Passive Network Traffic Analysis for Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network monitoring techniques involve active scanning, which increases network traffic, disrupts device operations, and can trigger false alerts, failing to effectively detect anomalous activity without causing congestion or impacting sensitive devices.

Innovation Solution

A method and system using passive network data collection to analyze pre-existing traffic data, assign identification labels based on metadata, and detect deviations from expected behavioral parameters to classify and alert on anomalous activity, thereby reducing network congestion and minimizing disruption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If active scanning techniques are used to gather network device behavior data, then network device activity can be detected, but network traffic increases and device operation is disrupted

Engineering Contradiction:
Improvenetwork device activity detectionVSAvoidnetwork traffic congestion
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

Instead of actively scanning network devices to gather behavior data (traditional approach), the patent inverts the approach by passively collecting data from network traffic flows. The system analyzes existing traffic patterns to infer device behavior and classify devices, eliminating the need for active scanning while maintaining detection capability.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The network devices themselves generate the data needed for analysis through their normal operational traffic. Rather than requiring external scanning tools to probe devices, the system uses the devices' own traffic patterns as the data source, allowing devices to essentially scan themselves through their natural communication behavior.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If active scanning tools are used to analyze network devices, then device behavior data can be collected, but device operation is adversely affected

Engineering Contradiction:
Improvedevice behavior data collectionVSAvoiddevice operation
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent reverses the traditional active scanning paradigm by passively observing network traffic. Instead of sending probe packets that disrupt device operation, the system analyzes existing traffic flows to collect behavior data, ensuring device operations are not adversely affected while still achieving comprehensive device characterization.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system introduces network traffic flow data as an intermediary medium to indirectly observe device behavior. Rather than directly interacting with devices through scanning tools (which causes disruption), the traffic flow serves as a mediator that carries information about device behavior without requiring direct probing of the devices themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-generated harmful factors

If existing network traffic data is analyzed passively, then network congestion is reduced, but detection accuracy may be compromised

Engineering Contradiction:
Improvenetwork congestionVSAvoidanomalous activity detection
Core Design Contradiction:
Object-generated harmful factorsVSMeasurement precision

Solution Approach 1:

The system performs preliminary device classification and behavioral parameter establishment by analyzing normal traffic patterns before detecting anomalies. By pre-characterizing devices through passive traffic analysis, the system builds baseline profiles that enable accurate anomaly detection when traffic patterns deviate from expected behavior, maintaining detection precision without congestion.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors traffic patterns and uses feedback from observed behavior to refine device classifications and expected behavioral parameters. This iterative feedback mechanism allows the system to adapt to changing network conditions and improve detection accuracy over time while maintaining passive, non-intrusive data collection.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11606377B1Device classification for identifying anomolous activity
Publication Date: 2023.03.14 RAPID7 INC
  • US11606377B1 patent drawing
  • US11606377B1 patent drawing
  • US11606377B1 patent drawing

AI summary

Methods and systems for detecting anomalous network device activity. The system may include an interface for receiving an identification label associated with a host device and pre-existing traffic data associated with the host device. The system may further detect that the pre-existing traffic data associated with the host device is anomalous based on the identification label. The system may then issue an alert upon detecting that the pre-existing traffic data associated with the host device is anomalous.