AI Cyber Defense System Using Behavioral Packet Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for defending against cyber attacks are inefficient, relying on costly CDN solutions and resource-intensive identity authentication, and require significant human effort and equipment to analyze and filter malicious network packets, while also being limited in defense range and prone to high computing resource consumption.

Innovation Solution

An artificial intelligence system that uses a packet filtering unit, identity authentication equipment, and an AI model to quickly identify and filter network packets with attacking behaviors, reducing the need for additional equipment and minimizing computing resource consumption by analyzing behavior characteristic information using characteristic templates and automatic labeling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional identity authentication protocols (TLS) are used to confirm user identity, then security is improved, but computing resource consumption increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements preliminary packet filtering based on behavioral characteristics before identity authentication. The system analyzes packet behavior patterns, source/destination addresses, and traffic characteristics to identify and block malicious packets in advance, preventing them from reaching the identity authentication stage and thus avoiding unnecessary computing resource consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the defense process into two stages: first, behavioral characteristic-based filtering to handle obvious malicious traffic; second, identity authentication for remaining legitimate traffic. This segmentation allows the system to apply different processing strategies to different traffic types, optimizing resource allocation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If CDN is used to mitigate DDoS attacks, then attack damage is reduced, but costs and human resource requirements increase

Engineering Contradiction:
Improveattack mitigationVSAvoidcost and human resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent implements automated behavioral characteristic analysis and packet filtering that operates without human intervention. The system automatically learns normal traffic patterns, identifies anomalies, and blocks malicious packets autonomously, eliminating the need for human analysts to manually analyze attack patterns and formulate rules.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the defense approach from infrastructure-based (CDN) to behavior-based filtering. By monitoring and analyzing traffic behavior parameters such as packet arrival rates, source address distributions, and protocol characteristics, the system can identify DDoS attacks and respond appropriately without requiring additional infrastructure.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If packet conversion to traffic images is performed for malicious traffic detection, then detection accuracy is improved, but operation efficiency decreases

Engineering Contradiction:
Improvedetection accuracyVSAvoidoperation efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts key behavioral characteristics directly from packet data without converting packets to traffic images. The system identifies and extracts relevant features such as source/destination addresses, packet sizes, inter-arrival times, and protocol characteristics, then analyzes these extracted features to detect malicious traffic, avoiding the time-consuming image conversion process.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4207681A1Artificial intelligence system and method thereof for defending against cyber attacks
Publication Date: 2023.07.05 ECOLUX TECH CO LTD
  • EP4207681A1 patent drawingFigure 1
  • EP4207681A1 patent drawingFigure 2
  • EP4207681A1 patent drawingFigure 3

AI summary

The invention relates to an artificial intelligence system and a method thereof for defending against cyber attacks by using an artificial intelligence model to quickly identify and filter network packets with attacking behaviors, and to avoid a large amount of computing resource consumption caused by identity authentication. In order to effectively solve problems of the prior art, a main object of the invention is to provide an artificial intelligence system and a method thereof for defending against cyber attacks by using an artificial intelligence model to quickly identify and filter network packets with attacking behaviors, and to avoid a large amount of computing resource consumption caused by using identity authentication alone.