Network Traffic Analysis System for False Alarm Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems are unable to reliably differentiate between targeted and omnidirectional network traffic, leading to an overwhelming number of false alarms for network security analysts, as both types of traffic can exhibit similar behaviors, resulting in wasted time reviewing insignificant security alerts.
Innovation Solution
A system comprising a network of nodes distributed across multiple geographical regions that collect mass scanning network traffic data, generate an omnidirectional network traffic database, and use this database to filter out omnidirectional traffic, allowing security analysts to focus on targeted traffic by providing contextual information and enriching records with historical, trending, and forecasting data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current systems monitor all network traffic without differentiation, then comprehensive security monitoring is achieved, but false alarms increase significantly
Solution Approach 1:
The patent segments network traffic into two distinct categories: omnidirectional traffic (scanning multiple targets) and targeted traffic (scanning specific targets). This segmentation is achieved by analyzing the scanning behavior patterns and grouping sources by their target selection criteria, allowing security systems to treat different traffic types differently and reduce false alarms from omnidirectional scanning.
Solution Approach 2:
The patent introduces an intermediary classification layer that sits between raw network traffic monitoring and security alert generation. This intermediary system analyzes scanning patterns, determines whether traffic is omnidirectional or targeted, and filters or tags alerts accordingly, preventing false alarms from reaching security analysts.
2Reliability
If systems treat all scanning traffic as potential threats, then security coverage is maximized, but analyst productivity decreases
Solution Approach 1:
The patent applies partial action by not treating all scanning traffic equally. Instead of full investigation of every scan alert, the system performs partial analysis by classifying traffic type first. Omnidirectional traffic receives minimal processing (filtering or low-priority tagging), while only targeted traffic receives full investigative attention, significantly improving analyst productivity while maintaining security coverage.
3Measurement precision
If networks perform Internet-wide mass scanning, then comprehensive vulnerability assessment is achieved, but background noise overwhelms security systems
Solution Approach 1:
The patent applies local quality by giving different characteristics and treatments to different portions of scanning traffic based on their nature. Omnidirectional scanning traffic (background noise) is identified and treated differently from targeted scanning traffic (potential threats). This allows comprehensive vulnerability assessment to continue while locally optimizing the response to each traffic type to minimize false alarm impact.
Data Source
AI summary
Systems and methods for analyzing network traffic are provided. An exemplary system may include a plurality of network nodes distributed in multiple geographical regions. The plurality of network nodes may be configured to collect mass scanning network traffic data. The system may also include at least one processor. The processor may be configured to receive, from a first network node, a first network scanning request from a source scanner. In response to the reception of the first network scanning request, the processor may also be configured to transmit, via a second network node, a second network scanning request to the source scanner. The processor may further be configured to determine, based on feedback from the source scanner, whether the source scanner is compromised.


