Wireless Intrusion Detection Verification via Statistical Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection systems in networks face inaccuracies due to false alerts from access points with limited processing capabilities, leading to desensitization of administrators and reduced network security, especially with the upcoming IEEE 802.11ac standard requiring more data processing for accurate detection.

Innovation Solution

A network device correlates network usage information with statistical data to verify anomalous behavior, suppressing unnecessary alerts and enhancing detection accuracy by comparing mean, standard deviation, and other statistical computations over time, thereby reducing false positives and improving network security without increasing processing demands on access points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If access points perform more accurate intrusion detection with increased data processing, then detection accuracy improves, but processing capability requirements increase beyond what cost-constrained APs can provide

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidprocessing capability requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The intrusion detection system is segmented into two parts: the access point performs lightweight real-time monitoring and alert generation, while the centralized controller performs complex statistical analysis and verification. This division allows accurate detection without overloading the AP's processing capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A centralized controller acts as an intermediary between multiple access points and the network administrator. It receives alerts from APs, performs comprehensive statistical analysis using gathered network usage information, and makes final determination about genuine attacks versus false positives, thereby improving detection accuracy without increasing AP processing requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If access points issue alerts for every suspected attack without verification, then response time improves, but false alert rate increases causing administrator desensitization

Engineering Contradiction:
Improvealert response timeVSAvoidalert accuracy
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The centralized controller performs preliminary statistical verification analysis before final alert issuance. It pre-gathers network usage information and computes statistical parameters so that when an AP sends an alert, the verification can quickly determine if it's a genuine attack without requiring lengthy analysis, thus maintaining fast response while improving accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by having the centralized controller analyze alerts against historical network usage patterns and statistical baselines. This feedback mechanism allows the system to learn from past behavior and distinguish genuine attacks from normal anomalies, reducing false alerts while maintaining appropriate response times.

Inventive Principle:
Principle #23Feedback

3Object-generated harmful factors

If access points perform time-out operations to suppress repeated alerts, then alert suppression improves, but network security detection capability decreases during the timeout period

Engineering Contradiction:
Improvealert suppressionVSAvoidsecurity detection capability
Core Design Contradiction:
Object-generated harmful factorsVSReliability

Solution Approach 1:

The centralized controller serves as an intermediary that maintains continuous monitoring and analysis capabilities even when individual alerts are suppressed. It uses statistical analysis to identify sustained attack patterns over time, ensuring that security detection capability is maintained through aggregated analysis rather than individual AP timeout operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9398039B2Apparatus, system and method for suppressing erroneous reporting of attacks on a wireless network
Publication Date: 2016.07.19 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9398039B2 patent drawing
  • US9398039B2 patent drawing
  • US9398039B2 patent drawing

AI summary

According to one embodiment, a method for suppressing erroneous alert messages for suspected network attacks comprises a first operation of determining an intrusion event. This may be conducted at a first network device. Then, the intrusion event is verified prior to transmission of the alert message. The verification may be conducted at a second network device. Thereafter, transmission of the alert message is suppressed in response to verifying that the intrusion event has been erroneously determined.