Network Worm Detection via Anomaly Correlation Engine
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current intrusion detection systems are slow to detect worm attacks, allowing them to spread extensively before identification and mitigation, and are prone to false positives and heavy processing overheads, with signature-based systems operating on known attacks and requiring frequent updates.
Innovation Solution
A real-time network intrusion detection system using an anomaly detection method with a knowledge database and correlation engine that generates a baseline of normal network activity, tracks deviations, and correlates alert events to identify patterns indicative of worm outbreaks, allowing for rapid detection and mitigation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If signature-based detection is used, then detection accuracy for known worms is improved, but detection speed deteriorates due to manual analysis and patch creation time
Solution Approach 1:
The system performs preliminary actions by proactively scanning network traffic for worm propagation patterns before widespread infection occurs. The correlation engine continuously monitors and correlates alert events in real-time, enabling early detection of worm outbreaks without waiting for manual signature analysis. This preliminary monitoring and correlation of network behavior allows the system to detect worms in their early propagation stages, significantly reducing detection time while maintaining accuracy.
2Measurement precision
If signature-based detection is used, then detection capability for known attacks is improved, but system adaptability deteriorates due to requirement for frequent signature updates
Solution Approach 1:
The system implements dynamics by transitioning from static signature databases to dynamic behavioral analysis. The correlation engine continuously adapts to new worm types by monitoring network traffic patterns and correlating alert events in real-time. This dynamic approach allows the system to automatically detect and respond to novel worm variants without requiring manual signature updates, thereby maintaining high detection capability while significantly improving system adaptability to emerging threats.
3Speed
If anomaly detection with baseline tracking is used, then detection speed is improved, but processing overhead increases
Solution Approach 1:
The system applies segmentation by dividing the network monitoring function into distributed network nodes that each perform local anomaly detection and baseline tracking. This segmentation distributes the processing overhead across multiple nodes rather than concentrating it in a single centralized system, thereby maintaining fast detection speed while reducing the processing burden on any single node. Each node independently monitors its local network segment and correlates alerts with the central correlation engine.
Data Source
AI summary
An intrusion detection system for a computer network includes a knowledge database that contains a baseline of normal host behavior, and a correlation engine that monitors network activity with reference to the knowledge database. The correlation engine accumulating information about anomalous events occurring on the network and then periodically correlating the anomalous events. The correlation engine generates a worm outbreak alarm when a certain number of hosts exhibit a role-reversal behavior. It is emphasized that this abstract is provided to comply with the rules requiring an abstract that will allow a searcher or other reader to quickly ascertain the subject matter of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. 37 CFR 1.72(b).


