Network Zone Identification in Security Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current intrusion detection systems face challenges in accurately and timely detecting intrusions due to high false alarm rates and difficulties in distinguishing between normal system usage and true threats, especially in networks with overlapping address spaces.
Innovation Solution
A distributed network security system that includes agents capable of normalizing security events by determining and populating zone fields, which helps in correlating events across different network segments with overlapping address spaces, using a zone table to accurately identify and label zones associated with each security event.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional intrusion detection systems are used in networks with overlapping address spaces, then intrusion detection capability is provided, but false alarm rate increases and detection accuracy deteriorates
Solution Approach 1:
The patent introduces zone tags as an intermediary labeling mechanism that is added to security events. These zone tags serve as mediators that disambiguate events from overlapping address spaces by providing contextual information about the network zone origin, enabling accurate correlation without confusion from address overlaps.
Solution Approach 2:
The patent changes the parameter representation by adding zone identification parameters to security events. Instead of relying solely on traditional IP addressing parameters that can overlap, the system enriches events with zone parameters that provide unique identification across the enterprise network, transforming the detection capability.
2Loss of information
If security events are correlated across network segments with overlapping address spaces, then enterprise-wide security picture is achieved, but event correlation accuracy deteriorates due to address ambiguity
Solution Approach 1:
The patent applies preliminary action by normalizing security events and adding zone tags at the source before events are correlated. This pre-processing step assigns the correct zone identification to each event as it is generated, so that when events are correlated later, the ambiguity of overlapping addresses has already been resolved.
Solution Approach 2:
The patent segments the network into distinct zones and assigns unique identifiers to each zone. This segmentation allows events from different network segments with overlapping IP addresses to be distinguished by their zone tags, enabling accurate correlation across the enterprise network.
3Object-affected harmful factors
If knowledge-based intrusion detection is used, then false alarm rate is reduced, but ability to detect new and unforeseen vulnerabilities deteriorates
Solution Approach 1:
The patent applies dynamics by enabling the security system to adapt to both known and unknown threats. The zone tag infrastructure provides a dynamic framework that works with knowledge-based detection for known threats while also supporting behavior-based detection for novel threats, allowing the system to evolve as new vulnerability patterns emerge.
Data Source
AI summary
Different network segments can have overlapping address spaces. In one embodiment, the present invention includes a distributed agent of a security system receiving a security event from a network device monitored by the agent. In one embodiment, the agent normalizes the security event into an event schema including one or more zone fields. In one embodiment, the agent also determines one or more zones associated with the received security event, the one or more zones each describing a part of a network, and populates the one or more zone fields using the determined one or more zones.


