Network Management Console Unauthorized Access Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data network management tools, such as SNMP, face challenges in detecting unauthorized access within trusted networks due to complexity and cost, especially when a centralized logging server and specialized logging DLL are required, and firewalls may not detect all unauthorized accesses within a 'trusted' network.

Innovation Solution

A system and method where a Network Management Console (NMC) periodically polls service nodes with installed agents to maintain and compare user access lists against authorized lists, identifying and notifying unauthorized accesses through various means, utilizing existing network capabilities and intelligence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If a centralized logging server with specialized logging DLL is deployed to monitor unauthorized access, then detection capability is improved, but device complexity and cost increase

Engineering Contradiction:
Improveunauthorized access detectionVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent extracts the logging functionality from a centralized server and distributes it to individual agents running on each monitored node. Each agent independently maintains access lists and performs local comparison, eliminating the need for complex centralized logging infrastructure while maintaining detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The agents perform self-monitoring by maintaining their own access lists and comparing them against authorized lists without requiring external intervention. The system uses pre-existing network capabilities and intelligence at each node to identify unauthorized accesses independently.

Inventive Principle:
Principle #25Self-service

2Reliability

If firewalls are deployed to block unauthorized access, then security is improved, but cost and implementation complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidfirewall implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the existing agent serve multiple functions: it not only performs its original monitoring role but also maintains access lists, compares them against authorized lists, and identifies unauthorized accesses. This eliminates the need for separate firewall hardware while maintaining security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of deploying physical firewalls at every network device, the patent creates virtual copies of security monitoring functionality through software agents that replicate the security check process at each node, reducing hardware requirements while maintaining comprehensive security monitoring.

Inventive Principle:
Principle #26Copying

3Productivity

If SNMP service is enabled for network management, then monitoring capability is improved, but security risks increase due to authentication vulnerabilities

Engineering Contradiction:
Improvemonitoring capabilityVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system continuously monitors access patterns and provides feedback by comparing actual accesses against authorized lists. When unauthorized access is detected, the system can trigger notifications or alerts, creating a feedback loop that enhances security without requiring SNMP authentication changes.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary actions by pre-configuring authorized access lists on each agent before monitoring begins. This allows the system to proactively identify unauthorized accesses rather than reacting to them, improving security posture without compromising the monitoring capability enabled by SNMP.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8676972B2Method and system for a network management console
Publication Date: 2014.03.18 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8676972B2 patent drawing
  • US8676972B2 patent drawing
  • US8676972B2 patent drawing

AI summary

A method and a system for identifying unauthorized accesses to a data network service by a particular node in a data network is disclosed. The NMC communicates with an agent periodically to gather a list of users of the service node. An agent is installed on the service node to monitor all network accesses to the service. By configuring the agent to monitor all access to the service node, through SNMP or a similar protocol, the agent maintains a list of all accesses to that service node. This list is stored internally by the agent and queried for by the NMC periodically. The access information stored by the agent is periodically retrieved by the NMC for all monitored nodes and compared with the authorization list for the node. If unauthorized accesses are found, they are identified by the NMC. These unauthorized accesses can be notified to the appropriate entity in a number of ways such as through paging, email or a report viewable through the NMC.