Private-learned IDS for Isolated Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Isolated networks, such as those in government and critical infrastructure, face challenges in maintaining effective intrusion detection systems (IDS) due to the need for constant updates and external synchronization, which they cannot easily implement without specialized teams and external connections.

Innovation Solution

A machine learning-based IDS that operates independently within a private network, allowing administrators to adjust and improve detection capabilities without external updates, by learning from single examples of threats and adjusting detector parameters to minimize false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional IDS require constant updates and external synchronization to maintain detection efficacy, then detection accuracy is improved, but isolated networks cannot implement these updates without external connections and specialized teams

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to receive updates
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The IDS enables isolated networks to perform self-updates by autonomously generating security updates from internally detected threats. The system allows any user to submit threat samples, automatically trains detection models on these samples, and deploys updates without requiring external threat intelligence feeds or specialized security teams, thus resolving the contradiction between maintaining detection accuracy and operating in isolated networks.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If isolated networks employ in-house security teams to create security updates internally, then update capability is improved, but system complexity and resource requirements increase significantly

Engineering Contradiction:
Improveupdate capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system automates the entire update creation process, allowing any user to contribute threat samples without requiring specialized security expertise. The automated model training and update deployment mechanisms eliminate the need for complex in-house security teams, reducing system complexity while maintaining update capability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback loops where detection results and threat samples are continuously fed back into the model training process. This automated feedback mechanism replaces manual security analysis processes, reducing the complexity associated with human expert involvement while maintaining effective update generation.

Inventive Principle:
Principle #23Feedback

3Reliability

If traditional IDS rely on external threat intelligence feeds, then threat detection coverage is improved, but networks that cannot connect externally cannot leverage these intelligence sources

Engineering Contradiction:
Improvethreat detection coverageVSAvoidexternal connectivity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system generates its own threat intelligence internally by learning from threat samples submitted by any user within the network. This self-generated intelligence replaces external threat feeds, enabling isolated networks to maintain comprehensive threat detection coverage without requiring external connectivity to threat intelligence sources.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the source of threat intelligence from external feeds to internal user-submitted samples. By transforming the intelligence generation process from externally-dependent to internally-generated, the system maintains reliable threat detection coverage while adapting to networks with restricted external connectivity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10708284B2Private-learned IDS
Publication Date: 2020.07.07 CISCO TECHNOLOGY INC
  • US10708284B2 patent drawing
  • US10708284B2 patent drawing
  • US10708284B2 patent drawing

AI summary

In one embodiment, a device in a network maintains a plurality of machine learning-based detectors for an intrusion detection system. Each detector is associated with a different portion of a feature space of traffic characteristics assessed by the intrusion detection system. The device provides data regarding the plurality of detectors to a user interface. The device receives an adjustment instruction from the user interface based on the data provided to the user interface regarding the plurality of detectors. The device adjusts the portions of the feature space associated with the plurality of detectors based on the adjustment instruction received from the user interface.