WO0245380A2

Flow-based detection of network intrusions

Abstract

A flow-based intrusion detection system for detecting intrusions in computer communication networks. Data packets representing communications between hosts in a computer-to-computer communication network are processed and assigned to various client/server flows. Statistics are collected for each flow. Then, the flow statistics are analyzed to determine if the flow appears to be legitimate traffic or possible suspicious activity. A concern index value is assigned to each flow that appears suspicious. By assigning a value to each flow that appears suspicious and adding that value to the total concern index of the responsible host, it is possible to identify hosts that are engaged in intrusion activity. When the concern index value of a host exceeds a preset alarm value, an alert is issued and appropriate action can be taken.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

11 claims: 6 independent, 5 dependent

  1. 1
    CLAIMS What is claimed is:1. A method of analyzing network communication traffic for potential intrusion activity, comprising the steps of: assigning packets to a flow;collecting flow data from packet headers;analyzing collected flow data to assign a concern index value to the flow based upon a probability that the flow was not normal for data communications;maintaining an accumulated concern index from flows associated with a host;and issuing an alarm signal once the accumulated concern index has exceeded an alarm threshold value.
  2. 6
    A method of analyzing network communication traffic for potential intrusion activity, comprising the steps of:assigning packets to a flow wherein a flow consists of the packets exchanged between two hosts that are associated with a single service;collecting flow data from packet headers;analyzing collected flow data to assign a concern index value wherein each concern index value associated with a respective potential intrusion activity is a predetermined fixed value;maintaining an accumulated concern index from flows associated with a host;and issuing an alarm signal once the accumulated concern index has exceeded an alarm threshold value.
  3. 7
    8. A method of analyzing network communication traffic for potential intrusion activity, comprising the steps of:assigning packets to a flow wherein a flow consists of the packets exchanged between two Internet Protocol addresses with at least one port remains constant;collecting flow data from packet headers;analyzing collected flow data to assign a concern index value tp the flow;maintaining a host structure containing an accumulated concern index from flows associated with the host;and issuing an alarm once the accumulated concern index has exceeded an alarm threshold value.
  4. 9
    10. A system for analyzing network communication traffic, comprising:a computer system operable to classify packets into flows, collect flow data from packet header information, analyze collected flow data to assign a concern index value wherein each concern index value associated with a respective potential intrusion activity is a predetermined fixed value, and generate an alarm signal;and a communication system coupled to the computer system operable to send packets from one host to another host.
  5. 10
    11. A system for analyzing network communication traffic, comprising:a processor operable to classify packets into flows, collect flow data from packet header information, analyze collected flow data to assign a concern index value wherein each concern index value associated with a respective potential intrusion activity is a predetermined fixed value, and generate an alarm signal;memory coupled to the processor operable to store the flow data;a database coupled to processor operable to store log files;and and a network interface coupled to the processor operable to monitor network traffic.
  6. 11
    12. A method of analyzing network communication traffic for potential intrusion activity, comprising the steps of:analyzing packet header information;determining a transport level protocol specifying a format of a data area ;issuing an alarm when the transport level protocol is identified as User Datagram Protocol and the data segment associated with User Datagram Protocol packet contains two or less bytes of data.