Network Service Detection via Protocol Baseline Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing complex enterprise networks is costly and challenging due to performance issues and security threats, with existing solutions failing to effectively detect and mitigate network anomalies and new service deployments in a timely manner.
Innovation Solution
A graphical user interface for an intrusion detection system that allows users to configure new service detection processes, including specifying entities to track, the scope of tracking, and alert severity, along with a method to retrieve baseline and current port protocols to identify new services, and a computer program product for detecting new services by comparing protocol lists.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network segmentation is implemented using firewalls, routers, VLANs and other technologies to provide fault isolation and mitigate worm spread, then network security and reliability are improved, but network complexity and management cost increase
Solution Approach 1:
The system automatically detects new services by comparing baseline protocol lists with current ones, eliminating the need for manual configuration and monitoring of each service. The intrusion detection system self-configures by retrieving and comparing protocol lists without requiring continuous human intervention to update security rules.
Solution Approach 2:
The system continuously monitors network traffic and compares current protocol usage against stored baseline data, providing feedback when new services are detected. This closed-loop approach automatically triggers alerts when deviations from baseline behavior occur, enabling dynamic adaptation to changing network conditions.
2Reliability
If manual monitoring and detection of network anomalies is performed, then security awareness is improved, but response time and productivity deteriorate
Solution Approach 1:
The intrusion detection system automatically performs anomaly detection by retrieving baseline protocol lists, comparing them with current traffic patterns, and generating alerts without requiring manual analysis. This automation eliminates the bottleneck of human review while maintaining high security awareness through continuous automated monitoring.
Solution Approach 2:
The system pre-retrieves and stores baseline protocol lists before anomalies occur, enabling immediate comparison with current traffic patterns. This preliminary preparation of reference data allows for rapid detection and response to new services, eliminating delays associated with manual baseline establishment.
3Reliability
If comprehensive service detection is implemented to detect all new services in the network, then security coverage is improved, but system complexity and resource consumption increase
Solution Approach 1:
The system extracts only the essential protocol information needed for detection by retrieving and comparing specific protocol lists rather than analyzing all network traffic in detail. This selective extraction of baseline protocol data enables comprehensive security coverage while reducing processing complexity and resource consumption.
Solution Approach 2:
The system uses partial action by comparing only the differences between baseline and current protocol lists rather than analyzing every network interaction in full detail. This approach provides sufficient security coverage to detect new services while minimizing the computational resources required for comprehensive monitoring.
Data Source
AI summary
A new service detection process in a network retrieves a baseline list of port protocols used by a entity being tracked. The baseline value is determined over a baseline period. A current list of port protocols for the entity being tracked is also retrieved and is compared to determine whether there is a difference in the port protocols, by having a protocol that was in a current list but was not in the baseline list. If there is a difference the process indicates a new service involving the tracked entity.


