Network Intrusion Detection False Alarm Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network Intrusion Detection Systems (NIDS) face high false alarm rates, requiring significant personnel monitoring and resource allocation, and struggle to analyze hosts behind strong firewalls due to real-time access requirements.

Innovation Solution

A method and system for offline passive analysis that receives data packets from NIDS, identifies attack types and operating system fingerprints, and compares them to determine vulnerability, reducing false alarms without needing direct network access, and can be used with various NIDS types, including legacy systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real-time passive OS analysis is used to reduce false alarms, then false alarm rate is reduced, but processing power requirements and direct network access requirements increase

Engineering Contradiction:
Improvefalse alarm rateVSAvoidprocessing power
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The system performs OS fingerprinting in advance by capturing packets during normal network operations and storing them in a database. When an alarm occurs, the pre-analyzed OS information is retrieved from the database rather than analyzing packets in real-time, significantly reducing processing power requirements during critical detection moments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system extracts and stores OS fingerprinting information separately from the main NIDS processing flow. By isolating the OS analysis function and storing results in a database, the system eliminates the need for continuous real-time packet analysis to determine OS type, reducing the processing burden on the NIDS.

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If real-time network access is required for OS identification, then OS type can be determined, but hosts behind firewalls cannot be analyzed

Engineering Contradiction:
ImproveOS identification accuracyVSAvoidability to analyze hosts behind firewalls
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system uses an intermediary database to store OS fingerprinting information that was captured during periods when network access was available. This database acts as a mediator, providing OS identification data to the NIDS without requiring direct real-time network access to the target host, enabling analysis of hosts behind firewalls.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs OS fingerprinting in advance when network access is possible, storing the results in a database. This preliminary action ensures that OS identification information is available even when real-time network access is blocked by firewalls, extending the system's ability to analyze protected hosts.

Inventive Principle:
Principle #10Preliminary action

3Speed

If NIDS monitors all network activity in real-time, then intrusion detection speed is improved, but false alarm rate increases

Engineering Contradiction:
Improveintrusion detection speedVSAvoidfalse alarm rate
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system segments the intrusion detection process into two independent parts: OS fingerprinting (performed in advance and stored in database) and intrusion detection (performed in real-time). By separating these functions, the NIDS can maintain fast real-time detection without the computational overhead of simultaneous OS analysis, reducing false alarms caused by resource constraints.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system extracts OS identification functionality from the real-time NIDS processing flow and stores it in a separate database. This extraction allows the NIDS to operate at full speed without the burden of continuous OS analysis, maintaining detection speed while reducing false alarm rates.

Inventive Principle:
Principle #2Taking out (Extraction)

4Measurement precision

If traditional NIDS requires direct network access for OS fingerprinting, then OS type can be identified, but legacy NIDS sensors cannot be used

Engineering Contradiction:
ImproveOS fingerprinting capabilityVSAvoidcompatibility with legacy NIDS
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system creates a universal OS fingerprinting database that can serve multiple NIDS systems simultaneously, including both modern and legacy sensors. By storing OS information in a standardized database format accessible to different NIDS types, the system enables legacy NIDS without native OS fingerprinting capabilities to benefit from this functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The database acts as an intermediary layer between OS fingerprinting capabilities and various NIDS systems. Legacy NIDS sensors that lack built-in OS fingerprinting can query the database for OS information, enabling them to function with enhanced capabilities without requiring hardware or software modifications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7805762B2Method and system for reducing the false alarm rate of network intrusion detection systems
Publication Date: 2010.09.28 CISCO TECHNOLOGY INC
  • US7805762B2 patent drawing
  • US7805762B2 patent drawing
  • US7805762B2 patent drawing

AI summary

According to one embodiment of the invention, a computerized method for reducing the false alarm rate of network intrusion detection systems includes receiving, from a network intrusion detection sensor, one or more data packets associated with an alarm indicative of a potential attack on a target host and identifying characteristics of the alarm from the data packets. The characteristics include at least an attack type and an operating system fingerprint of the target host. The method further includes identifying the operating system type from the operating system fingerprint, comparing the attack type to the operating system type, and indicating whether the target host is vulnerable to the attack based on the comparison.