Passive Network Endpoint Discovery for Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional intrusion detection systems (IDSs) are ineffective due to the lack of contextual information about network end points, making them susceptible to attacks and generating false positives, and existing methods for providing this information are either manual, time-consuming, or destructive to the network.
Innovation Solution
A system and method for automatically and passively determining network characteristics by reading packets, identifying network devices, operating systems, and services using packet detectors, decoders, and protocol analyzers, and reporting this information to IDSs or network management systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual auditing is used to gather contextual information about network hosts, then information accuracy is improved, but time consumption and operational complexity increase
Solution Approach 1:
The system enables hosts to self-report their contextual information (operating system, services, applications) automatically to the IDS through intercepted communication packets, eliminating the need for manual auditing while maintaining high accuracy of the collected information
Solution Approach 2:
The patent replaces manual mechanical auditing processes with automated electronic packet interception and analysis systems, using software-based detection to gather contextual information without human intervention, thereby reducing time consumption while maintaining information accuracy
2Extent of automation
If active scanning systems are used to discover network vulnerabilities, then automated information gathering is improved, but network stability deteriorates due to destructive testing
Solution Approach 1:
The system uses an intermediary approach by intercepting and analyzing existing communication packets between hosts and network services, rather than directly probing hosts. This passive observation method automates information gathering without injecting disruptive test traffic that could destabilize network operations
Solution Approach 2:
The system creates a virtual model of network hosts by analyzing copied packets from network traffic, building contextual information about operating systems and services without directly interacting with or testing the actual hosts, thereby avoiding network disruption while maintaining automated discovery capabilities
3Extent of automation
If active scanning is performed to detect vulnerabilities, then automated detection capability is improved, but information completeness worsens due to transient service availability
Solution Approach 1:
The system continuously intercepts and analyzes network packets over extended periods, maintaining persistent observation of host services and applications. This continuous passive monitoring ensures that transient services are detected when they become active, providing complete vulnerability information without the timing constraints of periodic active scanning
Solution Approach 2:
The system performs preliminary packet interception and analysis to build comprehensive contextual profiles of hosts before security incidents occur. By continuously gathering information about services and applications in advance, the system ensures complete vulnerability detection even for transiently available services, eliminating the need for repeated scanning attempts
4Device complexity
If IDS operates without contextual information about end points, then system simplicity is maintained, but detection effectiveness deteriorates due to evasion susceptibility
Solution Approach 1:
The system performs preliminary packet interception and analysis to automatically build contextual profiles of network hosts, including operating system types, running services, and applications. This pre-gathered contextual information is stored and used by the IDS to improve detection effectiveness without requiring complex manual configuration or increasing operational complexity
Solution Approach 2:
The system enables hosts to effectively self-identify their characteristics through their own communication packets, which are automatically analyzed and used to build contextual profiles. This self-reporting mechanism provides comprehensive detection capabilities without requiring the IDS to actively probe or complexity the system architecture
Data Source
AI summary
A packet transmitted on a network is read and decoded. A network device and its operating system are identified by analyzing the decoded packet. If more than one operating system is identified from the decoded packet, the operating system is selecting by comparing confidence values assigned to the operating systems identified. A service running on the network device is identified from the decoded packet or subsequent packets that are read, decoded and analyzed. The network topology of a network is determined by reading, decoding, and analyzing a plurality of packets. A flow between two network devices is determined by reading, decoding, and analyzing a plurality of packets. Vulnerabilities are assigned to operating systems and services identified by reading, decoding, and analyzing packets. Network configuration policy is enforced on operating systems and services identified by reading, decoding, and analyzing packets.


