Passive Network Map Modification for Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional intrusion detection systems (IDSs) are ineffective due to the lack of contextual information about network end points, making them susceptible to attacks like evasion and generating false positives, and existing methods for providing this information are either manual, time-consuming, or destructive to the network.

Innovation Solution

A system and method for automatically and passively determining network characteristics by analyzing packets to identify network devices, recording their information, and providing a graphical user interface for users to modify vulnerability parameters, ensuring up-to-date and non-destructive contextual data for IDSs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual auditing is used to gather contextual information about network hosts, then information accuracy is improved, but time consumption and operational complexity increase

Engineering Contradiction:
Improvecontextual information accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables hosts to self-report their contextual information (services, vulnerabilities, configurations) automatically to the intrusion detection system, eliminating the need for manual auditing while maintaining information accuracy. Hosts periodically push their own configuration data, making the information gathering process autonomous and time-efficient.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

An intermediary component is introduced between the hosts and the IDS that automatically collects, validates, and manages contextual information from multiple hosts. This intermediary layer handles the complexity of information gathering and presentation, reducing both time consumption and operational burden while ensuring data accuracy through systematic collection processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If active scanning is used to discover network vulnerabilities, then contextual information is obtained, but network stability deteriorates due to destructive testing

Engineering Contradiction:
Improvevulnerability informationVSAvoidnetwork stability
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

Instead of the IDS actively scanning hosts to discover vulnerabilities (which can be destructive), the approach is inverted: hosts actively report their own vulnerability information to the IDS. This passive discovery method eliminates the destabilizing effect of active scanning while still obtaining comprehensive vulnerability data across the network.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

Hosts autonomously generate and report their own vulnerability assessments, service configurations, and system information without requiring external probing. This self-reporting mechanism provides the IDS with accurate contextual information while completely avoiding the network instability caused by active scanning operations.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If active scanning is performed to update network maps, then information currency is improved, but network performance deteriorates

Engineering Contradiction:
Improvenetwork map accuracyVSAvoidnetwork performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

Hosts perform periodic self-assessments and report their configuration changes at scheduled intervals rather than continuously. This periodic reporting maintains network map accuracy by capturing changes when they occur, while avoiding the continuous network traffic and performance degradation associated with constant active scanning or monitoring.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

Hosts autonomously monitor their own configuration changes and trigger reports only when changes are detected, rather than responding to external scanning requests. This event-driven approach ensures network maps remain accurate and current while minimizing network traffic and performance impact, as reports are generated only when necessary.

Inventive Principle:
Principle #25Self-service

4Measurement precision

If contextual information is collected from multiple sources, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system employs a universal data collection interface and standardized information format that can accommodate multiple information sources (host self-reports, external databases, configuration files) through a single unified mechanism. This multi-functional approach allows the IDS to integrate diverse contextual information without proportionally increasing system complexity, as the same infrastructure handles all data sources.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP1949242B1Systems and methods for modifying network map attributes
Publication Date: 2020.04.08 CISCO TECHNOLOGY INC
  • EP1949242B1 patent drawingFigure 1
  • EP1949242B1 patent drawingFigure 2
  • EP1949242B1 patent drawingFigure 3

AI summary

The disclosed systems and methods provide a user interface for modifying host configuration data that has been automatically and passively determined and for adding or modifying other parameters associated with a host. A host data table can store various parameters descriptive of a host including the applicability of specific vulnerabilities. If it is determined that one or more hosts should not be identified as associated with a specific vulnerability, a graphical user interface can be used to modify the vulnerability parameter.