED TECH LLC
  • US7698730B2 patent drawing
  • US7698730B2 patent drawing
  • US7698730B2 patent drawing

AI summary

A new service detection process in a network retrieves a baseline list of port protocols used by a entity being tracked. The baseline value is determined over a baseline period. A current list of port protocols for the entity being tracked is also retrieved and is compared to determine whether there is a difference in the port protocols, by having a protocol that was in a current list but was not in the baseline list. If there is a difference the process indicates a new service involving the tracked entity.