Network Traffic Profiling for Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network administrators face challenges in accurately determining the security posture of computer networks due to varying security vulnerabilities across different services and communication protocols, misconfigurations, and unwanted applications, making it difficult to detect and prevent network attacks effectively.
Innovation Solution
An intrusion detection and prevention (IDP) device with network profiling capabilities that monitors and learns network elements, utilizes protocol-specific decoders to analyze traffic, and builds correlations between application-layer and network elements within a relational database, allowing for the detection of policy violations and changes that may expose security risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network administrators manually monitor and analyze network traffic to determine security posture, then security assessment can be performed, but the complexity and time required increases significantly due to the variety of services and protocols
Solution Approach 1:
The patent introduces an intermediary system comprising a profiler module and correlation database that automatically captures, profiles, and correlates network traffic data. This intermediary handles the complexity of monitoring multiple services and protocols, presenting simplified security posture information to administrators without requiring manual analysis of each protocol type.
Solution Approach 2:
The system enables self-service by automatically profiling network traffic and generating security assessments without requiring administrator intervention. The profiler module continuously monitors traffic, builds correlations between network elements and applications, and maintains an updated correlation database that automatically reflects current security posture.
2Loss of information
If protocol-specific decoders are used to analyze application-layer traffic, then detailed network profiling is achieved, but the processing time and computational resources increase
Solution Approach 1:
The system performs preliminary action by pre-profiling network traffic and building correlation databases in advance. The profiler module continuously captures and stores correlation information between network elements and applications, so that when security analysis is needed, the data is already prepared and readily available, eliminating the need for real-time deep packet inspection.
Solution Approach 2:
The patent extracts only the essential correlation information from network traffic - specifically the relationships between network elements (IP addresses, ports) and application-layer elements (protocols, services). This selective extraction of relevant correlation data reduces processing requirements while maintaining complete application-layer information for security analysis.
3Speed
If the correlation database is stored locally on the IDP device, then fast access is achieved, but storage capacity and device resources are limited
Solution Approach 1:
The system uses copying by maintaining local copies of correlation database entries on IDP devices while allowing remote access to the full database. Each IDP device can quickly access its local cache for immediate security decisions, while the complete correlation database is available remotely for comprehensive analysis and reporting.
Data Source
AI summary
A plurality of network devices monitor network traffic and generate profiling data that describes packet flows within the network traffic. The network devices output communications that include the profiling data. An aggregation device receives the communications and builds a correlation database to aggregate the profiling data generated by the plurality of network devices. The profiling data may relate low-level network elements associated with the packet flows and application-layer elements extracted from application-layer communications reassembled from the packet flows.


