Network Traffic Profiling for Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network administrators face challenges in accurately determining the security posture of computer networks due to varying security vulnerabilities across different services and communication protocols, misconfigurations, and unwanted applications, making it difficult to detect and prevent network attacks effectively.

Innovation Solution

An intrusion detection and prevention (IDP) device with network profiling capabilities that monitors and learns network elements, utilizes protocol-specific decoders to analyze traffic, and builds correlations between application-layer and network elements within a relational database, allowing for the detection of policy violations and changes that may expose security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network administrators manually monitor and analyze network traffic to determine security posture, then security assessment can be performed, but the complexity and time required increases significantly due to the variety of services and protocols

Engineering Contradiction:
Improvesecurity posture assessment accuracyVSAvoidnetwork monitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system comprising a profiler module and correlation database that automatically captures, profiles, and correlates network traffic data. This intermediary handles the complexity of monitoring multiple services and protocols, presenting simplified security posture information to administrators without requiring manual analysis of each protocol type.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by automatically profiling network traffic and generating security assessments without requiring administrator intervention. The profiler module continuously monitors traffic, builds correlations between network elements and applications, and maintains an updated correlation database that automatically reflects current security posture.

Inventive Principle:
Principle #25Self-service

2Loss of information

If protocol-specific decoders are used to analyze application-layer traffic, then detailed network profiling is achieved, but the processing time and computational resources increase

Engineering Contradiction:
Improveapplication-layer information completenessVSAvoidtraffic analysis time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-profiling network traffic and building correlation databases in advance. The profiler module continuously captures and stores correlation information between network elements and applications, so that when security analysis is needed, the data is already prepared and readily available, eliminating the need for real-time deep packet inspection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts only the essential correlation information from network traffic - specifically the relationships between network elements (IP addresses, ports) and application-layer elements (protocols, services). This selective extraction of relevant correlation data reduces processing requirements while maintaining complete application-layer information for security analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

3Speed

If the correlation database is stored locally on the IDP device, then fast access is achieved, but storage capacity and device resources are limited

Engineering Contradiction:
Improvedatabase access speedVSAvoidlocal storage capacity
Core Design Contradiction:
SpeedVSVolume of stationary object

Solution Approach 1:

The system uses copying by maintaining local copies of correlation database entries on IDP devices while allowing remote access to the full database. Each IDP device can quickly access its local cache for immediate security decisions, while the complete correlation database is available remotely for comprehensive analysis and reporting.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS7809826B1Remote aggregation of network traffic profiling data
Publication Date: 2010.10.05 JUNIPER NETWORKS INC
  • US7809826B1 patent drawing
  • US7809826B1 patent drawing
  • US7809826B1 patent drawing

AI summary

A plurality of network devices monitor network traffic and generate profiling data that describes packet flows within the network traffic. The network devices output communications that include the profiling data. An aggregation device receives the communications and builds a correlation database to aggregate the profiling data generated by the plurality of network devices. The profiling data may relate low-level network elements associated with the packet flows and application-layer elements extracted from application-layer communications reassembled from the packet flows.