Split-Flow Attack Detection Across Incompatible Protocols

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively identify and analyze split-flow communications sessions occurring over two incompatible communication protocols, which can lead to undetected malicious activity as these data streams are typically analyzed separately.

Innovation Solution

A method and system that monitor and correlate data streams using different communication protocols to determine if they share a common target endpoint, allowing for the identification of split-flow communications sessions and subsequent analysis for malicious content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data streams using different communication protocols are analyzed separately, then the analysis process is simple and straightforward, but malicious activity in split-flow communications goes undetected

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the analysis process by protocol type while maintaining correlation between different protocol streams. Each protocol stream is monitored independently using protocol-specific monitoring components, but the correlation component links them by target endpoint to detect split-flow attacks that span multiple protocols.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A correlation component acts as an intermediary between separate protocol monitoring components. This intermediary correlates data streams from different protocols by matching target endpoints, enabling detection of split-flow communications without requiring a single complex multi-protocol parser.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate monitoring systems are used for different communication protocols, then each system remains simple and specialized, but split-flow communications terminating at the same device are not correlated

Engineering Contradiction:
Improvesession correlation accuracyVSAvoidcorrelation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The correlation component performs a universal function across multiple protocol types by correlating data streams based on target endpoint matching. Rather than creating specialized correlation logic for each protocol combination, a single multi-functional correlation mechanism handles all protocol pairs, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8381301B1Split-flow attack detection
Publication Date: 2013.02.19 T MOBILE INNOVATIONS LLC
  • US8381301B1 patent drawing
  • US8381301B1 patent drawing
  • US8381301B1 patent drawing

AI summary

A system, method, and computer-readable media are described for identifying a split-flow communications session occurring over two or more incompatible communications protocols. A data stream governed by a first communications protocol is associated with a device or end device by comparing information in the data packet headers with information in a device database that matches devices with the header characteristics such as an IP address. A second data stream governed by a second incompatible communications protocol is similarly associated with the same target endpoint or device. The two incompatible data streams may then be evaluated as a single split-flow communications session for malicious content, or for other purposes. If malicious content is detected, corrective policies may be implemented on the split-flow communications session to protect the device from the malicious content.