Adaptive Network Intrusion Calibration via Inverse Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for recognizing attempts to penetrate a computer network, such as those in motor vehicles, often result in false positive and false negative reports due to statically defined limits, which are not adaptive to data asymmetries and do not effectively differentiate between normal and penetrative activity.

Innovation Solution

A method that estimates parameters from a data set characterizing message occurrences in a computer network, determines a distribution function, and calibrates limits using an inverse distribution to set adaptive ranges, reducing false negatives and eliminating false positives through data-based calibration and probability-defined sensitivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If statically defined limits are used for recognizing penetration attempts, then the recognition system is simple to implement, but false positive and false negative reports occur due to inability to adapt to data asymmetries

Engineering Contradiction:
Improveaccuracy of penetration attempt detectionVSAvoidcomplexity of limit determination
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameters from static fixed limits to dynamic statistically determined limits. The limits are calculated based on distribution functions (e.g., Gaussian distribution) using parameters like mean and standard deviation derived from actual message occurrence data. This allows the recognition system to adapt to data asymmetries and reduce false positives/negatives while maintaining reasonable complexity through automated statistical calculations.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent performs preliminary statistical analysis and calibration before actual penetration detection. Distribution functions are determined in advance from training data, and limits are pre-calculated based on these distributions. This preliminary action enables the system to be ready for accurate detection without requiring complex real-time adjustments during operation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If narrowly defined limits are used to reduce false negatives, then penetration attempts are detected more accurately, but false positive reports increase

Engineering Contradiction:
Improvedetection accuracy of penetration attemptsVSAvoidfalse positive reports
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent uses statistical distribution parameters (mean, standard deviation) to dynamically adjust limits rather than fixed narrow ranges. By calculating limits as mean ± k×standard deviation (where k is a confidence factor), the system adapts to actual data characteristics, reducing both false negatives and false positives simultaneously through statistically optimized boundaries.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent accounts for asymmetric data distributions in message occurrences by using appropriate distribution functions and calibration procedures. The limit determination adapts to asymmetric patterns in normal versus penetrative activity, allowing different margins for false positives and false negatives based on the specific asymmetries observed in the data.

Inventive Principle:
Principle #4Asymmetry

3Measurement precision

If manual calibration with many test runs is performed to achieve accurate limits, then detection precision improves, but calibration time and effort increase significantly

Engineering Contradiction:
Improveprecision of calibrated limitsVSAvoidcalibration time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements self-service calibration where the system automatically determines distribution functions and calculates limits from its own operational data without requiring extensive manual test runs. The calibration process uses statistical methods that can be executed automatically, reducing human intervention and time investment while achieving high precision through data-driven limit determination.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical calibration processes with automated statistical calculations. Instead of manually adjusting limits based on extensive testing, the system uses computational algorithms to automatically determine distribution parameters and calculate optimal limits, significantly reducing calibration time while maintaining or improving precision.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11206274B2Method and apparatus for calibrating a system for recognizing attempts to penetrate a computer network
Publication Date: 2021.12.21 ROBERT BOSCH GMBH
  • US11206274B2 patent drawing
  • US11206274B2 patent drawing
  • US11206274B2 patent drawing

AI summary

An apparatus and a method for calibrating a system for recognizing attempts to penetrate into a computer network, in particular of a motor vehicle, at least one parameter being estimated on the basis of a data set, the data set encompassing values that characterize a detected occurrence of messages in the computer network; a distribution function being determined on the basis of the at least one parameter; an inverse of the distribution function being determined; and at least one limit for the values being calibrated, on the basis of the inverse, in a rule for rule-based recognition of attempts to penetrate into the computer network.