Passive Network Endpoint Discovery for Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional intrusion detection systems (IDSs) are ineffective due to the lack of contextual information about network end points, making them susceptible to attacks and generating false positives, and existing methods for providing this information are either manual, time-consuming, or destructive to the network.

Innovation Solution

A system and method for automatically and passively determining network characteristics by reading packets, identifying network devices, operating systems, and services using packet detectors, decoders, and protocol analyzers, and reporting this information to IDSs or network management systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual auditing is used to gather contextual information about network hosts, then information accuracy is improved, but time consumption and operational complexity increase

Engineering Contradiction:
Improvecontextual information accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables hosts to self-report their contextual information (operating system, services, applications) automatically to the IDS through intercepted communication packets, eliminating the need for manual auditing while maintaining high accuracy of the collected information

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical auditing processes with automated electronic packet interception and analysis systems, using software-based detection to gather contextual information without human intervention, thereby reducing time consumption while maintaining information accuracy

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Extent of automation

If active scanning systems are used to discover network vulnerabilities, then automated information gathering is improved, but network stability deteriorates due to destructive testing

Engineering Contradiction:
Improveautomated discoveryVSAvoidnetwork stability
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The system uses an intermediary approach by intercepting and analyzing existing communication packets between hosts and network services, rather than directly probing hosts. This passive observation method automates information gathering without injecting disruptive test traffic that could destabilize network operations

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a virtual model of network hosts by analyzing copied packets from network traffic, building contextual information about operating systems and services without directly interacting with or testing the actual hosts, thereby avoiding network disruption while maintaining automated discovery capabilities

Inventive Principle:
Principle #26Copying

3Extent of automation

If active scanning is performed to detect vulnerabilities, then automated detection capability is improved, but information completeness worsens due to transient service availability

Engineering Contradiction:
Improvevulnerability detectionVSAvoidinformation completeness
Core Design Contradiction:
Extent of automationVSLoss of information

Solution Approach 1:

The system continuously intercepts and analyzes network packets over extended periods, maintaining persistent observation of host services and applications. This continuous passive monitoring ensures that transient services are detected when they become active, providing complete vulnerability information without the timing constraints of periodic active scanning

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs preliminary packet interception and analysis to build comprehensive contextual profiles of hosts before security incidents occur. By continuously gathering information about services and applications in advance, the system ensures complete vulnerability detection even for transiently available services, eliminating the need for repeated scanning attempts

Inventive Principle:
Principle #10Preliminary action

4Device complexity

If IDS operates without contextual information about end points, then system simplicity is maintained, but detection effectiveness deteriorates due to evasion susceptibility

Engineering Contradiction:
Improvesystem simplicityVSAvoiddetection effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system performs preliminary packet interception and analysis to automatically build contextual profiles of network hosts, including operating system types, running services, and applications. This pre-gathered contextual information is stored and used by the IDS to improve detection effectiveness without requiring complex manual configuration or increasing operational complexity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables hosts to effectively self-identify their characteristics through their own communication packets, which are automatically analyzed and used to build contextual profiles. This self-reporting mechanism provides comprehensive detection capabilities without requiring the IDS to actively probe or complexity the system architecture

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7949732B1Systems and methods for determining characteristics of a network and enforcing policy
Publication Date: 2011.05.24 CISCO TECHNOLOGY INC
  • US7949732B1 patent drawing
  • US7949732B1 patent drawing
  • US7949732B1 patent drawing

AI summary

A packet transmitted on a network is read and decoded. A network device and its operating system are identified by analyzing the decoded packet. If more than one operating system is identified from the decoded packet, the operating system is selecting by comparing confidence values assigned to the operating systems identified. A service running on the network device is identified from the decoded packet or subsequent packets that are read, decoded and analyzed. The network topology of a network is determined by reading, decoding, and analyzing a plurality of packets. A flow between two network devices is determined by reading, decoding, and analyzing a plurality of packets. Vulnerabilities are assigned to operating systems and services identified by reading, decoding, and analyzing packets. Network configuration policy is enforced on operating systems and services identified by reading, decoding, and analyzing packets.