Passive Network Map Modification for Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional intrusion detection systems (IDSs) are ineffective due to the lack of contextual information about network end points, making them susceptible to attacks like evasion and generating false positives, and existing methods for providing this information are either manual, time-consuming, or destructive to the network.
Innovation Solution
A system and method for automatically and passively determining network characteristics by analyzing packets to identify network devices, recording their information, and providing a graphical user interface for users to modify vulnerability parameters, ensuring up-to-date and non-destructive contextual data for IDSs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual auditing is used to gather contextual information about network hosts, then information accuracy is improved, but time consumption and operational complexity increase
Solution Approach 1:
The system enables hosts to self-report their contextual information (services, vulnerabilities, configurations) automatically to the intrusion detection system, eliminating the need for manual auditing while maintaining information accuracy. Hosts periodically push their own configuration data, making the information gathering process autonomous and time-efficient.
Solution Approach 2:
An intermediary component is introduced between the hosts and the IDS that automatically collects, validates, and manages contextual information from multiple hosts. This intermediary layer handles the complexity of information gathering and presentation, reducing both time consumption and operational burden while ensuring data accuracy through systematic collection processes.
2Loss of information
If active scanning is used to discover network vulnerabilities, then contextual information is obtained, but network stability deteriorates due to destructive testing
Solution Approach 1:
Instead of the IDS actively scanning hosts to discover vulnerabilities (which can be destructive), the approach is inverted: hosts actively report their own vulnerability information to the IDS. This passive discovery method eliminates the destabilizing effect of active scanning while still obtaining comprehensive vulnerability data across the network.
Solution Approach 2:
Hosts autonomously generate and report their own vulnerability assessments, service configurations, and system information without requiring external probing. This self-reporting mechanism provides the IDS with accurate contextual information while completely avoiding the network instability caused by active scanning operations.
3Measurement precision
If active scanning is performed to update network maps, then information currency is improved, but network performance deteriorates
Solution Approach 1:
Hosts perform periodic self-assessments and report their configuration changes at scheduled intervals rather than continuously. This periodic reporting maintains network map accuracy by capturing changes when they occur, while avoiding the continuous network traffic and performance degradation associated with constant active scanning or monitoring.
Solution Approach 2:
Hosts autonomously monitor their own configuration changes and trigger reports only when changes are detected, rather than responding to external scanning requests. This event-driven approach ensures network maps remain accurate and current while minimizing network traffic and performance impact, as reports are generated only when necessary.
4Measurement precision
If contextual information is collected from multiple sources, then detection accuracy is improved, but system complexity increases
Solution Approach 1:
The system employs a universal data collection interface and standardized information format that can accommodate multiple information sources (host self-reports, external databases, configuration files) through a single unified mechanism. This multi-functional approach allows the IDS to integrate diverse contextual information without proportionally increasing system complexity, as the same infrastructure handles all data sources.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The disclosed systems and methods provide a user interface for modifying host configuration data that has been automatically and passively determined and for adding or modifying other parameters associated with a host. A host data table can store various parameters descriptive of a host including the applicability of specific vulnerabilities. If it is determined that one or more hosts should not be identified as associated with a specific vulnerability, a graphical user interface can be used to modify the vulnerability parameter.