Network Zone Identification in Security Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection systems face challenges in accurately and timely detecting intrusions due to high false alarm rates and difficulties in distinguishing between normal system usage and true threats, especially in networks with overlapping address spaces.

Innovation Solution

A distributed network security system that includes agents capable of normalizing security events by determining and populating zone fields, which helps in correlating events across different network segments with overlapping address spaces, using a zone table to accurately identify and label zones associated with each security event.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional intrusion detection systems are used in networks with overlapping address spaces, then intrusion detection capability is provided, but false alarm rate increases and detection accuracy deteriorates

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidfalse alarm rate
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces zone tags as an intermediary labeling mechanism that is added to security events. These zone tags serve as mediators that disambiguate events from overlapping address spaces by providing contextual information about the network zone origin, enabling accurate correlation without confusion from address overlaps.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter representation by adding zone identification parameters to security events. Instead of relying solely on traditional IP addressing parameters that can overlap, the system enriches events with zone parameters that provide unique identification across the enterprise network, transforming the detection capability.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If security events are correlated across network segments with overlapping address spaces, then enterprise-wide security picture is achieved, but event correlation accuracy deteriorates due to address ambiguity

Engineering Contradiction:
Improvesecurity event correlation accuracyVSAvoidevent normalization complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by normalizing security events and adding zone tags at the source before events are correlated. This pre-processing step assigns the correct zone identification to each event as it is generated, so that when events are correlated later, the ambiguity of overlapping addresses has already been resolved.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the network into distinct zones and assigns unique identifiers to each zone. This segmentation allows events from different network segments with overlapping IP addresses to be distinguished by their zone tags, enabling accurate correlation across the enterprise network.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If knowledge-based intrusion detection is used, then false alarm rate is reduced, but ability to detect new and unforeseen vulnerabilities deteriorates

Engineering Contradiction:
Improvefalse alarm rateVSAvoiddetection of new vulnerabilities
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by enabling the security system to adapt to both known and unknown threats. The zone tag infrastructure provides a dynamic framework that works with knowledge-based detection for known threats while also supporting behavior-based detection for novel threats, allowing the system to evolve as new vulnerability patterns emerge.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9100422B1Network zone identification in a network security system
Publication Date: 2015.08.04 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9100422B1 patent drawing
  • US9100422B1 patent drawing
  • US9100422B1 patent drawing

AI summary

Different network segments can have overlapping address spaces. In one embodiment, the present invention includes a distributed agent of a security system receiving a security event from a network device monitored by the agent. In one embodiment, the agent normalizes the security event into an event schema including one or more zone fields. In one embodiment, the agent also determines one or more zones associated with the received security event, the one or more zones each describing a part of a network, and populates the one or more zone fields using the determined one or more zones.