Reverse Shell Intrusion Detection via Packet Pattern Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional database systems face challenges in securing server systems from unauthorized access over external networks, particularly in detecting reverse shell connections that can compromise security without impeding authorized access.

Innovation Solution

Implementing mechanisms for reverse shell network intrusion detection that monitor packets in secure shell sessions, analyze transmission directions and payload sizes, and identify reverse shell sessions based on predetermined patterns to detect and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If server systems are connected to external networks for convenient remote access, then ease of operation is improved, but security vulnerability increases due to unauthorized access risks

Engineering Contradiction:
Improveremote access convenienceVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a network intrusion detection system as an intermediary component that monitors secure shell sessions between client systems and server systems. This mediator analyzes packet transmission patterns, payload sizes, and transmission directions to detect reverse shell connections, allowing remote access to remain convenient while adding a security layer that identifies and alerts unauthorized access attempts

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security monitoring is implemented to detect reverse shell connections, then security reliability is improved, but system complexity increases due to packet analysis requirements

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidpacket monitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent monitors changes in packet parameters such as payload size, transmission direction, and session state to detect reverse shell connections. By focusing on specific parameter variations rather than analyzing entire packet contents, the system achieves reliable security detection while maintaining manageable complexity through targeted parameter monitoring

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If reverse shell detection mechanisms are deployed, then harmful factors are reduced, but ease of operation deteriorates due to additional security protocols

Engineering Contradiction:
Improveunauthorized accessVSAvoidauthorized access flow
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The detection system operates passively by monitoring packet patterns and providing feedback through alerts when suspicious reverse shell connections are detected. Authorized access flows continue uninterrupted since the system only intervenes when anomaly patterns matching reverse shell behavior are identified, maintaining ease of operation for legitimate users while reducing harmful unauthorized access

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10135847B2Reverse shell network intrusion detection
Publication Date: 2018.11.20 SALESFORCE INC
  • US10135847B2 patent drawing
  • US10135847B2 patent drawing
  • US10135847B2 patent drawing

AI summary

A client system such as a database system may be vulnerable to intrusion by an unauthorized user or system through a reverse secure shell connection that enables the intruder to execute OS-level or shell commands on the client system. A reverse shell connection may be detected by monitoring and inspecting packet data traffic between the client system or internal network, and an exterior or “foreign” network. In one example of such a process, after detecting a normal shell session originating inside the internal network, a reverse shell connection exploiting the initial shell detection is detected by analyzing the transmission directions and payload sizes of a sequence of the monitored packets relative to a predetermined traffic pattern. The specific pattern may be selected for different operating systems.