Network Threat Testing System Using GUI and Repository

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection systems (IDS) are ineffective in detecting new and sophisticated hacking threats in real-time, as they rely on manual programming and are 'behind the curve' in addressing emerging threats, leading to networks being vulnerable until after damage has occurred.

Innovation Solution

A network threat testing system that generates and applies real hacking techniques without programmatic coding, using an intermediate representational form and graphical user interface (GUI) to create threat signatures, and maintains an online database for quick distribution, enabling efficient replication and testing of threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual programming is used to create intrusion detection applications, then the system can detect known threats, but the time to respond to new threats is excessive (weeks to complete)

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidtime to replicate and deploy threat testing application
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent uses a threat repository that stores standardized threat definitions and signatures. Instead of manually programming each threat detection application, the system copies pre-defined threat patterns from the repository and automatically generates testing applications. This copying mechanism reduces the time to replicate and deploy threat testing from weeks to minutes while maintaining accurate threat detection capability.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an intermediary layer between threat discovery and application deployment. The threat repository acts as a mediator that stores threat definitions in a standardized format, and the automated generation system translates these definitions into executable testing applications. This intermediary mechanism eliminates the need for manual programming while ensuring accurate threat representation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If intrusion detection systems are updated manually, then existing threats can be addressed, but the systems are always 'behind the curve' and networks remain vulnerable

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidspeed of threat response
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-storing threat definitions and signatures in the threat repository before actual attacks occur. When a new threat is discovered, the system can immediately query the repository and generate testing applications without waiting for manual analysis and programming. This preliminary preparation enables rapid response to new threats while maintaining detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates feedback mechanisms where threat intelligence from various sources is continuously fed into the threat repository. The automated generation system then uses this feedback to create updated testing applications, ensuring that intrusion detection systems remain current with the latest threats without manual intervention delays.

Inventive Principle:
Principle #23Feedback

3Reliability

If network equipment manufacturers spend majority of R&D budgets on intrusion detection, then security capability is improved, but the complexity of manually replicating and deploying threats increases

Engineering Contradiction:
Improvenetwork security capabilityVSAvoidcomplexity of threat replication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent simplifies the threat replication process by using a standardized threat repository that stores threat definitions in a uniform format. Instead of manually programming each threat scenario, the system copies pre-defined threat patterns and automatically generates testing applications. This copying approach reduces the complexity of threat replication from manual programming to automated template instantiation.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The threat repository serves multiple functions: it stores threat definitions, provides standardized signatures, enables automated generation of testing applications, and facilitates rapid deployment. This universal system handles various threat types through a single standardized interface, reducing the complexity that would otherwise require separate manual processes for each threat type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7620989B1Network testing methods and systems
Publication Date: 2009.11.17 VIAVI SOLUTIONS LICENSING LLC
  • US7620989B1 patent drawing
  • US7620989B1 patent drawing
  • US7620989B1 patent drawing

AI summary

Network vulnerability testing methods, systems, devices, appliances and software products generate stateful and stateless network representative of network threats. The traffic is applied to a network or device under test, thereby to test the vulnerability of the network or device to threats. A graphical user interface, which does not require a programming or scripting language can be used to generate an intermediate descriptive format that can in turn be used to generate stateful or stateless threat signatures. By using the intermediate descriptive form, threats can be generated under the control of the graphical user interface and in accordance with stored threat signatures, without the need for a programming or scripting language.