Web Application Security via Behavioral Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for Web applications are inadequate in protecting against targeted attacks, as traditional network security solutions are ineffective in addressing the unique vulnerabilities of Web applications, and existing application firewalls rely on list-based models that fail to provide comprehensive protection.

Innovation Solution

A method and system that adapt to changed conditions by analyzing network communication using a profile of acceptable behavior, developed from historical data, to validate current network communications and trigger responsive actions based on probability values, incorporating a dynamic profiling module, correlation and analysis module, and adaptive measures to enhance Web application security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security solutions are used, then network protection is provided, but Web application-specific vulnerabilities are not addressed

Engineering Contradiction:
ImproveWeb application securityVSAvoidAbility to address Web application vulnerabilities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments security protection into two distinct layers: traditional network security (firewalls, intrusion detection) and application-specific security (behavioral analysis, profiling). This segmentation allows each layer to address its specific vulnerabilities without compromising the other, thereby improving Web application security while maintaining network protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary component between the network and the Web application - a behavioral analysis system that monitors and analyzes communication patterns. This intermediary provides application-specific protection without replacing traditional network security, resolving the contradiction between network protection and application vulnerability addressing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If list-based application firewalls are used, then some security coverage is achieved, but comprehensive protection is not provided

Engineering Contradiction:
ImproveSecurity coverageVSAvoidSecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transitions from static list-based security rules to dynamic behavioral parameters. By monitoring communication patterns, data flow characteristics, and interaction sequences, the system adapts security criteria based on observed behavior rather than fixed rules, achieving comprehensive protection without proportionally increasing complexity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The behavioral analysis system automatically learns and adapts to legitimate application patterns, reducing the need for manual rule configuration. The system self-adjusts to changing application behaviors while maintaining security, thereby achieving comprehensive coverage without linearly increasing operational complexity.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If behavioral analysis with probability values is implemented, then detection accuracy is improved, but computational requirements increase

Engineering Contradiction:
ImproveAnomaly detection accuracyVSAvoidComputational resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies behavioral analysis selectively to specific communication patterns and data flows rather than uniformly to all traffic. By focusing computational resources on high-risk or abnormal patterns identified through profiling, the system achieves high detection accuracy without requiring excessive computational resources for every packet analysis.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary behavioral profiling during normal operation to establish baseline patterns. This preliminary action creates a reference framework that enables faster, more accurate anomaly detection without requiring intensive real-time computation for every decision, thereby improving detection accuracy while managing computational requirements.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8180886B2Method and apparatus for detection of information transmission abnormalities
Publication Date: 2012.05.15 TRUSTWAVE HOLDINGS INC
  • US8180886B2 patent drawing
  • US8180886B2 patent drawing
  • US8180886B2 patent drawing

AI summary

In one embodiment, a method for securing a network application is described. The method for securing a network application includes receiving network information within a network application and assigning a probability value to an independent aspect of the network information. The probability value is based on a verification of the independent aspect of the information against a profile of acceptable behavior. The method for securing a network application also includes aggregating the probability values of the independent aspects of the network information to determine the probability of the entire network traffic. In addition, the method for securing a network application includes determining whether the probability value of the entire network information is above or below a threshold probability value. The entire network information is screened out based on the probability value of the entire message with respect to the threshold probability value.