Network Worm Detection via Anomaly Correlation Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection systems are slow to detect worm attacks, allowing them to spread extensively before identification and mitigation, and are prone to false positives and heavy processing overheads, with signature-based systems operating on known attacks and requiring frequent updates.

Innovation Solution

A real-time network intrusion detection system using an anomaly detection method with a knowledge database and correlation engine that generates a baseline of normal network activity, tracks deviations, and correlates alert events to identify patterns indicative of worm outbreaks, allowing for rapid detection and mitigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If signature-based detection is used, then detection accuracy for known worms is improved, but detection speed deteriorates due to manual analysis and patch creation time

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by proactively scanning network traffic for worm propagation patterns before widespread infection occurs. The correlation engine continuously monitors and correlates alert events in real-time, enabling early detection of worm outbreaks without waiting for manual signature analysis. This preliminary monitoring and correlation of network behavior allows the system to detect worms in their early propagation stages, significantly reducing detection time while maintaining accuracy.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If signature-based detection is used, then detection capability for known attacks is improved, but system adaptability deteriorates due to requirement for frequent signature updates

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem adaptability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system implements dynamics by transitioning from static signature databases to dynamic behavioral analysis. The correlation engine continuously adapts to new worm types by monitoring network traffic patterns and correlating alert events in real-time. This dynamic approach allows the system to automatically detect and respond to novel worm variants without requiring manual signature updates, thereby maintaining high detection capability while significantly improving system adaptability to emerging threats.

Inventive Principle:
Principle #15Dynamics

3Speed

If anomaly detection with baseline tracking is used, then detection speed is improved, but processing overhead increases

Engineering Contradiction:
Improvedetection speedVSAvoidprocessing overhead
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system applies segmentation by dividing the network monitoring function into distributed network nodes that each perform local anomaly detection and baseline tracking. This segmentation distributes the processing overhead across multiple nodes rather than concentrating it in a single centralized system, thereby maintaining fast detection speed while reducing the processing burden on any single node. Each node independently monitors its local network segment and correlates alerts with the central correlation engine.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8161554B2System and method for detection and mitigation of network worms
Publication Date: 2012.04.17 CISCO TECHNOLOGY INC
  • US8161554B2 patent drawing
  • US8161554B2 patent drawing
  • US8161554B2 patent drawing

AI summary

An intrusion detection system for a computer network includes a knowledge database that contains a baseline of normal host behavior, and a correlation engine that monitors network activity with reference to the knowledge database. The correlation engine accumulating information about anomalous events occurring on the network and then periodically correlating the anomalous events. The correlation engine generates a worm outbreak alarm when a certain number of hosts exhibit a role-reversal behavior. It is emphasized that this abstract is provided to comply with the rules requiring an abstract that will allow a searcher or other reader to quickly ascertain the subject matter of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. 37 CFR 1.72(b).