Network Management Console Unauthorized Access Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data network management tools, such as SNMP, face challenges in detecting unauthorized access within trusted networks due to complexity and cost, especially when a centralized logging server and specialized logging DLL are required, and firewalls may not detect all unauthorized accesses within a 'trusted' network.
Innovation Solution
A system and method where a Network Management Console (NMC) periodically polls service nodes with installed agents to maintain and compare user access lists against authorized lists, identifying and notifying unauthorized accesses through various means, utilizing existing network capabilities and intelligence.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If a centralized logging server with specialized logging DLL is deployed to monitor unauthorized access, then detection capability is improved, but device complexity and cost increase
Solution Approach 1:
The patent extracts the logging functionality from a centralized server and distributes it to individual agents running on each monitored node. Each agent independently maintains access lists and performs local comparison, eliminating the need for complex centralized logging infrastructure while maintaining detection capability.
Solution Approach 2:
The agents perform self-monitoring by maintaining their own access lists and comparing them against authorized lists without requiring external intervention. The system uses pre-existing network capabilities and intelligence at each node to identify unauthorized accesses independently.
2Reliability
If firewalls are deployed to block unauthorized access, then security is improved, but cost and implementation complexity increase
Solution Approach 1:
The patent makes the existing agent serve multiple functions: it not only performs its original monitoring role but also maintains access lists, compares them against authorized lists, and identifies unauthorized accesses. This eliminates the need for separate firewall hardware while maintaining security capabilities.
Solution Approach 2:
Instead of deploying physical firewalls at every network device, the patent creates virtual copies of security monitoring functionality through software agents that replicate the security check process at each node, reducing hardware requirements while maintaining comprehensive security monitoring.
3Productivity
If SNMP service is enabled for network management, then monitoring capability is improved, but security risks increase due to authentication vulnerabilities
Solution Approach 1:
The system continuously monitors access patterns and provides feedback by comparing actual accesses against authorized lists. When unauthorized access is detected, the system can trigger notifications or alerts, creating a feedback loop that enhances security without requiring SNMP authentication changes.
Solution Approach 2:
The patent performs preliminary actions by pre-configuring authorized access lists on each agent before monitoring begins. This allows the system to proactively identify unauthorized accesses rather than reacting to them, improving security posture without compromising the monitoring capability enabled by SNMP.
Data Source
AI summary
A method and a system for identifying unauthorized accesses to a data network service by a particular node in a data network is disclosed. The NMC communicates with an agent periodically to gather a list of users of the service node. An agent is installed on the service node to monitor all network accesses to the service. By configuring the agent to monitor all access to the service node, through SNMP or a similar protocol, the agent maintains a list of all accesses to that service node. This list is stored internally by the agent and queried for by the NMC periodically. The access information stored by the agent is periodically retrieved by the NMC for all monitored nodes and compared with the authorization list for the node. If unauthorized accesses are found, they are identified by the NMC. These unauthorized accesses can be notified to the appropriate entity in a number of ways such as through paging, email or a report viewable through the NMC.


